[
 {
  "cve": "CVE-2026-68082",
  "published": "2026-08-08",
  "subsystem": "libceph",
  "title": "libceph: fix two unsafe bare decodes in decode_lockers()",
  "introduced_in": [
   "4.9"
  ],
  "fixed_in": [
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-68081",
  "published": "2026-08-08",
  "subsystem": "KVM",
  "title": "KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state",
  "introduced_in": [
   "5.2"
  ],
  "fixed_in": [
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-68480",
  "published": "2026-08-06",
  "subsystem": "x86/bugs",
  "title": "x86/bugs: Make Safe-RET robust against interrupt injection",
  "introduced_in": [],
  "fixed_in": [
   "5.10.263",
   "5.15.214",
   "6.1.181",
   "6.6.149",
   "6.18.43",
   "7.1.7"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64604",
  "published": "2026-08-06",
  "subsystem": "KVM",
  "title": "KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode",
  "introduced_in": [],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64603",
  "published": "2026-08-06",
  "subsystem": "platform/x86",
  "title": "platform/x86: intel-hid: Protect ACPI notify handler against recursion",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64602",
  "published": "2026-08-06",
  "subsystem": "iio",
  "title": "iio: adc: spear: Initialize completion before requesting IRQ",
  "introduced_in": [
   "3.16"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64601",
  "published": "2026-08-06",
  "subsystem": "ALSA",
  "title": "ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64599",
  "published": "2026-08-06",
  "subsystem": "crypto",
  "title": "crypto: amlogic - avoid double cleanup in meson_crypto_probe()",
  "introduced_in": [
   "5.5"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64598",
  "published": "2026-08-06",
  "subsystem": "smb/client",
  "title": "smb/client: Fix error code in smb2_aead_req_alloc()",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64597",
  "published": "2026-08-06",
  "subsystem": "smb",
  "title": "smb: client: fix double-free in SMB2_close() replay",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64596",
  "published": "2026-08-06",
  "subsystem": "libfs",
  "title": "libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()",
  "introduced_in": [
   "6.15.6",
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64595",
  "published": "2026-08-06",
  "subsystem": "HID",
  "title": "HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64594",
  "published": "2026-08-06",
  "subsystem": "usb",
  "title": "usb: gadget: f_fs: initialize reset_work at allocation time",
  "introduced_in": [
   "4.0"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64593",
  "published": "2026-08-06",
  "subsystem": "btrfs",
  "title": "btrfs: do not trim a device which is not writeable",
  "introduced_in": [
   "4.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64592",
  "published": "2026-08-06",
  "subsystem": "riscv",
  "title": "riscv: mm: Unconditionally sfence.vma for spurious fault",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64591",
  "published": "2026-08-06",
  "subsystem": "iommu/vt-d",
  "title": "iommu/vt-d: Avoid WARNING in sva unbind path",
  "introduced_in": [
   "6.18.20",
   "6.19.10",
   "7.0"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64590",
  "published": "2026-08-06",
  "subsystem": "dma-buf/udmabuf",
  "title": "dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64589",
  "published": "2026-08-06",
  "subsystem": "i2c",
  "title": "i2c: core: fix NULL-deref on adapter registration failure",
  "introduced_in": [
   "6.12.11",
   "6.13"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64588",
  "published": "2026-08-06",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: fix data races on ring->ready",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64587",
  "published": "2026-08-06",
  "subsystem": "net",
  "title": "net: ethernet: arc: emac: quiesce interrupts before requesting IRQ",
  "introduced_in": [
   "3.11"
  ],
  "fixed_in": [
   "5.10.253",
   "5.15.203",
   "6.1.167",
   "6.6.130",
   "6.12.78",
   "6.18.19",
   "6.19.9",
   "7.0"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64586",
  "published": "2026-08-06",
  "subsystem": "wifi",
  "title": "wifi: brcmfmac: drain bus_reset work on device removal",
  "introduced_in": [
   "5.2"
  ],
  "fixed_in": [
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64585",
  "published": "2026-08-06",
  "subsystem": "can",
  "title": "can: esd_usb: kill anchored URBs before freeing netdevs",
  "introduced_in": [
   "2.6.36"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64584",
  "published": "2026-08-06",
  "subsystem": "usb",
  "title": "usb: gadget: f_midi: cancel pending IN work before freeing the midi object",
  "introduced_in": [
   "5.4.291",
   "5.10.235",
   "5.12"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64583",
  "published": "2026-08-06",
  "subsystem": "usb",
  "title": "usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown",
  "introduced_in": [
   "3.19"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64582",
  "published": "2026-08-05",
  "subsystem": "RDMA/rxe",
  "title": "RDMA/rxe: Fix a use-after-free problem in rxe_mmap",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64581",
  "published": "2026-08-05",
  "subsystem": "xfrm",
  "title": "xfrm: fix sk_dst_cache double-free in xfrm_user_policy()",
  "introduced_in": [
   "3.16.52",
   "3.18.101",
   "4.1.52",
   "4.4.123",
   "4.4.163",
   "4.9.89",
   "4.14"
  ],
  "fixed_in": [
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64580",
  "published": "2026-08-05",
  "subsystem": "xfrm6",
  "title": "xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()",
  "introduced_in": [
   "3.0.79",
   "3.2.46",
   "3.4.46",
   "3.9.3",
   "3.10"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64579",
  "published": "2026-08-05",
  "subsystem": "xfrm",
  "title": "xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert",
  "introduced_in": [
   "5.0"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64578",
  "published": "2026-08-05",
  "subsystem": "ksmbd",
  "title": "ksmbd: validate compound request size before reading StructureSize2",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64577",
  "published": "2026-08-05",
  "subsystem": "gtp",
  "title": "gtp: check skb_pull_data() return in gtp1u_send_echo_resp()",
  "introduced_in": [
   "5.18"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64576",
  "published": "2026-08-05",
  "subsystem": "nexthop",
  "title": "nexthop: initialize extack in nh_res_bucket_migrate()",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64575",
  "published": "2026-08-05",
  "subsystem": "bpf",
  "title": "bpf: tcp: fix double sock release on batch realloc",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64574",
  "published": "2026-08-05",
  "subsystem": "wifi",
  "title": "wifi: mac80211: tear down new links on vif update error path",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64573",
  "published": "2026-08-05",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: qca: fix NVM tag length underflow in TLV parser",
  "introduced_in": [
   "5.15.159",
   "6.1.91",
   "6.6.31",
   "6.8.10",
   "6.9"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64572",
  "published": "2026-08-05",
  "subsystem": "ipv4",
  "title": "ipv4: fib: free fib_alias with kfree_rcu() on insert error path",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64571",
  "published": "2026-08-05",
  "subsystem": "wifi",
  "title": "wifi: p54: validate RX frame length in p54_rx_eeprom_readback()",
  "introduced_in": [
   "2.6.28"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64570",
  "published": "2026-08-05",
  "subsystem": "wifi",
  "title": "wifi: mac80211: fix fils_discovery double free on alloc failure",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64569",
  "published": "2026-08-05",
  "subsystem": "mpls",
  "title": "mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64568",
  "published": "2026-08-05",
  "subsystem": "wifi",
  "title": "wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64567",
  "published": "2026-08-05",
  "subsystem": "btrfs",
  "title": "btrfs: reject free space cache with more entries than pages",
  "introduced_in": [
   "3.2"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64566",
  "published": "2026-08-05",
  "subsystem": "xfrm",
  "title": "xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64565",
  "published": "2026-08-04",
  "subsystem": "Input",
  "title": "Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()",
  "introduced_in": [
   "3.10"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64564",
  "published": "2026-08-04",
  "subsystem": "sctp",
  "title": "sctp: don't free the ASCONF's own transport in DEL-IP processing",
  "introduced_in": [
   "2.6.25"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64563",
  "published": "2026-08-04",
  "subsystem": "rhashtable",
  "title": "rhashtable: clear stale iter->p on table restart",
  "introduced_in": [
   "4.18"
  ],
  "fixed_in": [
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64562",
  "published": "2026-08-04",
  "subsystem": "KVM",
  "title": "KVM: nVMX: Hide shadow VMCS right after VMCLEAR",
  "introduced_in": [
   "4.9"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64561",
  "published": "2026-08-04",
  "subsystem": "KVM",
  "title": "KVM: x86: Check for invalid/obsolete root *after* making MMU pages available",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "6.6.148",
   "6.12.101",
   "6.18.42",
   "7.1.6",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2022-4994",
  "published": "2026-07-30",
  "subsystem": "KVM",
  "title": "KVM: x86: wean fast IN from emulator_pio_in",
  "introduced_in": [
   "4.10"
  ],
  "fixed_in": [
   "6.0"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64560",
  "published": "2026-07-29",
  "subsystem": "posix-cpu-timers",
  "title": "posix-cpu-timers: Prevent UAF caused by non-leader exec() race",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64559",
  "published": "2026-07-29",
  "subsystem": "s390/pkey",
  "title": "s390/pkey: Check length in PKEY_VERIFYPROTK ioctl",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64558",
  "published": "2026-07-29",
  "subsystem": "s390/pkey",
  "title": "s390/pkey: Check length in pkey_pckmo handler implementation",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64557",
  "published": "2026-07-29",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()",
  "introduced_in": [
   "3.13"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64556",
  "published": "2026-07-29",
  "subsystem": "perf/core",
  "title": "perf/core: Detach event groups during remove_on_exec",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64555",
  "published": "2026-07-27",
  "subsystem": "KVM",
  "title": "KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64554",
  "published": "2026-07-27",
  "subsystem": "netfilter",
  "title": "netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64553",
  "published": "2026-07-27",
  "subsystem": "net",
  "title": "net: psample: fix info leak in PSAMPLE_ATTR_DATA",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64552",
  "published": "2026-07-27",
  "subsystem": "virtio-net",
  "title": "virtio-net: fix len check in receive_big()",
  "introduced_in": [
   "6.1.159",
   "6.6.117",
   "6.12.58",
   "6.17.8",
   "6.18"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64551",
  "published": "2026-07-27",
  "subsystem": "sctp",
  "title": "sctp: validate STALE_COOKIE cause length before reading staleness",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64550",
  "published": "2026-07-27",
  "subsystem": "net",
  "title": "net: qualcomm: rmnet: validate MAP frame length before ingress parsing",
  "introduced_in": [
   "4.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64549",
  "published": "2026-07-27",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()",
  "introduced_in": [
   "4.4"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64548",
  "published": "2026-07-27",
  "subsystem": "bpf, sockmap",
  "title": "bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64547",
  "published": "2026-07-27",
  "subsystem": "net",
  "title": "net: usb: net1080: validate packet_len before pad-byte access in rx_fixup",
  "introduced_in": [
   "2.6.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64546",
  "published": "2026-07-27",
  "subsystem": "drm/edid",
  "title": "drm/edid: fix OOB read in drm_parse_tiled_block()",
  "introduced_in": [
   "3.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64545",
  "published": "2026-07-27",
  "subsystem": "net, bpf",
  "title": "net, bpf: check master for NULL in xdp_master_redirect()",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64544",
  "published": "2026-07-27",
  "subsystem": "crypto",
  "title": "crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents",
  "introduced_in": [
   "3.17"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64543",
  "published": "2026-07-27",
  "subsystem": "tipc",
  "title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
  "introduced_in": [
   "4.17"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64542",
  "published": "2026-07-27",
  "subsystem": "ipv6",
  "title": "ipv6: ndisc: fix NULL deref in accept_untracked_na()",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64541",
  "published": "2026-07-27",
  "subsystem": "net/smc",
  "title": "net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket",
  "introduced_in": [
   "4.18"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64540",
  "published": "2026-07-27",
  "subsystem": "usbnet",
  "title": "usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()",
  "introduced_in": [
   "2.6.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64539",
  "published": "2026-07-27",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: eir: Fix stack OOB write when prepending the Flags AD",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "6.1.178",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64538",
  "published": "2026-07-27",
  "subsystem": "ipv6",
  "title": "ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64537",
  "published": "2026-07-27",
  "subsystem": "bridge",
  "title": "bridge: cfm: reject invalid CCM interval at configuration time",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64536",
  "published": "2026-07-27",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64535",
  "published": "2026-07-27",
  "subsystem": "nvmet-tcp",
  "title": "nvmet-tcp: Fix potential UAF when ddgst mismatch",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64534",
  "published": "2026-07-27",
  "subsystem": "nvmet-tcp",
  "title": "nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path",
  "introduced_in": [],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64533",
  "published": "2026-07-27",
  "subsystem": "fs/ntfs3",
  "title": "fs/ntfs3: validate lcns_follow in log_replay conversion",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64532",
  "published": "2026-07-27",
  "subsystem": "fs/ntfs3",
  "title": "fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64531",
  "published": "2026-07-27",
  "subsystem": "net",
  "title": "net: openvswitch: reject oversized nested action attrs",
  "introduced_in": [
   "5.15.180",
   "6.1.132",
   "6.6.84",
   "6.12.20",
   "6.13.8",
   "6.14"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2024-14040",
  "published": "2026-07-26",
  "subsystem": "net",
  "title": "net: nexthop: Increase weight to u16",
  "introduced_in": [],
  "fixed_in": [
   "6.12"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64530",
  "published": "2026-07-26",
  "subsystem": "net/sched",
  "title": "net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle",
  "introduced_in": [
   "5.15.148",
   "6.1.75",
   "6.6.14",
   "6.7.2",
   "6.8"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.5",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64529",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: qat - remove unused character device and IOCTLs",
  "introduced_in": [
   "3.17"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64528",
  "published": "2026-07-25",
  "subsystem": "tty",
  "title": "tty: serial: samsung: Remove redundant port lock acquisition in rx helpers",
  "introduced_in": [
   "2.6.27"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64527",
  "published": "2026-07-25",
  "subsystem": "drm/hyperv",
  "title": "drm/hyperv: validate VMBus packet size in receive callback",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64526",
  "published": "2026-07-25",
  "subsystem": "ethtool",
  "title": "ethtool: tsconfig: fix missing ethnl_ops_complete()",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64525",
  "published": "2026-07-25",
  "subsystem": "xfrm",
  "title": "xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit",
  "introduced_in": [
   "6.6.136",
   "6.12.83",
   "6.18.24",
   "6.19.14",
   "7.0"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64524",
  "published": "2026-07-25",
  "subsystem": "drm/hyperv",
  "title": "drm/hyperv: validate resolution_count and fix WIN8 fallback",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64523",
  "published": "2026-07-25",
  "subsystem": "net/handshake",
  "title": "net/handshake: Take a long-lived file reference at submit",
  "introduced_in": [],
  "fixed_in": [
   "6.12.93",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64522",
  "published": "2026-07-25",
  "subsystem": "net/mlx5e",
  "title": "net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA",
  "introduced_in": [
   "6.17.4",
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64521",
  "published": "2026-07-25",
  "subsystem": "pinctrl",
  "title": "pinctrl: meson: amlogic-a4: fix deadlock issue",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64520",
  "published": "2026-07-25",
  "subsystem": "firmware",
  "title": "firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64519",
  "published": "2026-07-25",
  "subsystem": "nfsd",
  "title": "NFSD: Fix infinite loop in layout state revocation",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64518",
  "published": "2026-07-25",
  "subsystem": "tcp",
  "title": "tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().",
  "introduced_in": [
   "6.12.5",
   "6.13"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64517",
  "published": "2026-07-25",
  "subsystem": "drm/xe/gsc",
  "title": "drm/xe/gsc: Fix double-free of managed BO in error path",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64516",
  "published": "2026-07-25",
  "subsystem": "drm/amdgpu/vce1",
  "title": "drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64515",
  "published": "2026-07-25",
  "subsystem": "wifi",
  "title": "wifi: mac80211: fix MLE defragmentation",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64514",
  "published": "2026-07-25",
  "subsystem": "userfaultfd",
  "title": "userfaultfd: gate must_wait writability check on pte_present()",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64513",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: x86: Unconditionally recompute CR8 intercept on PPR update",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64512",
  "published": "2026-07-25",
  "subsystem": "ACPI",
  "title": "ACPI: CPPC: Suppress UBSAN warning caused by field misuse",
  "introduced_in": [
   "5.15.154",
   "6.1.90",
   "6.6.30",
   "6.8.9",
   "6.9"
  ],
  "fixed_in": [
   "5.15.155",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64511",
  "published": "2026-07-25",
  "subsystem": "ACPI",
  "title": "ACPI: NFIT: core: Fix possible NULL pointer dereference",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64510",
  "published": "2026-07-25",
  "subsystem": "ACPI",
  "title": "ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup",
  "introduced_in": [
   "4.6"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64509",
  "published": "2026-07-25",
  "subsystem": "rust",
  "title": "rust: block: fix GenDisk cleanup paths",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64508",
  "published": "2026-07-25",
  "subsystem": "bpf",
  "title": "bpf: Support for hardening against JIT spraying",
  "introduced_in": [],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64507",
  "published": "2026-07-25",
  "subsystem": "x86/bugs",
  "title": "x86/bugs: Enable IBPB flush on BPF JIT allocation",
  "introduced_in": [],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64506",
  "published": "2026-07-25",
  "subsystem": "wifi",
  "title": "wifi: rtw89: correct drop logic for malformed AMPDU frames",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64505",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: function: rndis: add length check for header",
  "introduced_in": [],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64504",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: accel: bmc150: clamp the device-reported FIFO frame count",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64503",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error",
  "introduced_in": [
   "4.9"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64502",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64501",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: adc: ad_sigma_delta: fix CS held asserted and state leaks",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64500",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: adc: lpc32xx: Initialize completion before requesting IRQ",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64499",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: adc: ti-ads1119: fix PM reference leak in buffer preenable",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64498",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: buffer: hw-consumer: free scan_mask on buffer release",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64497",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: chemical: scd30: Cleanup initializations and fix sign-extension bug",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64496",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: event: Fix event FIFO reset race",
  "introduced_in": [
   "3.15"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64495",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: gyro: bmg160: bail out when bandwidth/filter is not in table",
  "introduced_in": [
   "3.18"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64494",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: light: gp2ap002: fix runtime PM leak on read error",
  "introduced_in": [
   "5.7.6",
   "5.8"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64493",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: pressure: mpl115: fix runtime PM leak on read error",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64492",
  "published": "2026-07-25",
  "subsystem": "iio",
  "title": "iio: temperature: tmp006: use devm_iio_trigger_register",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64491",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: usx2y: us144mkii: fix work UAF on disconnect",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64490",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: virtio: Validate control metadata from the device",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64489",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: ymfpci: check snd_ctl_new1() return value",
  "introduced_in": [
   "6.1.34",
   "6.3.8",
   "6.4"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64488",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: aoa: check snd_ctl_new1() return value",
  "introduced_in": [
   "2.6.18"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64487",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser",
  "introduced_in": [
   "2.6.37"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64486",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: cmipci: check snd_ctl_new1() return value",
  "introduced_in": [
   "6.1.34",
   "6.3.8",
   "6.4"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64485",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: compress: Fix task creation error unwind",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64484",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: es1938: check snd_ctl_new1() return value",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64483",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: firewire: isight: bound the sample count to the packet payload",
  "introduced_in": [
   "3.0"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64482",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: gus: check snd_ctl_new1() return value",
  "introduced_in": [
   "6.1.34",
   "6.3.8",
   "6.4"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64481",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: hda/cs35l41: Fix firmware load work teardown",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64480",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: ice1712: check snd_ctl_new1() return value",
  "introduced_in": [
   "6.1.34",
   "6.3.8",
   "6.4"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64479",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64478",
  "published": "2026-07-25",
  "subsystem": "ALSA",
  "title": "ALSA: usb-audio: avoid kobject path lookup in DualSense match",
  "introduced_in": [
   "5.4.300",
   "5.10.245",
   "5.15.194",
   "6.1.155",
   "6.6.109",
   "6.12.50",
   "6.16.10",
   "6.17"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64477",
  "published": "2026-07-25",
  "subsystem": "x86,fs/resctrl",
  "title": "x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64476",
  "published": "2026-07-25",
  "subsystem": "vfio/pci",
  "title": "vfio/pci: Latch disable_idle_d3 per device",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64475",
  "published": "2026-07-25",
  "subsystem": "vfio/pci",
  "title": "vfio/pci: Release the VGA arbiter client on register_device() failure",
  "introduced_in": [
   "5.10.37",
   "5.11.21",
   "5.12.4",
   "5.13"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64474",
  "published": "2026-07-25",
  "subsystem": "vfio",
  "title": "vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64473",
  "published": "2026-07-25",
  "subsystem": "vfio",
  "title": "vfio: Remove device debugfs before releasing devres",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64472",
  "published": "2026-07-25",
  "subsystem": "vfio/mlx5",
  "title": "vfio/mlx5: Fix racy bitfields and tighten struct layout",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64471",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: btusb: fix use-after-free on registration failure",
  "introduced_in": [
   "2.6.27"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64470",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: btusb: fix use-after-free on marvell probe failure",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64469",
  "published": "2026-07-25",
  "subsystem": "binder",
  "title": "binder: fix UAF in binder_thread_release()",
  "introduced_in": [
   "4.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64468",
  "published": "2026-07-25",
  "subsystem": "binder",
  "title": "binder: fix UAF in binder_free_transaction()",
  "introduced_in": [
   "4.14.136",
   "4.19.64",
   "5.1.15",
   "5.2"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64467",
  "published": "2026-07-25",
  "subsystem": "rust_binder",
  "title": "rust_binder: use a u64 stride when cleaning up the offsets array",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64466",
  "published": "2026-07-25",
  "subsystem": "rust_binder",
  "title": "rust_binder: clear freeze listener on node removal",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64465",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: xhci: Fix sleep in atomic context in xhci_free_streams()",
  "introduced_in": [
   "2.6.35"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64464",
  "published": "2026-07-25",
  "subsystem": "xhci",
  "title": "xhci: sideband: fix ring sg table pages leak",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64463",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: typec: tcpci_rt1711h: unregister TCPCI port with devres",
  "introduced_in": [
   "4.19.131",
   "5.4.50",
   "5.7.7",
   "5.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64462",
  "published": "2026-07-25",
  "subsystem": "PCI",
  "title": "PCI: altera: Fix resource leaks on probe failure",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64461",
  "published": "2026-07-25",
  "subsystem": "PCI",
  "title": "PCI: mediatek: Fix IRQ domain leak when port fails to enable",
  "introduced_in": [
   "4.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64460",
  "published": "2026-07-25",
  "subsystem": "PCI/IOV",
  "title": "PCI/IOV: Skip VF Resizable BAR restore on read error",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64459",
  "published": "2026-07-25",
  "subsystem": "tcp",
  "title": "tcp: restore RCU grace period in tcp_ao_destroy_sock",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64458",
  "published": "2026-07-25",
  "subsystem": "mm/damon/ops-common",
  "title": "mm/damon/ops-common: handle extreme intervals in damon_hot_score()",
  "introduced_in": [
   "5.16"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64457",
  "published": "2026-07-25",
  "subsystem": "virtio_pci",
  "title": "virtio_pci: fix vq info pointer lookup via wrong index",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64456",
  "published": "2026-07-25",
  "subsystem": "hwrng",
  "title": "hwrng: virtio: clamp device-reported used.len at copy_data()",
  "introduced_in": [
   "2.6.26"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64455",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: chaoskey: Fix slab-use-after-free in chaoskey_release()",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64454",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: dwc3: run gadget disconnect from sleepable suspend context",
  "introduced_in": [
   "5.15.128",
   "6.1.30",
   "6.3.4",
   "6.4"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64453",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: misc: usbio: fix disconnect UAF in client teardown",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64452",
  "published": "2026-07-25",
  "subsystem": "6lowpan",
  "title": "6lowpan: fix NHC entry use-after-free on error path",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64451",
  "published": "2026-07-25",
  "subsystem": "tracing",
  "title": "tracing: Fix NULL pointer dereference in func_set_flag()",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64450",
  "published": "2026-07-25",
  "subsystem": "tipc",
  "title": "tipc: fix out-of-bounds read in broadcast Gap ACK blocks",
  "introduced_in": [
   "5.8"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64449",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: vme_user: bound slave read/write to the kern_buf size",
  "introduced_in": [
   "2.6.32"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64448",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: restrict implied bcc[0] exemption to responses without data area",
  "introduced_in": [
   "3.6"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64447",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: media: ipu7: fix double-free and use-after-free in error paths",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64446",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64445",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64444",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64443",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64442",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64441",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64440",
  "published": "2026-07-25",
  "subsystem": "staging",
  "title": "staging: rtl8723bs: fix OOB write in HT_caps_handler()",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64439",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: krb5 - filter out async aead implementations at alloc",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64438",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()",
  "introduced_in": [
   "4.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64437",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL",
  "introduced_in": [
   "6.1.176",
   "6.6.143",
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64436",
  "published": "2026-07-25",
  "subsystem": "net",
  "title": "net: af_key: initialize alg_key_len for IPComp states",
  "introduced_in": [
   "2.6.21"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64435",
  "published": "2026-07-25",
  "subsystem": "audit",
  "title": "audit: Fix data races of skb_queue_len() readers on audit_queue",
  "introduced_in": [
   "4.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64434",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref",
  "introduced_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64433",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete",
  "introduced_in": [
   "6.6.92",
   "6.12.30",
   "6.14.8",
   "6.15"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64432",
  "published": "2026-07-25",
  "subsystem": "fs/ntfs3",
  "title": "fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64431",
  "published": "2026-07-25",
  "subsystem": "ntfs",
  "title": "ntfs: avoid calling post_write_mst_fixup() for invalid index_block",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64430",
  "published": "2026-07-25",
  "subsystem": "ntb",
  "title": "NTB: epf: Avoid calling pci_irq_vector() from hardirq context",
  "introduced_in": [
   "5.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64429",
  "published": "2026-07-25",
  "subsystem": "gpio",
  "title": "gpio: eic-sprd: use raw_spinlock_t in the irq startup path",
  "introduced_in": [
   "4.17"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64428",
  "published": "2026-07-25",
  "subsystem": "gpio",
  "title": "gpio: sch: use raw_spinlock_t in the irq startup path",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64427",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: logitech-dj: Fix maxfield check in DJ short report validation",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64426",
  "published": "2026-07-25",
  "subsystem": "io_uring/nop",
  "title": "io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64425",
  "published": "2026-07-25",
  "subsystem": "io_uring/io-wq",
  "title": "io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item",
  "introduced_in": [
   "5.10.253",
   "5.15.203",
   "6.1.167",
   "6.6.122",
   "6.12.68",
   "6.18.8",
   "6.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64424",
  "published": "2026-07-25",
  "subsystem": "netpoll",
  "title": "netpoll: fix a use-after-free on shutdown path",
  "introduced_in": [
   "3.6"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64423",
  "published": "2026-07-25",
  "subsystem": "ipv4",
  "title": "ipv4: igmp: remove multicast group from hash table on device destruction",
  "introduced_in": [
   "3.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64422",
  "published": "2026-07-25",
  "subsystem": "net",
  "title": "net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes",
  "introduced_in": [
   "2.6.24"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64421",
  "published": "2026-07-25",
  "subsystem": "media",
  "title": "media: nxp: imx8-isi: Fix use-after-free on remove",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64420",
  "published": "2026-07-25",
  "subsystem": "mfd",
  "title": "mfd: cros_ec: Delay dev_set_drvdata() until probe success",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64419",
  "published": "2026-07-25",
  "subsystem": "mm/shrinker",
  "title": "mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64418",
  "published": "2026-07-25",
  "subsystem": "mm",
  "title": "mm: shrinker: fix shrinker_info teardown race with expansion",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64417",
  "published": "2026-07-25",
  "subsystem": "mm",
  "title": "mm: shrinker: fix NULL pointer dereference in debugfs",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64416",
  "published": "2026-07-25",
  "subsystem": "mm",
  "title": "mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64415",
  "published": "2026-07-25",
  "subsystem": "mm/swap",
  "title": "mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64414",
  "published": "2026-07-25",
  "subsystem": "netfilter",
  "title": "netfilter: handle unreadable frags",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64413",
  "published": "2026-07-25",
  "subsystem": "netfilter",
  "title": "netfilter: ebtables: zero chainstack array",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64412",
  "published": "2026-07-25",
  "subsystem": "netfilter",
  "title": "netfilter: ebtables: module names must be null-terminated",
  "introduced_in": [
   "4.6"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64411",
  "published": "2026-07-25",
  "subsystem": "netfilter",
  "title": "netfilter: ebtables: terminate table name before find_table_lock()",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64410",
  "published": "2026-07-25",
  "subsystem": "netfilter",
  "title": "netfilter: flowtable: IPIP tunnel hardware offload is not yet support",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64409",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64408",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: bnep: pin L2CAP connection during netdev registration",
  "introduced_in": [
   "3.13"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64407",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64406",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: fix UAF in bt_accept_dequeue()",
  "introduced_in": [
   "5.10.259",
   "5.15.210",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64405",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()",
  "introduced_in": [
   "6.1.83",
   "6.4.16",
   "6.5.3",
   "6.6"
  ],
  "fixed_in": [
   "6.1.118",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64404",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()",
  "introduced_in": [
   "6.12.6",
   "6.13"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64403",
  "published": "2026-07-25",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: validate option length before reading conf opt value",
  "introduced_in": [
   "3.16.66",
   "3.18.138",
   "4.4.178",
   "4.9.167",
   "4.14.110",
   "4.19.33",
   "5.0.6",
   "5.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64402",
  "published": "2026-07-25",
  "subsystem": "coresight",
  "title": "coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64401",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: resolve SWN tcon from live registrations",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64400",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: prevent path traversal bypass by restricting caseless retry",
  "introduced_in": [],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.6,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64399",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64398",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: add a permission check for FSCTL_SET_ZERO_DATA",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64397",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: serialize QUERY_DIRECTORY requests per file",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64396",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64395",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: require source read access for duplicate extents",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64394",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64393",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: run set info with opener credentials",
  "introduced_in": [],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64392",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: use opener credentials for delete-on-close",
  "introduced_in": [],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64391",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: use opener credentials for ADS I/O",
  "introduced_in": [],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64390",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: track the connection owning a byte-range lock",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64389",
  "published": "2026-07-25",
  "subsystem": "ksmbd",
  "title": "ksmbd: validate NTLMv2 response before updating session key",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64388",
  "published": "2026-07-25",
  "subsystem": "smb/client",
  "title": "smb/client: fix chown/chgrp with SMB3 POSIX Extensions",
  "introduced_in": [],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64387",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix query directory replay double-free",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64386",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix query_info() replay double-free",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64385",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix double-free in SMB2_ioctl() replay",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64384",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix change notify replay double-free",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64383",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix double-free in SMB2_flush() replay",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64382",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: fix double-free in SMB2_open() replay",
  "introduced_in": [
   "6.6.32",
   "6.8"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64381",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: Fix next buffer leak in receive_encrypted_standard()",
  "introduced_in": [
   "4.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64380",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: harden POSIX SID length parsing",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64379",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: mask server-provided mode to 07777 in modefromsid",
  "introduced_in": [
   "5.4"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64378",
  "published": "2026-07-25",
  "subsystem": "writeback",
  "title": "writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
  "introduced_in": [
   "4.4.5",
   "4.5"
  ],
  "fixed_in": [
   "5.10.261",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64377",
  "published": "2026-07-25",
  "subsystem": "cpufreq",
  "title": "cpufreq: qcom-cpufreq-hw: Fix possible double free",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64376",
  "published": "2026-07-25",
  "subsystem": "firmware_loader",
  "title": "firmware_loader: fix device reference leak in firmware_upload_register()",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64375",
  "published": "2026-07-25",
  "subsystem": "proc",
  "title": "proc: protect ptrace_may_access() with exec_update_lock (FD links)",
  "introduced_in": [
   "2.6.18"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64374",
  "published": "2026-07-25",
  "subsystem": "sched/rt",
  "title": "sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64373",
  "published": "2026-07-25",
  "subsystem": "cpufreq",
  "title": "cpufreq: Fix hotplug-suspend race during reboot",
  "introduced_in": [
   "4.4.198",
   "4.9.198",
   "4.14.151",
   "4.19.81",
   "5.3.8",
   "5.4"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64372",
  "published": "2026-07-25",
  "subsystem": "cpufreq",
  "title": "cpufreq: pcc: fix use-after-free and double free in _OSC evaluation",
  "introduced_in": [
   "2.6.34"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64371",
  "published": "2026-07-25",
  "subsystem": "proc",
  "title": "proc: protect ptrace_may_access() with exec_update_lock (part 1)",
  "introduced_in": [
   "2.6.27.23",
   "2.6.29.3",
   "2.6.30"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64370",
  "published": "2026-07-25",
  "subsystem": "posix-cpu-timers",
  "title": "posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64369",
  "published": "2026-07-25",
  "subsystem": "s390",
  "title": "s390: Revert support for DCACHE_WORD_ACCESS",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64368",
  "published": "2026-07-25",
  "subsystem": "mm/slab",
  "title": "mm/slab: do not limit zeroing to orig_size when only red zoning is enabled",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64367",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: hid-goodix-spi: validate report size to prevent stack buffer overflow",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64366",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64365",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: letsketch: fix UAF on inrange_timer at driver unbind",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64364",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: multitouch: fix out-of-bounds bit access on mt_io_flags",
  "introduced_in": [
   "5.10.246",
   "5.15.196",
   "6.1.158",
   "6.6.114",
   "6.12.55",
   "6.17.5",
   "6.18"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64363",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: appleir: fix UAF on pending key_up_timer in remove()",
  "introduced_in": [
   "3.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64362",
  "published": "2026-07-25",
  "subsystem": "HID",
  "title": "HID: lg-g15: cancel pending work on remove to fix a use-after-free",
  "introduced_in": [
   "5.5"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64361",
  "published": "2026-07-25",
  "subsystem": "hfs/hfsplus",
  "title": "hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length",
  "introduced_in": [
   "5.4.297",
   "5.10.241",
   "5.15.190",
   "6.1.149",
   "6.6.103",
   "6.12.43",
   "6.15.11",
   "6.16.2",
   "6.17"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64360",
  "published": "2026-07-25",
  "subsystem": "hfs/hfsplus",
  "title": "hfs/hfsplus: zero-initialize buffer in hfs_bnode_read",
  "introduced_in": [
   "5.4.297",
   "5.10.241",
   "5.15.190",
   "6.1.149",
   "6.6.103",
   "6.12.43",
   "6.15.11",
   "6.16.2",
   "6.17"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64359",
  "published": "2026-07-25",
  "subsystem": "nilfs2",
  "title": "nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers",
  "introduced_in": [
   "2.6.31"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64358",
  "published": "2026-07-25",
  "subsystem": "media",
  "title": "media: mtk-jpeg: cancel workqueue on release for supported platforms only",
  "introduced_in": [
   "6.6.140",
   "6.12.86",
   "6.18.27",
   "7.0.4",
   "7.1"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64357",
  "published": "2026-07-25",
  "subsystem": "xfs",
  "title": "xfs: fix exchmaps reservation limit check",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64356",
  "published": "2026-07-25",
  "subsystem": "xfs",
  "title": "xfs: fix memory leak in xfs_dqinode_metadir_create()",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64355",
  "published": "2026-07-25",
  "subsystem": "bpf",
  "title": "bpf: Reject fragmented frames in devmap",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64354",
  "published": "2026-07-25",
  "subsystem": "bpf",
  "title": "bpf: Validate BTF repeated field counts before expansion",
  "introduced_in": [
   "6.11.6",
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64353",
  "published": "2026-07-25",
  "subsystem": "bpf",
  "title": "bpf: Keep dynamic inner array lookups nullable",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64352",
  "published": "2026-07-25",
  "subsystem": "bpf",
  "title": "bpf: Allow LPM map access from sleepable BPF programs",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64351",
  "published": "2026-07-25",
  "subsystem": "net",
  "title": "net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()",
  "introduced_in": [
   "3.0"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64350",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()",
  "introduced_in": [
   "5.12"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64349",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()",
  "introduced_in": [
   "6.18.32",
   "7.0"
  ],
  "fixed_in": [
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64348",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: free iso schedules on failed submit",
  "introduced_in": [
   "2.6.15"
  ],
  "fixed_in": [
   "5.10.261",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64347",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler",
  "introduced_in": [
   "4.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64346",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: udc: Fix use-after-free in gadget_match_driver",
  "introduced_in": [],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64345",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: f_printer: take kref only for successful open",
  "introduced_in": [
   "4.4.241",
   "4.9.241",
   "4.14.203",
   "4.19.154",
   "5.4.73",
   "5.8.17",
   "5.9.2",
   "5.10"
  ],
  "fixed_in": [
   "5.10.261",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64344",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: idmouse: fix use-after-free on disconnect race",
  "introduced_in": [
   "2.6.24"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64343",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: ldusb: fix use-after-free on disconnect race",
  "introduced_in": [
   "2.6.26"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64342",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: iowarrior: fix use-after-free on disconnect",
  "introduced_in": [
   "2.6.21"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64341",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: iowarrior: fix use-after-free on disconnect race",
  "introduced_in": [
   "2.6.21"
  ],
  "fixed_in": [
   "6.12.97",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64340",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: legousbtower: fix use-after-free on disconnect race",
  "introduced_in": [
   "2.6.25"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64339",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: misc: usbio: bound bulk IN response length to the received transfer",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64338",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: misc: uss720: unregister parport on probe failure",
  "introduced_in": [
   "4.19.317",
   "5.4.279",
   "5.10.221",
   "5.15.162",
   "6.1.96",
   "6.6.36",
   "6.9.7",
   "6.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64337",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: mtu3: unmap request DMA on queue failure",
  "introduced_in": [
   "4.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64336",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: serial: keyspan_pda: fix information leak",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64335",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: serial: digi_acceleport: fix broken rx after throttle",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64334",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: serial: digi_acceleport: fix hard lockup on disconnect",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64333",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: serial: digi_acceleport: fix write buffer corruption",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64332",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "USB: ulpi: fix memory leak on registration failure",
  "introduced_in": [
   "4.2"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64331",
  "published": "2026-07-25",
  "subsystem": "usbip",
  "title": "usbip: vudc: fix NULL deref in vep_dequeue()",
  "introduced_in": [
   "4.7"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64330",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: typec: tcpm: Validate SVID index in svdm_consume_modes()",
  "introduced_in": [
   "4.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64329",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove",
  "introduced_in": [
   "5.5"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64328",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: f_fs: Fix DMA fence leak",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64327",
  "published": "2026-07-25",
  "subsystem": "usb",
  "title": "usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64326",
  "published": "2026-07-25",
  "subsystem": "block",
  "title": "block: skip sync_blockdev() on surprise removal in bdev_mark_dead()",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64325",
  "published": "2026-07-25",
  "subsystem": "wifi",
  "title": "wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64324",
  "published": "2026-07-25",
  "subsystem": "udf",
  "title": "udf: validate free block extents against the partition length",
  "introduced_in": [
   "4.19.320",
   "5.4.282",
   "5.10.224",
   "5.15.165",
   "6.1.105",
   "6.6.46",
   "6.10.5",
   "6.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64323",
  "published": "2026-07-25",
  "subsystem": "udf",
  "title": "udf: validate VAT header length against the VAT inode size",
  "introduced_in": [
   "2.6.26"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64322",
  "published": "2026-07-25",
  "subsystem": "udf",
  "title": "udf: validate sparing table length as an entry count, not a byte count",
  "introduced_in": [
   "2.6.32.60",
   "2.6.34.14",
   "3.0.37",
   "3.2.23",
   "3.4.5",
   "3.5"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64321",
  "published": "2026-07-25",
  "subsystem": "nvme",
  "title": "nvme: target: rdma: fix ndev refcount leak on queue connect",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64320",
  "published": "2026-07-25",
  "subsystem": "nvmet",
  "title": "nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64319",
  "published": "2026-07-25",
  "subsystem": "nvmet-auth",
  "title": "nvmet-auth: validate reply message payload bounds against transfer length",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64318",
  "published": "2026-07-25",
  "subsystem": "partitions",
  "title": "partitions: aix: bound the pp_count scan to the ppe array",
  "introduced_in": [
   "3.11"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64317",
  "published": "2026-07-25",
  "subsystem": "isofs",
  "title": "isofs: bound Rock Ridge symlink components to the SL record",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64316",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64315",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64314",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: chacha20poly1305 - validate poly1305 template argument",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64313",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: ecc - Fix carry overflow in vli multiplication",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64312",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: pcrypt - restore callback for non-parallel fallback",
  "introduced_in": [
   "4.19.325",
   "5.4.287",
   "5.10.231",
   "5.15.174",
   "6.1.120",
   "6.6.64",
   "6.11.11",
   "6.12.2",
   "6.13"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64311",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: loongson - Remove broken and unused loongson-rng",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64310",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: ccp - Do not initialize SNP for SEV ioctls",
  "introduced_in": [
   "6.12.75",
   "6.16"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64309",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)",
  "introduced_in": [
   "6.12.75",
   "6.16"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64308",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)",
  "introduced_in": [
   "6.12.75",
   "6.16"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64307",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)",
  "introduced_in": [
   "6.12.75",
   "6.16"
  ],
  "fixed_in": [
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64306",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: drbg - Fix returning success on failure in CTR_DRBG",
  "introduced_in": [
   "3.12.44",
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64305",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: qat - protect service table iterations with service_lock",
  "introduced_in": [
   "3.17"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64304",
  "published": "2026-07-25",
  "subsystem": "crypto",
  "title": "crypto: qat - validate RSA CRT component lengths",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64303",
  "published": "2026-07-25",
  "subsystem": "spi",
  "title": "spi: fsl-lpspi: terminate the RX channel on TX prepare failure path",
  "introduced_in": [
   "5.2"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64302",
  "published": "2026-07-25",
  "subsystem": "x86/mm",
  "title": "x86/mm: Fix freeing of PMD-sized vmemmap pages",
  "introduced_in": [
   "6.18.7",
   "6.19"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64301",
  "published": "2026-07-25",
  "subsystem": "regulator",
  "title": "regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64300",
  "published": "2026-07-25",
  "subsystem": "perf/aux",
  "title": "perf/aux: Fix page UAF in map_range()",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64299",
  "published": "2026-07-25",
  "subsystem": "tracing",
  "title": "tracing: Prevent out-of-bounds read in glob matching",
  "introduced_in": [
   "4.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64298",
  "published": "2026-07-25",
  "subsystem": "NFSv4",
  "title": "NFSv4: include MAY_WRITE in open permission mask for O_TRUNC",
  "introduced_in": [
   "2.6.24"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64297",
  "published": "2026-07-25",
  "subsystem": "module",
  "title": "module: decompress: check return value of module_extend_max_pages()",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64296",
  "published": "2026-07-25",
  "subsystem": "exfat",
  "title": "exfat: bound uniname advance in exfat_find_dir_entry()",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64295",
  "published": "2026-07-25",
  "subsystem": "mm",
  "title": "mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64294",
  "published": "2026-07-25",
  "subsystem": "mm",
  "title": "mm: do file ownership checks with the proper mount idmap",
  "introduced_in": [
   "5.12"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64293",
  "published": "2026-07-25",
  "subsystem": "iommufd",
  "title": "iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64292",
  "published": "2026-07-25",
  "subsystem": "iommufd",
  "title": "iommufd: Move vevent memory allocation outside spinlock",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64291",
  "published": "2026-07-25",
  "subsystem": "iommufd",
  "title": "iommufd: Set veventq_depth upper bound",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64290",
  "published": "2026-07-25",
  "subsystem": "iommufd",
  "title": "iommufd: Break the loop on failure in iommufd_fault_fops_read()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64289",
  "published": "2026-07-25",
  "subsystem": "iommufd",
  "title": "iommufd: Set upper bounds on cache invalidation entry_num and entry_len",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64288",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64287",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64286",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64285",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: SEV: Pin source page for write when adding CPUID data for SNP guest",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64284",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64283",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: guest_memfd: Treat memslot binding offset+size as unsigned values",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64282",
  "published": "2026-07-25",
  "subsystem": "KVM",
  "title": "KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64281",
  "published": "2026-07-25",
  "subsystem": "svcrdma",
  "title": "svcrdma: wake sq waiters when the transport closes",
  "introduced_in": [
   "7.1"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64280",
  "published": "2026-07-25",
  "subsystem": "fpga",
  "title": "fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()",
  "introduced_in": [
   "4.19"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64279",
  "published": "2026-07-25",
  "subsystem": "i2c",
  "title": "i2c: core: fix adapter deregistration race",
  "introduced_in": [
   "2.6.31"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64278",
  "published": "2026-07-25",
  "subsystem": "i2c",
  "title": "i2c: imx-lpi2c: mark I2C adapter when hardware is powered down",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64277",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64276",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count",
  "introduced_in": [
   "4.14"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64275",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: elan_i2c - prevent division by zero and arithmetic underflow",
  "introduced_in": [
   "3.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64274",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: goodix - clamp the device-reported contact count",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64273",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: iforce - bound the device-reported force-feedback effect index",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64272",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: mms114 - fix touch indexing for MMS134S and MMS136",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64271",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: touchwin - reset the packet index on every complete packet",
  "introduced_in": [
   "2.6.19"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64270",
  "published": "2026-07-25",
  "subsystem": "Input",
  "title": "Input: mms114 - reject an oversized device packet size",
  "introduced_in": [
   "3.6"
  ],
  "fixed_in": [
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64269",
  "published": "2026-07-25",
  "subsystem": "RDMA/rtrs-srv",
  "title": "RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg",
  "introduced_in": [
   "5.8"
  ],
  "fixed_in": [
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64268",
  "published": "2026-07-25",
  "subsystem": "RDMA/siw",
  "title": "RDMA/siw: bound Read Response placement to the RREAD length",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64267",
  "published": "2026-07-25",
  "subsystem": "fuse",
  "title": "fuse: avoid 32-bit prune notification count wrap",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64266",
  "published": "2026-07-25",
  "subsystem": "fuse",
  "title": "fuse: re-lock request before returning from fuse_ref_folio()",
  "introduced_in": [
   "2.6.35"
  ],
  "fixed_in": [
   "5.10.261",
   "5.15.212",
   "6.1.178",
   "6.6.145",
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64265",
  "published": "2026-07-25",
  "subsystem": "fuse",
  "title": "fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64264",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: fix EFAULT clobber in fuse_uring_commit",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64263",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: fix moving cancelled entry to ent_in_userspace list",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64262",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: end fuse_req on io-uring cancel task work",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64261",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64260",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: Avoid queue->stopped races and set/read that value under lock",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64259",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: make a fuse_req on SQE commit only findable after memcpy",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64258",
  "published": "2026-07-25",
  "subsystem": "fuse-uring",
  "title": "fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64257",
  "published": "2026-07-25",
  "subsystem": "smb",
  "title": "smb: client: reject overlapping data areas in SMB2 responses",
  "introduced_in": [
   "5.10.261",
   "5.15.212",
   "7.2"
  ],
  "fixed_in": [
   "7.2"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64256",
  "published": "2026-07-25",
  "subsystem": "xfs",
  "title": "xfs: don't wrap around quota ids in dqiterate",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64255",
  "published": "2026-07-24",
  "subsystem": "wifi",
  "title": "wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers",
  "introduced_in": [],
  "fixed_in": [
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64254",
  "published": "2026-07-24",
  "subsystem": "ntb",
  "title": "NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64253",
  "published": "2026-07-24",
  "subsystem": "kernel/fork",
  "title": "kernel/fork: clear PF_BLOCK_TS in copy_process()",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64252",
  "published": "2026-07-24",
  "subsystem": "MIPS",
  "title": "MIPS: DEC: Prevent initial console buffer from landing in XKPHYS",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64251",
  "published": "2026-07-24",
  "subsystem": "pwrseq",
  "title": "pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64250",
  "published": "2026-07-24",
  "subsystem": "LoongArch",
  "title": "LoongArch: Report dying CPU to RCU in stop_this_cpu()",
  "introduced_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64249",
  "published": "2026-07-24",
  "subsystem": "fpga",
  "title": "fpga: region: fix use-after-free in child_regions_with_firmware()",
  "introduced_in": [
   "4.10"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64248",
  "published": "2026-07-24",
  "subsystem": "MIPS",
  "title": "MIPS: smp: report dying CPU to RCU in stop_this_cpu()",
  "introduced_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "fixed_in": [
   "6.1.178",
   "6.6.145",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64247",
  "published": "2026-07-24",
  "subsystem": "KVM",
  "title": "KVM: x86: hyper-v: Bound the bank index when querying sparse banks",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64246",
  "published": "2026-07-24",
  "subsystem": "power",
  "title": "power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64245",
  "published": "2026-07-24",
  "subsystem": "fbdev",
  "title": "fbdev: modedb: fix a possible UAF in fb_find_mode()",
  "introduced_in": [],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64244",
  "published": "2026-07-24",
  "subsystem": "drivers/base/memory",
  "title": "drivers/base/memory: set mem->altmap after successful device registration",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64243",
  "published": "2026-07-24",
  "subsystem": "ASoC",
  "title": "ASoC: codecs: simple-mux: Fix enum control bounds check",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64242",
  "published": "2026-07-24",
  "subsystem": "usb",
  "title": "usb: gadget: net2280: Fix double free in probe error path",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64241",
  "published": "2026-07-24",
  "subsystem": "gpio",
  "title": "gpio: rockchip: teardown bugs and resource leaks",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64240",
  "published": "2026-07-24",
  "subsystem": "media",
  "title": "media: rc: igorplugusb: fix control request setup packet",
  "introduced_in": [
   "6.6.140",
   "6.12.86",
   "6.18.27",
   "7.0.4"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64239",
  "published": "2026-07-24",
  "subsystem": "mm/damon/sysfs-schemes",
  "title": "mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64238",
  "published": "2026-07-24",
  "subsystem": "gpio",
  "title": "gpio: shared: fix deadlock on shared proxy's parent removal",
  "introduced_in": [
   "6.19.12",
   "7.0"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64237",
  "published": "2026-07-24",
  "subsystem": "Input",
  "title": "Input: elan_i2c - validate firmware size before use",
  "introduced_in": [],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64236",
  "published": "2026-07-24",
  "subsystem": "i2c",
  "title": "i2c: davinci: fix division by zero on missing clock-frequency",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64235",
  "published": "2026-07-24",
  "subsystem": "x86/ftrace",
  "title": "x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64234",
  "published": "2026-07-24",
  "subsystem": "tty",
  "title": "tty: serial: pch_uart: add check for dma_alloc_coherent()",
  "introduced_in": [
   "2.6.38"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64233",
  "published": "2026-07-24",
  "subsystem": "usb",
  "title": "usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64232",
  "published": "2026-07-24",
  "subsystem": "block",
  "title": "block: recompute nr_integrity_segments in blk_insert_cloned_request",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64231",
  "published": "2026-07-24",
  "subsystem": "drm/msm/dsi",
  "title": "drm/msm/dsi: don't dump registers past the mapped region",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64230",
  "published": "2026-07-24",
  "subsystem": "regulator",
  "title": "regulator: tps65219: fix irq_data.rdev not being assigned",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64229",
  "published": "2026-07-24",
  "subsystem": "x86/mm",
  "title": "x86/mm: Disable broadcast TLB flush when PCID is disabled",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64228",
  "published": "2026-07-24",
  "subsystem": "net",
  "title": "net: ethtool: phy: avoid NULL deref when PHY driver is unbound",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64227",
  "published": "2026-07-24",
  "subsystem": "ACPI",
  "title": "ACPI: driver: Check ACPI_COMPANION() against NULL during probe",
  "introduced_in": [],
  "fixed_in": [
   "6.6.145",
   "6.12.97",
   "6.18.40",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64226",
  "published": "2026-07-24",
  "subsystem": "sched_ext",
  "title": "sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64225",
  "published": "2026-07-24",
  "subsystem": "octeontx2-af",
  "title": "octeontx2-af: CGX: add bounds check to cgx_speed_mbps index",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64224",
  "published": "2026-07-24",
  "subsystem": "octeontx2-pf",
  "title": "octeontx2-pf: fix double free in rvu_rep_rsrc_init()",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64223",
  "published": "2026-07-24",
  "subsystem": "wifi",
  "title": "wifi: mac80211: consume only present negotiated TTLM maps",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64222",
  "published": "2026-07-24",
  "subsystem": "octeontx2-pf",
  "title": "octeontx2-pf: avoid double free of pool->stack on AQ init failure",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64221",
  "published": "2026-07-24",
  "subsystem": "spi",
  "title": "spi: ti-qspi: fix use-after-free after DMA setup failure",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64220",
  "published": "2026-07-24",
  "subsystem": "device property",
  "title": "device property: set fwnode->secondary to NULL in fwnode_init()",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64219",
  "published": "2026-07-24",
  "subsystem": "drm/amd/display",
  "title": "drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async",
  "introduced_in": [],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64218",
  "published": "2026-07-24",
  "subsystem": "batman-adv",
  "title": "batman-adv: bla: fix report_work leak on backbone_gw purge",
  "introduced_in": [
   "3.5"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64217",
  "published": "2026-07-24",
  "subsystem": "netfs",
  "title": "netfs: Fix overrun check in netfs_extract_user_iter()",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64216",
  "published": "2026-07-24",
  "subsystem": "netfs",
  "title": "netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64215",
  "published": "2026-07-24",
  "subsystem": "drm/msm/a6xx",
  "title": "drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64214",
  "published": "2026-07-24",
  "subsystem": "powerpc/time",
  "title": "powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()",
  "introduced_in": [
   "5.18"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64213",
  "published": "2026-07-24",
  "subsystem": "hwmon",
  "title": "hwmon: (lm90) Add lock protection to lm90_alert",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64212",
  "published": "2026-07-24",
  "subsystem": "wifi",
  "title": "wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it",
  "introduced_in": [],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64211",
  "published": "2026-07-24",
  "subsystem": "srcu",
  "title": "srcu: Don't queue workqueue handlers to never-online CPUs",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64210",
  "published": "2026-07-24",
  "subsystem": "net/mlx5e",
  "title": "net/mlx5e: xsk: Fix unlocked writing to ICOSQ",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64209",
  "published": "2026-07-24",
  "subsystem": "phy",
  "title": "phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64208",
  "published": "2026-07-24",
  "subsystem": "crypto/krb5, rxrpc",
  "title": "crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64600",
  "published": "2026-07-23",
  "subsystem": "xfs",
  "title": "xfs: resample the data fork mapping after cycling ILOCK",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64207",
  "published": "2026-07-20",
  "subsystem": "net/sched",
  "title": "net/sched: dualpi2: fix GSO backlog accounting",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64206",
  "published": "2026-07-20",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock",
  "introduced_in": [
   "3.15.5",
   "3.16"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64205",
  "published": "2026-07-20",
  "subsystem": "i2c",
  "title": "i2c: i801: fix hardware state machine corruption in error path",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64192",
  "published": "2026-07-20",
  "subsystem": "bpf",
  "title": "bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64191",
  "published": "2026-07-20",
  "subsystem": "i2c",
  "title": "i2c: stub: Reject I2C block transfers with invalid length",
  "introduced_in": [
   "2.6.33"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64190",
  "published": "2026-07-20",
  "subsystem": "net",
  "title": "net: team: fix NULL pointer dereference in team_xmit during mode change",
  "introduced_in": [
   "3.3"
  ],
  "fixed_in": [
   "6.18.35",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64189",
  "published": "2026-07-20",
  "subsystem": "netfilter",
  "title": "netfilter: ipset: fix race between dump and ip_set_list resize",
  "introduced_in": [
   "4.19.5",
   "4.20"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64188",
  "published": "2026-07-20",
  "subsystem": "net",
  "title": "net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()",
  "introduced_in": [
   "4.14"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64187",
  "published": "2026-07-20",
  "subsystem": "xfs",
  "title": "xfs: fail recovery on a committed log item with no regions",
  "introduced_in": [
   "4.3"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.4",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64186",
  "published": "2026-07-19",
  "subsystem": "iommu/amd",
  "title": "iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64185",
  "published": "2026-07-19",
  "subsystem": "sysfs",
  "title": "sysfs: don't remove existing directory on update failure",
  "introduced_in": [
   "4.19"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64184",
  "published": "2026-07-19",
  "subsystem": "mm/damon/sysfs-schemes",
  "title": "mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64183",
  "published": "2026-07-19",
  "subsystem": "efi",
  "title": "efi: Allocate runtime workqueue before ACPI init",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64182",
  "published": "2026-07-19",
  "subsystem": "drivers/base/memory",
  "title": "drivers/base/memory: fix memory block reference leak in poison accounting",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64181",
  "published": "2026-07-19",
  "subsystem": "mm",
  "title": "mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64180",
  "published": "2026-07-19",
  "subsystem": "mm/memory_hotplug",
  "title": "mm/memory_hotplug: fix memory block reference leak on remove",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64179",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: wwan: iosm: fix potential memory leaks in ipc_imem_init()",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64178",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: bnep: Fix UAF read of dev->name",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64177",
  "published": "2026-07-19",
  "subsystem": "phonet/pep",
  "title": "phonet/pep: disable BH around forwarded sk_receive_skb()",
  "introduced_in": [
   "2.6.28"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64176",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: iwlwifi: mvm: fix driver-set TX rates on old devices",
  "introduced_in": [],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64175",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: iwlwifi: mld: stop TX during firmware restart",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64174",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: cfg80211: advance loop vars in cfg80211_merge_profile()",
  "introduced_in": [
   "5.2"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64173",
  "published": "2026-07-19",
  "subsystem": "tracing",
  "title": "tracing: Do not call map->ops->elt_free() if elt_alloc() fails",
  "introduced_in": [
   "4.17"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64172",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64171",
  "published": "2026-07-19",
  "subsystem": "i2c",
  "title": "i2c: tegra: fix pm_runtime leak on mutex_lock failure",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64170",
  "published": "2026-07-19",
  "subsystem": "spi",
  "title": "spi: qup: fix error pointer deref after DMA setup failure",
  "introduced_in": [
   "4.1"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64169",
  "published": "2026-07-19",
  "subsystem": "spi",
  "title": "spi: ep93xx: fix error pointer deref after DMA setup failure",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64168",
  "published": "2026-07-19",
  "subsystem": "spi",
  "title": "spi: sprd: fix error pointer deref after DMA setup failure",
  "introduced_in": [
   "5.1"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64167",
  "published": "2026-07-19",
  "subsystem": "kho",
  "title": "kho: skip KHO for crash kernel",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64166",
  "published": "2026-07-19",
  "subsystem": "firmware",
  "title": "firmware: arm_ffa: Check for NULL FF-A ID table while driver registration",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64165",
  "published": "2026-07-19",
  "subsystem": "ARM",
  "title": "ARM: integrator: Fix early initialization",
  "introduced_in": [
   "4.9"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64164",
  "published": "2026-07-19",
  "subsystem": "btrfs",
  "title": "btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()",
  "introduced_in": [
   "6.6.136",
   "6.12.83",
   "6.18.24",
   "6.19.14",
   "7.0"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64163",
  "published": "2026-07-19",
  "subsystem": "test_kprobes",
  "title": "test_kprobes: clear kprobes between test runs",
  "introduced_in": [
   "5.16"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64162",
  "published": "2026-07-19",
  "subsystem": "idpf",
  "title": "idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64161",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ti: icssm-prueth: fix eth_ports_node leak in probe",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64160",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix potential for tearing in ->remote_i_size and ->zero_point",
  "introduced_in": [
   "5.18"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64159",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix zeropoint update where i_size > remote_i_size",
  "introduced_in": [
   "6.10.8",
   "6.11"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64158",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix write streaming disablement if fd open O_RDWR",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64157",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix partial invalidation of streaming-write folio",
  "introduced_in": [
   "6.10.8",
   "6.11"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64156",
  "published": "2026-07-19",
  "subsystem": "netfs, afs",
  "title": "netfs, afs: Fix write skipping in dir/link writepages",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64155",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: ath11k: fix error path leaks in some WMI WOW calls",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64154",
  "published": "2026-07-19",
  "subsystem": "drm/msm/adreno",
  "title": "drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64153",
  "published": "2026-07-19",
  "subsystem": "drm/msm",
  "title": "drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64152",
  "published": "2026-07-19",
  "subsystem": "iommu",
  "title": "iommu: Handle unmap error when iommu_debug is enabled",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64151",
  "published": "2026-07-19",
  "subsystem": "iommupt",
  "title": "iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64150",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: nft_inner: release local_lock before re-enabling softirqs",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64149",
  "published": "2026-07-19",
  "subsystem": "dma-mapping",
  "title": "dma-mapping: move dma_map_resource() sanity check into debug code",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64148",
  "published": "2026-07-19",
  "subsystem": "pds_core",
  "title": "pds_core: fix error handling in pdsc_devcmd_wait",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64147",
  "published": "2026-07-19",
  "subsystem": "pds_core",
  "title": "pds_core: fix debugfs_lookup dentry leak and error handling",
  "introduced_in": [
   "6.6.16",
   "6.7.4",
   "6.8"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64146",
  "published": "2026-07-19",
  "subsystem": "erofs",
  "title": "erofs: fix metabuf leak in inode xattr initialization",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64145",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: wilc1000: fix dma_buffer leak on bus acquire failure",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64144",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: btmtk: fix urb->setup_packet leak in error paths",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64143",
  "published": "2026-07-19",
  "subsystem": "platform/x86",
  "title": "platform/x86: uniwill-laptop: Do not enable the charging limit even when forced",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64142",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: close durable scavenger races against m_fp_list lookups",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64141",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix null pointer dereference in compare_guid_key()",
  "introduced_in": [
   "6.6.32",
   "6.9"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64140",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix null pointer dereference in proc_show_files()",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64139",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow",
  "introduced_in": [
   "6.1.175",
   "6.6.136",
   "6.12.84",
   "6.18.25",
   "7.0.2"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64138",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: validate SID in parent security descriptor during ACL inheritance",
  "introduced_in": [],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64137",
  "published": "2026-07-19",
  "subsystem": "smb",
  "title": "smb: client: require net admin for CIFS SWN netlink",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64136",
  "published": "2026-07-19",
  "subsystem": "smb",
  "title": "smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()",
  "introduced_in": [
   "6.6.128",
   "6.12.75",
   "6.18.16",
   "6.19.6",
   "7.0"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64135",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64134",
  "published": "2026-07-19",
  "subsystem": "ALSA",
  "title": "ALSA: pcm: Don't setup bogus iov_iter for silencing",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64133",
  "published": "2026-07-19",
  "subsystem": "ALSA",
  "title": "ALSA: asihpi: Fix potential OOB array access at reading cache",
  "introduced_in": [],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64132",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: ioam: refresh hdr pointer before ioam6_event()",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64131",
  "published": "2026-07-19",
  "subsystem": "mm/memory",
  "title": "mm/memory: fix spurious warning when unmapping device-private/exclusive pages",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64130",
  "published": "2026-07-19",
  "subsystem": "mm/page_alloc",
  "title": "mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64129",
  "published": "2026-07-19",
  "subsystem": "mm/migrate_device",
  "title": "mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64128",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: ISO: drop ISO_END frames received without prior ISO_START",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64127",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64126",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: MGMT: validate Add Extended Advertising Data length",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64125",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: bcmgenet: keep RBUF EEE/PM disabled",
  "introduced_in": [
   "3.19"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64124",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: devmem: reject dma-buf bind with non-page-aligned size or SG length",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64123",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: hsr: defer node table free until after RCU readers",
  "introduced_in": [
   "5.2.12",
   "5.3"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64122",
  "published": "2026-07-19",
  "subsystem": "net/mlx5e",
  "title": "net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover",
  "introduced_in": [
   "6.18.14",
   "6.19.4",
   "7.0"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64121",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ifb: report ethtool stats over num_tx_queues",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64120",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ethtool: fix NULL pointer dereference in phy_reply_size",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64119",
  "published": "2026-07-19",
  "subsystem": "l2tp",
  "title": "l2tp: use list_del_rcu in l2tp_session_unhash",
  "introduced_in": [
   "6.11.3",
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64118",
  "published": "2026-07-19",
  "subsystem": "qed",
  "title": "qed: fix double free in qed_cxt_tables_alloc()",
  "introduced_in": [
   "4.4"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64117",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64116",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64115",
  "published": "2026-07-19",
  "subsystem": "vsock/vmci",
  "title": "vsock/vmci: fix UAF when peer resets connection during handshake",
  "introduced_in": [
   "3.9"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64114",
  "published": "2026-07-19",
  "subsystem": "ipv4",
  "title": "ipv4: raw: reject IP_HDRINCL packets with ihl < 5",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64113",
  "published": "2026-07-19",
  "subsystem": "ixgbevf",
  "title": "ixgbevf: fix use-after-free in VEPA multicast source pruning",
  "introduced_in": [
   "3.19"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64112",
  "published": "2026-07-19",
  "subsystem": "rbd",
  "title": "rbd: eliminate a race in lock_dwork draining on unmap",
  "introduced_in": [],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64111",
  "published": "2026-07-19",
  "subsystem": "LSM",
  "title": "lsm: hold cred_guard_mutex for lsm_set_self_attr()",
  "introduced_in": [],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64110",
  "published": "2026-07-19",
  "subsystem": "igc",
  "title": "igc: fix potential skb leak in igc_fpe_xmit_smd_frame()",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64109",
  "published": "2026-07-19",
  "subsystem": "af_unix",
  "title": "af_unix: Fix UAF read of tail->len in unix_stream_data_wait()",
  "introduced_in": [
   "4.2"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64108",
  "published": "2026-07-19",
  "subsystem": "cifs",
  "title": "cifs: Fix busy dentry used after unmounting",
  "introduced_in": [
   "6.1.167",
   "6.6.130",
   "6.12.78",
   "6.18.20",
   "6.19.10",
   "7.0"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64107",
  "published": "2026-07-19",
  "subsystem": "ASoC",
  "title": "ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64106",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits",
  "introduced_in": [
   "4.12"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64105",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: arm64: vgic: Free private_irqs when init fails after allocation",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64104",
  "published": "2026-07-19",
  "subsystem": "virt",
  "title": "virt: sev-guest: Explicitly leak pages in unknown state",
  "introduced_in": [
   "6.13.8",
   "6.14"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64103",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: isci: Fix use-after-free in device removal path",
  "introduced_in": [
   "3.0"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64102",
  "published": "2026-07-19",
  "subsystem": "RDMA/siw",
  "title": "RDMA/siw: Reject MPA FPDU length underflow before signed receive math",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64101",
  "published": "2026-07-19",
  "subsystem": "fwctl",
  "title": "fwctl: pds: Validate RPC input size before parsing",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64100",
  "published": "2026-07-19",
  "subsystem": "drm/msm",
  "title": "drm/msm: Fix shrinker deadlock",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64099",
  "published": "2026-07-19",
  "subsystem": "drm/v3d",
  "title": "drm/v3d: Fix use-after-free of CPU job query arrays on error path",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64098",
  "published": "2026-07-19",
  "subsystem": "drm/virtio",
  "title": "drm/virtio: use uninterruptible resv lock for plane updates",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64097",
  "published": "2026-07-19",
  "subsystem": "drm/amd/display",
  "title": "drm/amd/display: Validate GPIO pin LUT table size before iterating",
  "introduced_in": [],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64096",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: mcast: fix use-after-free in orig_node RCU release",
  "introduced_in": [
   "3.15"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64095",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: bla: avoid double decrement of bla.num_requests",
  "introduced_in": [
   "3.5"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64094",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface",
  "introduced_in": [
   "3.5"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64093",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tp_meter: directly shut down timer on cleanup",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64092",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown",
  "introduced_in": [
   "5.10.259",
   "6.6.140",
   "6.12.90",
   "6.18.32",
   "7.0.9"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64091",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tt: fix TOCTOU race for reported vlans",
  "introduced_in": [
   "3.16.60",
   "4.4.217",
   "4.9.217",
   "4.14.174",
   "4.17"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64090",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tt: avoid empty VLAN responses",
  "introduced_in": [
   "3.13"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64089",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tt: fix negative last_changeset_len",
  "introduced_in": [
   "3.1"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64088",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tt: fix negative tt_buff_len",
  "introduced_in": [
   "3.1"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64087",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) reject implausible blackbox record_count",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64086",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64085",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64084",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64083",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64082",
  "published": "2026-07-19",
  "subsystem": "riscv",
  "title": "riscv: Fix register corruption from uninitialized cregs on error",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64081",
  "published": "2026-07-19",
  "subsystem": "firmware",
  "title": "firmware: arm_ffa: Validate framework notification message layout",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64080",
  "published": "2026-07-19",
  "subsystem": "firmware",
  "title": "firmware: arm_ffa: Snapshot notifier callbacks under lock",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64079",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: x_tables: allocate hook ops while under mutex",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64078",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: x_tables: add and use xtables_unregister_table_exit",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64077",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: ebtables: move to two-stage removal scheme",
  "introduced_in": [
   "5.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64076",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: bridge: eb_tables: close module init race",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64075",
  "published": "2026-07-19",
  "subsystem": "fprobe",
  "title": "fprobe: Fix unregister_fprobe() to wait for RCU grace period",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64074",
  "published": "2026-07-19",
  "subsystem": "fs/statmount",
  "title": "fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64073",
  "published": "2026-07-19",
  "subsystem": "irq_work",
  "title": "irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT",
  "introduced_in": [
   "5.16"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64072",
  "published": "2026-07-19",
  "subsystem": "nvme",
  "title": "nvme: fix bio leak on mapping failure",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64071",
  "published": "2026-07-19",
  "subsystem": "nvme-pci",
  "title": "nvme-pci: fix use-after-free in nvme_free_host_mem()",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64070",
  "published": "2026-07-19",
  "subsystem": "powerpc/hv-gpci",
  "title": "powerpc/hv-gpci: fix preempt count leak in sysfs show paths",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64069",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix cancellation of a DIO and single read subrequests",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64068",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix missing locking around retry adding new subreqs",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64067",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix missing barriers when accessing stream->subrequests locklessly",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64066",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix netfs_read_to_pagecache() to pause on subreq failure",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64065",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64064",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64063",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix streaming write being overwritten",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64062",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix potential deadlock in write-through mode",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64061",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix early put of sink folio in netfs_read_gaps()",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64060",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix leak of request in netfs_write_begin() error handling",
  "introduced_in": [
   "5.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64059",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix folio->private handling in netfs_perform_write()",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64058",
  "published": "2026-07-19",
  "subsystem": "netfs",
  "title": "netfs: Fix netfs_read_folio() to wait on writeback",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64057",
  "published": "2026-07-19",
  "subsystem": "afs",
  "title": "afs: Fix the locking used by afs_get_link()",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64056",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ethernet: cortina: Make RX SKB per-port",
  "introduced_in": [
   "4.16"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64055",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ethernet: cortina: Carry over frag counter",
  "introduced_in": [
   "4.16"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64054",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: shaper: reject duplicate leaves in GROUP request",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64053",
  "published": "2026-07-19",
  "subsystem": "block",
  "title": "block: don't overwrite bip_vcnt in bio_integrity_copy_user()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64052",
  "published": "2026-07-19",
  "subsystem": "block",
  "title": "block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()",
  "introduced_in": [
   "6.8"
  ],
  "fixed_in": [
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64051",
  "published": "2026-07-19",
  "subsystem": "accel/qaic",
  "title": "accel/qaic: Add overflow check to remap_pfn_range during mmap",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64050",
  "published": "2026-07-19",
  "subsystem": "drm/msm/dpu",
  "title": "drm/msm/dpu: don't mix devm and drmm functions",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64049",
  "published": "2026-07-19",
  "subsystem": "drm/msm/adreno",
  "title": "drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64048",
  "published": "2026-07-19",
  "subsystem": "net/smc",
  "title": "net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64047",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring",
  "introduced_in": [
   "5.4.14",
   "5.5"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64046",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: tls: prevent chain-after-chain in plain text SG",
  "introduced_in": [
   "5.4.14",
   "5.5"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64045",
  "published": "2026-07-19",
  "subsystem": "ovpn",
  "title": "ovpn: tcp - use cached peer pointer in ovpn_tcp_close()",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64044",
  "published": "2026-07-19",
  "subsystem": "ovpn",
  "title": "ovpn: respect peer refcount in CMD_NEW_PEER error path",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64043",
  "published": "2026-07-19",
  "subsystem": "ovpn",
  "title": "ovpn: fix race between deleting interface and adding new peer",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64042",
  "published": "2026-07-19",
  "subsystem": "vfio/pci",
  "title": "vfio/pci: Check BAR resources before exporting a DMABUF",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64041",
  "published": "2026-07-19",
  "subsystem": "ASoC",
  "title": "ASoC: codecs: fs210x: fix possible buffer overflow",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64040",
  "published": "2026-07-19",
  "subsystem": "cachefiles",
  "title": "cachefiles: Fix error return when vfs_mkdir() fails",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64039",
  "published": "2026-07-19",
  "subsystem": "drm/msm/snapshot",
  "title": "drm/msm/snapshot: fix dumping of the unaligned regions",
  "introduced_in": [
   "5.14"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.7,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64038",
  "published": "2026-07-19",
  "subsystem": "hwmon",
  "title": "hwmon: (lm90) Stop work before releasing hwmon device",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64037",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64036",
  "published": "2026-07-19",
  "subsystem": "cgroup/rstat",
  "title": "cgroup/rstat: validate cpu before css_rstat_cpu() access",
  "introduced_in": [
   "6.1"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64035",
  "published": "2026-07-19",
  "subsystem": "igc",
  "title": "igc: set tx buffer type for SMD frames",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64034",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64033",
  "published": "2026-07-19",
  "subsystem": "RDMA/rtrs",
  "title": "RDMA/rtrs: Fix use-after-free in path file creation cleanup",
  "introduced_in": [
   "5.15.61",
   "5.17"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64032",
  "published": "2026-07-19",
  "subsystem": "bridge",
  "title": "bridge: mcast: Fix a possible use-after-free when removing a bridge port",
  "introduced_in": [
   "5.15.186",
   "6.1.142",
   "6.6.95",
   "6.12.35",
   "6.15.4",
   "6.16"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64031",
  "published": "2026-07-19",
  "subsystem": "erofs",
  "title": "erofs: fix managed cache race for unaligned extents",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64030",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64029",
  "published": "2026-07-19",
  "subsystem": "ALSA",
  "title": "ALSA: seq: Serialize UMP output teardown with event_input",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64028",
  "published": "2026-07-19",
  "subsystem": "tracing",
  "title": "tracing: Avoid NULL return from hist_field_name() on truncation",
  "introduced_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64027",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: shaper: rework the VALID marking (again)",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64026",
  "published": "2026-07-19",
  "subsystem": "rxrpc",
  "title": "rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64025",
  "published": "2026-07-19",
  "subsystem": "bpf, skmsg",
  "title": "bpf, skmsg: fix verdict sk_data_ready racing with ktls rx",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64024",
  "published": "2026-07-19",
  "subsystem": "tcp",
  "title": "tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.4,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64023",
  "published": "2026-07-19",
  "subsystem": "gpio",
  "title": "gpio: aggregator: fix a potential use-after-free",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64022",
  "published": "2026-07-19",
  "subsystem": "gpio",
  "title": "gpio: aggregator: remove the software node when deactivating the aggregator",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64021",
  "published": "2026-07-19",
  "subsystem": "drm/xe/oa",
  "title": "drm/xe/oa: Fix exec_queue leak on width check in stream open",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64020",
  "published": "2026-07-19",
  "subsystem": "nvme-pci",
  "title": "nvme-pci: fix dma_vecs leak on p2p memory",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64019",
  "published": "2026-07-19",
  "subsystem": "nvme-pci",
  "title": "nvme-pci: fix dma mapping leak on data setup error",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64018",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: mana: validate rx_req_idx to prevent out-of-bounds array access",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64017",
  "published": "2026-07-19",
  "subsystem": "blk-mq",
  "title": "blk-mq: pop cached request if it is usable",
  "introduced_in": [
   "6.1.72",
   "6.1.75",
   "6.5.13",
   "6.6.3",
   "6.6.14",
   "6.7"
  ],
  "fixed_in": [
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64016",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix durable reconnect error path file lifetime",
  "introduced_in": [
   "6.18.33",
   "7.0.10"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64015",
  "published": "2026-07-19",
  "subsystem": "security/keys",
  "title": "security/keys: fix missed RCU read section on lookup",
  "introduced_in": [],
  "fixed_in": [
   "6.1.175",
   "6.6.142",
   "6.12.92",
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64014",
  "published": "2026-07-19",
  "subsystem": "Input",
  "title": "Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size",
  "introduced_in": [
   "2.6.34"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64013",
  "published": "2026-07-19",
  "subsystem": "ACPI",
  "title": "ACPI: button: Fix ACPI GPE handler leak during removal",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64012",
  "published": "2026-07-19",
  "subsystem": "net/sched",
  "title": "net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
  "introduced_in": [
   "2.6.39"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64011",
  "published": "2026-07-19",
  "subsystem": "nfc",
  "title": "nfc: llcp: Fix use-after-free in llcp_sock_release()",
  "introduced_in": [
   "3.10.10",
   "3.11"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64010",
  "published": "2026-07-19",
  "subsystem": "nfc",
  "title": "nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()",
  "introduced_in": [
   "3.6"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-64009",
  "published": "2026-07-19",
  "subsystem": "xfrm",
  "title": "xfrm: Check for underflow in xfrm_state_mtu",
  "introduced_in": [
   "2.6.22"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64008",
  "published": "2026-07-19",
  "subsystem": "accel/rocket",
  "title": "accel/rocket: fix UAF via dangling GEM handle in create_bo",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64007",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: synproxy: refresh tcphdr after skb_ensure_writable",
  "introduced_in": [
   "3.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64006",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: nf_tables: fix dst corruption in same register operation",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "6.6.143",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64005",
  "published": "2026-07-19",
  "subsystem": "net/smc",
  "title": "net/smc: Do not re-initialize smc hashtables",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64004",
  "published": "2026-07-19",
  "subsystem": "net/iucv",
  "title": "net/iucv: fix locking in .getsockopt",
  "introduced_in": [
   "3.4"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64003",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-64002",
  "published": "2026-07-19",
  "subsystem": "ipv4",
  "title": "ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()",
  "introduced_in": [
   "3.16"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-64001",
  "published": "2026-07-19",
  "subsystem": "ALSA",
  "title": "ALSA: pcm: oss: Fix setup list UAF on proc write error",
  "introduced_in": [
   "2.6.17"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-64000",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: hsr: fix potential OOB access in supervision frame handling",
  "introduced_in": [
   "5.16"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63999",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: rss: fix indir_table and hkey leak on get_rxfh failure",
  "introduced_in": [
   "5.15.181",
   "6.1.135",
   "6.6.88",
   "6.12.24",
   "6.13.12",
   "6.14.3",
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63998",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: module: call ethnl_ops_complete() on module flash errors",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63997",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: module: avoid leaking a netdev ref on module flash errors",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63996",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: cmis: require exact CDB reply length",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63995",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: cmis: validate start_cmd_payload_size from module",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63994",
  "published": "2026-07-19",
  "subsystem": "tunnels",
  "title": "tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63993",
  "published": "2026-07-19",
  "subsystem": "vxlan",
  "title": "vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63992",
  "published": "2026-07-19",
  "subsystem": "tunnels",
  "title": "tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.1,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63991",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()",
  "introduced_in": [
   "3.14"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63990",
  "published": "2026-07-19",
  "subsystem": "bonding",
  "title": "bonding: refuse to enslave CAN devices",
  "introduced_in": [
   "2.6.25"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63989",
  "published": "2026-07-19",
  "subsystem": "bridge",
  "title": "bridge: Fix sleep in atomic context in netlink path",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63988",
  "published": "2026-07-19",
  "subsystem": "bridge",
  "title": "bridge: Fix sleep in atomic context in sysfs path",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63987",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63986",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63985",
  "published": "2026-07-19",
  "subsystem": "ethtool",
  "title": "ethtool: eeprom: add more safeties to EEPROM Netlink fallback",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63984",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63983",
  "published": "2026-07-19",
  "subsystem": "net/sched",
  "title": "net/sched: fix packet loop on netem when duplicate is on",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "6.12.93",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63982",
  "published": "2026-07-19",
  "subsystem": "net/sched",
  "title": "net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63981",
  "published": "2026-07-19",
  "subsystem": "net/sched",
  "title": "net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63980",
  "published": "2026-07-19",
  "subsystem": "net/handshake",
  "title": "net/handshake: Use spin_lock_bh for hn_lock",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63979",
  "published": "2026-07-19",
  "subsystem": "net/handshake",
  "title": "net/handshake: hand off the pinned file reference to accept_doit",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63978",
  "published": "2026-07-19",
  "subsystem": "net/handshake",
  "title": "net/handshake: Drain pending requests at net namespace exit",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.12.93",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63977",
  "published": "2026-07-19",
  "subsystem": "dpll",
  "title": "dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63976",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63975",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63974",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close",
  "introduced_in": [
   "5.18.18",
   "5.19.2",
   "6.0"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63973",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: mana: Add NULL guards in teardown path to prevent panic on attach failure",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63972",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: mana: Skip redundant detach on already-detached port",
  "introduced_in": [
   "6.18.33",
   "7.0"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63971",
  "published": "2026-07-19",
  "subsystem": "sctp",
  "title": "sctp: fix race between sctp_wait_for_connect and peeloff",
  "introduced_in": [
   "4.16"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63970",
  "published": "2026-07-19",
  "subsystem": "vsock/virtio",
  "title": "vsock/virtio: bind uarg before filling zerocopy skb",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63969",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: fix possible infinite loop in rt6_fill_node()",
  "introduced_in": [
   "6.1.128",
   "6.6.75",
   "6.11.11",
   "6.12.2",
   "6.13"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63968",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: fix possible infinite loop in fib6_select_path()",
  "introduced_in": [
   "6.1.128",
   "6.6.75",
   "6.11.11",
   "6.12.2",
   "6.13"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63967",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer",
  "introduced_in": [
   "5.9.5",
   "5.10"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63966",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: imu: adis16550: fix stack leak in trigger handler",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63965",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: pressure: bmp280: fix stack leak in bmp580 trigger handler",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63964",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: ucsi: ccg: reject firmware images without a ':' record header",
  "introduced_in": [],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63963",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers",
  "introduced_in": [],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63962",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()",
  "introduced_in": [],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63961",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: altmodes/displayport: validate count before reading Status Update VDO",
  "introduced_in": [],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63960",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()",
  "introduced_in": [],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63959",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT",
  "introduced_in": [],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63958",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: typec: ucsi: validate connector number in ucsi_connector_change()",
  "introduced_in": [],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63957",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: safe_serial: fix memory corruption with small endpoint",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63956",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: cypress_m8: fix memory corruption with small endpoint",
  "introduced_in": [
   "2.6.26"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63955",
  "published": "2026-07-19",
  "subsystem": "mm/vmalloc",
  "title": "mm/vmalloc: do not trigger BUG() on BH disabled context",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63954",
  "published": "2026-07-19",
  "subsystem": "hpfs",
  "title": "hpfs: fix a crash if hpfs_map_dnode_bitmap fails",
  "introduced_in": [],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63953",
  "published": "2026-07-19",
  "subsystem": "mm/migrate_device",
  "title": "mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63952",
  "published": "2026-07-19",
  "subsystem": "memfd",
  "title": "memfd: deny writeable mappings when implying SEAL_WRITE",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63951",
  "published": "2026-07-19",
  "subsystem": "zram",
  "title": "zram: fix use-after-free in zram_writeback_endio",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63950",
  "published": "2026-07-19",
  "subsystem": "mm/rmap",
  "title": "mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63949",
  "published": "2026-07-19",
  "subsystem": "auxdisplay",
  "title": "auxdisplay: line-display: fix OOB read on zero-length message_store()",
  "introduced_in": [
   "5.16"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63948",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn",
  "introduced_in": [
   "4.19.314",
   "5.4.276",
   "5.10.217",
   "5.15.159",
   "6.1.91",
   "6.6.31",
   "6.8.10",
   "6.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63947",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: HIDP: fix missing length checks in hidp_input_report()",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63946",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: ISO: fix UAF in iso_recv_frame",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63945",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63944",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63943",
  "published": "2026-07-19",
  "subsystem": "Input",
  "title": "Input: xpad - fix out-of-bounds access for Share button",
  "introduced_in": [
   "6.6.91",
   "6.12.29",
   "6.14.7",
   "6.15"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63942",
  "published": "2026-07-19",
  "subsystem": "parport",
  "title": "parport: Fix race between port and client registration",
  "introduced_in": [
   "4.2"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63941",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63940",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SEV: Ignore Port I/O requests of length '0'",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63939",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SEV: Compute the correct max length of the in-GHCB scratch area",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63938",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SEV: Check PSC request indices against the actual size of the buffer",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.3,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63937",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63936",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: adc: mt6359: fix unchecked return value in mt6358_read_imp",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63935",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: adc: nxp-sar-adc: fix division by zero in write_raw",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63934",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: gyro: itg3200: fix i2c read into the wrong stack location",
  "introduced_in": [
   "3.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63933",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: gyro: adis16260: fix division by zero in write_raw",
  "introduced_in": [
   "2.6.35"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63932",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: chemical: mhz19b: reject oversized serial replies",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63931",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: chemical: scd30: fix division by zero in write_raw",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63930",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: buffer: hw-consumer: fix use-after-free in error path",
  "introduced_in": [
   "4.16"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63929",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63928",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: omninet: fix memory corruption with small endpoint",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63927",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: dwc2: Fix use after free in debug code",
  "introduced_in": [
   "3.10"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63926",
  "published": "2026-07-19",
  "subsystem": "bpf",
  "title": "bpf: sockmap: fix tail fragment offset in bpf_msg_push_data",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63925",
  "published": "2026-07-19",
  "subsystem": "macsec",
  "title": "macsec: fix replay protection at XPN lower-PN wrap",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63924",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63923",
  "published": "2026-07-19",
  "subsystem": "octeontx2-af",
  "title": "octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63922",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: exthdrs: refresh nh after handling HAO option",
  "introduced_in": [
   "2.6.19"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63921",
  "published": "2026-07-19",
  "subsystem": "ip6",
  "title": "ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().",
  "introduced_in": [
   "3.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63920",
  "published": "2026-07-19",
  "subsystem": "ipv6",
  "title": "ipv6: validate extension header length before copying to cmsg",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63919",
  "published": "2026-07-19",
  "subsystem": "xfrm",
  "title": "xfrm: input: hold netns during deferred transport reinjection",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63918",
  "published": "2026-07-19",
  "subsystem": "l2tp",
  "title": "l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname",
  "introduced_in": [
   "6.12"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63917",
  "published": "2026-07-19",
  "subsystem": "ip6",
  "title": "ip6: vti: Use ip6_tnl.net in vti6_changelink().",
  "introduced_in": [
   "3.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63916",
  "published": "2026-07-19",
  "subsystem": "HID",
  "title": "HID: wacom: Fix OOB write in wacom_hid_set_device_mode()",
  "introduced_in": [
   "3.18"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63915",
  "published": "2026-07-19",
  "subsystem": "nfc",
  "title": "nfc: hci: fix out-of-bounds read in HCP header parsing",
  "introduced_in": [
   "3.5"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63914",
  "published": "2026-07-19",
  "subsystem": "xfrm",
  "title": "xfrm: route MIGRATE notifications to caller's netns",
  "introduced_in": [
   "2.6.21"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63913",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check",
  "introduced_in": [
   "2.6.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63912",
  "published": "2026-07-19",
  "subsystem": "xfrm",
  "title": "xfrm: esp: restore combined single-frag length gate",
  "introduced_in": [
   "4.14.288",
   "4.19.252",
   "5.4.205",
   "5.10.113",
   "5.15.36",
   "5.17.5",
   "5.18"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63911",
  "published": "2026-07-19",
  "subsystem": "xfrm",
  "title": "xfrm: iptfs: reset runtime state when cloning SAs",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63910",
  "published": "2026-07-19",
  "subsystem": "dma-buf",
  "title": "dma-buf: fix UAF in dma_buf_fd() tracepoint",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63909",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops",
  "introduced_in": [
   "6.6.140",
   "6.12.84",
   "6.18.25",
   "7.0.2"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63908",
  "published": "2026-07-19",
  "subsystem": "Input",
  "title": "Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem",
  "introduced_in": [
   "3.17"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63907",
  "published": "2026-07-19",
  "subsystem": "uio",
  "title": "uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63906",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: musb: omap2430: Fix use-after-free in omap2430_probe()",
  "introduced_in": [
   "6.0.16",
   "6.1.2",
   "6.2"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63905",
  "published": "2026-07-19",
  "subsystem": "usbip",
  "title": "usbip: vudc: Fix use after free bug in vudc_remove due to race condition",
  "introduced_in": [
   "4.7"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63904",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: usbtmc: check URB actual_length for interrupt-IN notifications",
  "introduced_in": [
   "4.6"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63903",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: belkin_sa: validate interrupt status length",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63902",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: cypress_m8: validate interrupt packet headers",
  "introduced_in": [
   "2.6.26"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63901",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: digi_acceleport: fix memory corruption with small endpoints",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63900",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: keyspan: fix missing indat transfer sanity check",
  "introduced_in": [
   "2.6.23"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63899",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: mxuport: fix memory corruption with small endpoint",
  "introduced_in": [
   "3.14"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63898",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: mct_u232: fix memory corruption with small endpoint",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.94",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63897",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "USB: serial: mct_u232: fix missing interrupt-in transfer sanity check",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63896",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63895",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: gadget: f_fs: copy only received bytes on short ep0 read",
  "introduced_in": [
   "2.6.35"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63894",
  "published": "2026-07-19",
  "subsystem": "usb",
  "title": "usb: gadget: f_fs: serialize DMABUF cancel against request completion",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63893",
  "published": "2026-07-19",
  "subsystem": "thunderbolt",
  "title": "thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()",
  "introduced_in": [
   "4.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63892",
  "published": "2026-07-19",
  "subsystem": "thunderbolt",
  "title": "thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow",
  "introduced_in": [
   "4.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63891",
  "published": "2026-07-19",
  "subsystem": "thunderbolt",
  "title": "thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()",
  "introduced_in": [
   "4.15"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63890",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker",
  "introduced_in": [
   "2.6.30"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63889",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63888",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()",
  "introduced_in": [
   "3.1"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63887",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf",
  "introduced_in": [
   "3.1"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63886",
  "published": "2026-07-19",
  "subsystem": "scsi",
  "title": "scsi: target: iscsi: Validate CHAP_R length before base64 decode",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63885",
  "published": "2026-07-19",
  "subsystem": "drm/gem",
  "title": "drm/gem: fix race between change_handle and handle_delete",
  "introduced_in": [
   "6.18.32",
   "7.0.9"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63884",
  "published": "2026-07-19",
  "subsystem": "drm/i915",
  "title": "drm/i915: Fix potential UAF in TTM object purge",
  "introduced_in": [
   "5.17"
  ],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63883",
  "published": "2026-07-19",
  "subsystem": "serial",
  "title": "serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ",
  "introduced_in": [
   "6.3"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.3,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63882",
  "published": "2026-07-19",
  "subsystem": "drm/amdkfd",
  "title": "drm/amdkfd: fix NULL pointer bug in svm_range_set_attr",
  "introduced_in": [],
  "fixed_in": [
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63881",
  "published": "2026-07-19",
  "subsystem": "drm/amdkfd",
  "title": "drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger",
  "introduced_in": [],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63880",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu",
  "title": "drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63879",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu",
  "title": "drm/amdgpu: fix amdgpu_hmm_range_get_pages",
  "introduced_in": [],
  "fixed_in": [
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63878",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu",
  "title": "drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63877",
  "published": "2026-07-19",
  "subsystem": "serial",
  "title": "serial: dz: Convert to use a platform device",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63876",
  "published": "2026-07-19",
  "subsystem": "serial",
  "title": "serial: zs: Convert to use a platform device",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63875",
  "published": "2026-07-19",
  "subsystem": "arm64",
  "title": "arm64: tlb: Flush walk cache when unsharing PMD tables",
  "introduced_in": [
   "5.10.253",
   "5.15.203",
   "6.1.167",
   "6.6.127",
   "6.12.74",
   "6.18.13",
   "6.19"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.93",
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63874",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: mctp: usb: fix race between urb completion and rx_retry cancellation",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63873",
  "published": "2026-07-19",
  "subsystem": "accel/amdxdna",
  "title": "accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63872",
  "published": "2026-07-19",
  "subsystem": "esp",
  "title": "esp: fix page frag reference leak on skb_to_sgvec failure",
  "introduced_in": [
   "4.11"
  ],
  "fixed_in": [
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63871",
  "published": "2026-07-19",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls",
  "introduced_in": [
   "6.1.9",
   "6.2"
  ],
  "fixed_in": [
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63870",
  "published": "2026-07-19",
  "subsystem": "ieee802154",
  "title": "ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()",
  "introduced_in": [
   "4.0"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63869",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 7.6,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63868",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: garp: fix unsigned integer underflow in garp_pdu_parse_attr",
  "introduced_in": [
   "2.6.27"
  ],
  "fixed_in": [
   "5.10.259",
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63867",
  "published": "2026-07-19",
  "subsystem": "mptcp",
  "title": "mptcp: close TOCTOU race while computing rcv_wnd",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.210",
   "6.1.176",
   "6.6.143",
   "6.12.94",
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 8.2,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63866",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()",
  "introduced_in": [
   "6.15"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63865",
  "published": "2026-07-19",
  "subsystem": "bpf",
  "title": "bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks",
  "introduced_in": [
   "5.11"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63864",
  "published": "2026-07-19",
  "subsystem": "bpf",
  "title": "bpf: Propagate error from visit_tailcall_insn",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63863",
  "published": "2026-07-19",
  "subsystem": "drm/gpusvm",
  "title": "drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63862",
  "published": "2026-07-19",
  "subsystem": "PCI",
  "title": "PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found",
  "introduced_in": [
   "5.13"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63861",
  "published": "2026-07-19",
  "subsystem": "spi",
  "title": "spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.1.175",
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63860",
  "published": "2026-07-19",
  "subsystem": "RDMA/core",
  "title": "RDMA/core: Prefer NLA_NUL_STRING",
  "introduced_in": [
   "3.16"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63859",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63858",
  "published": "2026-07-19",
  "subsystem": "netfilter",
  "title": "netfilter: nf_tables: add hook transactions for device deletions",
  "introduced_in": [
   "5.10.122",
   "5.15.47",
   "5.17.15",
   "5.18.4",
   "5.19"
  ],
  "fixed_in": [
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63857",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()",
  "introduced_in": [
   "6.11"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63856",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings",
  "introduced_in": [
   "5.3"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63855",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings",
  "introduced_in": [
   "5.4"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63854",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63853",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63852",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63851",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63850",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63849",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vcn",
  "title": "drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63848",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63847",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63846",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63845",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring",
  "introduced_in": [
   "5.19"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63844",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring",
  "introduced_in": [
   "6.5"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63843",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63842",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring",
  "introduced_in": [
   "6.9"
  ],
  "fixed_in": [
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63841",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63840",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/jpeg",
  "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.0.10",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63839",
  "published": "2026-07-19",
  "subsystem": "platform/x86",
  "title": "platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63838",
  "published": "2026-07-19",
  "subsystem": "ASoC",
  "title": "ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.141",
   "6.12.91",
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63837",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ena: PHC: Check return code before setting timestamp output",
  "introduced_in": [
   "6.17"
  ],
  "fixed_in": [
   "6.18.33",
   "7.0.10",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63836",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63835",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: v: prevent OGM aggregation on disabled hardif",
  "introduced_in": [
   "5.4"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63834",
  "published": "2026-07-19",
  "subsystem": "batman-adv",
  "title": "batman-adv: tp_meter: restrict number of unacked list entries",
  "introduced_in": [
   "4.8"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63833",
  "published": "2026-07-19",
  "subsystem": "ntfs3",
  "title": "ntfs3: reject direct userspace writes to reserved $LX* xattrs",
  "introduced_in": [],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63832",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: mt76: add wcid publish check in mt76_sta_add",
  "introduced_in": [],
  "fixed_in": [
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63831",
  "published": "2026-07-19",
  "subsystem": "mac802154",
  "title": "mac802154: llsec: add skb_cow_data() before in-place crypto",
  "introduced_in": [
   "3.16"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Adjacent"
 },
 {
  "cve": "CVE-2026-63830",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: skmsg: preserve sg.copy across SG transforms",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.4,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63829",
  "published": "2026-07-19",
  "subsystem": "net",
  "title": "net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink",
  "introduced_in": [
   "3.16"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63828",
  "published": "2026-07-19",
  "subsystem": "apparmor",
  "title": "apparmor: mediate the implicit connect of TCP fast open sendmsg",
  "introduced_in": [
   "3.6"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63827",
  "published": "2026-07-19",
  "subsystem": "apparmor",
  "title": "apparmor: fix use-after-free in rawdata dedup loop",
  "introduced_in": [
   "5.10.253",
   "5.15.203",
   "6.1.169",
   "6.6.130",
   "6.12.77",
   "6.18.18",
   "6.19.8",
   "7.0"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63826",
  "published": "2026-07-19",
  "subsystem": "fbdev",
  "title": "fbdev: fix use-after-free in store_modes()",
  "introduced_in": [],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63825",
  "published": "2026-07-19",
  "subsystem": "gcov",
  "title": "gcov: use atomic counter updates to fix concurrent access crashes",
  "introduced_in": [],
  "fixed_in": [
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63824",
  "published": "2026-07-19",
  "subsystem": "KEYS",
  "title": "KEYS: fix overflow in keyctl_pkey_params_get_2()",
  "introduced_in": [
   "4.20"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63823",
  "published": "2026-07-19",
  "subsystem": "KEYS",
  "title": "keys: Pin request_key_auth payload in instantiate paths",
  "introduced_in": [
   "2.6.16"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63822",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: ath11k: fix warning when unbinding",
  "introduced_in": [
   "5.6"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63821",
  "published": "2026-07-19",
  "subsystem": "wifi",
  "title": "wifi: rtw88: usb: fix memory leaks on USB write failures",
  "introduced_in": [
   "6.2"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63820",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: fix missing read bio submission on large folio error",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63819",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: fix to do sanity check on f2fs_get_node_folio_ra()",
  "introduced_in": [],
  "fixed_in": [
   "6.18.39",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63818",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: validate orphan inode entry count",
  "introduced_in": [
   "3.8"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63817",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: validate compress cache inode only when enabled",
  "introduced_in": [
   "5.13.19",
   "5.14"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63816",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode",
  "introduced_in": [
   "5.18.18",
   "5.19"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63815",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: bound i_inline_xattr_size for non-inline-xattr inodes",
  "introduced_in": [
   "4.15"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63814",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: validate ACL entry sizes in f2fs_acl_from_disk()",
  "introduced_in": [
   "3.8"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63813",
  "published": "2026-07-19",
  "subsystem": "Revert \"f2fs",
  "title": "Revert \"f2fs: remove non-uptodate folio from the page cache in move_data_block\"",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63812",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()",
  "introduced_in": [
   "6.6.140",
   "6.12.88",
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63811",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: read COW data with the original inode during atomic write",
  "introduced_in": [
   "6.4"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63810",
  "published": "2026-07-19",
  "subsystem": "block",
  "title": "block: Avoid mounting the bdev pseudo-filesystem in userspace",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63809",
  "published": "2026-07-19",
  "subsystem": "bpf",
  "title": "bpf: use kvfree() for replaced sysctl write buffer",
  "introduced_in": [
   "5.10.20",
   "5.11.3",
   "5.12"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63808",
  "published": "2026-07-19",
  "subsystem": "exfat",
  "title": "exfat: fix potential use-after-free in exfat_find_dir_entry()",
  "introduced_in": [
   "5.7"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63807",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level",
  "introduced_in": [
   "5.12"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63806",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()",
  "introduced_in": [
   "2.6.32"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63805",
  "published": "2026-07-19",
  "subsystem": "crypto",
  "title": "crypto: nx - fix nx_crypto_ctx_exit argument",
  "introduced_in": [
   "5.5"
  ],
  "fixed_in": [
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63804",
  "published": "2026-07-19",
  "subsystem": "gfs2",
  "title": "gfs2: fix use-after-free in gfs2_qd_dealloc",
  "introduced_in": [
   "6.6"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63803",
  "published": "2026-07-19",
  "subsystem": "hdlc_ppp",
  "title": "hdlc_ppp: sync per-proto timers before freeing hdlc state",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63802",
  "published": "2026-07-19",
  "subsystem": "blk-cgroup",
  "title": "blk-cgroup: fix UAF in __blkcg_rstat_flush()",
  "introduced_in": [
   "6.3.9",
   "6.4"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63801",
  "published": "2026-07-19",
  "subsystem": "tipc",
  "title": "tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done",
  "introduced_in": [
   "5.5"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63800",
  "published": "2026-07-19",
  "subsystem": "pNFS",
  "title": "pNFS: Fix use-after-free in pnfs_update_layout()",
  "introduced_in": [
   "5.4.91",
   "5.10.9",
   "5.11"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63799",
  "published": "2026-07-19",
  "subsystem": "sched/mmcid",
  "title": "sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63798",
  "published": "2026-07-19",
  "subsystem": "irqchip/imgpdc",
  "title": "irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove",
  "introduced_in": [
   "3.12"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63797",
  "published": "2026-07-19",
  "subsystem": "rpmsg",
  "title": "rpmsg: char: Fix use-after-free on probe error path",
  "introduced_in": [
   "5.18"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-63796",
  "published": "2026-07-19",
  "subsystem": "ocfs2",
  "title": "ocfs2: reject oversized group bitmap descriptors",
  "introduced_in": [
   "2.6.16"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63795",
  "published": "2026-07-19",
  "subsystem": "9p",
  "title": "9p: avoid putting oldfid in p9_client_walk() error path",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 10,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-63794",
  "published": "2026-07-19",
  "subsystem": "KVM",
  "title": "KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path",
  "introduced_in": [
   "4.16"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-63793",
  "published": "2026-07-19",
  "subsystem": "ntfs",
  "title": "ntfs: serialize volume label accesses",
  "introduced_in": [],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53403",
  "published": "2026-07-19",
  "subsystem": "fbdev",
  "title": "fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var",
  "introduced_in": [],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53402",
  "published": "2026-07-19",
  "subsystem": "fbdev",
  "title": "fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()",
  "introduced_in": [
   "5.10.249",
   "5.15.64",
   "5.19.6",
   "6.0"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53401",
  "published": "2026-07-19",
  "subsystem": "fbdev",
  "title": "fbdev: omap2: fix use-after-free in omapfb_mmap",
  "introduced_in": [],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53400",
  "published": "2026-07-19",
  "subsystem": "i2c",
  "title": "i2c: core: fix adapter registration race",
  "introduced_in": [
   "2.6.22"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53399",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: release layout stid on setlease failure",
  "introduced_in": [
   "4.0"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.39",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53398",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "NFSD: Fix SECINFO_NO_NAME decode error cleanup",
  "introduced_in": [
   "5.10.220",
   "5.15.154",
   "6.1"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53397",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: fix posix_acl leak on SETACL decode failure",
  "introduced_in": [
   "2.6.13"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53396",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: fix posix_acl leak and ignored error in nfsd4_create_file",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53395",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: fix dead ACL conflict guard in nfsd4_create",
  "introduced_in": [
   "7.0"
  ],
  "fixed_in": [
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53394",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race",
  "introduced_in": [
   "6.10"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53393",
  "published": "2026-07-19",
  "subsystem": "nfsd",
  "title": "nfsd: reset write verifier on deferred writeback errors",
  "introduced_in": [
   "5.10.124",
   "5.15.49",
   "5.17"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53392",
  "published": "2026-07-19",
  "subsystem": "NFSv4/flexfiles",
  "title": "NFSv4/flexfiles: reject zero filehandle version count",
  "introduced_in": [
   "4.0"
  ],
  "fixed_in": [
   "6.12.96",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53391",
  "published": "2026-07-19",
  "subsystem": "NFSv4/pNFS",
  "title": "NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr",
  "introduced_in": [
   "4.0"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53390",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: fix out-of-bounds read in smb_check_perm_dacl()",
  "introduced_in": [
   "5.15.210",
   "6.1.176",
   "6.6.140",
   "6.12.84",
   "6.18.25",
   "7.0.2",
   "7.1"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 8.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53389",
  "published": "2026-07-19",
  "subsystem": "net/tcp-ao",
  "title": "net/tcp-ao: fix use-after-free of key in del_async path",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53388",
  "published": "2026-07-19",
  "subsystem": "fuse",
  "title": "fuse: re-lock request before replacing page cache folio",
  "introduced_in": [
   "2.6.35"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53387",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: light: veml6075: add bounds check to veml6075_it_ms index",
  "introduced_in": [],
  "fixed_in": [
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53386",
  "published": "2026-07-19",
  "subsystem": "iio",
  "title": "iio: adc: ti-ads1298: add bounds check to pga_settings index",
  "introduced_in": [],
  "fixed_in": [
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53385",
  "published": "2026-07-19",
  "subsystem": "vc_screen",
  "title": "vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write",
  "introduced_in": [
   "4.14.327",
   "4.19.284",
   "5.4.244",
   "5.10.181",
   "5.15.113",
   "6.1.30",
   "6.3.4",
   "6.4"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53384",
  "published": "2026-07-19",
  "subsystem": "serial",
  "title": "serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails",
  "introduced_in": [
   "5.9"
  ],
  "fixed_in": [
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53383",
  "published": "2026-07-19",
  "subsystem": "ksmbd",
  "title": "ksmbd: reject non-VALID session in compound request branch",
  "introduced_in": [
   "5.15.121",
   "6.1.36",
   "6.3.10",
   "6.4"
  ],
  "fixed_in": [
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.5,
  "cvss_severity": "HIGH",
  "attack_vector": "Network"
 },
 {
  "cve": "CVE-2026-53382",
  "published": "2026-07-19",
  "subsystem": "media",
  "title": "media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si",
  "introduced_in": [
   "5.10"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53381",
  "published": "2026-07-19",
  "subsystem": "virtiofs",
  "title": "virtiofs: fix UAF on submount umount",
  "introduced_in": [
   "5.10.246",
   "5.15.196",
   "6.1.158",
   "6.6.115",
   "6.12.54",
   "6.17.4",
   "6.18"
  ],
  "fixed_in": [
   "5.10.260",
   "5.15.211",
   "6.1.177",
   "6.6.144",
   "6.12.95",
   "6.18.37",
   "7.0.14",
   "7.1.2",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53380",
  "published": "2026-07-19",
  "subsystem": "media",
  "title": "media: rzv2h-ivc: Fix concurrent buffer list access",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.9",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53379",
  "published": "2026-07-19",
  "subsystem": "media",
  "title": "media: i2c: ov8856: free control handler on error in ov8856_init_controls()",
  "introduced_in": [
   "5.1"
  ],
  "fixed_in": [
   "5.15.209",
   "6.1.175",
   "6.6.140",
   "6.12.90",
   "6.18.32",
   "7.0.9",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53378",
  "published": "2026-07-19",
  "subsystem": "drm/colorop",
  "title": "drm/colorop: Fix blob property reference tracking in state lifecycle",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.9",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53377",
  "published": "2026-07-19",
  "subsystem": "drm/msm",
  "title": "drm/msm: always recover the gpu",
  "introduced_in": [],
  "fixed_in": [
   "6.18.32",
   "7.0.9",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53376",
  "published": "2026-07-19",
  "subsystem": "drm/amdkfd",
  "title": "drm/amdkfd: Add upper bound check for num_of_nodes",
  "introduced_in": [],
  "fixed_in": [
   "6.6.140",
   "6.12.90",
   "6.18.32",
   "7.0.9",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53375",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu/vce",
  "title": "drm/amdgpu/vce: Prevent partial address patches",
  "introduced_in": [],
  "fixed_in": [
   "6.1.175",
   "6.6.140",
   "6.12.90",
   "6.18.32",
   "7.0.9",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53374",
  "published": "2026-07-19",
  "subsystem": "drm/amdgpu",
  "title": "drm/amdgpu: zero-initialize GART table on allocation",
  "introduced_in": [],
  "fixed_in": [
   "6.1.175",
   "6.6.140",
   "6.12.90",
   "6.18.32",
   "7.0.9",
   "7.1"
  ],
  "cvss_score": 8.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53373",
  "published": "2026-07-19",
  "subsystem": "mm/vma",
  "title": "mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()",
  "introduced_in": [
   "6.19"
  ],
  "fixed_in": [
   "7.0.9",
   "7.1"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53372",
  "published": "2026-07-19",
  "subsystem": "iommu/vt-d",
  "title": "iommu/vt-d: Block PASID attachment to nested domain with dirty tracking",
  "introduced_in": [
   "6.13"
  ],
  "fixed_in": [
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53371",
  "published": "2026-07-19",
  "subsystem": "RDMA/ionic",
  "title": "RDMA/ionic: bound node_desc sysfs read with %.64s",
  "introduced_in": [
   "6.18"
  ],
  "fixed_in": [
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53370",
  "published": "2026-07-19",
  "subsystem": "perf/x86/intel",
  "title": "perf/x86/intel: Improve validation and configuration of ACR masks",
  "introduced_in": [
   "6.16"
  ],
  "fixed_in": [
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53369",
  "published": "2026-07-19",
  "subsystem": "udf",
  "title": "udf: reject descriptors with oversized CRC length",
  "introduced_in": [
   "2.6.12"
  ],
  "fixed_in": [
   "5.10.258",
   "5.15.209",
   "6.1.175",
   "6.6.140",
   "6.12.88",
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": 8.4,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53368",
  "published": "2026-07-19",
  "subsystem": "f2fs",
  "title": "f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage",
  "introduced_in": [
   "3.18"
  ],
  "fixed_in": [
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": 7.1,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53367",
  "published": "2026-07-19",
  "subsystem": "selinux",
  "title": "selinux: fix avdcache auditing",
  "introduced_in": [
   "6.17.10",
   "6.18"
  ],
  "fixed_in": [
   "6.18.30",
   "7.0.7",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53366",
  "published": "2026-07-16",
  "subsystem": "ipv4",
  "title": "ipv4: account for fraggap on the paged allocation path",
  "introduced_in": [
   "6.0"
  ],
  "fixed_in": [
   "6.6.144",
   "6.12.95",
   "6.18.38",
   "7.1.3",
   "7.2"
  ],
  "cvss_score": 7.8,
  "cvss_severity": "HIGH",
  "attack_vector": "Local"
 },
 {
  "cve": "CVE-2026-53365",
  "published": "2026-07-13",
  "subsystem": "vsock/virtio",
  "title": "vsock/virtio: fix zerocopy completion for multi-skb sends",
  "introduced_in": [
   "6.7"
  ],
  "fixed_in": [
   "6.18.34",
   "7.0.11",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53364",
  "published": "2026-07-13",
  "subsystem": "Bluetooth",
  "title": "Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()",
  "introduced_in": [
   "6.16.4",
   "6.17"
  ],
  "fixed_in": [
   "6.18.35",
   "7.0.12",
   "7.1"
  ],
  "cvss_score": null,
  "cvss_severity": null,
  "attack_vector": null
 },
 {
  "cve": "CVE-2026-53363",
  "published": "2026-07-10",
  "subsystem": "xfrm",
  "title": "xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()",
  "introduced_in": [
   "6.14"
  ],
  "fixed_in": [
   "6.18.36",
   "7.0.13",
   "7.1"
  ],
  "cvss_score": 9.8,
  "cvss_severity": "CRITICAL",
  "attack_vector": "Network"
 }
]