Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-63905 — usbip: vudc: Fix use after free bug in vudc_remove due to race condition

In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: Fix use after free bug in vudc_remove due to race condition This patch follows up Zheng Wang's 2023 report of a use-…

linux_kernel | Race Condition
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63904 — usb: usbtmc: check URB actual_length for interrupt-IN notifications

In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: check URB actual_length for interrupt-IN notifications USBTMC devices can use an optional interrupt endpoint for not…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63903 — USB: serial: belkin_sa: validate interrupt status length

In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt callback treats interrupt data as a four-byte statu…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63902 — USB: serial: cypress_m8: validate interrupt packet headers

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: validate interrupt packet headers cypress_read_int_callback() parses the interrupt-in buffer according t…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63901 — USB: serial: digi_acceleport: fix memory corruption with small endpoints

In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix memory corruption with small endpoints Add the missing bulk-out buffer size sanity checks to av…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63900 — USB: serial: keyspan: fix missing indat transfer sanity check

In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan: fix missing indat transfer sanity check Add the missing sanity check on the size of usa49wg indat transfers…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63899 — USB: serial: mxuport: fix memory corruption with small endpoint

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least …

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63898 — USB: serial: mct_u232: fix memory corruption with small endpoint

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific de…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63897 — USB: serial: mct_u232: fix missing interrupt-in transfer sanity check

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix missing interrupt-in transfer sanity check Add the missing sanity check on the size of interrupt-in tr…

linux_kernel | Information Disclosure
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63896 — usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling The WebUSB GET_URL handler in composite_setup() narrows …

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63895 — usb: gadget: f_fs: copy only received bytes on short ep0 read

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: copy only received bytes on short ep0 read ffs_ep0_read() allocates its control-OUT data buffer with kmalloc()…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
7.8 HIGH
CVE-2026-63894 — usb: gadget: f_fs: serialize DMABUF cancel against request completion

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: serialize DMABUF cancel against request completion ffs_epfile_dmabuf_io_complete() calls usb_ep_free_request()…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
8.1 HIGH
CVE-2026-63893 — thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is perf…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63892 — thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_l…

linux_kernel | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63891 — thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset…

linux_kernel | Denial of Service
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
0.0 NA
CVE-2026-63890 — scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker

In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() adv…

linux_kernel | Denial of Service
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
8.1 HIGH
CVE-2026-63889 — scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32

In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN E…

linux_kernel | Denial of Service
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
9.8 CRITICAL
CVE-2026-63888 — scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both…

linux_kernel | Remote | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
9.8 CRITICAL
CVE-2026-63887 — scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" re…

linux_kernel | Remote | Memory Corruption
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
9.8 CRITICAL
CVE-2026-63886 — scsi: target: iscsi: Validate CHAP_R length before base64 decode

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(ch…

linux_kernel | Remote | Misconfiguration
Jul 19, 2026 Jul 27, 2026
Jul 19, 2026
Jul 27, 2026
Showing 20 of 11491 Results