Codex Security
The latest Codex Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-53401: Why Your Embedded Linux Device Needs a Kernel Update, Not Your PC
CVE-2026-53401 exposes a race condition in the Linux kernel's OMAP2 framebuffer driver that can lead to memory corruption on legacy TI hardware. While Windows desktops are unaffected, administrators managing embedded Linux devices must verify their kernel versions and apply updates to prevent privilege escalation or system crashes.
Linux Kernel Crash in fbdev Console Can Take Down WSL 2 and Hyper-V: Here’s the Fix
CVE-2026-53403 is a Linux kernel vulnerability in the legacy framebuffer subsystem that can cause a null-pointer dereference and system crash when the console attempts to switch modes after a userspace mode list change. The bug affects all recent kernel versions and directly impacts Windows users running Linux via WSL 2, Hyper-V, or dual-boot. Fixed kernels are available for every maintained stable series, and administrators should update immediately to prevent availability outages.
Linux Gets Urgent Patch for AMD GPU Video Flaw; Windows PCs Are Safe
CVE-2026-63853 is a Linux kernel vulnerability in AMD's VCN 4.0 video driver that can cause GPU instability when userspace submits unsupported 64-bit user-fence requests. The one-line fix rejects such requests cleanly, and stable kernel updates 6.18.33 and 7.0.10 contain the patch. Windows users are unaffected because the flaw exists only in the Linux amdgpu driver, not in AMD's Windows display drivers.
Patch Now: Linux Console Font Bug Unleashes Kernel Memory Leak (CVE-2026-53402)
CVE-2026-53402 is a Linux kernel memory disclosure vulnerability in the framebuffer console (fbcon) triggered when a font change fails but leaves the console in a corrupted state, allowing an out-of-bounds read. Patches are available in stable kernel branches, and all Linux admins—including those managing WSL 2 instances—should update immediately.
IBM Power Linux Systems Face Kernel Crash Bug; Patch Arrives, Windows Spared
CVE-2026-63805 is a Linux kernel bug in the nx-crypto driver that can crash IBM Power systems when cryptographic contexts are torn down. Windows PCs, servers, and WSL 2 are not affected. IBM Power Linux admins must apply the kernel fix now available in stable branches.
Linux TIPC Decrypt Bug CVE-2026-63801: How a Missing Net Reference Left Systems Open to Use-After-Free Since Kernel 5.5
A newly disclosed Linux kernel vulnerability, CVE-2026-63801, is a use-after-free in TIPC’s encrypted receive path that mirrors a previously fixed encrypt-side bug. Affecting kernels since version 5.5, the flaw occurs when a network namespace is torn down while an asynchronous decryption callback is still pending. Patches have been backported to all stable branches, requiring only a kernel update and reboot. Windows systems are not directly affected; the primary risk is to Linux workloads running TIPC with crypto enabled, including WSL custom kernels, Hyper-V guests, and container hosts.
That Linux Kernel Bug Can Crash Your WSL 2 — Here’s How Microsoft Wants You to Fix It
A newly disclosed Linux kernel memory flaw, CVE-2026-63809, affects WSL 2 on Windows and can be triggered by an unprivileged user writing to /proc/sys when BPF cgroup filtering is active. The fix is a one-line kernel change that replaces kfree() with kvfree() to correct an allocation mismatch. Users should update WSL 2 immediately via `wsl --update` and restart their instances; Linux server admins need to apply distribution kernel patches.
Linux Kernel’s Qualcomm Wi-Fi Double-Free Bug Gets Patched—Here’s What Windows Users Need to Know
CVE-2026-63822 patches a double-free bug in the Linux kernel’s Qualcomm ath11k Wi-Fi driver that can crash systems or trigger kernel warnings. The fix has been backported to multiple stable kernels. Windows itself is unaffected, but users running Linux in dual-boot or VM setups with Qualcomm Wi-Fi passthrough should update their kernels promptly.
Linux Kernel Bug in AMD Video Engine Fixed: What It Means for Your PC, Windows or Otherwise
CVE-2026-53375 is a Linux kernel bug in the AMDGPU driver that can cause video encoding failures and GPU hangs. Fixed upstream kernels are available, and native Windows systems are unaffected. The article explains who needs to patch and provides a step-by-step action plan.
Linux Kernel CVE-2026-63829 Exposes GRE Tunnels to Cross-Namespace Hijacking—What WSL 2 Users Must Patch Now
A newly disclosed Linux kernel vulnerability, CVE-2026-63829, allows a process with networking privileges in one container to reconfigure GRE or ERSPAN tunnels in another namespace, breaking container isolation. While Windows does not run the vulnerable code natively, its widespread use of WSL 2, Docker Desktop, and Hyper-V Linux guests means millions of systems may be exposed. Fixed kernels (6.12.95, 6.18.38, 7.1.3, and 7.2-rc1) are available, and patching through WSL updates, Docker Desktop updates, or Linux guest package managers is urgently recommended for environments using these tunneling protocols.
AMD GPU Compute Bug Patched in Latest Linux Kernels: Here’s Why WSL 2 Users Should Pay Attention
A newly disclosed Linux kernel vulnerability (CVE-2026-53376) in the AMD KFD compute driver can be exploited by a local attacker to send oversized requests, but there's no active exploitation or severity score yet. The fix is available in stable kernels 6.6.140, 6.12.90, 6.18.32, and 7.0.9. Windows users are only affected if they run WSL 2 with GPU acceleration or dual-boot a Linux distro with an AMD GPU—updating the Linux kernel eliminates the risk.
AMDGPU GART Table Flaw (CVE-2026-53374) Gets Linux Kernel Patch – Update Now
CVE-2026-53374 is a flaw in the Linux kernel's AMDGPU driver that can cause the GPU to use stale memory mappings from an uninitialized GART table. Patched kernels are available (6.1.175, 6.6.140, 6.12.90, 6.18.32, 7.0.9), and Linux users with AMD graphics should update immediately. Windows systems are not affected, but mixed environments and Linux GPU compute nodes need attention.
Out-of-Band Fix KB5121767 Unlocks July Patch for Affected Dell PCs Running Windows 11
Microsoft’s out-of-band cumulative update KB5121767, released July 18, 2026, resolves a compatibility issue between Windows 11 and Intel IPF drivers on specific Dell PCs. Home users should check for the update if they missed the July Patch Tuesday; IT admins need to target only affected devices. The fix lifts a hold without requiring fleet-wide deployment.