Security Box Score — July 19, 2026 — page 2
Edition of July 19, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-63794 | 7.8 | 3.7 | Linux | Linux | CWE-787 | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path |
| CVE-2026-64152 | 7.8 | 3.7 | Linux | Linux | — | iommu: Handle unmap error when iommu_debug is enabled |
| CVE-2026-63818 | 8.4 | 3.6 | Linux | Linux | — | f2fs: validate orphan inode entry count |
| CVE-2026-63815 | 8.4 | 3.5 | Linux | Linux | — | f2fs: bound i_inline_xattr_size for non-inline-xattr inodes |
| CVE-2026-53381 | 7.8 | 3.5 | Linux | Linux | CWE-416 | virtiofs: fix UAF on submount umount |
| CVE-2026-63807 | 8.8 | 3.3 | Linux | Linux | CWE-125 | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level |
| CVE-2026-63804 | 7.8 | 3.3 | Linux | Linux | CWE-416 | gfs2: fix use-after-free in gfs2_qd_dealloc |
| CVE-2026-64139 | 5.5 | 3.3 | Linux | Linux | CWE-401 | ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow |
| CVE-2026-64112 | 7.8 | 3.2 | Linux | Linux | CWE-367 | rbd: eliminate a race in lock_dwork draining on unmap |
| CVE-2026-53402 | 7.1 | 3.2 | Linux | Linux | CWE-125 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() |
| CVE-2026-63817 | 7.8 | 3.1 | Linux | Linux | — | f2fs: validate compress cache inode only when enabled |
| CVE-2026-53388 | 7.8 | 3.0 | Linux | Linux | CWE-416 | fuse: re-lock request before replacing page cache folio |
| CVE-2026-63803 | 7.8 | 3.0 | Linux | Linux | CWE-416 | hdlc_ppp: sync per-proto timers before freeing hdlc state |
| CVE-2026-63802 | 7.8 | 3.0 | Linux | Linux | CWE-416 | blk-cgroup: fix UAF in __blkcg_rstat_flush() |
| CVE-2026-53382 | 5.5 | 3.0 | Linux | Linux | CWE-476 | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si |
| CVE-2026-53385 | 5.5 | 3.0 | Linux | Linux | CWE-476 | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write |
| CVE-2026-63828 | 8.4 | 2.9 | Linux | Linux | — | apparmor: mediate the implicit connect of TCP fast open sendmsg |
| CVE-2026-63824 | 7.8 | 2.8 | Linux | Linux | — | KEYS: fix overflow in keyctl_pkey_params_get_2() |
| CVE-2026-53403 | 5.5 | 2.8 | Linux | Linux | CWE-476 | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var |
| CVE-2026-53393 | 5.5 | 2.8 | Linux | Linux | — | nfsd: reset write verifier on deferred writeback errors |
| CVE-2026-64090 | 5.5 | 2.7 | Linux | Linux | — | batman-adv: tt: avoid empty VLAN responses |
| CVE-2026-64092 | 5.5 | 2.7 | Linux | Linux | — | batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown |
| CVE-2026-63811 | await | 2.7 | Linux | Linux | — | f2fs: read COW data with the original inode during atomic write |
| CVE-2026-53374 | 8.8 | 2.6 | Linux | Linux | — | drm/amdgpu: zero-initialize GART table on allocation |
| CVE-2026-53375 | 8.8 | 2.6 | Linux | Linux | — | drm/amdgpu/vce: Prevent partial address patches |
| CVE-2026-63829 | 8.8 | 2.6 | Linux | Linux | — | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-63814 | 7.8 | 2.6 | Linux | Linux | — | f2fs: validate ACL entry sizes in f2fs_acl_from_disk() |
| CVE-2026-64145 | 7.8 | 2.6 | Linux | Linux | CWE-787 | wifi: wilc1000: fix dma_buffer leak on bus acquire failure |
| CVE-2026-64147 | 5.5 | 2.6 | Linux | Linux | CWE-401 | pds_core: fix debugfs_lookup dentry leak and error handling |
| CVE-2026-63816 | 7.8 | 2.5 | Linux | Linux | — | f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode |
| CVE-2026-64103 | 7.8 | 2.5 | Linux | Linux | CWE-416 | scsi: isci: Fix use-after-free in device removal path |
| CVE-2026-64121 | 7.1 | 2.5 | Linux | Linux | CWE-125 | net: ifb: report ethtool stats over num_tx_queues |
| CVE-2026-63798 | 5.5 | 2.5 | Linux | Linux | CWE-401 | irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove |
| CVE-2026-64101 | 5.5 | 2.5 | Linux | Linux | — | fwctl: pds: Validate RPC input size before parsing |
| CVE-2026-64017 | 7.8 | 2.4 | Linux | Linux | — | blk-mq: pop cached request if it is usable |
| CVE-2026-63833 | 7.1 | 2.4 | Linux | Linux | — | ntfs3: reject direct userspace writes to reserved $LX* xattrs |
| CVE-2026-63823 | 7.8 | 2.4 | Linux | Linux | — | keys: Pin request_key_auth payload in instantiate paths |
| CVE-2026-63827 | 7.8 | 2.4 | Linux | Linux | — | apparmor: fix use-after-free in rawdata dedup loop |
| CVE-2026-53370 | 5.5 | 2.4 | Linux | Linux | — | perf/x86/intel: Improve validation and configuration of ACR masks |
| CVE-2026-53377 | 5.5 | 2.3 | Linux | Linux | — | drm/msm: always recover the gpu |
| CVE-2026-64129 | 5.5 | 2.3 | Linux | Linux | CWE-401 | mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page |
| CVE-2026-64135 | 5.5 | 2.2 | Linux | Linux | CWE-674 | hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX |
| CVE-2026-64155 | 5.5 | 2.3 | Linux | Linux | CWE-401 | wifi: ath11k: fix error path leaks in some WMI WOW calls |
| CVE-2026-64131 | 5.5 | 2.2 | Linux | Linux | — | mm/memory: fix spurious warning when unmapping device-private/exclusive pages |
| CVE-2026-64119 | 5.5 | 2.1 | Linux | Linux | — | l2tp: use list_del_rcu in l2tp_session_unhash |
| CVE-2026-64161 | 5.5 | 2.1 | Linux | Linux | CWE-401 | net: ti: icssm-prueth: fix eth_ports_node leak in probe |
| CVE-2026-53376 | 5.5 | 2.0 | Linux | Linux | — | drm/amdkfd: Add upper bound check for num_of_nodes |
| CVE-2026-53379 | 5.5 | 2.1 | Linux | Linux | CWE-908 | media: i2c: ov8856: free control handler on error in ov8856_init_controls() |
| CVE-2026-64166 | 5.5 | 2.0 | Linux | Linux | CWE-476 | firmware: arm_ffa: Check for NULL FF-A ID table while driver registration |
| CVE-2026-64174 | 5.5 | 2.0 | Linux | Linux | — | wifi: cfg80211: advance loop vars in cfg80211_merge_profile() |
| CVE-2026-64165 | 5.5 | 2.0 | Linux | Linux | CWE-476 | ARM: integrator: Fix early initialization |
| CVE-2026-64154 | 5.5 | 1.9 | Linux | Linux | — | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() |
| CVE-2026-64185 | 5.5 | 1.8 | Linux | Linux | — | sysfs: don't remove existing directory on update failure |
| CVE-2026-64186 | 7.1 | 1.8 | Linux | Linux | CWE-125 | iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs |
| CVE-2026-64168 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: sprd: fix error pointer deref after DMA setup failure |
| CVE-2026-64164 | 5.5 | 1.7 | Linux | Linux | CWE-476 | btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() |
| CVE-2026-64169 | 5.5 | 1.6 | Linux | Linux | CWE-476 | spi: ep93xx: fix error pointer deref after DMA setup failure |
| CVE-2026-64173 | 5.5 | 1.7 | Linux | Linux | — | tracing: Do not call map->ops->elt_free() if elt_alloc() fails |
| CVE-2026-64143 | 5.5 | 1.5 | Linux | Linux | — | platform/x86: uniwill-laptop: Do not enable the charging limit even when forced |
| CVE-2026-16213 | 4.8 | 1.4 | Fantomas42 | django-blog-zinnia | CWE-310 | Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cl… |
| CVE-2026-53400 | 7.8 | 1.1 | Linux | Linux | CWE-362 | i2c: core: fix adapter registration race |
| CVE-2026-64167 | 5.5 | 1.0 | Linux | Linux | CWE-476 | kho: skip KHO for crash kernel |
| CVE-2026-64100 | 5.5 | 0.8 | Linux | Linux | CWE-667 | drm/msm: Fix shrinker deadlock |
| CVE-2026-64171 | 5.5 | 0.2 | Linux | Linux | CWE-667 | i2c: tegra: fix pm_runtime leak on mutex_lock failure |