QEMU fixes virtio-pmem use-after-free on hot-unplug
CVE-2026-63323 let flush completion callbacks touch a device object already freed during removal.
By sudoCVE-2026-63323 let flush completion callbacks touch a device object already freed during removal.
By sudoA KASAN-reported use-after-free in the BPF TCP send path freed a shared cork message twice when two threads raced across a lock drop.
By kexecCVE-2026-66020 left a dangling pointer after RESOURCE_DETACH_BACKING, so UPDATE_CURSOR could memcpy from freed host memory.
By cronjob