1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:05 AM 16,292 active 1,443 known exploited

Catalog summary

16,292

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:05 AM 16,292 active 1,443 known exploited

Catalog summary

16,292

Active CVEs

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,301–2,350 of 16,292 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64387Unknown severity
    smb: client: fix query directory replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64386Unknown severity
    smb: client: fix query_info() replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-64385Unknown severity
    smb: client: fix double-free in SMB2_ioctl() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-64384Unknown severity
    smb: client: fix change notify replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-64383Unknown severity
    smb: client: fix double-free in SMB2_flush() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-64382Unknown severity
    smb: client: fix double-free in SMB2_open() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-64380Unknown severity
    smb: client: harden POSIX SID length parsing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-64379Unknown severity
    smb: client: mask server-provided mode to 07777 in modefromsid
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-64378Unknown severity
    writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-64375Unknown severity
    proc: protect ptrace_may_access() with exec_update_lock (FD links)
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-64374Unknown severity
    sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64372Unknown severity
    cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-64368Unknown severity
    mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-64367Unknown severity
    HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-64366Unknown severity
    HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64364Unknown severity
    HID: multitouch: fix out-of-bounds bit access on mt_io_flags
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64361Unknown severity
    hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-64355Unknown severity
    bpf: Reject fragmented frames in devmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-64354Unknown severity
    bpf: Validate BTF repeated field counts before expansion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-64333Unknown severity
    USB: serial: digi_acceleport: fix write buffer corruption
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-64324Unknown severity
    udf: validate free block extents against the partition length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-64323Unknown severity
    udf: validate VAT header length against the VAT inode size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64322Unknown severity
    udf: validate sparing table length as an entry count, not a byte count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-64320Unknown severity
    nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-64319Unknown severity
    nvmet-auth: validate reply message payload bounds against transfer length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-64318Unknown severity
    partitions: aix: bound the pp_count scan to the ppe array
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-64317Unknown severity
    isofs: bound Rock Ridge symlink components to the SL record
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-64315Unknown severity
    crypto: caam - use print_hex_dump_devel to guard key hex dumps
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-64313Unknown severity
    crypto: ecc - Fix carry overflow in vli multiplication
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-64312Unknown severity
    crypto: pcrypt - restore callback for non-parallel fallback
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-64311Unknown severity
    crypto: loongson - Remove broken and unused loongson-rng
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-64304Unknown severity
    crypto: qat - validate RSA CRT component lengths
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-64303Unknown severity
    spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-64300Unknown severity
    perf/aux: Fix page UAF in map_range()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-64299Unknown severity
    tracing: Prevent out-of-bounds read in glob matching
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-64298Unknown severity
    NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-64296Unknown severity
    exfat: bound uniname advance in exfat_find_dir_entry()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-64293Unknown severity
    iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-64287Unknown severity
    KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64286Unknown severity
    KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-64284Unknown severity
    KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-64281Unknown severity
    svcrdma: wake sq waiters when the transport closes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64280High
    fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64279Unknown severity
    i2c: core: fix adapter deregistration race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64277Unknown severity
    Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64276Unknown severity
    Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64269Unknown severity
    RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64268Unknown severity
    RDMA/siw: bound Read Response placement to the RREAD length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64266Unknown severity
    fuse: re-lock request before returning from fuse_ref_folio()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64265Unknown severity
    fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 47 of 326
Previous4546474849Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,447

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,301–2,350 of 16,292 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-64387Unknown severity
    smb: client: fix query directory replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  2. CVE-2026-64386Unknown severity
    smb: client: fix query_info() replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  3. CVE-2026-64385Unknown severity
    smb: client: fix double-free in SMB2_ioctl() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  4. CVE-2026-64384Unknown severity
    smb: client: fix change notify replay double-free
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  5. CVE-2026-64383Unknown severity
    smb: client: fix double-free in SMB2_flush() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  6. CVE-2026-64382Unknown severity
    smb: client: fix double-free in SMB2_open() replay
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  7. CVE-2026-64380Unknown severity
    smb: client: harden POSIX SID length parsing
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  8. CVE-2026-64379Unknown severity
    smb: client: mask server-provided mode to 07777 in modefromsid
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  9. CVE-2026-64378Unknown severity
    writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  10. CVE-2026-64375Unknown severity
    proc: protect ptrace_may_access() with exec_update_lock (FD links)
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  11. CVE-2026-64374Unknown severity
    sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  12. CVE-2026-64372Unknown severity
    cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  13. CVE-2026-64368Unknown severity
    mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  14. CVE-2026-64367Unknown severity
    HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  15. CVE-2026-64366Unknown severity
    HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  16. CVE-2026-64364Unknown severity
    HID: multitouch: fix out-of-bounds bit access on mt_io_flags
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  17. CVE-2026-64361Unknown severity
    hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  18. CVE-2026-64355Unknown severity
    bpf: Reject fragmented frames in devmap
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  19. CVE-2026-64354Unknown severity
    bpf: Validate BTF repeated field counts before expansion
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  20. CVE-2026-64333Unknown severity
    USB: serial: digi_acceleport: fix write buffer corruption
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  21. CVE-2026-64324Unknown severity
    udf: validate free block extents against the partition length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  22. CVE-2026-64323Unknown severity
    udf: validate VAT header length against the VAT inode size
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  23. CVE-2026-64322Unknown severity
    udf: validate sparing table length as an entry count, not a byte count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  24. CVE-2026-64320Unknown severity
    nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  25. CVE-2026-64319Unknown severity
    nvmet-auth: validate reply message payload bounds against transfer length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  26. CVE-2026-64318Unknown severity
    partitions: aix: bound the pp_count scan to the ppe array
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  27. CVE-2026-64317Unknown severity
    isofs: bound Rock Ridge symlink components to the SL record
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  28. CVE-2026-64315Unknown severity
    crypto: caam - use print_hex_dump_devel to guard key hex dumps
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  29. CVE-2026-64313Unknown severity
    crypto: ecc - Fix carry overflow in vli multiplication
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  30. CVE-2026-64312Unknown severity
    crypto: pcrypt - restore callback for non-parallel fallback
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  31. CVE-2026-64311Unknown severity
    crypto: loongson - Remove broken and unused loongson-rng
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  32. CVE-2026-64304Unknown severity
    crypto: qat - validate RSA CRT component lengths
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  33. CVE-2026-64303Unknown severity
    spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  34. CVE-2026-64300Unknown severity
    perf/aux: Fix page UAF in map_range()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  35. CVE-2026-64299Unknown severity
    tracing: Prevent out-of-bounds read in glob matching
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  36. CVE-2026-64298Unknown severity
    NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  37. CVE-2026-64296Unknown severity
    exfat: bound uniname advance in exfat_find_dir_entry()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  38. CVE-2026-64293Unknown severity
    iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  39. CVE-2026-64287Unknown severity
    KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  40. CVE-2026-64286Unknown severity
    KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  41. CVE-2026-64284Unknown severity
    KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  42. CVE-2026-64281Unknown severity
    svcrdma: wake sq waiters when the transport closes
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  43. CVE-2026-64280High
    fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
    CVSS 8.8
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 3, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  44. CVE-2026-64279Unknown severity
    i2c: core: fix adapter deregistration race
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  45. CVE-2026-64277Unknown severity
    Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  46. CVE-2026-64276Unknown severity
    Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  47. CVE-2026-64269Unknown severity
    RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  48. CVE-2026-64268Unknown severity
    RDMA/siw: bound Read Response placement to the RREAD length
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  49. CVE-2026-64266Unknown severity
    fuse: re-lock request before returning from fuse_ref_folio()
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
  50. CVE-2026-64265Unknown severity
    fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
    Not scoredSource severity not reported
    Linux/Linuxgeneric
    PublishedJul 25, 2026First seen at HOL Aug 5, 2026Updated Aug 5, 2026 Fix availableView HOL analysis
Page 47 of 326
Previous4546474849Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard