VYPR
patchPublished Jul 20, 2026· Updated Jul 21, 2026· 1 source

Linux Kernel: 17 Vulnerabilities Across Subsystems Disclosed and Patched Together

Key findings • 17 Linux kernel vulnerabilities disclosed on July 20, 2026, affecting networking, storage, graphics, and crypto subsystems. • All disclosed vulnerabilities were addressed in De…

Key findings

  • 17 Linux kernel vulnerabilities disclosed on July 20, 2026, affecting networking, storage, graphics, and crypto subsystems.
  • All disclosed vulnerabilities were addressed in Debian's Linux kernel packages on the same day.
  • Issues include out-of-bounds reads, use-after-free, deadlocks, and divide-by-zero errors.
  • No active exploitation or specific threat actors were mentioned in the disclosure.
  • Updates to the Linux kernel are recommended to mitigate these risks.

On July 20, 2026, a significant batch of 17 vulnerabilities was disclosed in the Linux kernel, affecting various subsystems including networking, storage, and graphics. These vulnerabilities were all addressed in Debian's Linux kernel packages on the same day. The disclosures highlight a broad range of potential issues within the kernel's complex architecture, with fixes released promptly to mitigate risks.

The vulnerabilities span several key areas:

Networking and Communication

Several issues were found in networking components. CVE-2026-64033 addresses a use-after-free in the RDMA/rtrs subsystem during path file creation cleanup. CVE-2026-63870 restricts the IEEE 802.15.4/6LoWPAN driver to only accept IPv6 packets. In the wifi subsystem, CVE-2026-64176 fixes driver-set TX rates on older iwlwifi devices. The batman-adv component has a fix for a potential divide-by-zero error in CVE-2026-63836. Additionally, CVE-2026-63993 resolves a potential use-after-free in the vxlan module related to cached IP header values. CVE-2026-63859 adds missing cleanup bits in the airoha network driver's TX queue.

Storage and File Systems

Storage-related vulnerabilities include CVE-2026-53390, which fixes an out-of-bounds read in the ksmbd SMB protocol handler. The scsi subsystem is affected by CVE-2026-63888, patching CRC overread and double-free bugs in the iscsi target, and CVE-2026-63889, which widens a counter in the scsi_transport_fc component. CVE-2026-64057 addresses locking issues in the afs filesystem's handling of symbolic links. The hpfs filesystem has a fix for a crash condition in CVE-2026-63954.

Graphics and Hardware Monitoring

In the graphics subsystem, CVE-2026-64100 fixes a shrinker deadlock in the drm/msm driver, while CVE-2026-63878 addresses an unchecked user-supplied value in the drm/amdgpu GEM_OP GET_MAPPING_INFO operation. Hardware monitoring is impacted by CVE-2026-63888 and CVE-2026-64086, both related to the hwmon (pmbus/adm1266) driver, addressing buffer size issues in blackbox information retrieval and PEC byte inclusion in block transfers, respectively. CVE-2026-53403 fixes a null-pointer dereference in the fbdev component when handling video modes.

Cryptography and Other

CVE-2026-63805 corrects an argument type issue in the nx crypto driver's context exit function.

All disclosed vulnerabilities have been addressed in Debian's Linux kernel packages. No active exploitation or specific threat actors were mentioned in the disclosure. Users are recommended to update their Linux kernel packages to the latest available versions provided by Debian to mitigate these risks.

The timely disclosure and resolution of these 17 vulnerabilities across multiple kernel subsystems underscore the ongoing efforts to maintain the security and stability of the Linux kernel. Users of Debian-based systems should ensure their systems are up-to-date.

Vypr Intelligence reported on this batch, noting that all 25 disclosed vulnerabilities (including these 17) were addressed in Debian's Linux kernel packages and that no active exploitation was mentioned.

The vulnerabilities patched include: CVE-2026-53390, CVE-2026-64033, CVE-2026-63888, CVE-2026-64100, CVE-2026-64135, CVE-2026-63889, CVE-2026-64057, CVE-2026-53403, CVE-2026-63954, CVE-2026-63870, CVE-2026-64176, CVE-2026-63836, CVE-2026-64086, CVE-2026-63859, CVE-2026-63805, CVE-2026-63878, CVE-2026-63993.

Synthesized by Vypr AI