Live

Codex Security

The latest Codex Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 8:47 AM
Latest Most Read Breaking
Sort
CVE-2026-53401 · Linux Kernel

CVE-2026-53401: Why Your Embedded Linux Device Needs a Kernel Update, Not Your PC

CVE-2026-53401 exposes a race condition in the Linux kernel's OMAP2 framebuffer driver that can lead to memory corruption on legacy TI hardware. While Windows desktops are unaffected, administrators managing embedded Linux devices must verify their kernel versions and apply updates to prevent privilege escalation or system crashes.

Security

Linux Kernel Crash in fbdev Console Can Take Down WSL 2 and Hyper-V: Here’s the Fix

CVE-2026-53403 is a Linux kernel vulnerability in the legacy framebuffer subsystem that can cause a null-pointer dereference and system crash when the console attempts to switch modes after a userspace mode list change. The bug affects all recent kernel versions and directly impacts Windows users running Linux via WSL 2, Hyper-V, or dual-boot. Fixed kernels are available for every maintained stable series, and administrators should update immediately to prevent availability outages.

Security Desk·now ·5 min
Security

Linux Gets Urgent Patch for AMD GPU Video Flaw; Windows PCs Are Safe

CVE-2026-63853 is a Linux kernel vulnerability in AMD's VCN 4.0 video driver that can cause GPU instability when userspace submits unsupported 64-bit user-fence requests. The one-line fix rejects such requests cleanly, and stable kernel updates 6.18.33 and 7.0.10 contain the patch. Windows users are unaffected because the flaw exists only in the Linux amdgpu driver, not in AMD's Windows display drivers.

Security Desk·5m ago ·5 min
Security

Patch Now: Linux Console Font Bug Unleashes Kernel Memory Leak (CVE-2026-53402)

CVE-2026-53402 is a Linux kernel memory disclosure vulnerability in the framebuffer console (fbcon) triggered when a font change fails but leaves the console in a corrupted state, allowing an out-of-bounds read. Patches are available in stable kernel branches, and all Linux admins—including those managing WSL 2 instances—should update immediately.

Security Desk·5m ago ·5 min
Advertisement
CVE-2026-63805 · Linux Kernel

IBM Power Linux Systems Face Kernel Crash Bug; Patch Arrives, Windows Spared

CVE-2026-63805 is a Linux kernel bug in the nx-crypto driver that can crash IBM Power systems when cryptographic contexts are torn down. Windows PCs, servers, and WSL 2 are not affected. IBM Power Linux admins must apply the kernel fix now available in stable branches.

SE Security Desk·10m ago
CVE-2026-63801 · Linux Kernel Vulnerability

Linux TIPC Decrypt Bug CVE-2026-63801: How a Missing Net Reference Left Systems Open to Use-After-Free Since Kernel 5.5

A newly disclosed Linux kernel vulnerability, CVE-2026-63801, is a use-after-free in TIPC’s encrypted receive path that mirrors a previously fixed encrypt-side bug. Affecting kernels since version 5.5, the flaw occurs when a network namespace is torn down while an asynchronous decryption callback is still pending. Patches have been backported to all stable branches, requiring only a kernel update and reboot. Windows systems are not directly affected; the primary risk is to Linux workloads running TIPC with crypto enabled, including WSL custom kernels, Hyper-V guests, and container hosts.

SE Security Desk·1h ago
CVE-2026-63809 · WSL 2

That Linux Kernel Bug Can Crash Your WSL 2 — Here’s How Microsoft Wants You to Fix It

A newly disclosed Linux kernel memory flaw, CVE-2026-63809, affects WSL 2 on Windows and can be triggered by an unprivileged user writing to /proc/sys when BPF cgroup filtering is active. The fix is a one-line kernel change that replaces kfree() with kvfree() to correct an allocation mismatch. Users should update WSL 2 immediately via `wsl --update` and restart their instances; Linux server admins need to apply distribution kernel patches.

SE Security Desk·1h ago
CVE-2026-63822 · Linux Kernel Vulnerability

Linux Kernel’s Qualcomm Wi-Fi Double-Free Bug Gets Patched—Here’s What Windows Users Need to Know

CVE-2026-63822 patches a double-free bug in the Linux kernel’s Qualcomm ath11k Wi-Fi driver that can crash systems or trigger kernel warnings. The fix has been backported to multiple stable kernels. Windows itself is unaffected, but users running Linux in dual-boot or VM setups with Qualcomm Wi-Fi passthrough should update their kernels promptly.

SE Security Desk·1h ago
CVE-2026-53375 · AMDGPU

Linux Kernel Bug in AMD Video Engine Fixed: What It Means for Your PC, Windows or Otherwise

CVE-2026-53375 is a Linux kernel bug in the AMDGPU driver that can cause video encoding failures and GPU hangs. Fixed upstream kernels are available, and native Windows systems are unaffected. The article explains who needs to patch and provides a step-by-step action plan.

SE Security Desk·1h ago
CVE-2026-63829 · Linux Kernel Vulnerability

Linux Kernel CVE-2026-63829 Exposes GRE Tunnels to Cross-Namespace Hijacking—What WSL 2 Users Must Patch Now

A newly disclosed Linux kernel vulnerability, CVE-2026-63829, allows a process with networking privileges in one container to reconfigure GRE or ERSPAN tunnels in another namespace, breaking container isolation. While Windows does not run the vulnerable code natively, its widespread use of WSL 2, Docker Desktop, and Hyper-V Linux guests means millions of systems may be exposed. Fixed kernels (6.12.95, 6.18.38, 7.1.3, and 7.2-rc1) are available, and patching through WSL updates, Docker Desktop updates, or Linux guest package managers is urgently recommended for environments using these tunneling protocols.

SE Security Desk·1h ago
Amd Kfd · Cve-2026-53376

AMD GPU Compute Bug Patched in Latest Linux Kernels: Here’s Why WSL 2 Users Should Pay Attention

A newly disclosed Linux kernel vulnerability (CVE-2026-53376) in the AMD KFD compute driver can be exploited by a local attacker to send oversized requests, but there's no active exploitation or severity score yet. The fix is available in stable kernels 6.6.140, 6.12.90, 6.18.32, and 7.0.9. Windows users are only affected if they run WSL 2 with GPU acceleration or dual-boot a Linux distro with an AMD GPU—updating the Linux kernel eliminates the risk.

SE Security Desk·1h ago
Amdgpu Driver · Cve 2026 53374

AMDGPU GART Table Flaw (CVE-2026-53374) Gets Linux Kernel Patch – Update Now

CVE-2026-53374 is a flaw in the Linux kernel's AMDGPU driver that can cause the GPU to use stale memory mappings from an uninitialized GART table. Patched kernels are available (6.1.175, 6.6.140, 6.12.90, 6.18.32, 7.0.9), and Linux users with AMD graphics should update immediately. Windows systems are not affected, but mixed environments and Linux GPU compute nodes need attention.

SE Security Desk·1h ago
Dell Devices · Intel Ipf

Out-of-Band Fix KB5121767 Unlocks July Patch for Affected Dell PCs Running Windows 11

Microsoft’s out-of-band cumulative update KB5121767, released July 18, 2026, resolves a compatibility issue between Windows 11 and Intel IPF drivers on specific Dell PCs. Home users should check for the update if they missed the July Patch Tuesday; IT admins need to target only affected devices. The fix lifts a hold without requiring fleet-wide deployment.

SE Security Desk·2h ago