CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63955

highCVSS 7.5covered by 6 sourcesfirst seen 2026-07-19
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: do not trigger BUG() on BH disabled context __get_vm_area_node() currently triggers a BUG() if in_interrupt() returns true. However, in_interrupt() also reports true when BH are disabled. The bridge code can call rhashtable_lookup_insert_fast() with bottom halves disabled: __vlan_add() -> br_fdb_add_local() spin_lock_bh(&br->hash_lock); <-- Disable BH -> fdb_add_local() -> fdb_create() -> rhashtable_lookup_insert_fast() -> kvmalloc() -> vmalloc() -> __get_vm_area_node() -> BUG_ON(in_interrupt()) spin_unlock_bh(&br->hash_lock) this triggers the BUG() despite the caller not being in NMI or hard IRQ context. Replace the in_interrupt() check with in_nmi() || in_hardirq().

CSIRTS triage

What
Multiple kernel vulnerabilities across architectures and driver subsystems including AMD processor microarchitectural flaws and cache isolation issues.
Who is affected
NVIDIA BaseOS systems running affected Linux kernel versions.
Urgency
Moderate; privilege escalation and DoS vectors present, primarily requiring local access.
Action
Apply USN-8664-1 kernel security update for NVIDIA BaseOS.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-63955

Get an email if CVE-2026-63955 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (6)

External references

NVD record for CVE-2026-63955

CVE.org record

Embed the live status

CVE-2026-63955 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63955 status](https://www.csirts.com/badge/CVE-2026-63955)](https://www.csirts.com/cve/CVE-2026-63955)