CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jul 20, 2026

WordPress Social Login, Passkeys, Magic Link & Email OTP Plugin Passwordless Login Vulnerability Allowing Unauthenticated Account Takeover

A vulnerability exists in the Social Login, Passkeys, Magic Link & Email OTP WordPress plugin in versions prior to 1.4.1. The plugin fails to implement rate limiting or effective attempt lockout on its passwordless email one-time-password (OTP) verification process. Additionally, the short numeric codes are stored in plaintext. This allows an unauthenticated attacker with knowledge of a registered email address to brute-force the OTP code and gain access to the corresponding user account, including those of administrators, potentially leading to a complete site takeover.

4.3
Jul 20, 2026

PayPlus Payment Gateway WordPress Plugin Unauthenticated Order Key Disclosure and Status Modification Vulnerability

A vulnerability exists in the PayPlus Payment Gateway WordPress plugin in versions prior to 8.2.2. The issue arises because the plugin's AJAX actions, accessible to unauthenticated users, lack proper authorization and order-ownership validation. This flaw enables the disclosure of secret order keys for arbitrary WooCommerce orders and, in some cases, allows modification of order statuses.

5.6
Jul 20, 2026

PayPlus Payment Gateway WordPress Plugin Unauthenticated Order Metadata Tampering Vulnerability

A vulnerability exists in the PayPlus Payment Gateway WordPress plugin in versions prior to 8.2.2. The issue arises because the plugin's AJAX action, available to unauthenticated users, lacks proper authorization and order-ownership validation. This oversight allows users to manipulate payment-related metadata for any WooCommerce order.

5.6
Jul 20, 2026

LearnPress WordPress Plugin Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the LearnPress WordPress plugin, affecting versions prior to 4.4.1. The issue arises because the plugin fails to properly escape a search parameter before reflecting it into an HTML attribute. This flaw allows an attacker to execute malicious scripts in the browser of a logged-in instructor or administrator who is deceived into clicking a crafted link.

6.9
Jul 20, 2026

All-in-One WP Migration and Backup WordPress Plugin Path Traversal Vulnerability Allowing Unauthenticated Arbitrary Log File Write

A vulnerability exists in the All-in-One WP Migration and Backup WordPress plugin in versions prior to 7.106. The issue arises because the plugin fails to properly sanitize user-supplied values before using them to construct file paths. This flaw allows unauthenticated attackers to create or append log files in arbitrary locations outside the plugin's designated storage directory.

8.2
Jul 20, 2026

Kirki WordPress Plugin Unauthenticated HTML Injection Vulnerability in Password Reset Email

A vulnerability exists in the Kirki WordPress plugin in versions prior to 6.0.12, where the plugin fails to properly sanitize or escape the email subject and body values before including them in the password reset email. This oversight allows unauthenticated users to inject arbitrary HTML into the message sent to registered users, potentially facilitating phishing attacks.

4.3
Jul 20, 2026

Kirki WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Comment Modification and Moderation Bypass

A vulnerability exists in the Kirki WordPress plugin in versions prior to 6.0.12, where one of its REST routes lacks proper authorization checks. This flaw enables unauthenticated users to overwrite the content of existing comments and to create pre-approved comments under a false identity, circumventing the comment moderation process.

4.8
Jul 20, 2026

SlimStat Analytics WordPress Plugin Unauthenticated Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the SlimStat Analytics WordPress plugin, affecting versions prior to 5.5.0. The issue arises because the plugin fails to properly escape geolocation values controlled by visitors before displaying them in admin analytics reports. This flaw allows unauthenticated visitors to inject a cross-site scripting payload that is executed in the browser of an administrator viewing the reports. Exploitation requires the plugin to be set up with the Cloudflare geolocation provider.

6.5
Jul 20, 2026

WP Travel WordPress Plugin Unauthenticated Arbitrary Booking Cancellation Vulnerability

A vulnerability exists in the WP Travel WordPress plugin in versions prior to 11.7.1, where the booking cancellation action lacks proper capability and ownership checks. This flaw is accessible to unauthenticated users, enabling them to cancel any booking on the site.

4.7
Jul 20, 2026

Modern Event Calendar WordPress Plugins Unauthenticated SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Modern Event Calendar Pro and Modern Events Calendar Lite WordPress plugins, both prior to version 7.34.0. The vulnerability arises because the plugins do not properly sanitize and escape a request parameter before incorporating it into a SQL statement. This issue is accessible through an AJAX action available to unauthenticated users, allowing attackers to exploit the vulnerability and extract sensitive data from the database.

7.3
Jul 20, 2026

All in One SEO WordPress Plugin Incorrect Authorization Vulnerability in AI Integration REST API

A vulnerability exists in the All in One SEO WordPress plugin in versions prior to 4.9.9, where access to certain AI integration REST API endpoints is not properly restricted. This flaw allows users with low-level privileges, such as Contributors, to overwrite or reset the site-wide AI integration state.

7.4
Jul 20, 2026

Reviews Feed WordPress Plugin Unauthenticated Stored Arbitrary Shortcode Execution Vulnerability

A vulnerability exists in the Reviews Feed WordPress plugin in versions prior to 2.6.5. The issue arises because the plugin fails to properly sanitize WordPress shortcodes in third-party review content before displaying it through its dynamic block. This oversight allows unauthenticated attackers to execute arbitrary shortcodes on pages that showcase the feed by inserting a shortcode into a review on the connected source.

6.3
Jul 20, 2026

Unlimited Elements For Elementor WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Unlimited Elements for Elementor WordPress plugin, affecting versions prior to 2.0.11. The issue arises because the plugin fails to properly sanitize or escape Google review content retrieved from the Serp API before displaying it in the Google Reviews widget. This oversight allows unauthenticated attackers to inject malicious reviews into the targeted business's Google listing, which are then executed as scripts when viewed by any visitor, including administrators, on WordPress pages that showcase those reviews.

6.8
Jul 20, 2026

CI4MS Stored Cross-Site Scripting Vulnerability via HTML Purification Bypass

A stored cross-site scripting vulnerability has been identified in CI4MS, a CodeIgniter 4-based content management system, in versions prior to 0.31.9.0. The issue arises from a custom 'html_purify' validation rule intended to sanitize blog post content. This rule relies on by-reference mutation, but CodeIgniter's validation system only passes a local copy of the data, causing the sanitized output to be discarded. As a result, raw HTML, including JavaScript, is stored in the database and executed in the browsers of all visitors, including superadmins, when posts are previewed or edited.

3.9
Jul 20, 2026

Meshtastic GitHub Actions Workflow Fork Checkout Vulnerability Allowing Arbitrary Code Execution

A critical vulnerability has been identified in the Meshtastic GitHub repository's main_matrix.yml workflow, prior to version 2.7.21.1370b23. This vulnerability arises from the workflow being triggered by pull_request_target, which allows external contributors to execute code from their forks with access to repository secrets and elevated GITHUB_TOKEN permissions. The absence of an approval gate means that pull requests from external users can automatically trigger this workflow. The vulnerability could lead to a supply chain compromise, a takeover of the repository, and a compromise of self-hosted GitHub runners.

4.6
Jul 20, 2026

Meshtastic User Long Name Encoding Vulnerability Causes Bluetooth Management Failure

A vulnerability in Meshtastic firmware versions through 2.7.22.96dd647 allows a single node to broadcast a User.long_name with malformed character encoding. This can disrupt the functionality of other radios over Bluetooth Low Energy (BLE) when managed through the iOS app. The issue can arise from normal buffer truncation, leaving a corrupted name in the node database. The iOS app's encoding validation fails to parse databases with such errors, causing a control loss over the affected device. This problem can degrade BLE management for iOS users across a wide area, making devices effectively unusable until the corrupted entry is removed or ages out of the database.

3.0
Jul 19, 2026

Keras-Team Keras Unsafe Deserialization Vulnerability in TorchModuleWrapper

A vulnerability exists in Keras-Team Keras version 3.15.0, allowing unsafe deserialization of attacker-controlled PyTorch pickle data through the public `TorchModuleWrapper.from_config` method. This method calls `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as `safe_mode=False`. When not within a `SafeModeScope(True)` context, the lack of an ambient safe mode state defaults to allowing unsafe deserialization. This vulnerability could lead to arbitrary code execution if untrusted Keras layer configurations are processed with this method.

4.2
Jul 19, 2026

Linux Kernel IOMMU Debugfs Out-of-Bounds Access Vulnerability

A vulnerability in the Linux kernel's IOMMU debugfs for AMD can lead to out-of-bounds memory access. The issue arises in the 'iommu_mmio_write()' and 'iommu_capability_write()' functions, where the 'dbg_mmio_offset' and 'dbg_cap_offset' variables are declared as integers but are populated using 'kstrtou32_from_user()'. This can allow a user to input a large value that is interpreted as a negative integer, potentially causing an out-of-bounds access. Although the AMD IOMMU debugfs implementation had some protections in place, such as limiting user input to 8 bytes and catching negative values during read operations, these measures were not sufficient to prevent the vulnerability. The issue has been addressed by changing the input parsing function to 'kstrtos32_from_user()', which allows for the detection of negative values, and by adding explicit checks in the write functions to prevent out-of-bounds accesses.

6.5
Jul 19, 2026

Linux Kernel Sysfs Directory Management Vulnerability on Update Failure

A vulnerability in the Linux kernel's sysfs directory management can lead to unintended consequences when updating named groups. If the file creation process fails, the system erroneously removes the associated directory, disrupting the sysfs group that was not user-created. This issue affects the Linux kernel stable tree.

6.2
Jul 19, 2026

Linux Kernel Memory Cgroup Reference Leak Vulnerability in DAMON Sysfs Schemes

A vulnerability in the Linux kernel's memory management subsystem, specifically within the DAMON (Data Access Monitor) framework, has been addressed. The issue arose because the function 'damon_sysfs_memcg_path_to_id()'' improperly exited a loop iterating over memory cgroups without calling 'mem_cgroup_iter_break()'. This oversight led to a leak of the cgroup reference. The vulnerability affects the Linux kernel stable tree, particularly versions 6.3.x. The problem has been fixed by ensuring 'mem_cgroup_iter_break()' is called before exiting the loop, thereby preventing the reference leak.

6.5
Jul 19, 2026

Linux Kernel ACPI PRM Runtime Workqueue Initialization Vulnerability

A vulnerability in the Linux kernel's handling of ACPI PRM calls can lead to NULL pointer dereferences. This issue arises because PRM accesses may occur before the EFI subsystem is fully initialized, specifically before the workqueue required to handle these calls is allocated. The problem is related to the order of initialization calls, which can be sensitive to dependencies. As a result, the vulnerability affects the Linux kernel's EFI runtime services, particularly in the context of ACPI PRM handling.

6.4
Jul 19, 2026

Linux Kernel Memory Block Reference Leak Vulnerability in Poison Accounting

A vulnerability exists in the Linux kernel's memory management system, specifically within the poison accounting feature. The issue arises in the 'drivers/base/memory' component, where the functions 'memblk_nr_poison_inc()' and 'memblk_nr_poison_sub()' improperly handle references to memory block devices. These functions look up memory blocks by their IDs, acquiring a reference to the corresponding device. However, they fail to release this reference after use, leading to a memory leak with each successful lookup. The vulnerability affects several versions of the Linux kernel.

6.5
Jul 19, 2026

Linux Kernel PMD Special Handling Vulnerability on x86 32-bit THP

A vulnerability in the Linux kernel's memory management for transparent huge pages (THP) on x86 32-bit architectures has been addressed. The issue arose because the _PAGE_SPECIAL bit was not set in the huge_zero page middle directory (PMD), leading to warnings and errors when the system attempted to reclaim memory. This oversight occurred because the PMD special handling is not enabled on 32-bit architectures, causing huge zero folios to be incorrectly accounted as file-backed, among other issues. The vulnerability was introduced in a previous commit that modified how normal pages are handled, and it could trigger warnings about the page state that, while problematic, had not been reported before.

6.4
Jul 19, 2026

Linux Kernel Memory Block Reference Leak Vulnerability

A memory block reference leak vulnerability has been identified in the Linux kernel's memory hotplug management. This issue arises in the 'remove_memory_blocks_and_altmaps' function, where the 'find_memory_block' method acquires a reference to the memory block device but fails to release it. As a result, the reference leak occurs when memory blocks and their alternative maps are removed. This vulnerability affects the Linux kernel stable tree.

6.5
Jul 19, 2026

Linux Kernel Memory Leak Vulnerability in IPC Interface

A memory leak vulnerability has been identified in the Linux kernel's IPC interface for the IOSM driver. The issue arises in the 'ipc_imem_init()' function, where memory allocated by 'ipc_protocol_init()' is not properly released on error paths. This oversight can lead to memory leaks, as the allocated resources are not freed when the initialization process encounters a failure.

6.5
Jul 19, 2026

Linux Kernel Bluetooth BNEP Use-After-Free Vulnerability in Connection Management

A use-after-free vulnerability has been addressed in the Linux kernel's Bluetooth BNEP (Bluetooth Network Encapsulation Protocol) implementation. The issue arises in the 'bnep_add_connection()' function, which failed to properly synchronize access to the 'dev->name' property of a network device. This oversight allowed a concurrent thread, handling the removal of a BNEP connection, to free the network device while it was still being accessed, leading to a potential use-after-free scenario. Although this vulnerability is not considered highly security-sensitive—since adding a BNEP connection requires administrative privileges and involves dismantling a network device during a brief, vulnerable period— it could still be exploited under specific conditions.

6.2
Jul 19, 2026

Linux Kernel iwlwifi Driver TX Rate Handling Vulnerability on Legacy Devices

A vulnerability exists in the Linux kernel's iwlwifi driver, specifically in the management of transmission (TX) rates for older devices like the 7265D. These devices still use an outdated rate encoding system that relies on Physical Layer Convergence Protocol (PLCP) values instead of the newer CCK/OFDM rate indices. The issue arose when the driver was updated to support a new rate version, leading to incorrect TX rate commands being sent to the device. This mismanagement could cause warnings when the device reported its used rates, potentially disrupting wireless communication.

6.0
Jul 19, 2026

Linux Kernel iwlwifi Driver Firmware Restart Transmission Issue Causes Denial-of-Service

A denial-of-service vulnerability has been identified in the Linux kernel's iwlwifi Wi-Fi driver, specifically in the MLD (Multi-Link Device) handling. This issue arises when the iwlwifi firmware crashes, such as during NMI_INTERRUPT_UNKNOWN events on Intel BE201 chipsets with Wi-Fi 7. The crash triggers a flag indicating that the firmware is restarting, but the driver fails to pause transmission before dequeuing frames from the mac80211 layer. As a result, the driver attempts to send these frames while the firmware is unresponsive, leading to a loop where failed transmission attempts are quickly freed, causing excessive CPU usage and memory fragmentation. This problem has been observed under heavy network conditions, such as with Tailscale UDP traffic or active SSH sessions, and has been tested on an ASUS Zenbook 14 UX3405CA.

6.4
Jul 19, 2026

Linux Kernel cfg80211 Multi-BSSID Profile Handling Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Linux kernel's cfg80211 wireless configuration subsystem. The issue arises in the 'cfg80211_merge_profile()' function, which processes Multi-BSSID profiles that are split across multiple elements. The vulnerability occurs because the function's loop does not properly advance its element pointers, causing it to repeatedly process the same data. This flaw can be exploited by sending specially crafted malicious beacons, leading the kernel to spend excessive time handling each one—potentially up to 2 milliseconds per beacon. This unnecessary processing time could be abused to degrade system performance.

6.9
Jul 19, 2026

Linux Kernel Tracing Map Element Memory Management Vulnerability

A vulnerability exists in the Linux kernel's handling of tracing map elements, specifically in the memory management functions. When the element allocation function fails, the corresponding free function should not be called. However, the current implementation incorrectly attempts to free memory for elements that were not successfully allocated, which can lead to memory management issues.

6.5
Jul 19, 2026

Linux Kernel Hygon Family 18h CPUs KVM AVIC IPI Virtualization Vulnerability

A vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) module for Hygon Family 18h CPUs has been addressed. These CPUs, derived from AMD Family 17h (Zen1), share a specific erratum (#1235) that can disrupt virtual interrupt handling. During emulation of interrupt control writes, the hardware may incorrectly read a stale 'IsRunning' bit, failing to signal when a virtual CPU is not active. This oversight prevents KVM from waking up blocked target virtual CPUs, causing them to hang and delaying guest execution. The issue has been resolved by extending the existing workaround for AMD Family 17h to also include Hygon Family 18h, ensuring proper virtualization of interrupt processing and preventing execution delays.

6.0
Jul 19, 2026

Linux Kernel Runtime Power Management Leak Vulnerability in Tegra I2C Driver

A vulnerability exists in the Linux kernel's Tegra I2C driver, where a failure to acquire a mutex lock leads to a leak of the runtime power management reference. This leak occurs because the function does not release the reference after a lock failure, preventing the device from entering a low-power suspend state. The issue has been addressed by adding the missing reference release before returning from the function on lock failure.

6.2
Jul 19, 2026

Linux Kernel QUP SPI Controller DMA Pointer Dereference Vulnerability

A vulnerability in the Linux kernel's SPI QUP driver can lead to a null pointer dereference after a failed DMA setup. When the DMA initialization fails, the driver correctly reverts to PIO mode but neglects to clear the DMA channel pointers. This oversight can cause the driver to later dereference an error pointer or attempt to release a DMA channel multiple times, potentially leading to a use-after-free condition. The issue was identified during a review of a devres allocation conversion patch.

6.6
Jul 19, 2026

Linux Kernel Cirrus EP93XX SPI Driver Error Pointer Dereference Vulnerability

A vulnerability in the Linux kernel's SPI driver for Cirrus EP93XX devices can lead to an error pointer dereference. This issue occurs because the driver does not properly clear DMA channel pointers when DMA setup fails, causing the driver to fall back on PIO mode. The problem was identified during a review of a devres allocation conversion patch.

6.4
Jul 19, 2026

Linux Kernel Pointer Dereference Vulnerability in SPI SPRD Driver After DMA Setup Failure

A vulnerability has been addressed in the Linux kernel's SPI SPRD driver, related to improper handling of pointer dereferencing after a failed Direct Memory Access (DMA) setup. During the probe process, if the DMA configuration fails, the driver reverts to Programmed Input/Output (PIO) mode. However, the driver did not initially verify whether DMA was enabled before attempting to release the DMA channels, particularly in cases of late probe errors. This oversight could lead to dereferencing an error pointer or unnecessarily releasing a DMA channel multiple times. The issue was identified by a developer named Sashiko while reviewing a patch related to resource allocation.

6.6
Jul 19, 2026

Linux Kernel Kexec Handover KHO Crash Kernel Vulnerability

A vulnerability in the Linux kernel's handling of Kexec images can lead to crashes when using crash kernels. The issue arises because the Kexec Handover (KHO) metadata is improperly applied to crash kernel images, which operate in a limited reserved memory area. This misallocation can cause the crash kernel to fault during initialization by attempting to access KHO data located outside its available memory. The problem has been addressed by modifying the KHO handling function to skip Kexec logic for crash kernels, ensuring that the KHO metadata does not interfere with the crash kernel's operation.

6.0
Jul 19, 2026

Linux Kernel NULL Pointer Dereference Vulnerability in FF-A Driver Registration

A vulnerability in the Linux kernel's handling of firmware drivers using the ARM Fast Functionality Architecture (FF-A) has been addressed. The issue arose because the bus match callback expected every FF-A driver to provide an ID table, which it accessed without checking for null values. This oversight could allow a faulty driver to crash the bus during the matching process. The vulnerability affects the Linux kernel stable tree.

6.5
Jul 19, 2026

Linux Kernel ARM Integrator Early Initialization Crash Vulnerability

A vulnerability in the Linux kernel's ARM Integrator platform has been addressed. The issue arose during early initialization when the 'intcp_init_early' function called 'syscon_regmap_lookup_by_compatible'. This sequence attempted to allocate memory before the memory management system was ready, leading to failures that either returned an error or caused a kernel crash due to a null pointer dereference. This problem was particularly reproducible with certain versions of the GCC compiler, which dereferenced the null pointer under specific conditions. The crash could be avoided, but doing so would prevent the necessary scheduling clock initialization from occurring. The vulnerability has been fixed by relocating the early initialization code to the standard machine initialization phase, ensuring that the memory management system is fully operational before any allocations are attempted.

6.8
Jul 19, 2026

Linux Kernel Btrfs Component Sleep Vulnerability in Atomic Context

A vulnerability exists in the Linux kernel's Btrfs file system component, specifically within the trace event 'btrfs_sync_file()'. This event is executed in an atomic context, where certain operations that can sleep are not permitted. The issue arises because 'btrfs_sync_file()' calls 'dput()', needed for 'dget_parent()', which can sleep and disrupt the atomic context, causing a kernel warning. This vulnerability can be reproduced by enabling the 'btrfs_sync_file' trace event and running the 'btrfs/056' test from the 'fstests' suite. The resulting kernel warning indicates that a sleeping function was called from an invalid context, violating the requirements for atomic operations.

6.5
Jul 19, 2026

Linux Kernel Kprobes Test Suite Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Linux kernel's kprobes test suite. When the kprobes sanity tests are run twice, all tests fail and the kernel eventually crashes. This issue arises because the test suite defines several kprobes and kretprobes as static variables that persist across test runs. After a kprobe is registered and then unregistered, it retains some residual data that must be cleared before it can be registered again. The tests set the symbol_name to define the probe location, and both the address and flags need to be cleared. While the existing code clears some probes between subsequent tests, it does not do so between two test runs. The leftover data from the first test run causes the registrations to fail in the next run, leading to a crash. The vulnerability affects the Linux kernel stable tree.

6.5
Jul 19, 2026

Linux Kernel IDPF Driver Read Clock Lock Initialization Vulnerability

A vulnerability exists in the Linux kernel's IDPF driver related to the improper initialization of a spinlock used for managing access to a clock register. This issue arises because the lock is initialized after a worker thread has already been scheduled, creating a race condition. The scheduled worker can access the uninitialized lock, leading to a warning from the kernel's lock dependency checker about a 'non-static key' registration issue. This vulnerability affects the Linux kernel stable tree.

6.4
Jul 19, 2026

Linux Kernel ICSSM PRUETH Ethernet Driver Eth Ports Node Leak Vulnerability

A memory leak vulnerability has been identified in the ICSSM PRUETH Ethernet driver of the Linux kernel. This issue arises in the 'icssm_prueth_probe' function, where the 'eth_ports_node' is not properly released after a failure in reading a property. The node, acquired before iterating through child nodes, is left dangling, leading to a resource leak.

6.5
Jul 19, 2026

Linux Kernel Netfs Size Management Vulnerability Allows for Data Tearing

A vulnerability in the Linux kernel's netfs component can lead to data tearing issues in the size management of files. This problem arises in the handling of remote file sizes and zero-point indicators, which are crucial for ensuring data consistency during file operations. The vulnerability is present in the stable Linux kernel and affects various file systems that utilize the netfs library, including AFS and CIFS.

6.4
Jul 19, 2026

Linux Kernel Netfs Zero Point Update Vulnerability

A vulnerability in the Linux kernel's netfs component affects the handling of the zero point update during the release of folios. This issue arises when there is uncommitted data in the page cache beyond the folio being released, but the on-server end-of-file (EOF) is within that folio. In such cases, the update incorrectly relies on the local file size, rather than the remote size tracked by the server. This vulnerability can lead to read gaps, where the system prematurely hits EOF, causing short reads. The issue was discovered using the fsx test tool, specifically with the CIFS file system and default caching options.

6.4
Jul 19, 2026

Linux Kernel Netfs Write Streaming Disablement Vulnerability

A vulnerability in the Linux kernel's netfs component has been addressed. The issue involved the improper management of 'write streaming' when a file descriptor is opened with read and write permissions. This streaming, which caches dirty data to prevent unnecessary reads before overwriting, was incorrectly disabled for O_RDWR file descriptors. The netfs now automatically manages read gaps, making the flush requirement obsolete. The fix removes the O_RDWR check, restoring proper streaming functionality. This vulnerability had caused issues with the generic/522 xfstest, which have now been resolved.

6.5
Jul 19, 2026

Linux Kernel Netfs Partial Invalidation of Streaming-Write Folio Vulnerability

A vulnerability exists in the Linux kernel's netfs component, specifically in the handling of partial invalidations of streaming-write folios. When a partial invalidation overlaps with dirty write data cached in a streaming write page, the netfs_invalidate_folio() function incorrectly adjusts the dirty region by moving it forward, rather than properly aligning it with the end of the invalidation. This issue affects several versions of the Linux kernel.

6.5
Jul 19, 2026

Linux Kernel Netfs AFS Write Skipping Vulnerability in Writeback Handling

A vulnerability in the Linux kernel's handling of write operations in the netfs and AFS file systems has been addressed. The issue arose because the writeback functions netfs_write_single() and afs_single_writepages() did not properly manage writes that were skipped due to lock contention and a specific writeback synchronization mode. This could lead to inconsistencies, as the virtual file system (VFS) might have cleared the dirty inode mark after a skipped write, potentially causing data loss. The vulnerability was primarily theoretical for directories, as the issue could only be encountered through a serialized path that validated locks, complicating write operations.

6.0
Jul 19, 2026

Linux Kernel ath11k WMI WOW Calls Error Path Leak Vulnerability

A vulnerability in the Linux kernel's ath11k wireless driver has been addressed, which involved improper error handling in certain Wake on Wireless (WoW) commands. The issue arose because the return value of a command sending function was not checked, leading to a failure to free a buffer in case of an error. This vulnerability affects the Linux kernel stable tree.

6.5
Jul 19, 2026

Linux Kernel Reference Leak Vulnerability in Adreno A6XX GPU Initialization

A reference leak vulnerability has been identified in the Linux kernel's handling of Adreno A6XX GPUs. The issue arises in the 'a6xx_gpu_init()' function, where a device node is parsed but not properly released in all error scenarios, leading to a memory leak. This vulnerability affects the Linux kernel stable tree.

6.0
Jul 19, 2026

Linux Kernel IOMMU Return Value Handling Vulnerability in DRM MSM

A vulnerability in the Linux kernel's DRM MSM component has been addressed. The issue arose because the IOMMU mapping function was not properly handling error return values. Instead of returning a negative error code when an issue occurred, it would issue a warning and return a zero, which could lead to incorrect behavior. This vulnerability affects the Linux kernel stable tree.

6.5