Edition of July 19, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-64110 | 5.5 | 2.2 | Linux | Linux | CWE-401 | igc: fix potential skb leak in igc_fpe_xmit_smd_frame() |
| CVE-2026-64119 | 5.5 | 2.3 | Linux | Linux | — | l2tp: use list_del_rcu in l2tp_session_unhash |
| CVE-2026-64120 | 5.5 | 2.2 | Linux | Linux | CWE-476 | net: ethtool: fix NULL pointer dereference in phy_reply_size |
| CVE-2026-64130 | 5.5 | 2.2 | Linux | Linux | CWE-908 | mm/page_alloc: fix initialization of tags of the huge zero folio with init_on… |
| CVE-2026-64156 | 5.5 | 2.2 | Linux | Linux | — | netfs, afs: Fix write skipping in dir/link writepages |
| CVE-2026-64161 | 5.5 | 2.3 | Linux | Linux | CWE-401 | net: ti: icssm-prueth: fix eth_ports_node leak in probe |
| CVE-2026-53374 | 8.8 | 2.2 | Linux | Linux | — | drm/amdgpu: zero-initialize GART table on allocation |
| CVE-2026-53375 | 8.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vce: Prevent partial address patches |
| CVE-2026-63812 | 7.8 | 2.1 | Linux | Linux | — | f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() |
| CVE-2026-63851 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring |
| CVE-2026-63852 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring |
| CVE-2026-63854 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings |
| CVE-2026-63855 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings |
| CVE-2026-63856 | 7.8 | 2.2 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings |
| CVE-2026-63977 | 7.8 | 2.2 | Linux | Linux | — | dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work |
| CVE-2026-64017 | 7.8 | 2.2 | Linux | Linux | — | blk-mq: pop cached request if it is usable |
| CVE-2026-64057 | 7.8 | 2.2 | Linux | Linux | — | afs: Fix the locking used by afs_get_link() |
| CVE-2026-64082 | 7.8 | 2.2 | Linux | Linux | — | riscv: Fix register corruption from uninitialized cregs on error |
| CVE-2026-53379 | 5.5 | 2.2 | Linux | Linux | CWE-908 | media: i2c: ov8856: free control handler on error in ov8856_init_controls() |
| CVE-2026-64166 | 5.5 | 2.1 | Linux | Linux | CWE-476 | firmware: arm_ffa: Check for NULL FF-A ID table while driver registration |
| CVE-2026-64174 | 5.5 | 2.1 | Linux | Linux | — | wifi: cfg80211: advance loop vars in cfg80211_merge_profile() |
| CVE-2026-64151 | 8.4 | 2.1 | Linux | Linux | — | iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap |
| CVE-2026-63813 | 7.8 | 2.1 | Linux | Linux | — | Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" |
| CVE-2026-63819 | 7.8 | 2.0 | Linux | Linux | — | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() |
| CVE-2026-63853 | 7.8 | 2.1 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring |
| CVE-2026-63874 | 7.8 | 2.1 | Linux | Linux | — | net: mctp: usb: fix race between urb completion and rx_retry cancellation |
| CVE-2026-64163 | 5.5 | 2.1 | Linux | Linux | — | test_kprobes: clear kprobes between test runs |
| CVE-2026-64165 | 5.5 | 2.1 | Linux | Linux | CWE-476 | ARM: integrator: Fix early initialization |
| CVE-2026-64183 | 5.5 | 2.1 | Linux | Linux | CWE-476 | efi: Allocate runtime workqueue before ACPI init |
| CVE-2026-64154 | 5.5 | 2.0 | Linux | Linux | — | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() |
| CVE-2026-64185 | 5.5 | 1.9 | Linux | Linux | — | sysfs: don't remove existing directory on update failure |
| CVE-2026-53368 | 7.1 | 1.9 | Linux | Linux | — | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage |
| CVE-2026-64186 | 7.1 | 1.9 | Linux | Linux | CWE-125 | iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs |
| CVE-2026-64168 | 5.5 | 1.8 | Linux | Linux | CWE-476 | spi: sprd: fix error pointer deref after DMA setup failure |
| CVE-2026-64179 | 5.5 | 1.8 | Linux | Linux | CWE-401 | net: wwan: iosm: fix potential memory leaks in ipc_imem_init() |
| CVE-2026-64164 | 5.5 | 1.7 | Linux | Linux | CWE-476 | btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() |
| CVE-2026-64169 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: ep93xx: fix error pointer deref after DMA setup failure |
| CVE-2026-64170 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: qup: fix error pointer deref after DMA setup failure |
| CVE-2026-64173 | 5.5 | 1.7 | Linux | Linux | — | tracing: Do not call map->ops->elt_free() if elt_alloc() fails |
| CVE-2026-64177 | 5.5 | 1.7 | Linux | Linux | — | phonet/pep: disable BH around forwarded sk_receive_skb() |
| CVE-2026-64180 | 5.5 | 1.7 | Linux | Linux | — | mm/memory_hotplug: fix memory block reference leak on remove |
| CVE-2026-64182 | 5.5 | 1.7 | Linux | Linux | — | drivers/base/memory: fix memory block reference leak in poison accounting |
| CVE-2026-64184 | 5.5 | 1.7 | Linux | Linux | — | mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() |
| CVE-2026-63863 | 8.8 | 1.6 | Linux | Linux | — | drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm() |
| CVE-2026-64098 | 7.8 | 1.6 | Linux | Linux | CWE-667 | drm/virtio: use uninterruptible resv lock for plane updates |
| CVE-2026-53367 | 5.5 | 1.6 | Linux | Linux | — | selinux: fix avdcache auditing |
| CVE-2026-53371 | 5.5 | 1.6 | Linux | Linux | — | RDMA/ionic: bound node_desc sysfs read with %.64s |
| CVE-2026-53372 | 5.5 | 1.6 | Linux | Linux | — | iommu/vt-d: Block PASID attachment to nested domain with dirty tracking |
| CVE-2026-53373 | 7.8 | 1.6 | Linux | Linux | — | mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap() |
| CVE-2026-53380 | 7.8 | 1.6 | Linux | Linux | CWE-787 | media: rzv2h-ivc: Fix concurrent buffer list access |
| CVE-2026-63858 | 7.8 | 1.6 | Linux | Linux | — | netfilter: nf_tables: add hook transactions for device deletions |
| CVE-2026-64107 | 5.5 | 1.6 | Linux | Linux | CWE-476 | ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put() |
| CVE-2026-64143 | 5.5 | 1.6 | Linux | Linux | — | platform/x86: uniwill-laptop: Do not enable the charging limit even when forced |
| CVE-2026-64146 | 5.5 | 1.6 | Linux | Linux | CWE-401 | erofs: fix metabuf leak in inode xattr initialization |
| CVE-2026-64152 | 7.8 | 1.4 | Linux | Linux | — | iommu: Handle unmap error when iommu_debug is enabled |
| CVE-2026-64159 | 5.5 | 1.3 | Linux | Linux | — | netfs: Fix zeropoint update where i_size > remote_i_size |
| CVE-2026-63811 | await | 1.2 | Linux | Linux | — | f2fs: read COW data with the original inode during atomic write |
| CVE-2026-53400 | 7.8 | 1.1 | Linux | Linux | CWE-362 | i2c: core: fix adapter registration race |
| CVE-2026-53378 | 5.5 | 1.0 | Linux | Linux | CWE-401 | drm/colorop: Fix blob property reference tracking in state lifecycle |
| CVE-2026-64167 | 5.5 | 1.0 | Linux | Linux | CWE-476 | kho: skip KHO for crash kernel |
| CVE-2026-64112 | 7.8 | 0.9 | Linux | Linux | CWE-367 | rbd: eliminate a race in lock_dwork draining on unmap |
| CVE-2026-64100 | 5.5 | 0.9 | Linux | Linux | CWE-667 | drm/msm: Fix shrinker deadlock |
| CVE-2026-64158 | 7.3 | 0.4 | Linux | Linux | — | netfs: Fix write streaming disablement if fd open O_RDWR |
| CVE-2026-16213 | 4.8 | 0.2 | Fantomas42 | django-blog-zinnia | CWE-310 | Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cl… |
| CVE-2026-64171 | 5.5 | 0.2 | Linux | Linux | CWE-667 | i2c: tegra: fix pm_runtime leak on mutex_lock failure |