Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
USB-C Firmware Bug Can Crash Linux PCs: Patches Released, Windows Dual-Booters Take Note
A flaw in the Linux kernel’s USB-C management code, disclosed on July 19, 2026, can allow a corrupted connector-change notification to force the kernel to access memory well outside its intended...
Linux USB-C Vulnerability Allows Kernel Memory Overwrite by Rogue Accessories
On July 19, 2026, the Linux kernel project disclosed a memory corruption flaw in the USB Type-C Port Manager (TCPM) that lets a malicious or malfunctioning USB-C device overwrite kernel memory....
USB-C Chargers Could Leak Your Linux PC’s Memory—The Kernel Fix Is Here
Linux kernel maintainers disclosed a vulnerability on July 19, 2026, that could let a malicious USB-C charger or dock read uninitialized stack memory from your machine. The flaw, tagged...
Linux Kernel Bug Fixed After 20 Years: WSL 2 and VM Users Must Update to Avoid Memory Attacks
A use-after-free vulnerability in the Linux kernel’s legacy audio compatibility layer was disclosed on July 19, 2026, after lurking in the code since 2006. The flaw, tracked as CVE-2026-64001, can...
Linux Kernel Crash Bug Hits WSL 2 and Docker — Here’s How to Patch It
A recently published Linux kernel flaw (CVE-2026-64079) can crash systems running Windows Subsystem for Linux 2 (WSL 2), Docker Desktop, or any Linux virtual machine, following a race condition in...
Linux Kernel BPF Flaw CVE-2026-64036 Exposes Local Attack Paths – Patch Now
Linux kernel maintainers have published a high-severity fix for CVE-2026-64036, a flaw in the cgroup rstat subsystem that can be triggered by eBPF programs with elevated privileges. The...
New Linux LM90 Driver Flaw: What Windows and WSL Administrators Should Do Right Now
On July 19, 2026, CVE-2026-64038 landed in the National Vulnerability Database, detailing a use-after-free race condition in the Linux kernel’s lm90 hardware-monitoring driver. The bug can corrupt...
BusyBox 1.38.0 Heap Overflow Puts Routers, Containers, and IoT at Risk—Here’s How to Respond
A newly disclosed vulnerability in BusyBox’s ash shell can be triggered by crafted input to cause a denial of service, potentially crashing routers, embedded appliances, and containerized systems....
CVE-2026-63882: A Missing Check in AMD’s Linux Kernel Driver Can Crash Your System
Linux kernel maintainers have patched a newly cataloged flaw in AMD’s GPU compute stack that can trigger an instant system crash. The vulnerability, tracked as CVE-2026-63882, was published on July...
Patch Now: AMDGPU Kernel Race Condition (CVE-2026-63879) Opens Linux Systems to Local Attacks
On July 19, 2026, the Linux kernel security team disclosed CVE-2026-63879, a high-severity vulnerability in the AMDGPU driver that could let a local attacker read or corrupt sensitive memory. The...
Fix Your WSL 2 Kernel Now: Linux Ebtables Flaw CVE-2026-64077 Scores High Severity
A high-severity Linux kernel vulnerability (CVE-2026-64077) was published on July 19, 2026, and it’s not just a problem for Linux admins. With a CVSS score of 7.8, the bug targets the ebtables...
A Zero-Length I/O Request Just Became a Critical Linux Kernel Vuln—Here’s What to Patch
On July 19, 2026, kernel.org disclosed CVE-2026-63940, a critical flaw in the Linux kernel’s KVM handling for AMD Secure Encrypted Virtualization. The vulnerability—a failure to reject Port I/O...