Friday, September 11, 2026

Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours

The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already incorporated into the upstream kernel tree.

These notices were distributed through the linux-cve-announce mailing list between July 19 and July 20, 2026, and cover a wide range of kernel subsystems, including networking, Bluetooth, storage, memory management, virtualization, graphics, wireless, device drivers, and filesystems.

The unusually high volume of advisories should not be seen as evidence of a coordinated attack or a mass-exploitation campaign.

Instead, it highlights the Linux kernel project’s ongoing efforts to associate individual upstream fixes with formal CVE identifiers, which provide downstream vendors, distribution maintainers, and security professionals with actionable vulnerability-tracking data.

Linux Kernel Team Publishes 440 CVE

According to the Advisory, many newly assigned CVEs address memory safety flaws that could lead to denial-of-service conditions and, depending on the potential for reachability and local privileges, may result in more serious impacts.

Several advisories reference issues such as use-after-free conditions, null-pointer dereferences, out-of-bounds access, integer underflows, race conditions, reference leaks, and insufficient input validation.

For example, CVE-2026-64188 addresses a use-after-free condition in the Qualcomm RMNET network driver’s endpoint removal path; CVE-2026-64122 addresses a use-after-free issue in the mlx5e transmit reporter recovery logic; and CVE-2026-64115 fixes a use-after-free scenario in the VMCI virtual socket handshake path.

Additionally, CVE-2026-64074 resolves a slab out-of-bounds write in the statmount filesystem interface, and CVE-2026-64102 corrects signed-receive arithmetic associated with an underflow in RDMA/siw MPA FPDU processing.

Networking components represent a significant portion of the disclosures. The advisories include fixes affecting netfilter, nftables, bridge code, IPv4 and IPv6 processing, tunnel implementations, TCP, TLS offload paths, OpenVPN, Bluetooth, Wi-Fi drivers, Ethernet adapters, and network filesystems.

Notably, CVE-2026-64024 fixes a stale per-CPU TCP time-wait initial sequence number leak that could enable Initial Sequence Number (ISN) prediction under specific circumstances. CVE-2026-64114 addresses raw IPv4 packets using IP_HDRINCL with invalid Internet Header Length values, while CVE-2026-64006 repairs destination corruption in an nf_tables same-register operation.

Administrators with systems exposing vulnerable subsystems to untrusted local users, network peers, or virtual machine tenants should prioritize an impact assessment.

The batch also contains several fixes related to Bluetooth and SMB code. CVE-2026-64206 resolves a locking-order issue in Bluetooth L2CAP pending receive work cancellation, and CVE-2026-64178 fixes a use-after-free read issue involving a Bluetooth BNEP device name.

In the SMB stack, CVE-2026-64138 strengthens validation of security identifiers during Access Control List (ACL) inheritance, and CVE-2026-64137 requires network administration privileges for CIFS SWN netlink operations.

These issues highlight that the kernel’s attack surface extends beyond internet-facing services to encompass enabled hardware drivers, protocol modules, containers, virtual machines, and local interfaces.

Organizations should identify their running kernel version, enabled modules, hardware profile, and workload exposure before reviewing the complete advisory set.

The kernel’s CVE notices typically identify the upstream commits that introduced and fixed each issue, making it easier to determine whether a distribution backport includes the necessary remediation, even when version numbers differ.

Administrators should obtain updated kernels from their Linux distribution or hardware vendor, conduct tests through standard change-control processes, and reboot affected hosts after applying updates.

Security teams should prioritize internet-facing servers, multi-tenant infrastructure, systems using KVM or confidential computing features, and hosts with exposed Bluetooth, Wi-Fi, SMB, RDMA, or specialized network drivers.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News