[kernel-cve-report] New CVE entries this week
Masami Ichikawa <[email protected]>
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <CAODzB9ruOdT89OuGg+-dzb9P0eE5rLgjY+HQ7uVOS19a7qCG_Q@mail.gmail.com> |
Hi!
It's this week's CVE report.
This week reported 223 new CVEs and 104 updated CVEs.
* New CVEs
CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52908
Introduced by commit b40656a ("RDMA/umem: remove FOLL_FORCE usage") in v6.2-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [badad6fad60def1b9805559dd81dbab3d97b82aa]
stable/6.12: [eba5df21eda0fe7418efbea2f799f8ea1b8ca94c]
stable/6.18: [2904e985a2917b5dac65df82733065e78a65fc9d]
stable/6.6: [09dc18894148381d3bfc550083b1236043870dce]
stable/7.0: [50334a05a950840b39a1ce3d2a173b4183db9b3e]
CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device.
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52909
Introduced by commit 61220ab ("vti6: Enable namespace changing") in v3.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d289d5307762d1838aaece22c6b6fcad9e8865f9]
stable/6.18: [ecf8904067dcba0dad86ece80874841e60317885]
stable/7.0: [dcdce3bc9f08026ff3739ee7339e1bef526fc5f3]
CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period.
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52910
Introduced by commit 538950a ("soreuseport: setsockopt
SO_ATTACH_REUSEPORT_[CE]BPF") in v4.5-rc1.
Fixed in v7.1-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [18fc650ccd7fe3376eca89203668cfb8268f60df]
stable/5.10: [08264d5bba0bdd3a79bc2984fee09286aba0c4eb]
stable/5.15: [fec41484e7c2aa7ded44c541bba98872be937754]
stable/6.1: [c3e3fddda6b5d9ba505d218b4055e7d8a282ac57]
stable/6.12: [298db6167f81e9c470a57cf652e4e47757b4293e]
stable/6.18: [87dfb977bdb6eaa47e9993a34e18f44970f88b1f]
stable/6.6: [f8b8f1d4bb76098e87b8269a0631019648330e6d]
stable/7.0: [90e47dc5c572d1c73971ac51c7428803f42b78eb]
CVE-2026-52911: ksmbd: scope conn->binding slowpath to bound sessions only
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52911
Introduced by commit f5a544e ("ksmbd: add support for SMB3
multichannel") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b0da97c034b6107d14e537e212d4ce8b22109a58]
stable/5.15: [e74c00c6af428a39e564cdc5bd3a3648c6d8de87]
stable/6.1: [e3a93ce6e25757b8f375e38b8f91e1d9da4edc1a]
stable/6.12: [974c1c224e85549dc3459f3bb2255bbbdd2b9372]
stable/6.18: [2cc8a4db633b10715450b291c1343859a4b2c509]
stable/6.6: [1ff46c9915c1cbf454db58a8cb87f7cac818e6a6]
stable/7.0: [1e2bec062c5c9ec282636715166056d0998d746d]
CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52912
Introduced by commit ac28634 ("netfilter: bridge: add nf_afinfo to
enable queuing to userspace") in v4.7-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e196115ec330a18de415bdb9f5071aa9f08e53ce]
stable/5.10: [950d809f154dca04e5fbe5d3c8b9c5e44769cd57]
stable/5.15: [a698ac8ab2561cf575d2d9f34095032651dd952e]
stable/6.1: [19924bdd8a45ebc72a7b84c57fd63057d1dc75ac]
stable/6.12: [3823c27099cfe2482299065814adbaa771be9644]
stable/6.18: [15d464265120ab9818bd673af301deee09bedab2]
stable/6.6: [1e5e20031c5eee8d2e490a90ff4d6a2feecfc3be]
stable/7.0: [3fb0f5c0f64162a8c3f25616a4f1e340b921737f]
CVE-2026-52913: batman-adv: v: stop OGMv2 on disabled interface
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52913
Introduced by commit 0da0035 ("batman-adv: OGMv2 - add basic
infrastructure") in v4.6-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f8ce8b8331a1bc44ad4905886a482214d428b253]
stable/5.10: [d7391a2b854a62235539c68e9cbf6fc7910a8e9a]
stable/5.15: [70c9f6ab0d8f785087fb74fb85464a9a5288bfdb]
stable/6.1: [040fe8eb34624002071dd21de9824dfe668ce65d]
stable/6.12: [aad70db50ea3d7dfe30e402b889ff075a293b287]
stable/6.18: [1be1e99cbd5b74a69d3f92200ca87cf1bce852db]
stable/6.6: [31dcb9711abd1dcd2080d9fac05c79dd9997d6bf]
stable/7.0: [4ff461af943efb5e74d09942d5ffee7644d1e1fe]
CVE-2026-52914: batman-adv: fix fragment reassembly length accounting
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52914
Introduced by commit 610bfc6 ("batman-adv: Receive fragmented packets
and merge") in v3.13-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9cd3f16c320bfdadd4509358122368deb56a5741]
stable/5.10: [e4f3f6b818aa6a678bc54a2d4e0bece2303c6a64]
stable/5.15: [37be61825b15534a16ff9cfc9546de155b6df982]
stable/6.1: [975563c5de1123dde1ec7946bf5556d20c89d74e]
stable/6.12: [e910dbf509125fe51ad68e4fa74dc8ab0a8e787a]
stable/6.18: [3eb8bcb823391bd58997831b3c9c152a4ba8e255]
stable/6.6: [f653b040dad1af70fa5cd4fe085e4758925480c9]
stable/7.0: [fdb2c96efb2baeb3725e9ce3ede8f1e36f5490f0]
CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52915
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4322dcde6b4173c2d8e8e6118ed290794263bcc8]
stable/5.10: [2d523ba48d4ecc46acfb6aba548292cfcce1ac02]
stable/5.15: [588933f1a2ca5ff99274f8c9f25dc3a25d0191c3]
stable/6.1: [784aadea7a108c9f90985683caa87fb0198c6a39]
stable/6.12: [db0250470f023f159094052c0bd5ab026a88ae93]
stable/6.18: [57b0ac5e1b46f1f0338dff392ef2092e2871b412]
stable/6.6: [41ec2e242f1702e8370ddfe14d22b7a766021c3e]
stable/7.0: [6feb43c0995ab3a9c826707eb46541a1696fe4f7]
CVE-2026-52916: batman-adv: frag: disallow unicast fragment in fragment
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52916
Introduced by commit 610bfc6 ("batman-adv: Receive fragmented packets
and merge") in v3.13-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bc62216dc8e221e3781afa14430f45208bfa9af9]
stable/5.10: [0c208fa3859e3a33a1c38bebc41d021166e94ac8]
stable/5.15: [bcda4814dc6524283c0b958882cb963d75fe411d]
stable/6.1: [aea54d0bbe156d5ab7d00d68f66149ff41f4612a]
stable/6.12: [5418be6c2e117bf8a316582795a8e3ff90f45e5d]
stable/6.18: [5895ad21c7059a652da83fb817510f7a1e962abf]
stable/6.6: [b54e459cf86943583c1aa2ee3081874e7ab1f5f3]
stable/7.0: [7138c35c9ad39a2fca6264af6b87466471f04ffc]
CVE-2026-52917: sctp: diag: reject stale associations in dump_one path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52917
Introduced by commit 8f840e4 ("sctp: add the sctp_diag.c file") in v4.7-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5eba3e48d78edd7551b992cb7ba687019b3a78da]
stable/5.10: [6657af827e21883ae90693e42e7f59a6aab690b5]
stable/5.15: [b2be72d401833194917e44fbd8d8144bb4f2db16]
stable/6.1: [5425de8bd6e9fe5bd67d158e3348171ae7510117]
stable/6.12: [480f754580b5686b928977d16a59f20cef83ff01]
stable/6.18: [78c4f964b2f94e405721c093773f6250e1e676b2]
stable/6.6: [e97c2a535e23ed0fdd2660993fb3f10d9535c9bc]
stable/7.0: [f5af203dec6e0e7a6090fcc2130e9f3901bfc84d]
CVE-2026-52918: Bluetooth: serialize accept_q access
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52918
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e83f5e24da741fa9405aeeff00b08c5ee7c37b88]
stable/5.10: [d9ce4de05df2385c19e2c7d12f529144e1a44af1]
stable/5.15: [41c8c1c7923e86e0eb59cfb4279349112756a336]
stable/6.1: [4ec17782fd186f901a7329605d11048b085b945a]
stable/6.12: [85f8674cae82053f1e6bab295f6a8422cca14db5]
stable/6.18: [8b4c412e001b0c670eb937beab491af974da55b3]
stable/6.6: [be43e6b4043113c3b3cf887c3c8350f67140274c]
stable/7.0: [a218bf69eb51fefe59a3976fa8925261141f681c]
CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52919
Introduced by commit 33a3bb4 ("batman-adv: throughput meter
implementation") in v4.8-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [94f3b133168d1c49895e7cc6afbcf1cc0b354602]
stable/5.10: [e75e2ab463b5b34df6b98f94d740aff327ce9f6b]
stable/5.15: [abae88fa254f2981d39ac003a7b302528a22af64]
stable/6.1: [c66d20a3ff095e3f000551d208ec2606616db15c]
stable/6.12: [01cefc5923889e29dbb5f281c3d457714ceb9c00]
stable/6.18: [90ae3eae06b7b8ab9f6250b9497c860915b4c17b]
stable/6.6: [c1bac194733aabd731aafa6a01350c229e187dba]
stable/7.0: [aeae11c5dad9cd0d50723890bdd866f8e6db2e7d]
CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52920
Introduced by commit c4b8851 ("[NETFILTER]: x_tables: replace
IPv4/IPv6 policy match by address family independant version") in
v2.6.20.16.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4b2b4d7d4e203c92db8966b163edfacb1f0e1e29]
stable/5.10: [eb323f7b82d2e2f638de0cc2a177803eb20e0707]
stable/5.15: [fc1c518bb1f054831ecabb32da9b8e1dff9699c6]
stable/6.1: [f98b7f85e04b40e28b08c461ded0cc79f14f5509]
stable/6.12: [b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9]
stable/6.18: [938867e870fb5471bb16f442aeac81326e05bf65]
stable/6.6: [82664d0f1ba25e4f9a71994954abae24c60f4067]
stable/7.0: [392cc1d8408b5665215c1e9290bbf0f92339b043]
CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52921
Introduced by commit 48596a8 ("netfilter: ipset: Fix adding an IPv4
range containing more than 2^31 addresses") in v4.14-rc5.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0d3a282ab5f165fc207ff49ea5b6ad8f54616bd6]
stable/5.10: [be75218fadea22e59c8673db212f29c681bf45bb]
stable/5.15: [383418c20e69f5761b6ec5238f599423f4fb77fb]
stable/6.1: [0d7b33ace701fe397e6e4de145f32e098178d901]
stable/6.12: [02f75f041a93ea045834da89cd3234f4c1d749b4]
stable/6.18: [952e988163c2ab9939c3db9f0f8e77af6a1bb436]
stable/6.6: [c281e018af98df91827d65bec00f4956c00a1b02]
stable/7.0: [0b530efb2cc9dbdddfd49d392e3a857f0d4ce8dc]
CVE-2026-52922: batman-adv: dat: handle forward allocation error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52922
Introduced by commit 785ea11 ("batman-adv: Distributed ARP Table -
create DHT helper functions") in v3.8-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d8826a2d3657cea66fb0370f9e521575a673871]
stable/5.10: [9bcebaedfb8479cb4affb23c7a0d000ca9a20e73]
stable/5.15: [2edb8aeb3cdda9d00ec4997252dc5bcd6f54d8ef]
stable/6.1: [ce0c381199402a2c58f4599f4f6ed100d872d0da]
stable/6.12: [4d420d9ee70a220a2cd95aa0dd2e15acad66a505]
stable/6.18: [9cceea8eeba710def2a5707ee00f00c74a9a1cac]
stable/6.6: [866ac1d57040ed0b44ca732e3c66b3aa6b93011c]
stable/7.0: [cf48e75fc4fe0d5cc7721c82d454221d01367b93]
CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52923
Introduced by commit 03f5956 ("ipc: add sysctl to specify desired next
object id") in v3.8-rc3.
Fixed in v7.1-rc6.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fa0b9b2b7ae3539908d69c2b9ac0d144d9bc5139]
stable/5.10: [3bbe2bb9111ce6967a951bfac79af142d816fae5]
stable/5.15: [8c58a92849175f5e2ab7bc2734b3b89afe79f6ef]
stable/6.1: [af24e202b543ded8a34f1d5d3db54eb916173f04]
stable/6.12: [41058d4c3f63ab64901560a704882e0565f4e456]
stable/6.18: [a3cc795129e5ec0f8948653a3bf471e7d8852f5e]
stable/6.6: [157ce2c6836ce0ff19108a819f38df061345425f]
stable/7.0: [bd4be70669af55b974860d13680348cfdf50bbed]
CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52924
Introduced by commit 5bbbbe3 ("sctp: introduce stream scheduler
foundations") in v4.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e374b22e9b07b72a25909621464ff74096151bfb]
stable/5.10: [84b7a319105db2f917ccdcf502bdc866082b1285]
stable/5.15: [f46e1d1a758878f0d22c4fbbd1bf42bb7165d1e8]
stable/6.1: [3c0741a441a7df7099d7ca6a64a6a0de09c677c8]
stable/6.12: [1d4652f677906a64487c13f9ace54b0eb263b5d0]
stable/6.18: [a6207349e703cfc04756a4d16dec9176135813a5]
stable/6.6: [2afc9e684dc7fecf73db1edc937ebbc47b4b68dc]
stable/7.0: [83ade59e5da365f4bf8bce72c5a38774202b442f]
CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52925
Introduced by commit fdeea7b ("net: vrf: Set slave's private flag
before linking") in v4.12-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2674d603a9e6970463b2b9ebcf8e31e90beae169]
stable/5.10: [2c022f582fd16a470df6ed9e7fb7e9fc48946d49]
stable/5.15: [4ab6fc60ed5a0344b60711b09bff1dc238d8d6a4]
stable/6.1: [468defa0b70902a22f4478c1207624bc1b31c124]
stable/6.12: [8c2b792f04a3db97c9d8d2a45817e93f8884baf5]
stable/6.18: [a7a97f2303e63ede105c1d55ef53dc497364e11d]
stable/6.6: [3db8d078f7f652379ee394132b169d304f6eb4c1]
stable/7.0: [d47204c127992da0c976ac9747070a575912e0fe]
CVE-2026-52926: batman-adv: clear current gateway during teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52926
Introduced by commit 2265c14 ("batman-adv: gateway election code
refactoring") in v3.1-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a340a51ed801eab7bb454150c226323b865263cc]
stable/5.10: [a3f3f1ec8aad84c5dd386c430b9c61cddd85b18f]
stable/5.15: [e2ec4c712d19141ca7bf7fbbb1d842f73abaa186]
stable/6.1: [9a1a8ed4facfe843bde6fdfcf7af0e9923eb2e17]
stable/6.12: [30bda3ef4b0cac777f1a7c314cd08b8ff6437365]
stable/6.18: [ae7aeb0ce3c0ebbe357ed525779acac197a18086]
stable/6.6: [6de089b545db013433cf934bb4e4433dec2dd65f]
stable/7.0: [17e3a441111cd1a530cd6ee69a22f3161d80d810]
CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52927
Introduced by commit 81e675c ("netfilter: ebtables: add CONFIG_COMPAT
support") in v2.6.34-rc1.
Fixed in v7.1-rc6.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f438d1786d657d57790c5d138d6db3fc9fdac392]
stable/5.10: [d7a8fb6f10d55a1c37b0bf8c20cca24dffd76e00]
stable/5.15: [21af4c030567d2e6c89bb927bc18b51fba52a400]
stable/6.1: [dad9ebf8107955bb54bd3f9cf22591b6ff37bac1]
stable/6.12: [7ad0e463fc7eafae2141cc38054264636f8b3e94]
stable/6.18: [bf8e8eac7ede51dc318e06acef5a896dcbba7595]
stable/6.6: [a27cb7325a6c69970041c7f8541fafed5a1ea3ec]
stable/7.0: [fcc4c043d137e7f1de4673dba1f3116e45377c67]
CVE-2026-52928: af_unix: Reject SIOCATMARK on non-stream sockets
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52928
Introduced by commit 314001f ("af_unix: Add OOB support") in v5.15-rc1.
Fixed in v7.1-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d119775f2bad827edc28071c061fdd4a91f889a5]
stable/6.12: [645b1ed3259af38b7814242a420bc2081bdd1eb6]
stable/6.18: [c34c41446acf6c0d13b5b06c809be11e0f7f2729]
stable/6.6: [0d7e7235bc543c6ed7b873e3015db814d8e8c414]
stable/7.0: [3147ddf5a41c20c45c2eb69e00b62f10f822056a]
CVE-2026-52929: sctp: stream: fully roll back denied add-stream state
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52929
Introduced by commit 637784a ("sctp: introduce priority based stream
scheduler") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a5f8a90ac9f77c678a9781c0a464b635e0d63e49]
stable/5.10: [0cd2dc6dce8ca47212cd306ccd52eb315ef3cf85]
stable/5.15: [a6724b7b812ac8793514a1d5938db5d9d29ae725]
stable/6.1: [9662eb0401518f0b4681f10e7fbf688f504f24cf]
stable/6.12: [39dc2b0eb5371a669ebc9ec6072b9184eac95418]
stable/6.18: [d5ea0b3e261fcb2cfff142675516165244cab1da]
stable/6.6: [7dd9a42b044aad2dbe037db1c1e2943582485b44]
stable/7.0: [1c6773b8c081509dcd5cd2954f2b02c50c00f151]
CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52930
Introduced by commit 4c677e2 ("shm: optimize locking and ipc_namespace
getting") in v3.1-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2e5c6f4fd4001562781e99bbfc7f1f0127187542]
stable/5.10: [b1e9aef48e4d8a0c1b54fb913077b0824ed7d650]
stable/5.15: [92cda2593cf2ed25b0e9d78e5e6d8303bba1a064]
stable/6.1: [1f0d01e35dbb228084d5187212e32c91a30dcbeb]
stable/6.12: [b5107b4ce3ad45fcf369ee2058c8910620f4b5a8]
stable/6.18: [db752ebfdaf2c7f27cd9690ef48b616af068319c]
stable/6.6: [6560be3f6a5bb84f006f184f0c966747bb58e1a3]
stable/7.0: [030bbc857bd51d4b25a90d931d3f8775ef22823a]
CVE-2026-52931: batman-adv: tp_meter: avoid use of uninit sender vars
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52931
Introduced by commit 33a3bb4 ("batman-adv: throughput meter
implementation") in v4.8-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6c65cf23d4c6170fcf5714c32aa64689718cb142]
stable/5.10: [0e388af04b3958b178a1b979527f93eb46ea1fee]
stable/5.15: [1a21c055f66e78973712a4a1be2a554f1ee2e4f4]
stable/6.1: [9884c9c02d3c90e9215db3c5128f59045d20ae91]
stable/6.12: [ecdaa3e4d91040206afe21bc8a0d1198a0971ff3]
stable/6.18: [dc2ae5fbd2dadc26735092f140b246841d969a11]
stable/6.6: [53f931e0146ae5bdab4cba302646827d06b3794b]
stable/7.0: [85397e48afe6be83ffca5ad3f4792296bfc81d3d]
CVE-2026-52932: xfrm: ipcomp: Free destination pages on acomp errors
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52932
Introduced by commit eb2953d ("xfrm: ipcomp: Use crypto_acomp
interface") in v6.15-rc1.
Fixed in v7.1-rc6.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7dbac7680eb629b3b4dc7e98c34f943b8814c0c8]
stable/6.18: [dc6dcba80d72a27ab61831ad3d253316e0c9b9d5]
stable/7.0: [b30aa173c3809f6af4c83a86099be1be19aa48eb]
CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52933
Introduced by commit a26a35e ("io_uring: make poll refs more robust")
in v6.1-rc7.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
stable/5.15
Fixed status
mainline: [326941b22806cbf2df1fbfe902b7908b368cce42]
stable/6.1: [81bf96b0abbfa4cd47ea32e12596aed3855fb2f3]
stable/6.12: [fc47043f3d9af3efa407665b47f8378ec691ba18]
stable/6.18: [ea0697129807d718037f618221037aa0660ee3c5]
stable/6.6: [cf522703d4f194991615763697ae25a3f9539763]
stable/7.0: [c6d191164dc81838d8dbf452a6000f68c558d1ae]
CVE-2026-52934: batman-adv: tvlv: reject oversized TVLV packets
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52934
Introduced by commit ef26157 ("batman-adv: tvlv - basic
infrastructure") in v3.13-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f50487e3566358b2b982b7801945e858c78ad9ab]
stable/5.10: [c02aa6c0c9d1bea9bb75dea362b75ad225137bae]
stable/5.15: [1595628a2f877d052eda18865ccf539392c47c04]
stable/6.1: [6448a49344e87487b61bd88cb850cd694a0f576d]
stable/6.12: [94db72e9dac202e017ee3db22c59d17e4f3bf171]
stable/6.18: [ede47988ac5687793745b17c1634a496a2299919]
stable/6.6: [13493b00dd1e05a705981e052158652ea23eb482]
stable/7.0: [94a3d72cd9b21116d7c6d5bdc57c11401fc28557]
CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52935
Introduced by commit e27cca9 ("xfrm: add espintcp (RFC 8229)") in v5.6-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c381039ade2e161ab08c0eda73c4f8b9a7115928]
stable/5.10: [6564e9c7af7e1dc7bfe7f3093b728abe484d7630]
stable/5.15: [1777ceac4bea5e568a5ad44b7f9bb219c1db21b6]
stable/6.1: [8c6c691bf062dc0753a139a4ab8cb92a70fcf8f3]
stable/6.12: [ba21439302db9a82fe4edbed1e38a97271529421]
stable/6.18: [f9b38a8fbfa07f1deaf7ee1eb38fa8b21ea13990]
stable/6.6: [aa82a078f70f7ff88ba7d1017134e79d1ac140f2]
stable/7.0: [37487d55bf3300e3d2c1368da5c2bd3e3834ea4f]
CVE-2026-52936: crypto: jitterentropy - replace long-held spinlock with mutex
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52936
Introduced by commit bb5530e ("crypto: jitterentropy - add
jitterentropy RNG") in v4.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [01d798e9feb30212952d4e992801ba6bd6a82351]
stable/6.12: [4c03e6eb98443dc4d6d422a9780034a5b75376b4]
stable/6.18: [ff734dbd9e2432601a6dcd167cfb0bf8a36d1880]
stable/6.6: [18216b8ab6904753eaf31baf453cb02ecd202ba4]
stable/7.0: [ec427dc5286da1ed08f2d510e2147a7581b0cb02]
CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52937
Introduced by commit 3b23a32 ("net: fix dev_ifsioc_locked() race
condition") in v5.12-rc1.
Fixed in v7.1-rc5.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt stable/5.10
Fixed status
mainline: [bddc09212c24934643bd44fc794748d2bbb3b6cd]
stable/6.18: [719007c3492f0f1f9e9cdbed8ac45ba45bb13eeb]
stable/7.0: [05305e832be7b9d65b2b72caacf7d850b3942b2a]
CVE-2026-52938: bpf: Fix NULL pointer dereference in
bpf_sk_storage_clone and diag paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52938
Introduced by commit 5d800f8 ("bpf: Support lockless unlink when
freeing map or local storage") in v7.0-rc1.
Fixed in v7.1-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [375e4e33c18dfa05c5dfd5f3dfffeb29343dd4c7]
CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler()
on masked atomic completion
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52939
Introduced by commit 20c72bd ("RDS: Implement masked atomic
operations") in v2.6.37-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [34080db3e70ddf94c38512ad2331e3c3afca6cc1]
stable/5.10: [a0148342badd8c9b2e46551766a27cb76c82e715]
stable/5.15: [4dd262f875e87653df50b138de1390ab0628e6b7]
stable/6.1: [6e4615164d185a26badb2f376a2449f4d174a5f0]
stable/6.12: [0f7baa82a24813cdad0b06a6f8f07e4824af5ed5]
stable/6.18: [dcf458120add64c96a6ef5cf719340453f6e6abf]
stable/6.6: [0f22412a2f4fbbe0251c132abee045d15a90e5b6]
stable/7.0: [4fd34669558085bcb589aa2078a13b0ca79e360d]
CVE-2026-52940: tun: zero the whole vnet header in tun_put_user()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52940
Introduced by commit 288f304 ("tun: enable gso over UDP tunnel
support.") in v6.17-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7f2fcff15e99bb852f6967396ed12b38376e2c8d]
stable/6.18: [5fd1fa5a4254bfdd70571c77f5e3bcb4e43738d5]
stable/7.0: [585cb85e9a29185be05f326369573c2663cf4380]
CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in
smc_msg_event tracepoint
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52941
Introduced by commit aff3083 ("net/smc: Introduce tracepoints for tx
and rx msg") in v5.16-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7bf563badd37cb796df5477d2b78bb64148a1268]
stable/6.1: [68200112534bb2acd1d7117dc2d5c124868d866d]
stable/6.12: [b706d6d76a2a2793fe5ad0fbc2a75b6a460094ef]
stable/6.18: [d2ea0b8aef8746e147602eac87ca8538f4bc7e66]
stable/6.6: [720c76b930c52cd58f50eb6b10569d03dccc7959]
stable/7.0: [561cf66fa9b6c86dfe4e687d2d1aeaaa6739917f]
CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52942
Introduced by commit 7eb9282 ("netfilter: ipt_LOG/ip6t_LOG: add option
to print decoded MAC header") in v2.6.36-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a84b6fedbc97078788be78dbdd7517d143ad1a77]
stable/5.15: [d704ee9c7bc68a161684c51a7ac05b446dcf38d4]
stable/6.1: [befb8968a2abdfa948d5600ea7f7a509a292a590]
stable/6.12: [c38d41134085193efd5b237cf513ad5b3421a60d]
stable/6.18: [af1b7699466f6556b351fa25d3dc870abfb5d310]
stable/6.6: [8a81e336da685423f5b64aac4d571e63d674c52a]
stable/7.0: [65ef7397eb9a296e91839f5fd10be96f23d332e7]
CVE-2026-52943: net: skbuff: fix missing zerocopy reference in
pskb_carve helpers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52943
Introduced by commit 6fa01cc ("skbuff: Add pskb_extract() helper
function") in v4.7-rc1.
Fixed in v7.1-rc6.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [98d0912e9f841e5529a5b89a972805f34cb1c69d]
stable/5.10: [8dbed691e43a50903658130bde0fcb5abc425b37]
stable/5.15: [9b40bdc2a3298225dffab8158208a0d8c6300578]
stable/6.1: [fd470f0a97b8e9a125f520265d2f3b088ffb5b8a]
stable/6.12: [2e0e74c59b2761a414d9f48d7bee1e45220b2427]
stable/6.18: [96a4713ae041cc85e712bac682cd2e644004d6c6]
stable/6.6: [ceafb893b12f23331dcc5ff9587e643c3a40ee9f]
stable/7.0: [474d6c771d798bca84f0a140b611e36743511e18]
CVE-2026-52944: ksmbd: fix FSCTL permission bypass by adding a
permission check for FSCTL_SET_SPARSE
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52944
Introduced by commit e2f3448 ("cifsd: add server-side procedures for
SMB3") in v5.15-rc1.
Fixed in v7.1-rc6.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cc57232cae23c0df91b4a59d0f519141ce9b5b02]
stable/6.18: [de9eb0b44fa9123170e6245b49638e0e453c10f8]
stable/6.6: [3127a884525dc8ca4def73254bfcd3ccef0bf812]
stable/7.0: [aef151bcfa494bfe983669de2726734b534adb73]
CVE-2026-52945: Revert "wireguard: device: enable threaded NAPI"
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52945
This fix revert e7096c1 ("net: WireGuard secure network tunnel").
Fixed by db9ae3b ("wireguard: device: enable threaded NAPI") in
v6.16-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e]
stable/6.12: [e94b369ff82f9bc84f090f271bd78f41c9f6ab2f]
CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52946
Fixed by 00633c4 ("fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync
signaling") in master branch.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [00633c4683828acd5256fa8d5163f440d74bbe71]
stable/5.10: [54626335ea4174ab2d9a183b511d825f6765e47b]
stable/6.1: [32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33]
stable/6.12: [1bee417678f1135e35b25a37734db46aa94258d2]
stable/6.18: [20a93e397abe850c49b6fa0e8cc827b5f634a8f5]
stable/6.6: [b5fa9e32fb6718f70c986ee14dd5d01b4846f331]
stable/7.0: [bfcc8e8d8a495bb34cae9e620adfb75fb13a3954]
CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF
in qrtr_port_remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52947
Introduced by commit bdabad3 ("net: Add Qualcomm IPC router") in v4.7-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a2171131ecda1ed61a594a1eb715e75fdad0fef5]
stable/5.10: [2aa4c12723fe432e623462a3be42a197a128722b]
stable/5.15: [03bfa95e452e2b6ccd76a332060ae4feaf5ad84d]
stable/6.1: [474293d90880622fde9d2430fb0165767090f7b3]
stable/6.12: [7de2d447072be3b1a76793f034432338fc9c494b]
stable/6.18: [ab269990ed58143a92a263be1bee626d82ac03da]
stable/6.6: [2047c2aa0963bb2872fd722300a15bcb441a4c00]
stable/7.0: [3b20ec8f31e8a6a6782243f473b0abd3463621df]
CVE-2026-52948: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52948
Introduced commit is not determined.Fixed in v7.1-rc3.
Fixed status
mainline: [617eb7c0961a8dfcfc811844a6396e406b2923ea]
stable/5.10: [e9ffd5f5050fbb199d270a85614cd27ebed6fbac]
stable/5.15: [0b88ecfbc9dc33b4db8836c37b50cf174e6c0691]
stable/6.1: [943e318eedbeaeea08ece3f5dd44c982f4ed2ef5]
stable/6.12: [ff02add34ffd03449b8115904ebe2ec4fed022d4]
stable/6.18: [ffbcf31f032eb454ebfd29309f51366fe57f4ac4]
stable/6.6: [aa6ef734016912653a909477fb30aeb66c98b3a2]
stable/7.0: [4576621dc6577f21a032acfd16c3ad61907a5ea7]
CVE-2026-52949: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52949
Introduced by commit 70d645d ("drm/ttm: Add helpers for shrinking") in
v6.15-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1d59f36e95f7f7134db0e313c9d787cb0adb2153]
stable/7.0: [9402ad98a047dd9894ec868a7df5ad9bd03327d3]
CVE-2026-52950: drm/xe/dma-buf: fix UAF with retry loop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52950
Introduced by commit eb289a5 ("drm/xe: Convert xe_dma_buf.c for
exhaustive eviction") in v6.18-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [155a372a1cc50fa93387c5d3cdfd614a61e1afd1]
stable/6.18: [39fdac6be02eb7c3460518c1c4085f75f935c4ce]
stable/7.0: [827062952ed9bdf4220466c1f05ce452d04bdedf]
CVE-2026-52951: drm/xe/dma-buf: handle empty bo and UAF races
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52951
Introduced by commit dd08ebf ("drm/xe: Introduce a new DRM driver for
Intel GPUs") in v6.8-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [981bedbbe61364fcc3a3b87ebaf648a66cd07108]
stable/6.12: [9894731e513019df22a29e5c52f1c98890355ff1]
stable/6.18: [20a99ea1e2fd720856d6ba497ff26b82c604751f]
stable/7.0: [c473ae25421fddc3dde247ba7b85225b10641d09]
CVE-2026-52952: iommu: Fix WARN_ON in
__iommu_group_set_domain_nofail() due to reset
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52952
Introduced by commit c279e83 ("iommu: Introduce
pci_dev_reset_iommu_prepare/done()") in v7.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5474e6e17a262db45c60575c73f70210f5c7001f]
stable/7.0: [8fc289e809f3eb7e36cadc4684ab6fad747a5a93]
CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52953
Introduced by commit 7d0c9da ("iommu/vt-d: Add set_dev_pasid callback
for dma domain") in v6.6-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6dea58d8625c06b9654c0555f101742481335c3]
stable/6.18: [88397fad7914ee74a7880fa5ce01f9eb6bfe0743]
stable/7.0: [1e659db468476733d217c1314c1e0d9244356d6c]
CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52954
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [d289478cfc0bcf81c7914200d6abdcb78bd04ded]
stable/5.10: [c7bf7864e2924fa5508ac270b0e9364bc13d5a6c]
stable/5.15: [f47430fc1f815e87406e2d3b4e476eff1bc7fd9b]
stable/6.1: [0b6a3bcb91bc5bfeda39f0df3b71bab62c13e9da]
stable/6.12: [80c73bd1b2b04355d1d0c29be8ccbd25a380905d]
stable/6.18: [4d2b37abda9536808655830d683dc491d31741a8]
stable/6.6: [534ebc08df97c47d4c7596f336fa31ecbf91519c]
stable/7.0: [0a1265a9ab875f92b6a3ffb497404f46cf9d76a3]
CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52955
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [4c79fc2d598694bda845b46229c9d48b65042970]
stable/5.10: [6e70ef53e818c53eab28d7b0026b7fd03dddaba5]
stable/5.15: [ebe76d58a48a48031b98543d86c4cd30a825b622]
stable/6.1: [3f42508191e129ee6b5ea96578d5cab14f2a013a]
stable/6.12: [cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5]
stable/6.18: [0f3604cbe4df14c5e58288ac9f57511e726a222d]
stable/6.6: [ea0d42137f0c06da71e37ffc647aab4c5309599a]
stable/7.0: [fb176a99e4c1a5a8448a83d83d3606203ba81faa]
CVE-2026-52956: libceph: Fix potential out-of-bounds access in
__ceph_x_decrypt()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52956
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [821365487aa58d06bda65c676ba215d506ba9768]
stable/7.0: [c7e9b53aebe401970f1b5f5a01b4e021b18e8bb2]
CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52957
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf]
stable/5.10: [d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f]
stable/5.15: [301286c0ccd37d66b0e40786fd35a4f19cdbd88a]
stable/6.1: [7169f326a23d0f547fcd90e68b72fd387622e126]
stable/6.12: [312ec973efac0efb9b9ed64214235910e9ecbaa8]
stable/6.18: [f2f95e6d4b97e70bb876139b0583fc8079983f85]
stable/6.6: [d7a65a34d2453f8cd3e0cc0e1319740af7e24276]
stable/7.0: [a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c]
CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52958
Introduced by commit dcbc919 ("libceph: switch osdmap decoding to use
ceph_decode_entity_addr") in v5.3-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [35d0ed82d03e5ee77ea4f31f20e29562a7721649]
stable/5.10: [36a79759a288961b1ff28a68ec2d1f56f6848098]
stable/5.15: [3f2575bb7f955d42569d96c3e04fa958a0dcf4b4]
stable/6.1: [8713bbc4b2b9ad78f803978e54b7e49dd21bd9be]
stable/6.12: [e7187f33c02488697ec0d01d82bf7a3f8deaba8f]
stable/6.18: [48df98d12b15360cd56af5c1f460307b340c1197]
stable/6.6: [0d2dd7e6bb74fd7712aa73457a4a821906c6863a]
stable/7.0: [ee933694645dac062d65fc2743f92bc06fa0db6b]
CVE-2026-52959: virt: sev-guest: Do not use host-controlled page order
in cleanup path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52959
Introduced by commit 3e385c0 ("virt: sev-guest: Move SNP Guest Request
data pages handling under snp_cmd_mutex") in v6.14-rc6.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [23e6a1ca04ae44806439a5a446e62e4d42e80bb4]
stable/6.18: [3f6fb0211b39aaa1b841260681dd02ca6b693ed5]
stable/7.0: [9e48b4f813d2c3db75d522aa82ab705ce04b7e2d]
CVE-2026-52960: ceph: put folios not suitable for writeback
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52960
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [544576f0f05c4a759806acddfaaeb686f14fb4b0]
stable/7.0: [86921e890fe1dea9791fb70bec552516fd47716a]
CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to
stale blob size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52961
Introduced by commit d93231a ("ceph: prevent a client from exceeding
the MDS maximum xattr size") in v6.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0c22d9511cbde746622f8e4c11aaa63fe76d45f9]
stable/6.12: [7eb72425c4e3234926502eb262f9d6193ccd572c]
stable/6.18: [d5bd8b4e39cfa8b087448adcd48088065cd629d5]
stable/7.0: [368d21ae9081c93497b1c8163bed3eddcb2443ff]
CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52962
Introduced commit is not determined.Fixed in v7.1-rc4.
Fixed status
mainline: [5d3cc36b4e77a27ce7b686b7c59c7072bcb3fa8e]
stable/5.10: [521e5aba857fd267624892c8dd6295f22ce0267e]
stable/5.15: [d0cb994605c84a159c1d00d72cdc8583c321ef95]
stable/6.1: [ecf94823c5c6a20790bb76ed2816822b0beb0c22]
stable/6.12: [7d3e8d2d648d5f0df29b4710246680f47695fe94]
stable/6.18: [3fa13ceefbc5f36131110342743994cb3de80637]
stable/6.6: [4bfdcefdaa6092a06cacd59389c7756b36e6de8c]
stable/7.0: [bc7abce4460e490dcb579eec770f175b150b685f]
CVE-2026-52963: ALSA: usb-audio: Bound MIDI endpoint descriptor scans
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52963
Introduced by commit 5c6cd70 ("ALSA: usb-audio: Fix case when USB MIDI
interface has more than one extra endpoint descriptor") in v5.7-rc1.
Fixed in v7.1-rc4.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/4.4 cip/4.4-rt cip/4.4-st
Fixed status
mainline: [d6854daa67be623860f4e1873fd3d3c275aba4ed]
stable/5.10: [e2f1260a056eb3215c13c48c5378f3e4112dc3af]
stable/5.15: [c65b137d351e21cbc5630e73ef0eb1e1d75f5b20]
stable/6.1: [728ab0c72e49ca27185067984cd565425eb69b2e]
stable/6.12: [a0226560540c16717efcceaf15c862cf115b01d3]
stable/6.18: [09141583bd97f4bbd7358e29fd138fe798467cdb]
stable/6.6: [3d3b2b01a3e73828e201ece96f863e7a3e0cdc6e]
stable/7.0: [c59159ce10e75b568cd0d4b29efcb0fb0ddecc94]
CVE-2026-52964: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52964
Introduced by commit ff49d1d ("ALSA: usb-audio: USB MIDI 2.0 UMP
support") in v6.5-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [918be519c7876329e1b6e2ea1c59f0b75e792dca]
stable/6.12: [a310b4bebda5e4a1b26520c0cc5145ccd6d617e2]
stable/6.18: [f9c184a83574549a36ea69b755f650e57d164c78]
stable/6.6: [fafc97bd01e4c737eaeafadfdadb1af4bbfa7307]
stable/7.0: [17e76b19de1aff5ff4de64d269290bd1b07a01d3]
CVE-2026-52965: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on
swapout failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52965
Introduced by commit fc5d966 ("drm/ttm: Move swapped objects off the
manager's LRU list") in v6.13-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b2ed01e7ad3de80333e9b962a44024b094bc0b2b]
stable/7.0: [0124a09e3e5f5f6080efe9663b27af27933f8382]
CVE-2026-52966: drm: Replace old pointer to new idr
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52966
Introduced by commit 5e28b7b ("drm: Set old handle to NULL before
prime swap in change_handle") in v7.1-rc3.
Fixed in v7.1-rc4.
Bug introduced commit was backported to following branches.
stable/6.18 stable/7.0
Fixed status
mainline: [dc366607c41c45fd0ae6f3db090f31dd611b644a]
stable/6.18: [318b995cffcfcaa69a234d28123a3f4ae186a9df]
stable/7.0: [38f12d0e10d83b66fa1466400d876a3a8da31542]
CVE-2026-52967: smb/client: fix possible infinite loop and oob read in
symlink_data()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52967
Introduced by commit 76894f3 ("cifs: improve symlink handling for
smb2+") in v6.1-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7d9a7f1f96cd617ee9e75bb22217c709038e26b8]
stable/6.1: [1cfa2d59f669db28d6292d10ff87ca6837c781b0]
stable/6.12: [cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23]
stable/6.18: [97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb]
stable/6.6: [b41598bf54b3fe528994e573df6008f8f4d0a4f4]
stable/7.0: [1b9331b16b0ed9414dcf7583d8134bdfeb117aae]
CVE-2026-52968: KVM: s390: pci: fix GAIT table indexing due to
double-scaling pointer arithmetic
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52968
Introduced by commit 3c5a1b6 ("KVM: s390: pci: provide routines for
enabling/disabling interrupt forwarding") in v6.0-rc1.
Introduced by commit 73f91b0 ("KVM: s390: pci: enable host forwarding
of Adapter Event Notifications") in v6.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [16d990a15491cf76cd6eef0846e1b4100e63261a]
stable/6.1: [31a9d9f9942885aae356a1a57c79e82c5b5b0828]
stable/6.12: [11b8ff5b930b351dd1f6f088dce0beb027ac92d0]
stable/6.18: [b22a2da8792a7bfe743c1a922e77fa499ddedbe8]
stable/6.6: [a99a25db131ece5e6c0f7632da606de631efe4f2]
stable/7.0: [e7216651b94e92e5433fb2f54b77864642b4ea48]
CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52969
Introduced by commit fb04a1e ("KVM: X86: Implement ring-based dirty
memory tracking") in v5.11-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [577a8d3bae0531f0e5ccfac919cd8192f920a804]
stable/5.15: [74f1a22f7a80f03d28ad8551a2d25d563433addf]
stable/6.1: [0eb281eb95b2d4eea4db1da5fe91023aecc97095]
stable/6.12: [b315b033a877b1ee6d827810b5d7bb4392ffcf8d]
stable/6.18: [0d419c23bb11b5c9664de777c47c1f04a235882d]
stable/6.6: [01b71b930f15728aa8599478a7ce90c19dcd9fc2]
stable/7.0: [ecf9b3ea7847fe14f34b8c41f00de1eb95c747da]
CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52970
Introduced by commit 857b460 ("netfilter: nft_ct: add ct expectations
support") in v5.3-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [19f94b6fee75b3ef7fbc06f3745b9a771a8a19a4]
stable/5.10: [cdb9a25dd3416d427e8b2753210f8baf44207577]
stable/5.15: [26ab32ec73941871c97562ee1f39587950dc3b68]
stable/6.1: [7b96242ceedfe249f158419f3254bcee04173ffe]
stable/6.12: [2aef1b13d5c0285f340512c6c07eb858fd018fd8]
stable/6.18: [1dced0725e2fae3ac3416274db20a7ff5a46931d]
stable/6.6: [ecca618e1e339494911090474ed87742c0f73976]
stable/7.0: [84c422cea5a45fe56be839f25880f21fd33940cd]
CVE-2026-52971: net: ena: PHC: Fix potential use-after-free in get_timestamp
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52971
Introduced by commit e0ea341 ("net: ena: Add PHC support in the ENA
driver") in v6.17-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e42c755582f0960e684298762f0ab927b3778376]
stable/6.18: [95e8ae9af2a61b4e72f5c585bf4c7d8aaf2a2c98]
stable/7.0: [ca9ed40f28949353911dcb524ff8fff2f3409c97]
CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52972
Introduced by 400c40c ("crypto: algif - add AEAD support"). Fixed by
e4c0647 ("crypto: af_alg - Cap AEAD AD length to 0x80000000") in
master branch.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e4c06479d7059888adf2f22bc1ebcf053bf691a2]
stable/5.10: [f8a5203596797f394ff3f9aa4005597a92249802]
stable/6.1: [a4fe4eb580bbc7439f649a496d4cf38415a4021c]
stable/6.12: [265ac26d1c5e17b34d497cbda1f754a1ec8552bc]
stable/6.18: [a1c5672faf8e93e38c2deac3979cc767ca5cf918]
stable/6.6: [e4c4a5074532eaaa14951994a3aad0d479aa7431]
stable/7.0: [97948906dc8e0ea84775e03e35b60a2063c70193]
CVE-2026-52973: futex: Drop CLONE_THREAD requirement for private
default hash alloc
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52973
Introduced by commit d9b0532 ("futex: Move futex_hash_free() back to
__mmput()") in v6.17-rc5.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ee9dce44362b2d8132c32964656ab6dff7dfbc6a]
stable/6.18: [1dcd36420af2da5bd59306dba9caf78e3d248b1d]
stable/7.0: [974ac49a9a068b0591a59f65c63eb06579a13091]
CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX
setup failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52974
Introduced by commit 84c61fe ("tls: rx: do not use the standard
strparser") in v6.0-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [58689498ca3384851145a754dbb1d8ed1cf9fb54]
stable/6.1: [0c9f399b37ce22a5ed94cc51f03ed07ac7f38e32]
stable/6.12: [3c405dfa9619e506e75b8e41f8b29a5b99731877]
stable/6.18: [9c54e76f8d6eb11735918777ef0e0509e089557d]
stable/6.6: [688f12aa44511dd57e448eb670075c6302ad1dc1]
stable/7.0: [bd07fe6c38b9e44ff3fc02692a53f095c5cc9afc]
CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port->aggregator
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52975
Introduced by commit 47e91f5 ("bonding: use RCU protection for 3ad
xmit path") in v3.13-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c4f050ce06c56cfb5993268af4a5cb66ed1cd04e]
stable/6.1: [ba2272be04f0cb1e74e1e355ff32ef95df280731]
stable/6.18: [c169c5837525ad842df6a542facf52b6f866a519]
stable/6.6: [3b7265b3a82f40d2357c4004b26eb794a095b186]
stable/7.0: [78f409fd34fe9de2b24ad8e9dca1b4608a48ed3d]
CVE-2026-52976: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52976
Introduced by commit 7970cb3 ("'drm/xe/hw_engine_group: Register hw
engine group's exec queues") in v6.12-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f3cc22d4df3ed58439ea7e21daa54c3608e03b78]
stable/6.12: [f93b00161213a0fe9f7ff1d8498ee5ca9e0a5c43]
stable/6.18: [753b149d5a433eb19e0c1b0eb4526a6e26120d1f]
stable/7.0: [1be55646d8a2035343b012dcb12210db7bb8b056]
CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/
timeout wakeup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52977
Introduced by commit 07d91ef ("futex: Prevent requeue_pi() lock
nesting issue on RT") in v5.15-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bc7304f3ae20972d11db6e0b1b541c63feda5f05]
stable/6.1: [4e0ed44e51727d56244a822ab941efe507c47966]
stable/6.12: [0aacb6d18f76552e3e0ee25d9f40d21b3486f4cf]
stable/6.18: [69a7cfc66405aeaa2483147653d031b3592ffc9c]
stable/6.6: [e3f95b1ba242e37093305812df7fdbe7288a43ac]
stable/7.0: [0304d60abb9dcc02bc7fe6d1850f4ca206e8f1a0]
CVE-2026-52978: net: psp: require admin permission for dev-set and key-rotate
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52978
Introduced by commit 00c94ca ("psp: base PSP device support") in v6.18-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b718342a7fbaa2dff5fefc31988c07af8c6cbc21]
stable/6.18: [aa1a08a4632af5d1117779e7ff0e32e3c69f29bd]
stable/7.0: [fb88a8c86109edb15971481e3de816a8bfdfe571]
CVE-2026-52979: net: psp: check for device unregister when creating assoc
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52979
Introduced by commit 6b46ca2 ("net: psp: add socket security
association code") in v6.18-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b89769f936a8fa9e66de72ddc1b71a9745a488e6]
stable/6.18: [d90df5ce6deb2424de3ad89bcc693ac1b67accc9]
stable/7.0: [e201c57073e624dd2ba5beaf9eda31e19b77b332]
CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52980
Introduced by commit 82e9d04 ("sched/fair: Avoid re-setting virtual
deadline on 'migrations'") in v6.12-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3da56dc063cd77b9c0b40add930767fab4e389f3]
stable/6.12: [c71bf35caba12bfd9bc23e32b0bcd9e02d1cf1ac]
stable/6.18: [f3c16e1f4a314a20717ab90a41885f8111a242ab]
stable/7.0: [8f4a16200785f49cf02c5b71bdfe7a9dab63f23a]
CVE-2026-52981: neigh: let neigh_xmit take skb ownership
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52981
Introduced by commit 4fd3d7d ("neigh: Add helper function neigh_xmit")
in v4.1-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4438113be604ee67a7bf4f81da6e1cca41332ce4]
stable/6.1: [8a89054a1ec0767aec25ed2bbac933da6ba3cf5a]
stable/6.12: [0084712e0bee204b284510cdb63182fd5a30c2b7]
stable/6.18: [63063ba60d2dc334e34f1e3f9271d7f3f6f30307]
stable/6.6: [9247d59ca15bf60a57dca08103f055d8a4340877]
stable/7.0: [445e45a2c3a078316a62d2d331a570cf34ef5079]
CVE-2026-52982: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52982
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [23f0e34c64acba15cad4d23e50f41f533da195fa]
stable/5.10: [5af290c86fa81ddbc86a08d54229af5daa40c6a4]
stable/5.15: [24831b0b2ada9fef18d1f486b7b7c444ee5ba637]
stable/6.1: [423b5b86e14e190f6e3161eb5f2ea5f908295ba7]
stable/6.12: [30cf9829d09ca958279c937af8e35495cd2f1e09]
stable/6.18: [6999d70e0eda39af029fa1891c48f0a8832b09d5]
stable/6.6: [5db090ca07b28a63fb1499690cf19a3f3adafacb]
stable/7.0: [4dd7eb94f79486b77ca6b4c8676aedbc465dc802]
CVE-2026-52983: net: airoha: fix BQL imbalance in TX path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52983
Introduced by commit 1d30417 ("net: airoha: Implement BQL support") in
v6.13-rc1.
Introduced by commit c9f9477 ("net: airoha: Reset BQL stopping the
netdevice") in v6.13-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d9f5a118205da2683ffcec78b9347f1f01a820e]
stable/6.18: [aaad53a55812acd2355c0e5478896381e78b0110]
stable/7.0: [ded2694247a55a16d0ebbe2d6f9139305c21457a]
CVE-2026-52984: net/sched: netem: fix queue limit check to include
reordered packets
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52984
Introduced by commit f8d4bc4 ("net/sched: netem: account for backlog
updates from child qdisc") in v6.13-rc3.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt cip/6.12 stable/5.10 stable/5.15 stable/6.1 stable/6.12
stable/6.6
Fixed status
mainline: [4185701fcce6b426b6c3630b25330dddd9c47b0d]
stable/5.10: [0f875d52db4c921da610e481b72f03cc82fdcb72]
stable/5.15: [ef9a41b3870fb90577da5b2de5bd140022d4021e]
stable/6.1: [74fcd8e127200a50ee22ba2b45c164722bdb9177]
stable/6.12: [54b5dbacd00dedffd5e2eed76de1c3839996b5e6]
stable/6.18: [8450462eaf91d5d2a9e863507b16d18e814baef3]
stable/6.6: [39a66e83ea41fe845631eeb8d326953de27d13f9]
stable/7.0: [936a7dd87251f6f3e88983350833edf60fe6a80b]
CVE-2026-52985: netdevsim: zero initialize struct iphdr in dummy sk_buff
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52985
Introduced by commit da58f90 ("netdevsim: Add devlink-trap support")
in v5.4-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [35eaa6d8d6c2ee65e96f507add856e0eacf24591]
stable/5.10: [175556c049eaec14efde8c6475e763b7579b9de7]
stable/5.15: [6e2cfd0904976e701d7a76b86b694e72af230ab0]
stable/6.1: [1b7b6ae0e93b8d512e208b1378d74af052e4f4e7]
stable/6.12: [978ca6ff789f1f19c03288ac20cc1f4774e88490]
stable/6.18: [750d0091bebf44975421268d37484ef87060d263]
stable/6.6: [818f7673ed7f4a29d4b9cee8184c47d6e57162b4]
stable/7.0: [bc6002865e8c4fcf9e94975f7cf023448d8764e2]
CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52986
Introduced by commit 05e3ced ("[NETFILTER]: nf_conntrack_sip:
introduce SIP-URI parsing helper") in v2.6.26-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8cf6809cddcbe301aedfc6b51bcd4944d45795f6]
stable/5.10: [8cd0358379570003659186706e077929d6930c40]
stable/5.15: [9c6afcb1c3cbb2c0da65b8515ac14d7273872f84]
stable/6.1: [b3264c977e79d8a25778d4fd11520f00fea1329c]
stable/6.12: [9f69c323ae0ab517e595c2cc74e0ae0d9d085611]
stable/6.18: [7df9863bf538a626e8a684e59cb2c43eac0ef3c8]
stable/6.6: [ea2ecd29b8f4433e52607192ca91084f95787ca0]
stable/7.0: [523762e3b6933fff81f01dfa3c60c0774044cdab]
CVE-2026-52987: drm/amdgpu: avoid double drm_exec_fini() in userq validate
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52987
Introduced by commit 42f1487 ("drm/amdgpu/userqueue: validate userptrs
for userqueues") in v6.19-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [508babf310365f1107a2e8831c267c292a286818]
stable/7.0: [c7c3ae7c01e5a0742b93cb9b40800bdd7f811e38]
CVE-2026-52988: netfilter: nf_tables: join hook list via
splice_list_rcu() in commit phase
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52988
Introduced by commit 78d9f48 ("netfilter: nf_tables: add devices to
existing flowtable") in v5.8-rc1.
Introduced by commit b9703ed ("netfilter: nf_tables: support for
adding new devices to an existing netdev chain") in v6.4-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6134e62dba2ea4f760b29d5226907f447c92400]
stable/7.0: [1346be9379639c30877083b12747d4eacb83c24f]
CVE-2026-52989: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec()
errors to its callers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52989
Introduced by commit 52a0a98 ("nvmet-tcp: add bounds checks in
nvmet_tcp_build_pdu_iovec") in v6.19.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [ea8e356acb165cb1fd75537a52e1f66e5e76c538]
stable/6.1: [3df42a854686fa06484e37ac1a3931c8e3e3453c]
stable/6.12: [f9204a2b78dd18374d3bcf9bf93d9021ce22de1b]
stable/6.18: [c2a11441538bdbbc5aa003f190995eba93a89b88]
stable/6.6: [d7c8f95f599b3b38a717d2e771c3f8c174f657c3]
stable/7.0: [046fa5c72d15cd8e2d592e275697ea399d8f76b0]
CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52990
Introduced by commit c3638b5 ("fsnotify: allow adding an inode mark
without pinning inode") in v5.19-rc1.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt stable/5.10 stable/5.15
Fixed status
mainline: [4aca914ac152f5d055ddcb36704d1e539ac08977]
stable/6.12: [8c8afa6444e6bdc145d2bf2f3aeeca6da3e36b42]
stable/6.18: [b740cc86816bbc87902ae9db74cd21abde3c8d63]
stable/7.0: [5c80289503da3658e3df80280598c68d181eadbd]
CVE-2026-52991: sched/psi: fix race between file release and pressure write
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52991
Introduced by commit 0e94682 ("psi: introduce psi monitor") in v5.2-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a5b98009f16d8a5fb4a8ff9a193f5735515c38fa]
stable/6.18: [03dc070fa0fc3cb4068693f468ccd5f8a7e58282]
stable/7.0: [d4352c0709bfd38c752fccbde7fd72a82ac78f23]
CVE-2026-52992: fs/adfs: validate nzones in adfs_validate_bblk()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52992
Introduced by commit f6f14a0 ("fs/adfs: map: move map-specific sb
initialisation to map.c") in v5.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dd9d3e16c2d5fa166e13dce07413be51f42c8f5d]
stable/5.10: [33aafd2418a59c96c0389d47ea09026661fa9ec6]
stable/5.15: [1f0ed0f57f0fc87e46fe19a05435c214dc464be2]
stable/6.1: [6ff8cca5cdb4f2e0ea6d28ecd78479dd3f221ebc]
stable/6.12: [1586bd2d2fb436a26df20a70e78b000d34a7d159]
stable/6.18: [a3fd5dc1c7b0aae947a67dc2e2c037d57557a4de]
stable/6.6: [a11372a8b1ceaa5e950a84b3b5fbf8228f25e277]
stable/7.0: [60d82592ac8b5637fbed871381eb0a16df0a492e]
CVE-2026-52993: tipc: fix double-free in tipc_buf_append()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52993
Introduced by commit d618d09 ("tipc: enforce valid ratio between skb
truesize and contents") in v4.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a]
stable/5.10: [a438975a6dcdbd70865978c021650d1485586f0b]
stable/5.15: [4ee4deadaae7cb2e3d53af0fc889cf92a73413c0]
stable/6.1: [d3556656c6daebf8def751c7e71d11dd0a180d24]
stable/6.12: [4d104882bc815d4ec666ace9155f5f52715879a6]
stable/6.18: [1d5e589055880fae229e229e1929e087dbe08cf3]
stable/6.6: [0274f24485fc38032d4093e463dc3ff5c7a667c9]
stable/7.0: [29940fff14110ca48c5ccc168d121665b51bb778]
CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52994
Introduced by commit 581512a ("vsock/virtio: MSG_ZEROCOPY flag
support") in v6.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1cb36e252211506f51095fe7ced8286cc77b4c80]
stable/6.18: [6af1736b5810bc8a4a43a8518530113f5a757dc1]
stable/7.0: [d0117950075f0a9d5944980784c719d8ebcd4bff]
CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52995
Introduced by commit ec16227 ("RDS/IB: Infiniband transport") in v2.6.30-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c88eb7e8d8397a8c1db59c425332c5a30b2a1682]
stable/5.10: [81651e9d7dea1c048d2952f57632a042931d7b43]
stable/5.15: [0797b2e6901827694aa9c34c4c72118c8c97fba1]
stable/6.1: [5e67cc262afb384e835c3327e9d954eeaedc6a87]
stable/6.12: [c7cb9eed8215a790f052f49cdccf577720d2bb62]
stable/6.18: [91ce1bb6e4194dc2321748f68145359dcf86e350]
stable/6.6: [b6ba93a7b71ed443c9843eb12d27ed86f1e52694]
stable/7.0: [912ba2e5704fdb8bc5decda96dfc1a57838f0099]
CVE-2026-52996: ksmbd: fix durable fd leak on ClientGUID mismatch in
durable v2 open
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52996
Introduced by commit c8efcc7 ("ksmbd: add support for durable handles
v1/v2") in v6.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [804054d19886ac6628883d82410f6ee42a818664]
stable/6.12: [f31beef633fbf2b5af7805fa187a10bcff1d4b49]
stable/6.18: [06f709d0e531f3e54d88665dd426be3998a774e6]
stable/6.6: [407b6e699ba8b45b72cc265eed8a1bc8a7191609]
stable/7.0: [8c4a0ef19c8264c150833131af34541495832cd0]
CVE-2026-52997: net/sched: sch_dualpi2: drain both C-queue and L-queue
in dualpi2_change()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52997
Introduced by commit 320d031 ("sched: Struct definition and parsing of
dualpi2 qdisc") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [478ed6b7d2577439c610f91fa8759a4c878a4264]
stable/6.18: [86cf2eba2056bcf9c41fba260e599bd95bf9943b]
stable/7.0: [3042add80c2c50bd127d570b83319af612efde65]
CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL
dereference in ttl check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52998
Introduced by commit 11eeef4 ("netfilter: passive OS fingerprint
xtables match") in v2.6.31-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [711987ba281fd806322a7cd244e98e2a81903114]
stable/5.10: [f4de0777e4554a7de19c920accde6319dd530782]
stable/5.15: [c996a90f3071cf43683e5423da31aadbe002b8b4]
stable/6.1: [edc806f9122961f0d3819f7c69c14cccde31f277]
stable/6.12: [95be653a76793856ff8b2d8bd82c2943c23f5ca8]
stable/6.18: [79b90a96688e521771fa6ed3dc7864b76b8df293]
stable/6.6: [5d05de2f0928d81309a815ecc76d1a3ad72cbc16]
stable/7.0: [83fc5dd63455a779ea2dd0f7ffee3c920919d80b]
CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on
option matching
Announce: https://www.cve.org/CVERecord?id=CVE-2026-52999
Introduced by commit 1a6a095 ("netfilter: nfnetlink_osf: add missing
fmatch check") in v5.0-rc5.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st
Fixed status
mainline: [f5ca450087c3baf3651055e7a6de92600f827af3]
stable/5.10: [0145548346c4a30981a870a8ca00eac46ba27e85]
stable/5.15: [1c136f2c44a5913646bac85303612fd0825197a0]
stable/6.1: [1e19a07291bb8682c14c39a64725a3ae54ab8ccc]
stable/6.12: [70a3f31d25cf2ec9d4ddfa408120171ead955623]
stable/6.18: [21883587593d7c8bb519a79460a0b5bc5ffbdabd]
stable/6.6: [32e50f92c7cf3f4eba29622179a5fcdc2aebab41]
stable/7.0: [edb78a142d2e5948e63647c0646aa7e7886935f0]
CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53000
Introduced by commit e2cf17d ("netfilter: add new hook nfnl
subsystem") in v5.14-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6eda0d771f94267f73f57c94630aa47e90957915]
stable/6.18: [32fdd2e38e7435a368d88f5977a7d6585ebc8b0e]
stable/7.0: [3c7511f38ab511b791196b13ae48bf4973bf7dfd]
CVE-2026-53001: netfilter: xtables: restrict several matches to inet family
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53001
Introduced by commit ab4f21e ("netfilter: xtables: use NFPROTO_UNSPEC
in more extensions") in v2.6.28-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b6fe26f86a1649f84e057f3f15605b08eda15497]
stable/5.10: [14203f9edf944b3fb63faadd62f38452421ecdfc]
stable/5.15: [7eaf9c740f33230cb224dc265f3c69f8531ff57b]
stable/6.1: [9a109751b297b0f2135495749ef5a18ba31ec7d4]
stable/6.12: [689a91ff18d6448d94c1ab7c076fecdb2b668bef]
stable/6.18: [76160e04440c9698b989dbd9492a7ec4f520c9ee]
stable/6.6: [cbeb259f31382de70a70a59ffd0e66f5e80d9818]
stable/7.0: [fa88161ef56e29bdaa05cc89dbc4ee221e94bfe9]
CVE-2026-53002: netfilter: conntrack: remove sprintf usage
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53002
Introduced by commit 9fafcd7 ("[NETFILTER]: nf_conntrack/nf_nat: add
SIP helper port") in v2.6.20.16.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6e7066bdb481a87fe88c4fa563e348c03b2d373d]
stable/5.10: [2f793ba78470a99f40389b7dc60a81d9f5ad3956]
stable/5.15: [6bbf829b4c1b44c941c47dd0d710f1393258f3d5]
stable/6.1: [ab64e61c9323fa6de21bd20da1ddb29a0fb65d34]
stable/6.12: [a8e0a32a23d3f34862af3b4da792ecb3a891a9a3]
stable/6.18: [8e3be0d12615a173fe260cd42753ca7a001acbf2]
stable/6.6: [1c9fb8aeed06790d42cdcd00f6c3ce0b9e926c1e]
stable/7.0: [c08ff52e44945e6ef4ce0790f49ea761b060c45b]
CVE-2026-53003: pppoe: drop PFC frames
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53003
Introduced by commit 7fb1b8c ("ppp: Move PFC decompression to PPP
generic layer") in v5.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cc1ff87bce1ccd38410ab10960f576dcd17db679]
stable/5.10: [cb3beef35ab5e0c1afca9fd7648c6ae499786377]
stable/5.15: [ba758fdf1399f310b30098b6faa3fd043de47dd2]
stable/6.1: [fcca1df05322bb04e344dd1178b54b76a08eb7c3]
stable/6.12: [49e41b60ccd1bdbe9e218420f716dd5f9a2f9c71]
stable/6.18: [0cab5d077dd1efd2bd1a47271acc35894f945b4f]
stable/6.6: [8a5e840babc5c0fbd10c73728a13192347771ec6]
stable/7.0: [2b5c3c040d020e3ab3b9a8887031202d96843b1e]
CVE-2026-53004: sctp: fix OOB write to userspace in
sctp_getsockopt_peer_auth_chunks
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53004
Introduced by commit 65b07e5 ("[SCTP]: API updates to suport SCTP-AUTH
extensions.") in v2.6.24-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0cf004ffb61cd32d140531c3a84afe975f9fc7ea]
stable/5.10: [a132e199de69e2a45628aa8534df1bf5d44e1b6e]
stable/5.15: [2b5a2c957c7769d40110f725cf23987fcef50d75]
stable/6.1: [d45c7e99caf915b0f6c716bd8ffe9d45b9685761]
stable/6.12: [6849b995cda88a677bf08a05765d1db7905974fc]
stable/6.18: [70a089cc9590aa347a61e84434116ab74619e3c3]
stable/6.6: [d67fbc6dea5dbf7f46c618ebf65910a276078e20]
stable/7.0: [6bcf8fe4ef7967b22b814cbae9a57bbd3c853410]
CVE-2026-53005: af_unix: Drop all SCM attributes for SOCKMAP.
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53005
Introduced by commit c638291 ("af_unix: Implement
->psock_update_sk_prot()") in v5.15-rc1.
Introduced by commit 77462de ("af_unix: Add read_sock for stream
socket types") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [965dc93481d1b80d341bdd16c27b16fe197175ee]
stable/7.0: [b34a1d83c74a124c968b5adb25c809db3e2eb86a]
CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53006
Introduced by commit 4b3418f ("ipv6: icmp: include addresses in debug
messages") in v4.4-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f996edd7615e686ada141b7f3395025729ff8ccb]
stable/5.10: [7bff2c8fe5c35ae58bf73104f53db3676e6e5d94]
stable/5.15: [aff0f28f5be803de2452ce702631c021fcd9ce8a]
stable/6.1: [38bdbc897c0d83a3e2b925a51b69420f1feba29a]
stable/6.12: [1e1f0f89ee4692a64be3f3707ff8ac1ae57b03e7]
stable/6.18: [7c66b368c6ff453f99cb39d84af93e908e51eef2]
stable/6.6: [0069813e6ca9309eca78022bcb3aeb1e9ef90a12]
stable/7.0: [085e31a811ef234ef8c3e219c4636dfebfe7e10f]
CVE-2026-53007: ice: fix potential NULL pointer deref in error path of
ice_set_ringparam()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53007
Introduced by commit ccde82e ("ice: add E830 Earliest TxTime First
Offload support") in v6.18-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fa28351f970fa5138c7c5dedfe5dea480a0ee065]
stable/7.0: [c54e3c270384829336b2526033d44ce1aa6dc67c]
CVE-2026-53008: ice: fix race condition in TX timestamp ring cleanup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53008
Introduced by commit ccde82e ("ice: add E830 Earliest TxTime First
Offload support") in v6.18-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7c72ec18c2a4111204c2e915f8e4f6d849ce9398]
stable/7.0: [097409d20465723283632515df73038a4a853eda]
CVE-2026-53009: ice: fix double-free of tx_buf skb
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53009
Introduced by commit d76a60b ("ice: Add support for VLANs and
offloads") in v4.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1a303baa715e6b78d6a406aaf335f87ff35acfcd]
stable/6.12: [fd95ef8d0f6dbe2daa95d6488c9e0f8a95a7e048]
stable/6.18: [7cb19ec8ac087f33bee60f5d6054b284a5b9bb6f]
stable/6.6: [ca6f9d9aee5408c47e6c0fac10955cb6825ecd96]
stable/7.0: [4c08fc2119ef0281cfa2cee007acf0a251be55f2]
CVE-2026-53010: ksmbd: fix use-after-free in smb2_open during durable reconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53010
Introduced by commit c8efcc7 ("ksmbd: add support for durable handles
v1/v2") in v6.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [1baff47b81f94f9231c91236aa511420d0e266b9]
stable/6.18: [ce2e164c1c51c3f7813b80f8c926836e896bcbb3]
stable/7.0: [97a0cd55283b4e63fd92804da91c8d9896adcad9]
CVE-2026-53011: net/sched: taprio: fix use-after-free in
advance_sched() on schedule switch
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53011
Introduced by commit a3d43c0 ("taprio: Add support adding an admin
schedule") in v5.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [105425b1969c5affe532713cfac1c0b320d7ac2b]
stable/5.10: [a8fc396519ef4f081bc545e88f61241728bb78d7]
stable/5.15: [3471874578160a28c171a607fa069f24062634b8]
stable/6.1: [7256996e1ef553716817f3bfd077c2f3b48b582f]
stable/6.12: [1bd286fa3e21200133478ed523cc6a2788baf38a]
stable/6.18: [b73235da5dde77ed1264f9767b62c28c9d71fd78]
stable/6.6: [eee072fe16c646190d33ae69c9983d8de1562bf8]
stable/7.0: [0e62171df8ed4804d00db088f17eed06468233fa]
CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53012
Introduced by commit 7bf4796 ("nexthops: add support for replace") in v5.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [29c95185ba32b621fbc3800fb86e7dc3edf5c2be]
stable/5.10: [ceffe81a0be92afc0cd1340bc8ca46559cce9bb4]
stable/5.15: [9c2d6770a5f4545a307eb66979bef7656a34d621]
stable/6.1: [6275796f22bb382f3e9aa58ed0b4ef7bdad78cb8]
stable/6.12: [ad85961004fd4bd2f31209ac4b07612c6cefb9e7]
stable/6.18: [613c8f4a501421dd258b07ea614205d4e16ec845]
stable/6.6: [aaac3bed034239e1d75732211d9b05f30b0b4f35]
stable/7.0: [b3b7e850e1541f0520c4a12ec884255c30427ff6]
CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space
for IFLA_MACVLAN_BC_CUTOFF
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53013
Introduced by commit 954d1fa ("macvlan: Add netlink attribute for
broadcast cutoff") in v6.4-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fa92a77b0ed4d5f11a71665a232ac5a54a4b055d]
stable/6.12: [77ecfa4e27f282d224215895ddfbeb916fc75e24]
stable/6.18: [b6b7154e9f5d75b608ceb2d05b376de8c638c40e]
stable/6.6: [4979252758387b338ca968ba7e0515b0ae2257e3]
stable/7.0: [1c004f14ccdc11585625c168bb9a7c5e1b8afb0c]
CVE-2026-53014: net/sched: act_mirred: fix wrong device for
mac_header_xmit check in tcf_blockcast_redir
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53014
Introduced by commit 42f3903 ("net/sched: act_mirred: Allow mirred to
block") in v6.8-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4510d140524ca7d6e772db962e013f26f09a63b1]
stable/6.12: [8fda5174286119addd28473fb2ec5bdf521c05a8]
stable/6.18: [7db3e4e03032261b1b519341123fc30d995478ca]
stable/7.0: [4764953c4b47585eb72797b216b63a831dc0c7e6]
CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53015
Introduced by commit 152a333 ("staging: erofs: add compacted
compression indexes support") in v5.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d8c7edcb661812249469f4a5b62e9339118846f]
stable/6.12: [4fc9b12e43a3f19a01a8fb61f7961be79de20253]
stable/6.18: [858e4d98a86adf34584767388deb6c9b217f70c5]
stable/7.0: [582b0bf201157632cb5474c885989a6ebda46521]
CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53016
Introduced by commit 2b78943 ("crypto: ccp - CCP AES crypto API
support") in v3.14-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4]
stable/5.10: [939061b2d0f7f15114e34b4ce878ef50ff4089c3]
stable/5.15: [798d409a8949f3f495f238549b86de2886b129bd]
stable/6.1: [dfb2cf434829819268fe50f41542aad318ad62b2]
stable/6.12: [bb01d8f1f385bc9034ca114d3508c7fdea24fc9a]
stable/6.18: [df9784bb5b637ac80f4a2768a58ca9a50bef28a9]
stable/6.6: [eecee15e263ccb8cd77170a56ab6c969cb54dd6a]
stable/7.0: [227c1e1d9e2aa4cfc65ba446d5690da1f546cda4]
CVE-2026-53017: f2fs: fix data loss caused by incorrect use of nat_entry flag
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53017
Introduced by commit e05df3b ("f2fs: add node operations") in v3.8-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [238e14eb7226f883b72caccd2d37bf5707df066b]
stable/7.0: [20cedb4d9f6b230d0ee469690b8f868f06a07c29]
CVE-2026-53018: f2fs: avoid reading already updated pages during GC
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53018
Introduced by commit 6aa58d8 ("f2fs: readahead encrypted block during
GC") in v4.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [570e2ccc7cb35fe720106964e65060602d3d2ac4]
stable/6.18: [4623c251496b99c530ce225c05334f4eac8b933a]
stable/7.0: [b663ebb8a340eae5442e605b6acd2cff5677f016]
CVE-2026-53019: clk: spacemit: ccu_mix: fix inverted condition in
ccu_mix_trigger_fc()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53019
Introduced by commit 1b72c59 ("clk: spacemit: Add clock support for
SpacemiT K1 SoC") in v6.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [54e97360b44bed6b4399dd3be3d65f392df940fa]
stable/6.18: [da99d0302d3ccccfb13c69e663bf8eae698b9562]
stable/7.0: [16dfbc4e95c46dd9c79cb8d550c7f267d4a79b91]
CVE-2026-53020: um: Fix potential race condition in TLB sync
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53020
Introduced by commit 1e4ee51 ("um: Add initial SMP support") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [102331b66bcaf1f41f50b9c4cd5c36e46bafa9f3]
stable/7.0: [f21c343ec7419377bff89ab11146c03ae117036f]
CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53021
Introduced by commit 86d7182 ("target: Add sbc_execute_unmap()
helper") in v3.10-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2bf2d65f76697820dbc4227d13866293576dd90a]
stable/5.10: [c08ab702c4699c6efb9d60bdb15b73e7a627ee7e]
stable/5.15: [2e1ed9a7b6ea5bfefb5d80a02b1c71c7dee1f0dd]
stable/6.1: [5efc3ef4758f8d98c257419fa21daca3227de61a]
stable/6.12: [3facdecc3fcf115cc4f9b3d8f118d6705e2456a8]
stable/6.18: [51075df70c46e60a9773f2dcd28299e40dac36fb]
stable/6.6: [d7aef29573c7c5cdb2dfad939253287a6329c2a4]
stable/7.0: [02115986d027ade793e7f6be87e91d6a796d0aa3]
CVE-2026-53022: platform/x86: dell-wmi-sysman: bound enumeration
string aggregation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53022
Introduced by commit e8a60aa ("platform/x86: Introduce support for
Systems Management Driver over WMI for Dell Systems") in v5.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3c34471c26abc52a37f5ad90949e2e4b8027eb14]
stable/5.15: [7b3dc1f764bf24eb99474a5de8173b0b43a8b071]
stable/6.1: [75c738d4f27fa18a2a033de153bd40302bde6a66]
stable/6.12: [5a04f9a36930792f6d64e28d43609e158d09b665]
stable/6.18: [c5683ca4949a514fbe656c6d0d08c4c126e21db9]
stable/6.6: [ba0843c1955864401295f7ba3b420afe19f2266d]
stable/7.0: [90b118d264845f7aaf539ac49f7c75f1f29590e2]
CVE-2026-53023: fs/ntfs3: terminate the cached volume label after
UTF-8 conversion
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53023
Introduced by commit 82cae26 ("fs/ntfs3: Add initialization of super
block") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6cd43fe9b083fa23fe1595666d5738856cb261a]
stable/5.15: [32b0686369e0afbb3549a0d93e2d8517da84cd30]
stable/6.1: [bc7a0c34c4ca259cfddf3bc18fc5b3c6411d26ed]
stable/6.12: [54d564b762389679e2f8fb9eeb20af7e82371e1c]
stable/6.18: [6136bbb054f7ab9f51ae99915541633b18bcef90]
stable/6.6: [0b11fcbe80a59acdf58337d80ebb5f72201d73d6]
stable/7.0: [5cd0707b81cb4589f00aec5c4c1288bd0980d2a4]
CVE-2026-53024: greybus: raw: fix use-after-free if write is called
after disconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53024
Introduced by commit e806c7f ("greybus: raw: add raw greybus kernel
driver") in v4.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [84265cbd96b97058ef67e3f8be3933667a000835]
stable/7.0: [48d6c32bc049abd114e8f0836c0e7d7cbfba7827]
CVE-2026-53025: greybus: raw: fix use-after-free on cdev close
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53025
Introduced by commit e806c7f ("greybus: raw: add raw greybus kernel
driver") in v4.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [983cc2c7efbce04ecbf6328448d895044dd6ab31]
stable/7.0: [ef2d97c15b19b3489de01695bce478601e236c3e]
CVE-2026-53026: NFSD: fix nfs4_file access extra count in
nfsd4_add_rdaccess_to_wrdeleg
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53026
Introduced by commit 8072e34 ("nfsd: fix nfsd_file reference leak in
nfsd4_add_rdaccess_to_wrdeleg()") in v6.19-rc4.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [b48f44f36e6607b2f818560f19deb86b4a9c717b]
stable/6.18: [4584229395d0d65bd517780afe97ffea07cb2c3d]
stable/7.0: [b81572b073441dfd32213e41857676d0dbff4665]
CVE-2026-53027: fs/ntfs3: fix missing run load for vcn0 in
attr_data_get_block_locked()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53027
Introduced by commit c380b52 ("fs/ntfs3: Change new sparse cluster
processing") in v6.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1
Fixed status
mainline: [d7ea8495fd307b58f8867acd81a1b40075b1d3ba]
stable/7.0: [2b4ae1ce613ade8a7e118fba4a5a77cd23e97e54]
CVE-2026-53028: usb: typec: Fix error pointer dereference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53028
Introduced by commit 82432bb ("usb: typec: tipd: Handle mode
transitions for CD321x") in v6.18-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f2529d08fcb429ea01bb87c326342f41483f8b2f]
stable/6.18: [19951118fb22b5ad512379ee64510fe0e2c40eb3]
stable/7.0: [9e31082f92c913d74fefb4e60cd0284e605ba3a3]
CVE-2026-53029: fs/ntfs3: prevent uninitialized lcn caused by zero len
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53029
Introduced by commit 10d7c95 ("fs/ntfs3: add delayed-allocation
(delalloc) support") in v7.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e98266e823a1fa06fe6499df61aeaac2fd6f7a49]
stable/7.0: [485f750cac3d8bdf5552a0e3d79ce5e3a03ece49]
CVE-2026-53030: i3c: master: renesas: Fix memory leak in renesas_i3c_i3c_xfers()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53030
Introduced by commit d028219 ("i3c: master: Add basic driver for the
Renesas I3C controller") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12
Fixed status
mainline: [d7665c3b4f575251e449e2656879392346ca612b]
stable/6.18: [1b6a7e94be678d34a9ccb9db7e2443ae02ad2bc8]
stable/7.0: [ab8f00ffcca0f618fb8198d358f24728950d9860]
CVE-2026-53031: bpf: Validate node_id in arena_alloc_pages()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53031
Introduced by commit 3174603 ("bpf: Introduce bpf_arena.") in v6.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2845989f2ebaf7848e4eccf9a779daf3156ea0a5]
stable/6.12: [31d3b4b28e55835646d6829d60023f730dd34e85]
stable/6.18: [e15900888c09480a4c632bc598f1c5bd39bed6d6]
stable/7.0: [fb66e20130f95a93ffea1677252526a9e39170b2]
CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53032
Introduced by commit ab6c637 ("bpf: Fix a bpf_kptr_xchg() issue with
local kptr") in v6.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4d0a375887ab4d49e4da1ff10f9606cab8f7c3ad]
stable/6.12: [0a36c1f72888bca0237295a4da19cd91821a90be]
stable/6.18: [6982653ce5f119982aa58f1af58e7bfbebf39252]
stable/6.6: [520454e839710c327808c2fcc98e28cee77355fc]
stable/7.0: [da1d615ce49a47986a8864e2371a26e97861085c]
CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53033
Introduced by commit 2c860a4 ("bpf: af_unix: Implement BPF iterator
for UNIX domain socket.") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [64c2f93fc3254d3bf5de4445fb732ee5c451edb6]
stable/6.1: [c6f4015eac2e3cbc3cb7a17539e10bbb5c2049c3]
stable/6.12: [1a59cc6b65fd3ad9915aae5970d859109d4ce9fb]
stable/6.18: [921920c34cb591947dd30c692500795a69f1e3fa]
stable/6.6: [d0d124dbcef9318e326956137b31671407094bd4]
stable/7.0: [98f744d204e5d6fca589cd2c44c3190a0c71697f]
CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53034
Introduced by commit c638291 ("af_unix: Implement
->psock_update_sk_prot()") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dca38b7734d2ea00af4818ff3ae836fab33d5d5a]
stable/6.1: [75b7d3b3f8bd4e59eb3af1b11a43c64c0c2db6f4]
stable/6.12: [4913c94a3adcdbb64c552110c0c243cb1fdbb317]
stable/6.18: [041eb6348d73ee5e15fc8161f1eac5a6e8289ca0]
stable/6.6: [a94d3dd78ee8b63e6b8ad629081c952c93ee5a10]
stable/7.0: [37bfcd164161b47d00b1c3bd20adc816a6977ce0]
CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53035
Introduced by commit 2c860a4 ("bpf: af_unix: Implement BPF iterator
for UNIX domain socket.") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4d328dd695383224aa750ddee6b4ad40c0f8d205]
stable/6.1: [bd3592129f24243713673a07225cf1f15a9bb835]
stable/6.12: [87828b380956d4986f59f2c086e0b09b3e6cdaae]
stable/6.18: [527057ebe8076dfbcaef51195ff1b7508646be2c]
stable/6.6: [3cef33b9813b78f227942572fb317afcd5c9ac94]
stable/7.0: [66d9fab4565eafe1afe7ba0581f79b76073b60fa]
CVE-2026-53036: bpf, arm64: Fix off-by-one in check_imm signed range check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53036
Introduced by commit e54bcde ("arm64: eBPF JIT compiler") in v3.18-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1dd8be4ec722ce54e4cace59f3a4ba658111b3ec]
stable/6.1: [a5dfeb3b61065039488342d43ae06d4729d955d4]
stable/6.12: [6927f0d6794aa73318bbfa929f1ff6065b0620df]
stable/6.18: [1a113b5497297871699cd498b1b83542e0db7f15]
stable/6.6: [7fd3b41260c6120e7b60164afea5d961af6224f9]
stable/7.0: [fb74defa1cca1a73177c0c761e641332e4f979a3]
CVE-2026-53037: HID: usbhid: fix deadlock in hid_post_reset()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53037
Introduced by commit dc3c78e ("HID: usbhid: Check HID report
descriptor contents after device reset") in v3.5-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8df2c1b47ee3cd50fd454f75c7a7e2ae8a6adf72]
stable/5.10: [56d318ef8766f0deb08517fd8f3007256ea7997d]
stable/5.15: [90550af0aad5e75110073c501e4fb42fca20ff80]
stable/6.1: [eeceb6f4dd42065fdda3a526a93d08b8fb90fb69]
stable/6.12: [4e900465296ce9fb12ed47dc77389b8dde95bfe0]
stable/6.18: [c7abd0e6c87441e99c759d40eb6fe589634e3041]
stable/6.6: [ad4505d2ab3aaac6498f17649608e70e80034bf2]
stable/7.0: [b3d16611d7cd78e9d5c6baa19b61b7caf9f1ab5e]
CVE-2026-53038: ima_fs: Correctly create securityfs files for
unsupported hash algos
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53038
Introduced by commit 9fa8e76 ("ima: add crypto agility support for
template-hash algorithm") in v6.10-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d7bd8cf0b348d3edae7bee33e74a32b21668b181]
stable/6.12: [081b557cb56e1cfa8d1619b2601b01c53e3f418c]
stable/6.18: [b6766b171a5c4c33b26ff6fec530cb798db1f75e]
stable/7.0: [88d4e89a39f0de07798ca3fd93bd1a9ea212a82e]
CVE-2026-53039: ocfs2: validate group add input before caching
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53039
Introduced by commit 7909f2b ("[PATCH 2/2] ocfs2: Implement group add
for online resize") in v2.6.25-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [70b672833f4025341c11b22c7f83778a5cd611bc]
stable/5.10: [f7e139d7563f6947ad509fb468903941d0bb7ddd]
stable/5.15: [22544ddedf381ed5191cfc783aea8d6c936bc201]
stable/6.1: [76bd722db0a92b84ccd99e03796a0b6f1ae71c31]
stable/6.12: [e7c2cb552e6eb85c0f5aefdd7f0f7c3c8591a6a3]
stable/6.18: [aed87e866d1a321edb9703563c2faa8fec89835d]
stable/6.6: [b9ae3942deec4c9e3fa2070521f90910f7490011]
stable/7.0: [6c5e70409c1961fe1278968f038eaaed6cc1145a]
CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53040
Introduced by commit d24a10b ("Ocfs2: Add a new code
'OCFS2_INFO_FREEFRAG' for o2info ioctl.") in v3.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8f687eeed3da3012152b0f9473f578869de0cd7b]
stable/5.10: [bb2906a1065ec28de021bac2ed03f2624edd7d07]
stable/5.15: [3e167e230d19cd273108bab2e4c61800fc335ae8]
stable/6.1: [0998674eec138c55e9e349b9cbd9dbc5129a9cc8]
stable/6.12: [05d0cbea41167b6b061c6ba5b70ee5a9a7a24c9e]
stable/6.18: [4c2d62ddde8928db12f4608950b67a20e67deab2]
stable/6.6: [bb3c54d1e71578521111f1a1ee7d5f4761a242b8]
stable/7.0: [e0dcf12665d6dde37facf790803cdad44d5c328c]
CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53041
Introduced by commit 936b883 ("ocfs2: Refactor xattr list and remove
ocfs2_xattr_handler().") in v2.6.28-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d12f558e6200b3f47dbef9331ed6d115d2410e59]
stable/5.10: [a35a1c2b170b5b578b1b3fecb95694796552af9a]
stable/5.15: [2323084c17370304f49c84b354fe7b3edbb264fe]
stable/6.1: [6f702b00b8124c5d3525f19172934544826a114d]
stable/6.12: [46e66fefb83811958127bc9ad736983ec629d82b]
stable/6.18: [2685df8577a38d83b367c8cf52eda9dc286959ff]
stable/6.6: [d919b905939eda93393e3572900ff70dbad2b47f]
stable/7.0: [50033ec1350fe68abdc63b950ced7ae57364b77a]
CVE-2026-53042: fwctl: Fix class init ordering to avoid NULL pointer
dereference on device removal
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53042
Introduced by commit 858ce2f ("cxl: Add FWCTL support to CXL") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a55f80233f384dc89ef3425b2e1dd0e6d44bcf29]
stable/6.18: [a28f56988c8e5bb9375806a5cfb0bf54d662ae3f]
stable/7.0: [1075f2f590fdac147f8b8010c35b606564b5c7d7]
CVE-2026-53043: ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53043
Introduced by commit ea20344 ("ocfs2/dlm: Add message
DLM_QUERY_REGION") in v2.6.37-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7ab3fbb01bc6d79091bc375e5235d360cd9b78be]
stable/5.10: [d3d5efade0c79dac1cac98c0cb1115432f804439]
stable/5.15: [f69551139caf6d24242a0ad049ee46b264e3aee0]
stable/6.1: [1f8b91275912cd428289c1fb424bebd7ff5302bd]
stable/6.12: [6c6e8fc3c007319981647b410c29bb5775048551]
stable/6.18: [3f474c33ebc2e2ca3fcb587d7de4375348f13373]
stable/6.6: [f37de46149db49abd2b24f4f0c5a88cf4dfb5f47]
stable/7.0: [3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21]
CVE-2026-53044: soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53044
Introduced by commit 25de5c8 ("soc/tegra: cbb: Improve handling for
per SoC fabric data") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [499f7e5ebbdd9ff0c4d532b1c432f8a61ff585b3]
stable/6.18: [f46870b451f7583802ed26eec8b93e138840fcd9]
stable/7.0: [5c009a5f8bb3c81f2cfb511701ce571e3c8733cd]
CVE-2026-53045: memory: tegra124-emc: Fix dll_change check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53045
Introduced by commit 73a7f0a ("memory: tegra: Add EMC (external memory
controller) driver") in v4.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9597ab9a8296ab337e6820f8a717ff621078b632]
stable/5.10: [a85967331144fde9300be38bb44d2558eb6b742e]
stable/5.15: [db0ae80865b515cc0b705c85877ec00f7eebe9fe]
stable/6.1: [2369b1831161356e1bcb51385d3e532dc4fe2771]
stable/6.12: [05f138fc7e27ee8e7a83ccf966c3fa26cda44dda]
stable/6.18: [1793249c067a4b28e1aba0ad0e4d73aa9f9e165a]
stable/6.6: [7e19e72f306484996c52ff96cc92f69b78ed5435]
stable/7.0: [1ebbbef47d11cc90219c081492ccf995aaa3e9b3]
CVE-2026-53046: ksmbd: fix use-after-free from async crypto on
Qualcomm crypto engine
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53046
Introduced by commit e2f3448 ("cifsd: add server-side procedures for
SMB3") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3e298897f41c61450c2e7a4f457e8b2485eb35b3]
stable/5.15: [57b47231055b431ed0a1a55f33cac32981564405]
stable/6.1: [cc2da381875d4a67026e4c8feb3dba51a2a2d1bc]
stable/6.12: [8ef183216feaa24b66b940510d8b68f680eb56e9]
stable/6.18: [7164b3953cefd540e7ebca828c793bc6869cfbc4]
stable/6.6: [8fcefe840fa8c14ce667768e5b043286ac3bbcbe]
stable/7.0: [b46aa129fa2807bfe1545fe74d9295d53c51520b]
CVE-2026-53047: efi/capsule-loader: fix incorrect sizeof in phys array
reallocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53047
Introduced by commit f24c4d4 ("efi/capsule-loader: Reinstate virtual
capsule mapping") in v4.15-rc7.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [48a428215782321b56956974f23593e40ce84b7a]
stable/5.10: [22022cd8851703a58f67615a17bc7e9e8682785b]
stable/5.15: [67adde6bfdfd563a54b045d59aeb9a2d90c80697]
stable/6.1: [608e1f7bc9d171ab26c1fba288c97fc76363c27d]
stable/6.12: [5e185330d902b12fe8e6eb4b8514b5d736d8d66d]
stable/6.18: [e0e6b14995fd6fa2c0df8c712d76ab32f0694c31]
stable/6.6: [8be69e9245f805566bac68ffc8574b64735fd996]
stable/7.0: [ab3f7098a3a27175b91cfc947950f5c26855801b]
CVE-2026-53048: gfs2: prevent NULL pointer dereference during unmount
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53048
Introduced by commit 3526490 ("gfs2: Fix NULL pointer dereference in
gfs2_log_flush") in v6.10-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/5.15 stable/6.1 stable/6.6
Fixed status
mainline: [74b4dbb946060a3233604d91859a9abd3708141d]
stable/5.15: [cec55674354794eddb80b914f73a6bf9b7fc304a]
stable/6.1: [2fc4c868c9060f424fd4a7cacb0aec5082aba4de]
stable/6.12: [e15f16761594e80b15776980b27c35477655a135]
stable/6.18: [d8ffae016c4a78693fe1283335d0b6833a9c1366]
stable/6.6: [233a0945a4b1dbe3f38c30afb7d05b76c67f1193]
stable/7.0: [abd73229f0e886a91a16ea781ab656bd9b4d1ee8]
CVE-2026-53049: gfs2: add some missing log locking
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53049
Introduced by commit 5e4c763 ("gfs2: Issue revokes more
intelligently") in v5.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8]
stable/5.15: [3b28eb75afe520972bacc833850c2b30aa0824cd]
stable/6.1: [ca95342cb1b39062a03c115830286f0a426053d5]
stable/6.12: [f2f225cf505ac016132ded21690f3ba0a080a4e8]
stable/6.18: [49d9be0722da3a4a893ba905720cba1921834ec3]
stable/6.6: [bf5fcd9c37c2546beaf7b401d31aefd89017dc3d]
stable/7.0: [98e8bf249c790d56de1abc4a5f8bd68035a00921]
CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53050
Introduced by commit 869b6ea ("quota: Fix slow quotaoff") in v6.6-rc6.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt stable/5.10 stable/5.15 stable/6.1
Fixed status
mainline: [e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d]
stable/5.10: [2bdc80f4619411e5bd4a3ef23f51e14021ed457c]
stable/5.15: [f9438cb8c8ec3adc84b2b450a3aab0123d074c3b]
stable/6.1: [ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a]
stable/6.12: [61e25f664dc2a08299e07d84c85776abc2350f75]
stable/6.18: [fdd424d7c35633ac577fd87d1b043d1b8a6cd350]
stable/6.6: [6678dde265708003c2b42551af4a2e3cb05decd5]
stable/7.0: [82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1]
CVE-2026-53051: PCI: tegra194: Fix CBB timeout caused by DBI access
before core power-on
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53051
Introduced by commit 40e2125 ("PCI: tegra194: Move controller cleanups
to pex_ep_event_pex_rst_deassert()") in v6.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [34b3eef48d980cd37b876e128bbf314f69fb5d70]
stable/6.12: [010983063a806720b45778d191335f8ea864fea3]
stable/6.18: [b059a41bdd5b202b2b9d7708403fb43c69689e53]
stable/7.0: [ce899f9c019591b73ef84b9afa332ed53beece25]
CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before
accessing data
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53052
Introduced by commit 36ad9bf ("ASoC: qdsp6: audioreach: add topology
support") in v5.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d5bfdd28e0cdd45043ae6e0ac168a451d59283dc]
stable/6.1: [8e8cd78b6000c9d19db249a5a68287158f288ef3]
stable/6.12: [296810e91f21a21794886c57f954495d8afd7f32]
stable/6.18: [a1a24d4b8c9682f9b7a9138f636ff004c721aef1]
stable/6.6: [1ac96689ce2984f4f6ef8892fcb65da377408421]
stable/7.0: [6d2491a585202a967ed91f30ec5960024f2536d0]
CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53053
Introduced by commit 3332364 ("iommu/amd: Support multiple PCI DMA
aliases in device table") in v5.5-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [faad224fe0f0857a04ff2eb3c90f0de57f47d0f3]
stable/6.12: [dbd76a537d8cb814e7f5b795ab21ecb7949c821d]
stable/6.18: [20b3c566e2702e5d4d0545be8a97029a2eebcc0e]
stable/7.0: [dae251ff11d2d2208a029f98923756831cefec46]
CVE-2026-53054: drm/msm: Fix VM_BIND UNMAP locking
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53054
Introduced by commit 2e6a8a1 ("drm/msm: Add VM_BIND ioctl") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [85042c2cd970a6b0e686329387096fe19989ae62]
stable/6.18: [206f812ef140727b75697111391ae320fd8aa652]
stable/7.0: [d9ecf758270501b2e7a0bc1dd69a6f28f1ae3cae]
CVE-2026-53055: crypto: hisilicon/sec2 - prevent req used-after-free for sec
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53055
Introduced by commit f0ae287 ("crypto: hisilicon/sec2 - implement full
backlog mode for sec") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [67b53a660e6bf0da2fa8d8872e897a14d8059eaf]
stable/6.18: [b375c3c7209cc59e40e97998aa9bc768369cca0e]
stable/7.0: [ad73563f3a1edbfddf2724136c6a15826b354e18]
CVE-2026-53056: drm/msm/dpu: fix mismatch between power and frequency
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53056
Introduced by commit b0530eb ("drm/msm/dpu: Use OPP API to set
clk/perf state") in v5.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bc1dccc518cc5ab5140fba06c27e7188e0ed342b]
stable/6.1: [1181a7028d37e0b1e720a36125a03f5db97e3d27]
stable/6.12: [c5735c7d0eef7a5240f9c1c66e44ba52a1be58d6]
stable/6.18: [0f7dd5839cfabaf9c007fb718ec66e907a473c93]
stable/6.6: [9830999c9e065c1813ec5435bfe4eab98ee54a87]
stable/7.0: [0ccf4f27b4652570b5de3de02a89a86435559de9]
CVE-2026-53057: iommu/riscv: Add IOTINVAL after updating DDT/PDT entries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53057
Introduced by commit 488ffbf ("iommu/riscv: Paging domain support") in
v6.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f5c262b544975e067ea265fc7403aefbbea8563e]
stable/6.18: [3f917d9bff68600f77561900f3145bd4706dc840]
stable/7.0: [d99d1c13faa793ff1abab0d20ab6473c838081b3]
CVE-2026-53058: drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp
connector earlier in atomic_enable()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53058
Introduced by commit c932ced ("drm/tidss: Update encoder/bridge chain
connect model") in v6.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [43d6508ddbf9fb974fbc359a033154f78c9d4c8b]
stable/6.12: [a3611554e599d1a24b45fd8415bacb72ce861e4b]
stable/6.18: [cf2ac2cac8b319f89b3a3851ca0c5ffb6a549575]
stable/6.6: [5302015daf26ef6b48e067f2b86c9482ac19e015]
stable/7.0: [1af3b42e08a957e53bab8e1897393fe0a27d9fbf]
CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53059
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c20e36b7631d83e7535877f08af8b0af72c44b1a]
stable/5.10: [44ab8875ae4a2842bde2d756bed195d375e0debb]
stable/5.15: [defe483e47173768c227532694dc78cb65db5f09]
stable/6.1: [3ec74da927b4e171a6fc0e77b1188ba4d019af51]
stable/6.12: [12bd5b88e91a02785244ff1d20fb157e96e9cdc8]
stable/6.18: [b455903eed4558982be0811f5b7f44f6bbc4ff57]
stable/6.6: [d4ac87567f86a55c3c92e9a5144dcd943a9772a1]
stable/7.0: [4ec8323b9f0764a14d532b1ae9b87f8a9fecb867]
CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53060
Introduced by commit 352b837 ("dm cache: Fix ABBA deadlock between
shrink_slab and dm_cache_metadata_abort") in v6.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/4.4 cip/4.4-rt cip/4.4-st
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt stable/5.10 stable/5.15
stable/6.1
Fixed status
mainline: [044ca491d4086dc5bf233e9fcb71db52df32f633]
stable/5.10: [14f60e957f34f95a626caec76a8fae88cf4c397f]
stable/5.15: [6b97cc7a42905755c56bbddc33aa8b792205caee]
stable/6.1: [d1a79620c419a0af1911f99c873014b30740e303]
stable/6.12: [b0bd35535bdb6f58505f3a30ee5793986943997a]
stable/6.18: [322a3b70368d49e39591fe9fc6c07d262128b05f]
stable/6.6: [15c30997dca681f90dbf2d45ee629c1828bf0c0d]
stable/7.0: [4311ca59a1891d33c4c8b7946f98c34f167fe833]
CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough
mode switching
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53061
Introduced by commit 2ee57d5 ("dm cache: add passthrough mode") in v3.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [322586745bd1a0e5f3559fd1635fdeb4dbd1d6b8]
stable/5.10: [c2e86f647561fcf5e1c6eba7d75e9e0c4299c94d]
stable/5.15: [5c98a3f1d7a554c9e920aa31daf92af6b5bbb8cc]
stable/6.1: [1443c32f24d6d8bcdf4beceef2afc09290b98717]
stable/6.12: [bd5a2c1018938e6b32670728bdb32a3f0efff00f]
stable/6.18: [21c503d60a257e54ca3ac58e2721bd24501d5bde]
stable/6.6: [12105c7f18375d7615dad7605d89eadae7eb12a6]
stable/7.0: [01b22656d8a68dbeae59f8b80866e7b11936b20a]
CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating
cache blocks
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53062
Introduced by commit b29d498 ("dm cache: significant rework to
leverage dm-bio-prison-v2") in v4.12-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d1f7b65f5deedd2e6b09fdc6ea27f8375f24b45]
stable/5.10: [4991b5a08751e2e82488fb93ae08849b6aea10d9]
stable/5.15: [1b2bec4a7dcf5f00b7a1cbeeec8997841d783513]
stable/6.1: [9a5fdfb9e57ec3a8ad2b8fce5e5ffa42d53b130e]
stable/6.12: [93627a29d4b66d4a2def938dfb8610cc80ae454b]
stable/6.18: [c348ae47d8e65f06429fa41adce9ad986b696766]
stable/6.6: [ac5ee99443891bdb161f5539606a66a1b5e72542]
stable/7.0: [2b62d0611c9af14a16bddf22df2612b4f40eb5a1]
CVE-2026-53063: dm cache: fix write hang in passthrough mode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53063
Introduced by commit b29d498 ("dm cache: significant rework to
leverage dm-bio-prison-v2") in v4.12-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4ca8b8bd952df7c3ccdc68af9bd3419d0839a04b]
stable/6.1: [9fa18d0b981776b190ca4632942a7c2174052b78]
stable/6.12: [64d6519b00be4116d365bd31f33a5e5ce2944c1a]
stable/6.18: [b8ace9e96983abb20ccf39edce8a60f1bb0b83d8]
stable/6.6: [ecb10c193cbebf5e6984246a9b4ff1f95d45ed87]
stable/7.0: [05798d091ebcfb6d68228890e593f209e8ac940d]
CVE-2026-53064: dm cache: fix null-deref with concurrent writes in
passthrough mode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53064
Introduced by commit b29d498 ("dm cache: significant rework to
leverage dm-bio-prison-v2") in v4.12-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7d1f98d668ee34c1d15bdc0420fdd062f24a27c0]
stable/5.10: [01264a6a3a3ad7ac1d73443299cd5a9568002454]
stable/5.15: [ee38fb00e1a80f46a4990e38f25ecb04ae7b7417]
stable/6.1: [c7fb6bc864c4910b344dafa36dd5028e9b980768]
stable/6.12: [a2635d541a93fd111e743cf14b6275dc81be2abc]
stable/6.18: [25dcc1989c194ba2b5fb6d03cbb9b83814ac0d15]
stable/6.6: [0aa745fea1f8dc81bcdd0a45e215b6706727b482]
stable/7.0: [df3b8ef06cc62de4fca5d2108e285085b3cffd44]
CVE-2026-53065: ASoC: sti: use managed regmap_field allocations
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53065
Introduced by commit 76c2145 ("ASoC: sti: Add CPU DAI driver for
playback") in v4.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1696fad8b259a2d46e51cd6e17e4bcdbe02279fa]
stable/5.10: [4b8dba4527727623a97948aff9f0969a14c203a9]
stable/5.15: [c3af3bcfc1deb3b230cc266a2ac75bca8f4dfba9]
stable/6.1: [43b67761d486d719128e164536e58de5a81dff9b]
stable/6.12: [9641071e3a8e0bc664477a0e54db5f9815f0fb79]
stable/6.18: [a3f3c332882c98ae7553af372191116d1384ca52]
stable/6.6: [002a5f925d42eca8ad547e55a4ae22714cfe9dec]
stable/7.0: [7422a11a753daacbc2409513cf65e1de0d17c291]
CVE-2026-53066: drm/sun4i: backend: fix error pointer dereference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53066
Introduced by commit 96180dd ("drm/sun4i: backend: Add a custom
atomic_check for the frontend") in v4.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [06277983eca4a31d3c2114fa33d99a6e82484b11]
stable/6.1: [ea51fd96aca01381e8f1ac0c671a57b7619193bb]
stable/6.12: [779c2f10743fc021f2f0ebe2b188cadfb973c5e4]
stable/6.18: [47038159c559824f4dbfb5b0d87b9b3416663372]
stable/6.6: [cf615b90a11a39a28e313be5e508e94bcde72016]
stable/7.0: [e9bef62f1bb9fcb38223730657af20f4c6283c16]
CVE-2026-53067: PCI: endpoint: pci-ep-msi: Fix error unwind and
prevent double alloc
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53067
Introduced by commit 1c3b002 ("PCI: endpoint: Add RC-to-EP doorbell
support using platform MSI controller") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1cba96c0a795124c3229293ed7b5b5765e66f259]
stable/6.18: [175717cfc06cab79f84cd037d66dda1b8564cd9e]
stable/7.0: [3c25587fbf8797b92090b064a6d239a873e55fb1]
CVE-2026-53068: drm/komeda: fix integer overflow in AFBC framebuffer size check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53068
Introduced by commit 65ad239 ("drm/komeda: Added AFBC support for
komeda driver") in v5.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [779ec12c85c9e4547519e3903a371a3b26a289de]
stable/5.10: [a3a2a9bdc0f9c2d863a5a290cb2d4a565f7268e7]
stable/5.15: [e27b58095d7d3ac72f230e318838dee956258460]
stable/6.1: [02ff8a7d3d0eecc546b9ab4c07b3d7c65d485583]
stable/6.12: [8165e8b28fdf392c2c7412518d602b4f193812a8]
stable/6.18: [fe1f80f8f6e8611ac6349b9d464e8750443390cf]
stable/6.6: [d8a541906860aa3519b1874780d933c766918a7c]
stable/7.0: [872d923b852705054bc099af663da862fdc1097d]
CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect()
for down master
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53069
Introduced by commit 879af96 ("net, core: Add support for XDP
redirection to slave device") in v5.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1921f91298d1388a0bb9db8f83800c998b649cb3]
stable/5.15: [3128b294b426533c8d9162187446d93a8a160359]
stable/6.1: [acbf45bd584d924b320bee2a7fe2a26f64904d95]
stable/6.12: [183128da0406b1c10e6f60b7b9fe70788b9c8c1d]
stable/6.18: [7bad93e99737e4a5c0c14ac50c05152cf4e28022]
stable/6.6: [866d3d9b87751b1944168fd82615505e0c0fd6cf]
stable/7.0: [ea690b3b6e58ae00979af8195b4cc24df466b65e]
CVE-2026-53070: sctp: disable BH before calling udp_tunnel_xmit_skb()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53070
Introduced by commit 6f1a914 ("net: add xmit recursion limit to tunnel
xmit functions") in v7.0-rc4.
Introduced by commit 046c052 ("sctp: enable udp tunneling socks") in v5.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.18
Fixed status
mainline: [2cd7e6971fc2787408ceef17906ea152791448cf]
stable/7.0: [790093245e35040c2adb15f48970020425aa3f47]
CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in
l2cap_ecred_reconf_rsp
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53071
Introduced by commit 15f02b9 ("Bluetooth: L2CAP: Add initial code for
Enhanced Credit Based Mode") in v5.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [42776497cdbc9a665b384a6dcb85f0d4bd927eab]
stable/5.10: [96dca51715d86559ed6ed8028e5445cecb80f3ae]
stable/5.15: [330b20ec97916961ee0e6c29c06bc0fa7c96e64c]
stable/6.1: [0ccd75c51f620374086f359e906917676e699a1c]
stable/6.12: [fe1188abdae9b7a8199dcdfcf9244d5e5d61eb14]
stable/6.18: [dc89961b76f12aff47124c1df4bdb32a080f4d0c]
stable/6.6: [77a853aec710b2fdf41fa298ea3cbc9a4358f917]
stable/7.0: [5501d055a1ce3c747141e3955ba8cf034d193f3e]
CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with
HCI_PROTO_DEFER
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53072
Introduced by commit 70c4642 ("Bluetooth: Refactor connection request
handling") in v3.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5c7209a341ff2ac338b2b0375c34a307b37c9ac2]
stable/5.10: [60e3f4ff02d1f2d55bfbf2ca32a97285a9771ee4]
stable/5.15: [9d4a6c0f43fc5e4d4f062e8e450e5483eb74176e]
stable/6.1: [c7777f534a8018ae4bb1c80d8925af4df588a314]
stable/6.12: [541d5bf9b5afaf41090b2a3aa7b47f2db2ff801f]
stable/6.18: [385b2d0468a0871fc716c549fa3b0c257c7dbcb3]
stable/6.6: [6b4d226d01ab7da0d2027a2a1e3a6079152e5065]
stable/7.0: [c27224daf0b08efbb2b24ed64b6139b294f5473a]
CVE-2026-53073: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53073
Introduced by commit 5df5daf ("Bluetooth: hci_uart: Fix another race
during initialization") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt cip/6.12 stable/5.10 stable/5.15 stable/6.1 stable/6.12
stable/6.6
Fixed status
mainline: [68d39ea5e0adc9ecaea1ce8abd842ec972eb8718]
stable/5.10: [ebb39b2d81731b83ee71a1ba6dd0291a57b5ac07]
stable/5.15: [ed4033fb85ccaaf6c3983be3c7b037e48253d232]
stable/6.1: [356dee1bcac4d0d9152390561fa63331ebff211b]
stable/6.12: [f4b69c35813c432973d340d3600c01de106ed474]
stable/6.18: [3daa5818e473ed60eb69d8b5c71b651909d28c5a]
stable/6.6: [a673cf6c4ac702cb79ac1f4d7fc4de763a6a3e40]
stable/7.0: [194f029a4d7f739e44ebc1f473120187b4de5104]
CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53074
Introduced by commit fa5cb54 ("bpf: Setup socket family and addresses
in bpf_prog_test_run_skb") in v5.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [12bec2bd4b76d81c5d3996bd14ec1b7f4d983747]
stable/5.10: [7254267799d083280c0e53effc101a33add95f7b]
stable/5.15: [6a9f38d5ff11e00bc54baab752642978805e81eb]
stable/6.1: [e6aa481f21fc7a41ed344767ea25aae9d03fae71]
stable/6.12: [1f882c492d46f90bdb36f4936876c88c28dab21c]
stable/6.18: [8042240412de3222d27b31e89d29336961cad9e4]
stable/6.6: [0a04db240effd85773f66244645a28cedddb72d2]
stable/7.0: [6def5fe753cbe5b279ee5fd10327b2611cbddaca]
CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53075
Introduced by commit 273ec51 ("net: ppp_generic - introduce
net-namespace functionality v2") in v2.6.30-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2bb6379416fd19f44c3423a00bfd8626259f6067]
stable/5.10: [c9edd90c57ae23692fff6b049fdfa4572a9fd532]
stable/5.15: [5080e188c914110034bbc569d5cfa2f06204681d]
stable/6.1: [67e901e28d177ac9a9bed76d69ce3471e704a89e]
stable/6.12: [3b2c2157dc2afc5c17cd7238afefca92f1ef330e]
stable/6.18: [5013be175c7ffd8b39efbc3c9c4db5b10b85fea8]
stable/6.6: [954745d0223e7caec917c0b2d1a889ff56fa6e54]
stable/7.0: [1a8a51ce85075a56a743b6f142606dd2696a391c]
CVE-2026-53076: bpf: Fix OOB in pcpu_init_value
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53076
Introduced by commit d3bec01 ("bpf: Zero-fill re-used per-cpu map
element") in v5.10-rc4.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [576afddfee8d1108ee299bf10f581593540d1a36]
stable/6.12: [e0378419b0e20178b5d100b27c9cc7e51064202e]
stable/6.18: [6086079e6d1c32ba4c4b422612b8aebb1129a96c]
stable/6.6: [e19c5ed9f1922a6854073f8651a63fa7be26e9e9]
stable/7.0: [634a793d0e1c822412095d25a1338f8831ad894c]
CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53077
Introduced by commit d5a8ac2 ("RDS-TCP: Make RDS-TCP work correctly
when it is set up in a netns other than init_net") in v4.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ebf71dd4aff46e8e421d455db3e231ba43d2fa8a]
stable/5.10: [3e7f14cd5a51533404e1ae4809caab46073fb5c7]
stable/5.15: [3174fc703d081d2ca538b22fba734e3ad5b52322]
stable/6.1: [c244b79adffad89a5173cf8bfaa06a6b40bbd09b]
stable/6.12: [fb407343c0c16e94584707b2dfdd350a5f81b000]
stable/6.18: [a7494479757d60d2413bfaa087f8431a26eea032]
stable/6.6: [07035306bf722f4676a1aee35cbeb3732c76194e]
stable/7.0: [b6a54f5e9ce9b97ae641855378d71c5154a085c0]
CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer
leak in sock_ops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53078
Introduced by commit fd09af0 ("bpf: sock_ops ctx access may stomp
registers in corner case") in v5.9-rc2.
Introduced by commit 84f44df ("bpf: sock_ops sk access may stomp
registers when dst_reg = src_reg") in v5.9-rc2.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [10f86a2a5c91fc4c4d001960f1c21abe52545ef6]
stable/7.0: [18e3ffde1822f0b48b1753bf34aa97ce839df1d8]
CVE-2026-53079: net_sched: fix skb memory leak in deferred qdisc drops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53079
Introduced by commit a6efc27 ("net_sched: use qdisc_dequeue_drop() in
cake, codel, fq_codel") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6bd339dbb3514bce690fdcf252e788dfab4ee76]
stable/7.0: [bf26ad92ffda7884825d67b46bd5efe615c3babf]
CVE-2026-53080: net/sched: cls_fw: fix NULL dereference of "old"
filters before change()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53080
Introduced by commit faeea8b ("net/sched: cls_fw: fix NULL pointer
dereference on shared blocks") in v7.0-rc7.
Introduced by commit ed76f5e ("net: sched: protect filter_chain list
with filter_chain_lock mutex") in v5.1-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [65782b2db7321d5f97c16718c4c7f6c7205a56be]
stable/5.10: [a719275da488835e987d28effc04679b4aace3a0]
stable/5.15: [c205da704c84eeb4247d770150440294fd547049]
stable/6.1: [5dcce34c57d5e5990869384d69deeb9414bf9b92]
stable/6.12: [829808cbf8cf8a6d07a0e67a5ea2c3fcd63a9e5c]
stable/6.18: [41845bc5bb64f3d615abe575ad655b5e7f193634]
stable/6.6: [5df49f0579f7e625f2358a219d31fbc7621be799]
stable/7.0: [4fabcfea7a9dd159df32c5df6587fe858cb0d748]
CVE-2026-53081: bpf: Enforce regsafe base id consistency for
BPF_ADD_CONST scalars
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53081
Introduced by commit 98d7ca3 ("bpf: Track delta between "linked"
registers.") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2f2ec8e7730e21fc9bd49e0de9cdd58213ea24d0]
stable/6.12: [13c02881e49aac4c82b261faa26db9edf2567231]
stable/6.18: [691adf738817275368ed56311b7d798d617823a3]
stable/7.0: [7d73c72cccac651acc891377a5e623e4021c6380]
CVE-2026-53082: net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53082
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bf9a38803b2626b01cc769aaf13485d8650f576f]
stable/5.10: [1d3abf0c3ddeefc6f6d913aa129acc06fce8240a]
stable/5.15: [d4cceb5184538613572fb79319453f281b1eeacb]
stable/6.1: [2951656b0de00153f2687f3a093890bce72b6215]
stable/6.12: [d9ce2a4b679122397d7f35bad7be46913ad1ca80]
stable/6.18: [987af7625ceb1ee59d70eb0abd7af11c75e45d79]
stable/6.6: [e9cf4018d74237d142cd66243c821d13593270f0]
stable/7.0: [578f3aba427c938fecfa0d8c83d9acb213a9b24a]
CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53083
Introduced by commit da765a2 ("bpf: Add poke dependency tracking for
prog array maps") in v5.5-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4406942e65ca128c56c67443832988873c21d2e9]
stable/6.12: [71ddb7defc442ab38c53123c384fedbfd8410a15]
stable/6.18: [e1ed678855e315f90c70c1723e94157a9a82e660]
stable/6.6: [b1f7158a86f3cbac4d5a32beb55ca0f8027d44cd]
stable/7.0: [67bdb4b0d26f2d6bbf1798a925ef5a3b9ed7357a]
CVE-2026-53084: bpf: return VMA snapshot from task_vma iterator
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53084
Introduced by commit 4ac4546 ("bpf: Introduce task_vma open-coded
iterator kfuncs") in v6.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4cbee026db54cad39c39db4d356100cb133412b3]
stable/6.12: [83b8802c034e843b83a3e1ef6f30cdd4e9ec291c]
stable/6.18: [592226d138378601ae28eb890e2bbc23ec3600f7]
stable/7.0: [13860ca37b8df0b856ee1ce3bdbd7c327d5f53e8]
CVE-2026-53085: bpf: fix mm lifecycle in open-coded task_vma iterator
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53085
Introduced by commit 4ac4546 ("bpf: Introduce task_vma open-coded
iterator kfuncs") in v6.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d8e27d2d22b6e2df3a0125b8c08e9aace38c954c]
stable/6.12: [239cec25a22662dbd80f57d94b38178c8be95269]
stable/6.18: [d0862de7c866c5bd7c32531f66738c21197af888]
stable/7.0: [43683bb280330f3d36f0f2a3932a4867b9603e9c]
CVE-2026-53086: net: bcmgenet: fix racing timeout handler
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53086
Introduced by commit 13ea657 ("net: bcmgenet: improve TX timeout") in v4.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5393b2b5bee2ac51a0043dc7f4ac3475f053d08d]
stable/6.1: [e85b0c0a12e967930044608311471b665baa315c]
stable/6.12: [681fdfe823b4f1036ed50b58b8838c7917ea389c]
stable/6.18: [c270e2bec3e55a716d25c35341091339457ac883]
stable/6.6: [e8206538cbaf4f4068e99a4cb1138690a1e00499]
stable/7.0: [7ce1c26aac3b318886a57425f64b522da7389153]
CVE-2026-53087: net: bcmgenet: fix leaking free_bds
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53087
Introduced by commit f1bacae ("net: bcmgenet: support reclaiming
unsent Tx packets") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [3f3168300efb839028328d720ab3962f91d6a0d0]
stable/6.1: [150d06aae1839a6564ab200ef0e7291c3528bbb0]
stable/6.12: [3c3abbcfa05bad17965498ff7cc94c2418fa94b3]
stable/6.18: [25ff3a3e47ea635ec08dc93e84dd2bfe15abfebb]
stable/6.6: [52b9f80993698138b90e5ca3a72550a2501f2a96]
stable/7.0: [ac4a29c331ecb5b10240c44247a8e010c95bc15b]
CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53088
Introduced by commit 876dbad ("net: bcmgenet: Fix unmapping of
fragments in bcmgenet_xmit()") in v4.13-rc2.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [57f3f53d2c9c5a9e133596e2f7bc1c50688a6d38]
stable/5.10: [14e9f86564fff7bcf7f45c1b69080e837b31d185]
stable/5.15: [fb9a3c1f547d0ff024dbfe7b6f327626ddf0a3de]
stable/6.1: [85f34ec320d3881badfd4edc5fee5cd5012bb54d]
stable/6.12: [29394f722f620281f2ee9a47f947734e53d72c90]
stable/6.18: [4cab761fc51c65aef741fcece4a18f3554edbc09]
stable/6.6: [2a74590170427a3ca7cc4bb8690cdd559129c29c]
stable/7.0: [72df896e31ddd06fcc5a789f025ad7a62a18bc9b]
CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53089
Introduced by commit 675fc27 ("bpf: offload: report device information
for offloaded programs") in v4.16-rc1.
Introduced by commit 52775b3 ("bpf: offload: report device information
about offloaded maps") in v4.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a0c584fc18056709c8e047a82a6045d6c209f4ce]
stable/7.0: [a51e7fbe94a87e236631a83973d4f558310b2cd2]
CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53090
Introduced by commit 09b28d7 ("bpf: Add abnormal return checks.") in v5.10-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ee861486e377edc55361c08dcbceab3f6b6577bd]
stable/7.0: [d846d83bdacbd8f14fc45c63b8c1d22608452e1c]
CVE-2026-53091: net: pull headers in qdisc_pkt_len_segs_init()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53091
Introduced by commit e876f20 ("net: Add a software TSO helper API") in
v3.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7fb4c19670110f052c04e1ec1d2b953b9f4f57e4]
stable/7.0: [9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a]
CVE-2026-53092: bpf: Fix linked reg delta tracking when src_reg == dst_reg
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53092
Introduced by commit 98d7ca3 ("bpf: Track delta between "linked"
registers.") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d7f14173c0d5866c3cae759dee560ad1bed10d2e]
stable/6.18: [d88e8e4a3b52bd5b2ff3eceba4b29d1b5506d066]
stable/7.0: [cc86a8b0a1c54d2bccf6f68cf49b82dea91b84de]
CVE-2026-53093: wifi: brcmfmac: Fix error pointer dereference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53093
Introduced by commit cb7cf7b ("brcmfmac: make chip related functions
host interface independent") in v3.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dd8592fc6007a451c3e4b9025de365e39de8178a]
stable/5.10: [a3b45090a91e2f0b9715870d8f8d9ca2fdfbc1af]
stable/5.15: [99ef547659178eef6d6ba4738a9d989ce90cf909]
stable/6.1: [bd6c906e0c4af6d5d0c49c3c4ee090b4913da17d]
stable/6.12: [2e0e5a43ed126f896a4ad31ade66c90270601bae]
stable/6.18: [cbea71b4480394708f9a6e007a0385acfe5e1ec8]
stable/6.6: [d3f280be48f1c672cb10e8026c236d0cca60048a]
stable/7.0: [334c68750eee84c2327db1d152be83ff5ad8e20b]
CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53094
Introduced by commit 2b3486b ("bpf: Introduce device-bound XDP
programs") in v6.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a1aa9ef47c299c5bbc30594d3c2f0589edf908e6]
stable/6.12: [25484c39d1ec82a0368798d956da3de5039b3fe8]
stable/6.18: [059525cf18e69a9313baf947d8898c6ee7ca6b65]
stable/6.6: [a713b72ff88cdab4d5d692908ab1259ada511f4d]
stable/7.0: [c79f8503d83d4665be461fb9e45e215d0380c67b]
CVE-2026-53095: bpf: Fix abuse of kprobe_write_ctx via freplace
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53095
Introduced by commit 7384893 ("bpf: Allow uprobe program to change
context registers") in v6.18-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [611fe4b79af72d00d80f2223354284447daafae9]
stable/6.18: [b312cf41b9e43f442613053f6cad39898e1baf96]
stable/7.0: [9836cadbd96c7e0dbb0018fa60e7872dd31ac4f8]
CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53096
Introduced by commit e624d4e ("xdp: Extend xdp_redirect_map with
broadcast support") in v5.14-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19]
stable/5.15: [4a3d0fe30b907ff324b1b49756f7e713d67f3645]
stable/6.1: [b089aa6e94d7a08e74d076a0fe274842dc9feccc]
stable/6.12: [cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a]
stable/6.18: [d4c4bd231ebad70e6f30db429e9640bf378b2f52]
stable/6.6: [571a05ea1baaccc0dc1e0d227b2cbc978b96d392]
stable/7.0: [7027e705062482a8cea43a1c13ede3c35653966f]
CVE-2026-53097: wifi: mt76: mt7996: fix use-after-free bugs in
mt7996_mac_dump_work()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53097
Introduced by commit 878161d ("wifi: mt76: mt7996: enable coredump
support") in v6.4-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c8f62f73bbced3a79894655bdb0b625462d956fc]
stable/6.12: [180182a3f23ff79430a32ca2c4c1885368ceab48]
stable/6.18: [aa4a31cd89f4fde5043ac613fe0e27014a60a60b]
stable/7.0: [188e10f9ea3109d23c6b7643aa6ec2f5cb0faa6d]
CVE-2026-53098: wifi: mt76: mt7915: fix use-after-free bugs in
mt7915_mac_dump_work()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53098
Introduced by commit 4dbcb91 ("wifi: mt76: mt7915: enable coredump
support") in v6.2-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1146d0946b5358fad24812bd39d68f31cd40cc34]
stable/6.12: [e6856af8a22a8e2cd18241a465ed00c2301b3a5e]
stable/6.18: [6b7cbb13c838cf2a5f2e7be0e96fe15250087939]
stable/6.6: [6d5202409467d621b6d1dfd7fc7dadb997fe66d2]
stable/7.0: [21ce6d867867645fff0ef657be18f61d9f39dcd8]
CVE-2026-53099: bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53099
Introduced by commit 99fde4d ("bpf, btf: Enforce destructor kfunc type
with CFI") in v7.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9b0cf064ea0a6bac5e1a5fb43b004fd52fbe2b3b]
stable/7.0: [f74fce43dbc059e059b5346a670f697c0e97b1d0]
CVE-2026-53100: wifi: mt76: fix deadlock in remain-on-channel
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53100
Introduced by commit a8f424c ("wifi: mt76: add multi-radio
remain_on_channel functions") in v6.14-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6939b97ddad3cf3dfbb3b5a0a12ef79cb886747e]
stable/6.18: [5fc8c5d45e44575dda9fcabdc2aac4ad97baf0cd]
stable/7.0: [7a89c245d203aa0ed5ff2d68ac05b48b2ef9fa3f]
CVE-2026-53101: wifi: mt76: mt7921: fix potential deadlock in
mt7921_roc_abort_sync
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53101
Introduced by commit 352d966 ("wifi: mt76: mt7921: fix a potential
association failure upon resuming") in v6.9-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d5059e52fd8bc624ec4255c9fa01a266513d126b]
stable/6.18: [35180c772f5e11e2fa4d80d3dfd50906cb6d9646]
stable/7.0: [91e77840bf13de3add125060cf8b32ca24a52c8c]
CVE-2026-53102: wifi: mt76: Fix memory leak after
mt76_connac_mcu_alloc_sta_req()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53102
Introduced by commit d1369e5 ("wifi: mt76: connac: introduce
mt76_connac_mcu_sta_wed_update utility routine") in v6.2-rc1.
Introduced by commit 6683d98 ("mt76: connac: move
mt76_connac_mcu_add_key in connac module") in v5.18-rc1.
Introduced by commit 4f831d1 ("wifi: mt76: mt7915: enable WED RX
support") in v6.2-rc1.
Introduced by commit c948b5d ("wifi: mt76: mt7925: add Mediatek Wi-Fi7
driver for mt7925 chips") in v6.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c41075ce8cf05ed8c0e7b7efef000dce548ffc42]
stable/7.0: [eb466406d2094deefadc2cd6ddb4f6eeb086d1b4]
CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in
mt7925_roc_abort_sync
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53103
Introduced by commit 45064d1 ("wifi: mt76: mt7925: fix a potential
association failure upon resuming") in v6.12-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dd08ca3f092f4185ece69ce2a835c23198b1628a]
stable/6.18: [153bcba36c87a1ba555b57b6c49028d5812f895b]
stable/7.0: [2d8e0053bca29143ace51e08c980ff076844a4b0]
CVE-2026-53104: wifi: mt76: Fix memory leak destroying device
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53104
Introduced by commit 950d0ab ("wifi: mt76: mt7996: add wed rx
support") in v6.8-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6b470f36616e3448d44b0ef4b1de2a3e3a31b5be]
stable/6.18: [dcbc13d19bef3326c72f324b10f5a3e5fc4d71de]
stable/7.0: [4b7c92fd8b8700fac387ff43c6f6e0c4e05ec93f]
CVE-2026-53105: wifi: mt76: mt7925: prevent NULL vif dereference in
mt7925_mac_write_txwi
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53105
Introduced by commit ebb1406 ("wifi: mt76: mt7925: add link handling
to txwi") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [962eb04e67552be406c906c83099c1d736aae3b6]
stable/6.12: [6c52fbdc6f656ac2e8ed1e3d0f42ed21ef285e15]
stable/6.18: [815db7fd57aa81c93fc8a66c2fac5f8bd0a8d153]
stable/7.0: [5d5bdea4ffcf54a6c4e751df713f95a1d783f298]
CVE-2026-53106: bpf: Do not allow deleting local storage in NMI
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53106
Introduced by commit a10787e ("bpf: Enable task local storage for
tracing programs") in v5.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [350de5b8a9befaa2a68861c51f671d4f5f751ca5]
stable/7.0: [e84acaf936970b5b0be2c93bbf255295ba9406df]
CVE-2026-53107: wifi: libertas: don't kill URBs in interrupt context
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53107
Introduced by commit d66676e ("wifi: libertas: fix WARNING in
usb_tx_block") in v7.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/4.4 cip/4.4-rt cip/4.4-st
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [7c5c2b661bdb78c1472b8833265c9ed1ee880039]
stable/6.18: [00c0317cebf44151df18fb647781f315268cdd98]
stable/7.0: [4f273d3f98ebc60c30bbfb3ed4a7f0477d3eaed2]
CVE-2026-53108: powerpc/64s: Fix unmap race with PMD migration entries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53108
Introduced by commit 75358ea ("powerpc/mm/book3s64: Fix MADV_DONTNEED
and parallel page fault race") in v5.8-rc1.
Introduced by commit a30b48b ("mm/migrate_device: implement THP
migration of zone device pages") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bbcbf045d6c778e82b47a35fc8728387708e9a3d]
stable/7.0: [829367e55012c053738ebe7db20c4a90d6609ece]
CVE-2026-53109: powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53109
Introduced by commit 32cc0b7 ("powerpc: add pte_free_defer() for
pgtables sharing page") in v6.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fda4d71651f71c44b35829d13f3c8bf920032f77]
stable/6.18: [c8b710655012a2993a9567873fb71a8a51f8459c]
stable/7.0: [a32db6fca3c74b4eb8bae5470f0680deb4cbac6f]
CVE-2026-53110: s390/bpf: Zero-extend bpf prog return values and kfunc arguments
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53110
Introduced by commit 528eb2c ("s390/bpf: Implement
arch_prepare_bpf_trampoline()") in v6.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [202e42e4aa890172366354b233c42c73107a3f59]
stable/6.12: [44c4f999b03f55debb1a0c5ab5c1796895a1adf8]
stable/6.18: [366b0e05ee24f5ba62bdc7ec1346038258b9a797]
stable/6.6: [edc90a12073b9a530064a99945c183dde120cb99]
stable/7.0: [834918a77be51419383bf1dda9f02b81ecf26b34]
CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue
in bpf_lwt_xmit_push_encap
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53111
Introduced by commit 52f2787 ("bpf: implement BPF_LWT_ENCAP_IP mode in
bpf_lwt_push_encap") in v5.1-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [972787479ee73006fddb5e59ab5c8e733810ff42]
stable/6.1: [5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0]
stable/6.12: [599905c3f10bb83e6e6881d5a7f5cea5df07dc23]
stable/6.18: [5500913516e071dbe23e5a404c861dd2d82c9589]
stable/6.6: [c7ad31fb948fdd4905263f4324160682c3fa7bc6]
stable/7.0: [94f95328b9070909b5b875c647b17a11d3d85567]
CVE-2026-53112: wifi: rtlwifi: pci: fix possible use-after-free caused
by unfinished irq_prepare_bcn_tasklet
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53112
Introduced by commit 0c81733 ("rtl8192ce: Add new driver") in v2.6.38-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [039cd522dc70151da13329a5e3ae19b1736f468a]
stable/5.10: [ae10d4a1ab6bcaa1336abb171908a9a365761d3e]
stable/5.15: [fac1079e0fdec6df6d7562c21941587236dc3def]
stable/6.1: [e40873820c9d245ce482faa7ad514ebdb3b8d23d]
stable/6.12: [7731b67bd59d1284d150cbe40a47e95a10613234]
stable/6.18: [aa10a452e34810987fb9f4a047995b30003fb53f]
stable/6.6: [008c456b76e9070979bc0e763897a5d3b0fdd4dc]
stable/7.0: [3c0e8a3179e6325a7dc6ce221aef0e03d854ab4b]
CVE-2026-53113: wifi: ath11k: fix memory leaks in beacon template setup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53113
Introduced by commit 3a415da ("wifi: ath11k: add P2P IE in beacon
template") in v6.10-rc1.
Introduced by commit 335a927 ("wifi: ath11k: MBSSID beacon support")
in v6.5-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ff49eba595df500e4ddccc593088c8a4ab5f2c27]
stable/7.0: [5d63aa38d5ca85206d9699ffdd616b58780dba07]
CVE-2026-53114: perf/amd/ibs: Avoid calling perf_allow_kernel() from
the IBS NMI handler
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53114
Introduced by commit 50a53b6 ("perf/amd/ibs: Prevent leaking sensitive
data to userspace") in v6.14.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b0a09142622a994c4f4088c3f61db5da87cfc711]
stable/6.18: [2783ed2442ce69ae240b787aee6dae801cef7aec]
stable/7.0: [0584e74fa2b27e9e722cfb5b579f79263df20040]
CVE-2026-53115: bus: fsl-mc: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53115
Introduced by commit 1f86a00 ("bus/fsl-mc: add support for
'driver_override' in the mc-bus") in v5.10-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6c8dfb0362732bf1e4829867a2a5239fedc592d0]
stable/6.12: [4911b836f35c034c36f102db4ecbe339b38e7d1d]
stable/6.18: [8139ce66b52a4a5638bfb445b037c07d4abeb08e]
stable/7.0: [60bfb563a399c4597dc80588a1109758a8908b97]
CVE-2026-53116: s390/ap: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53116
Introduced by commit d38a87d ("s390/ap: Support driver_override for AP
queue devices") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [81d6f7c3a70b10ff757ee8b5f8114a190871cf1e]
stable/7.0: [8f2eca0570438b94602da1297353eb7b10dcb6cb]
CVE-2026-53117: s390/cio: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53117
Introduced by commit ebc3d17 ("s390/cio: introduce driver_override on
the css bus") in v5.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ac4d8bb6e2e13e8684a76ea48d13ebaaaf5c24c4]
stable/6.12: [106d594711e97762788046c5bbb94f580abc4bf4]
stable/6.18: [2081957d8c323ffb58a10bc64837717ac5a042a1]
stable/6.6: [c4295487124f461405e1ef64dfa8c4ab0cb7ebcf]
stable/7.0: [b660ba045b2b22cf3b4be72773de00cb48f47be5]
CVE-2026-53118: vdpa: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53118
Introduced by commit 539fec7 ("vdpa: add driver_override support") in v5.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [85bb534ff12aab6916058897b39c748940a7a4c6]
stable/6.18: [654ef9c33e138ede6734ac286282df9faf83cd11]
stable/7.0: [fb5cb4913ce333cc4647722e8c2b8378e12f2464]
CVE-2026-53119: platform/wmi: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53119
Introduced by commit 12046f8 ("platform/x86: wmi: Add driver_override
support") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8a700b1fc94df4d847a04f14ebc7f8532592b367]
stable/6.12: [13d201bd840d2e2a645ef899f81342cd27ced346]
stable/6.18: [2c5507010fc3b8e2bd596c63c88f6ad39a69b1c4]
stable/7.0: [4dc755d86deed88789540d960e421124bad4c568]
CVE-2026-53120: PCI: use generic driver_override infrastructure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53120
Introduced by commit 782a985 ("PCI: Introduce new device binding path
using pci_dev.driver_override") in v3.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [10a4206a24013be4d558d476010cbf2eb4c9fa64]
stable/6.12: [dfe950d9464cad609f3b118c6203e2708055bc61]
stable/6.18: [58a42be0d70307d765594fc581f5f5e5ef059712]
stable/7.0: [c5b2c5755495507e14f310c2653c85de0a309b1f]
CVE-2026-53121: amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53121
Introduced by commit f9a378f ("cpufreq/amd-pstate: Set different
default EPP policy for Epyc and Ryzen") in v6.14-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [beda3b363546a423e4e29a7395e04c0ac4ff677e]
stable/6.18: [539aabbab190825c77eb455ec35652cb3720625f]
stable/7.0: [7f9aa2359742eaa6ea65ec0d20dafdfd0add9b8b]
CVE-2026-53122: btrfs: fix deadlock between reflink and transaction
commit when using flushoncommit
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53122
Introduced by commit 05a5a76 ("Btrfs: implement full reflink support
for inline extents") in v5.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b48c980b6a7e409050bb3067165db31cc6205e3e]
stable/6.12: [73be4a08306bb84f4d5d16f62cb80e1543109ffa]
stable/6.18: [9a24f0000876b8755cf21972b41632f4d6f3dafb]
stable/7.0: [6f0f9c0a368aa1fe078109091322d3b0632d9380]
CVE-2026-53123: md: wake raid456 reshape waiters before suspend
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53123
Introduced by commit 714d201 ("md: add new helpers to suspend/resume
array") in v6.7-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cf86bb53b9c92354904a328e947a05ffbfdd1840]
stable/6.12: [8b6a72420821e6da2cab6a69d5233500d2698b93]
stable/6.18: [ff6b93410192b812d73cc54062529715b2dc849f]
stable/7.0: [8ae3e14d7f3df58f7f49c02d74344e3dcd5f84f0]
CVE-2026-53124: ublk: reset per-IO canceled flag on each fetch
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53124
Introduced by commit 728cbac ("ublk: move device reset into
ublk_ch_release()") in v6.15-rc3.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0842186d2c4e67d2f8c8c2d1d779e8acffd41b5b]
stable/7.0: [63335e5a67d89bb7cb9b023bbb3785896587a648]
CVE-2026-53125: md: fix array_state=clear sysfs deadlock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53125
Introduced by commit 9e59d60 ("md: call del_gendisk in control path")
in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2aa72276fab9851dbd59c2daeb4b590c5a113908]
stable/6.18: [62c44566da7493ee48ef17e8507bb798338a07cb]
stable/7.0: [92ad0ec509ffb188d8f849b63148664df37b4a52]
CVE-2026-53126: blk-cgroup: fix disk reference leak in
blkcg_maybe_throttle_current()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53126
Introduced by commit f05837e ("blk-cgroup: store a gendisk to throttle
in struct task_struct") in v6.3-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [23308af722fefed00af5f238024c11710938fba3]
stable/6.12: [73a5af059905d171b398c8b2381632ee499948b5]
stable/6.18: [b3e005f16cd98f815429a87aef4c61e9c140779f]
stable/6.6: [4048ed98860d3785645ebbd34f69566a6c7320c3]
stable/7.0: [000e8454692cab9d1f1b80130e2870e355301d06]
CVE-2026-53127: block: fix zones_cond memory leak on zone revalidation
error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53127
Introduced by commit 6e945ff ("block: use zone condition to determine
conventional zones") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2a2f520fda824b5a25c93f2249578ea150c24e06]
stable/7.0: [29153d128384fa7c48a8ca8d34094b1cbe2d5bdc]
CVE-2026-53128: drbd: Balance RCU calls in drbd_adm_dump_devices()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53128
Introduced by commit a55bbd3 ("drbd: Backport the "status" command")
in v4.5-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2b31e86387e60b3689339f0f0fbb4d3623d9d494]
stable/5.10: [ae12bb44b392637a8321ade305c883f9ffc0daea]
stable/5.15: [68ebb9183ac3621b96b18e046841eadb9508783c]
stable/6.1: [6cd27bcb71bb73f955d104cc3a62be6f83724392]
stable/6.12: [8092713a10c19fa0f731b71b2853af4319ca54fd]
stable/6.18: [996d279f2c985d771d6cfdd923e447d825726e06]
stable/6.6: [282e06e6d494a7bee85af78c747527b7d4009cc3]
stable/7.0: [1f112240531f0a0b437b2e001c1d89e8b25a8328]
CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53129
Introduced by commit c2f3140 ("mbcache2: limit cache size") in v4.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d227786ab1119669df4dc333a61510c52047cce4]
stable/6.12: [a88d39a74a208e197c03bffaa2df34de732af19f]
stable/6.18: [0e4eff315d799f5842b95872199b0f0fb8ef5f51]
stable/7.0: [b25fd3523bef88fb7ffd4c5b63bbe9c08f73bb4c]
CVE-2026-53130: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53130
Introduced by commit a3ab715 ("omfs: add directory routines") in v2.6.27-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0621c385fda1376e967f37ccd534c26c3e511d14]
stable/5.10: [fbc72f5c645155dc2ed3573243ed20f9913e3a54]
stable/5.15: [5822a05a841a10794ad818620dd2af490b0705d3]
stable/6.1: [754ff1bea3819a90c6f33cccfc1a299ef7609f07]
stable/6.12: [79f84af38c9fef9deb0e02c79eb969b5541c2644]
stable/6.18: [6561afc38398e3518a29c5eebb975c30468f98a6]
stable/6.6: [131ea3e57fc22936ed0e2c8330f2e36106172f51]
stable/7.0: [817f16ed62bc58a168417bfb5e859c2a370bab03]
* Updated CVEs
CVE-2021-47211: ALSA: usb-audio: fix null pointer dereference on pointer cs_desc
stable/5.10 was fixed.
Fixed status
stable/5.10: [3455984b16eeb6914caf8b59498ef24fcc1f0a78]
CVE-2023-54125: fs/ntfs3: Return error for inconsistent extended attributes
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [6557c4504c5a1bbbbac25d14d7dcf2a4912d1508]
stable/6.1: [486666c2c2714788705d02d98d0332c8a2328575]
CVE-2023-54129: octeontx2-af: Add validation for lmac type
stable/5.10 was fixed.
Fixed status
stable/5.10: [4392454c694b13d78c84165c0964729772cd3b73]
CVE-2023-54271: blk-cgroup: Fix NULL deref caused by blkg_policy_data
being installed before init
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [da6cc648c1f570290af1ddbe6b7ca3d91b1d6db9]
stable/6.1: [33f0370bb7ce15a59d72a4d8a05421d334a04add]
CVE-2024-27012: netfilter: nf_tables: restore set elements when delete set fails
stable/6.1 was fixed.
Fixed status
stable/6.1: [faa0deee272128b95a838fe7c6ebf6a2a426df14]
CVE-2025-21863: io_uring: prevent opcode speculation
stable/5.10 was fixed.
Fixed status
stable/5.10: [87e9eef43c758da267f6332678058a79764c7eba]
CVE-2025-22026: nfsd: don't ignore the return code of svc_proc_register()
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [51107e768de6821b68aa34a136d07bc7a09cf6c3]
stable/5.15: [e4316bd85e42b01125b2aab691769234a388b8a3]
CVE-2025-38129: page_pool: Fix use-after-free in page_pool_recycle_in_ring
stable/5.10 was fixed.
Fixed status
stable/5.10: [c2c906142293931e33ef4be79ebc36c25c4e21dd]
CVE-2025-38250: Bluetooth: hci_core: Fix use-after-free in vhci_flush()
stable/5.10 was fixed.
Fixed status
stable/5.10: [dd4becd3fd4102696e1c15e6d260a1712a2d8685]
CVE-2025-39863: wifi: brcmfmac: fix use-after-free when rescheduling
brcmf_btcoex_info work
stable/5.15 was fixed.
Fixed status
stable/5.15: [c75600e69e66a751cc046cd9c407b942f298d852]
CVE-2025-39929: smb: client: fix smbdirect_recv_io leak in
smbd_negotiate() error path
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [5aa69aabcb275a8012265233c7694076ce1d9102]
stable/5.15: [aa4cf7615328eae44f3b4bf5f4fde3fb390c27c6]
CVE-2025-40164: usbnet: Fix using smp_processor_id() in preemptible
code warnings
stable/5.10 was fixed.
Fixed status
stable/5.10: [6635e52bc4165793aefd686962d912d73d323afe]
CVE-2025-68296: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
stable/6.6 was fixed.
Fixed status
stable/6.6: [711ebd961190def4c69ea24b2f0be75e995af24a]
CVE-2025-68340: team: Move team device type change at the end of team_port_add
stable/5.10 was fixed.
Fixed status
stable/5.10: [f82d1fb65549de241fe312fcb2bcb8e0ad7b424d]
CVE-2025-68736: landlock: Fix handling of disconnected directories
stable/6.6 was fixed.
Fixed status
stable/6.6: [fbf718d5afe21057694a0c0223a18b0c7a5960b6]
CVE-2025-68768: inet: frags: flush pending skbs in fqdir_pre_exit()
stable/6.6 was fixed.
Fixed status
stable/6.6: [22ee4010866da81aeee08e1ea3fddbe418feb212]
CVE-2026-23099: bonding: limit BOND_MODE_8023AD to Ethernet devices
stable/5.10 was fixed.
Fixed status
stable/5.10: [19266182b82e9100c799d8a29f5e0452f0bf7703]
CVE-2026-23247: tcp: secure_seq: add back ports to TS offset
stable/6.12 was fixed.
Fixed status
stable/6.12: [5da5662181ef8a251e3ba564903002c2e87de452]
CVE-2026-23310: bpf/bonding: reject vlan+srcmac xmit_hash_policy
change when XDP is loaded
stable/6.1 was fixed.
Fixed status
stable/6.1: [0a80e6ecaf669c77260b44254f4a84d76bf83e89]
CVE-2026-23346: arm64: io: Extract user memory type in ioremap_prot()
stable/6.6 was fixed.
Fixed status
stable/6.6: [64858b76ec67c5fc40fef8ec1841fecb78c1ebde]
CVE-2026-23364: ksmbd: Compare MACs in constant time
stable/5.15 was fixed.
Fixed status
stable/5.15: [8a665d733940592e671ec6afadcd0be80a091a80]
CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
stable/5.15 was fixed.
Fixed status
stable/5.15: [2665887a69437a8a4f552f69509eecfb73d4aa19]
CVE-2026-31419: net: bonding: fix use-after-free in bond_xmit_broadcast()
stable/6.6 was fixed.
Fixed status
stable/6.6: [2de5c8eea0a9db99dae7c36f4b541b74b41d3a04]
CVE-2026-31432: ksmbd: fix OOB write in QUERY_INFO for compound requests
stable/6.6 was fixed.
Fixed status
stable/6.6: [850452af77f55d185f9445e1f7a1db53c5e4aad4]
CVE-2026-31449: ext4: validate p_idx bounds in ext4_ext_correct_indexes
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [39d6e2b67651614bac0dc6592fa9836321910067]
stable/5.15: [c5839b34704c9c2f47f079451bdbb22de0da1ed1]
CVE-2026-31486: hwmon: (pmbus/core) Protect regulator operations with mutex
stable/6.6 was fixed.
Fixed status
stable/6.6: [b26849cffaa7c43355b82e9bef3725e786973a1a]
CVE-2026-31489: spi: meson-spicc: Fix double-put in remove path
stable/5.10 was fixed.
Fixed status
stable/5.10: [01f5f7976c24d6e9beef6b5a410af3b9b1d4d476]
CVE-2026-31663: xfrm: hold dev ref until after transport_finish NF_HOOK
stable/6.12 was fixed.
Fixed status
stable/6.12: [4236c30b437b80f673b9e08c8fae38b8d471ac9e]
CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [0f4c9754956b86de158a4af5278c5cf5bda9439e]
stable/5.15: [714aa973da8163925eda7efd49361ccbee21ee46]
stable/6.1: [1490f82353bdabc09265a74e645b07f05cf4188e]
CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn()
stable/6.12 was fixed.
Fixed status
stable/6.12: [156cc63691c1f20905510b1007896e090355e6c2]
CVE-2026-31708: smb: client: fix OOB read in smb2_ioctl_query_info
QUERY_INFO path
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [e66bdc0704977ecee667a81d38255b579c2353d0]
stable/5.15: [9e203dbb5402897c43130fb171a2617008a91f45]
CVE-2026-31709: smb: client: validate the whole DACL before rewriting
it in cifsacl
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [b8603d9ae6c9087662b098619996bc4a8064319d]
stable/6.1: [c2abdebf72000a64603ced84d36ccbd164f11391]
CVE-2026-31711: smb: server: fix active_num_conn leak on transport
allocation failure
stable/5.15 was fixed.
Fixed status
stable/5.15: [dc2e7d595d68cf1be1ba64e3d30ebf3266bf7242]
CVE-2026-31712: ksmbd: require minimum ACE size in smb_check_perm_dacl()
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [282cbbb476b9f35793452bc461934af4c7eca169]
stable/6.1: [f20adc4ef7428bc485ee83fd1a592252fb87718b]
CVE-2026-31715: f2fs: fix UAF caused by decrementing sbi->nr_pages[]
in f2fs_write_end_io()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [7dbdab4430e4654db9aacef12b9b3b8b29ca25cb]
stable/5.15: [ffb94770dbdfb5411be5d9f44a960b010ec890ad]
stable/6.1: [0d40b26377f891e6dcb6efaf8ef9374c99be1b1d]
CVE-2026-31727: usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
stable/6.1, stable/6.6 were fixed.
Fixed status
stable/6.1: [f9f987472f4b8ab177be2b6492a59278ed969479]
stable/6.6: [7fce959e9be3bf63bb0fdf4b05f9cc42cb289fe2]
CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
stable/6.6 was fixed.
Fixed status
stable/6.6: [7502c1cf303b69f71d085f5ff7251b0e1b0f09df]
CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper
stable/5.10 was fixed.
Fixed status
stable/5.10: [e602246235fc2ef06c39b2e9cf147d84d0896b73]
CVE-2026-43064: dmaengine: idxd: Fix not releasing workqueue on .release()
stable/5.15 was fixed.
Fixed status
stable/5.15: [70ae35be58d476e2fd9f7a941a5e03b2f5fadb8d]
CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports
stable/6.6 was fixed.
Fixed status
stable/6.6: [3c19cb8a84ef709d57943bd6664cf31cb91ba6ec]
CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack
stable/6.1, stable/6.12, stable/6.6 were fixed.
Fixed status
stable/6.1: [9e1196d27ef496f404c76f7a9d03761142d991c4]
stable/6.12: [d52fa1fa7440676b8c238037a050ab008c22737f]
stable/6.6: [5e1c1d22268ae710c238342c8030c21daf298168]
CVE-2026-43129: ima: verify the previous kernel's IMA buffer lies in
addressable RAM
stable/6.6 was fixed.
Fixed status
stable/6.6: [43308106a1762b72f3b20a44b75b2df5cb25b77b]
CVE-2026-43219: net: cpsw_new: Fix potential unregister of netdev that
has not been registered yet
stable/5.15, stable/6.1, stable/6.6 were fixed.
Fixed status
stable/5.15: [d31a12cee10bbc12b4b523a4709fd1fdee8b7d0f]
stable/6.1: [23acc565186ee27e788408cbd81b92730b6aaa3a]
stable/6.6: [67cca9df4d17f2c824655d31195b2e75334ae286]
CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare()
stable/6.1, stable/6.6 were fixed.
Fixed status
stable/6.1: [e7790ab165713b79b1617ce659742ceb3a859d05]
stable/6.6: [3edb8ebbf79b9016040e8f3421d723ae3d542b32]
CVE-2026-43311: soc/tegra: pmc: Fix unsafe generic_handle_irq() call
stable/6.6 was fixed.
Fixed status
stable/6.6: [d1c9c79eb06ed7c4e0a090ba5b1d4e475f7d0681]
CVE-2026-43331: x86/kexec: Disable KCOV instrumentation after load_segments()
stable/6.6 was fixed.
Fixed status
stable/6.6: [0e96cd314c0d819c1635d68125a4d77852c2162e]
CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill
stable/5.15 was fixed.
Fixed status
stable/5.15: [d3a1fb2ca323d7a4e10ab3afbfa25e6d8921e4f2]
CVE-2026-43350: smb: client: require a full NFS mode SID before
reading mode bits
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [23b54d6cc3ef30a51d984dc74364f24039ae2ecb]
stable/5.15: [1592a6cd6f653f2d24572a6976c7a775b19f4940]
CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time
stable/5.15 was fixed.
Fixed status
stable/5.15: [ff44ec94d4fc8348600a69de0a8fa1102c23bce8]
CVE-2026-43421: usb: gadget: f_ncm: Fix net_device lifecycle with device_move
stable/6.1, stable/6.6 were fixed.
Fixed status
stable/6.1: [7c97366f5dac5255e60a317ffe3a5b18f3745547]
stable/6.6: [36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4]
CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in
mpi_read_raw_from_sgl()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [a1793a48881ec8d26e9c79b0ee65753f1c6846a4]
stable/5.15: [1abd50fc3cfa16fc2074a3c8c2729c50fd9d7043]
stable/6.1: [6d63615c796c085b4984e3031b9fa77fffb47360]
CVE-2026-43495: net: wwan: t7xx: validate port_count against message
length in t7xx_port_enum_msg_handler
stable/6.1 was fixed.
Fixed status
stable/6.1: [307c5d0f36a5c74042217136da5bfbd9f7504650]
CVE-2026-45850: ipvs: skip ipv6 extension headers for csum checks
stable/5.10, stable/5.15, stable/6.1, stable/6.12, stable/6.18,
stable/6.6 were fixed.
Fixed status
stable/5.10: [0bf92a90bf05ecafe52e92d5bc15a585021a64ac]
stable/5.15: [54add3b7d3c154ca89ef5bac2582b0ed1a3a15d5]
stable/6.1: [768f665f3685b455ed686370ed7ccb852a125a3b]
stable/6.12: [d643c1ec80b70508f54dac12179e36920e2c00de]
stable/6.18: [cdce1e797addab72393c0dfee31aaca41ef7d937]
stable/6.6: [9aa7edc1347b98774e5167ca34e5b8aa6083bde7]
CVE-2026-45930: net: mctp: ensure our nlmsg responses are initialised
stable/5.15, stable/6.1, stable/6.6 were fixed.
Fixed status
stable/5.15: [b37da3ac099e145bcd3be82c745a8d335772e3af]
stable/6.1: [c4f840437e7641764de15f2de951ac8335d641f1]
stable/6.6: [963537a26fd892f7e414a091f807b44aeee97a7d]
CVE-2026-45991: udf: fix partition descriptor append bookkeeping
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [ad3c0c4400686f6f37b382aaa48fac2b9aefccbe]
stable/5.15: [68013a9bd4c01acd42073715f00e1a1992f089ee]
stable/6.1: [e8474cfbac9ada2cdaa4eaedec22aadfa0f58559]
CVE-2026-45993: LoongArch: Add spectre boundry for syscall dispatch table
stable/6.1 was fixed.
Fixed status
stable/6.1: [c8a8e863928424046b8fd328f02c359baa0a0c3f]
CVE-2026-45996: spi: imx: fix use-after-free on unbind
stable/6.1 was fixed.
Fixed status
stable/6.1: [c7c40c3e7b9fb900504aa746de3e53c5275b24bd]
CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [778acd52e9497806fbd2cea7f770c41d6850fc48]
stable/6.1: [118ff71ff09ebaf323a09af9e911517321a299f4]
CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [b703ee903b24974aca4bde99c7d25d66309d35dd]
stable/5.15: [823310645065bd49666e84af689fa95192819f55]
stable/6.1: [ed29887286aba96d1930f4ddb9f235f6b421073c]
CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg()
stable/6.1 was fixed.
Fixed status
stable/6.1: [ed2d6442e61169e565727ba15c4f6a0cb5ce16df]
CVE-2026-46006: drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
stable/5.10 was fixed.
Fixed status
stable/5.10: [3429275684f4bad42876955301f3c5c814aae909]
CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [a172fa18bc370b776ac1510abb0dcb50a7a35fac]
stable/5.15: [8e563d8db50f303171aceb79eec0807e7ba06951]
stable/6.1: [d4eb861adde5ce22e459fbd29366f47bb2167977]
CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [bd69e0e8a7643ba5385f19f479e8e3da71f8d495]
stable/5.15: [91cb30b6bb1880ba0748ca059bef50b8ac13793d]
stable/6.1: [6e3675251fcea06caecc61eb76462467558adfa6]
CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [6c9cca46acb6f22e63f015ea7b2ed6032d2badf5]
stable/5.15: [a5a454f3364877b22f0e5a165df8b3702ff96ae7]
stable/6.1: [25d580a46b079a7963ff024a5195e547baf12b64]
CVE-2026-46044: ipmi:ssif: Clean up kthread on errors
stable/6.1 was fixed.
Fixed status
stable/6.1: [e662be2d0d05253d0fd7deda9771aa036c23393e]
CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [4147ae08824cc8b65d2b2018f79d416af2937108]
stable/5.15: [73b47a1f06dee5e61b00dee5227d75d3f1f6d977]
stable/6.1: [79ffcbeac6bc1dc1bcdb0434acf250f6215ec111]
CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [ea18732d2614557e59f4c0d8cdbe6611aeab33b7]
stable/5.15: [d28311539ac9f65e29308ea219ecaa48aa5e76e5]
CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the
lifetime of struct fb_info
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [4aab89603b637a2e441b38808c4f6fe7d1184df6]
stable/6.1: [4fda0d6b45faad44926dd3e4f55f118d899b2e27]
CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [c3508895450cca4aeaf5dbadbb5e582363005264]
stable/5.15: [1958a92599b2653d730ccb6f5685fc3fbed21812]
stable/6.1: [a88f5391dc68f78cae5eb6a8cd341cafee795d3d]
CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for
trailing dirents
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [a8ee527807f7d97e55ce2ef2906f7f34975eb1c7]
stable/5.15: [aa16dca1b062355181ef215229eeac249d7c0d61]
CVE-2026-46083: spi: fix resource leaks on device setup failure
stable/6.1 was fixed.
Fixed status
stable/6.1: [e0401de43dac00f3e4841ca2aeb98bc10a4c5f13]
CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [c502fa9f094cb03d1d1685c71e2105ab359bc2b8]
stable/5.15: [a6ae4511c07b91f597e461406c6330f0d4ff810e]
stable/6.1: [1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a]
CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [83bd62fa9620ac98d5d694bde14c50f98c8e7189]
stable/5.15: [345c24b2bcf0923dfae1ab41497351c68214ff76]
CVE-2026-46091: media: rc: igorplugusb: heed coherency rules
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [bc04b8633b375af6ac8a8bb615258b80fe06cdaa]
stable/5.15: [81f0fb813e4bf28b3ca28dc218938a32eb48f740]
stable/6.1: [0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a]
CVE-2026-46092: wifi: rtw88: check for PCI upstream bridge existence
stable/5.15 was fixed.
Fixed status
stable/5.15: [959c13da6c36167ce1016d400a6104d2367f686e]
CVE-2026-46103: can: ucan: fix devres lifetime
stable/5.10, stable/5.15 were fixed.
Fixed status
stable/5.10: [a90f0815aaa9c629ac4750e7c71c357dd7f231d7]
stable/5.15: [cb2e41e87a2893345859440017e7178bf7a4c70d]
CVE-2026-46107: dm-thin: fix metadata refcount underflow
stable/5.10 was fixed.
Fixed status
stable/5.10: [b719d12cb94df345e9ad2715fd0abe9afcaeb111]
CVE-2026-46110: net: stmmac: Prevent NULL deref when RX memory exhausted
stable/6.1 was fixed.
Fixed status
stable/6.1: [fdeb95b1fc7de25c9362990efb9996a8d761055c]
CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [3943fcad7694a7d0b15aeabe7d3cc2a2eb8e92e8]
stable/6.1: [2c617848ae6e4f07a3e397f604208c293bbecacc]
CVE-2026-46125: wifi: mac80211: remove station if connection prep fails
stable/6.1 was fixed.
Fixed status
stable/6.1: [18fed0a209500bfea5c4c08609ec93855e4e500b]
CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [d9b272a85fe6b8f993e37915311e4038c814a533]
stable/5.15: [23079e0b7742ec114d3507c3e3aad01b7b69e4af]
stable/6.1: [b35605e1f1e877038c8c9d499babbc891cdd234f]
CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU
which can lead to info-leak
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [f407aad350bdea4db300c47433573b7a41630d33]
stable/5.15: [d8224b1be6627c6c3b204bfb264508d27c65ac44]
stable/6.1: [d69a4a6813fdba7c4cc3695a7e843842b240790d]
CVE-2026-46160: btrfs: fix missing last_unlink_trans update when
removing a directory
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [af467162290f5fe79d6a361b7c84302e45b1fd9f]
stable/5.15: [2525998ac956476bded26b9f34c4164dc890b87a]
stable/6.1: [6acbb2f6dff23c9bb9761fb98b516525b9cf1ce9]
CVE-2026-46164: btrfs: fix double free in
create_space_info_sub_group() error path
stable/6.1 was fixed.
Fixed status
stable/6.1: [c2d59527cba6d59f0d77a75c1101ab4e69758bea]
CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [3003dbf62d151d47a6b90f71655292a51a05f244]
stable/5.15: [8be69532e399eec9d9d990f6958b4ff2383b19b3]
stable/6.1: [3bc337697c66db2e2a4a94f0509c282c1a014b86]
CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue
when stopping watchdog task
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [a21f735fb1017ef89c6f9dbf4d799513b4e7bd5a]
stable/5.15: [df2e90d6a9955510f24f1dada78cfc439fd9fa88]
stable/6.1: [d616bb10de79e5c2bd8a24230a1128aeaf715615]
CVE-2026-46190: mtd: spi-nor: debugfs: fix out-of-bounds read in
spi_nor_params_show()
stable/6.1 was fixed.
Fixed status
stable/6.1: [231b8e1f604f6e0a7e100536f506cdf482e2c5f5]
CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [b51c343a81e6e806525a4435e22532c107dd7e9d]
stable/5.15: [46cf3646dea54baeaa2eafe3fb1ba769947f31b0]
stable/6.1: [524a6079395916fb3d790ef2bb46a1d2939b27dd]
CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [ec406c26c97594124e79d14516b729a8d5dced62]
stable/6.1: [1dae77078ceb4bab833f7a4935f05c5b8c97b9ba]
CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers
stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.15: [5de2665e913a10ad70aaeecf736b97276e83d995]
stable/6.1: [f9dc3be8f403c1216df73e57221f44b045e7ee0b]
CVE-2026-46196: tracepoint: balance regfunc() on func_add() failure in
tracepoint_add_func()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [5787052e5f69beb649f3d6a80a8aa37d9e683e4e]
stable/5.15: [4f1756d043e56ea2e9a6c858fb290a0cf6fc2251]
stable/6.1: [36ff362235307af95152d510b53c2d9b8773a342]
CVE-2026-46203: spi: cadence-quadspi: fix unclocked access on unbind
stable/6.12, stable/6.18 were fixed.
Fixed status
stable/6.12: [2e7cd62c37f51823c2bb79de1d4d76d0c1678c7e]
stable/6.18: [63a9f6012f453578898c9fcc13c8452a8651104e]
CVE-2026-46208: batman-adv: stop tp_meter sessions during mesh teardown
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [5e7d0ac936354c36810e74ac3056b334ed1f4058]
stable/5.15: [268078acae72daa12b17b2b299701cb9924e469a]
stable/6.1: [58943b7ea356294749dae3e75b96c0ee292c00be]
CVE-2026-46280: lib: test_hmm: evict device pages on file close to
avoid use-after-free
stable/6.1 was fixed.
Fixed status
stable/6.1: [234071b4318feaeb27cd2e4e1b16ef6b055adf89]
CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [e8e72fdf47bd5ef7abe642b034c6178a61a8580a]
stable/5.15: [cd849c07b8d706425e60a4dfcef54b7b67c967ce]
stable/6.1: [a9207798fe619cbc85c8744a9b9e2af1db2b6e1a]
CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual
devices in genpd
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [e8f8dad44f024a5c99e54a48ad5c943fa8e54319]
stable/5.15: [98b8104978474d381256a2b2fb0e7ca8e05a7bfa]
stable/6.1: [52e485ed0dcb5496864003ba9ffcef7d5b613f83]
CVE-2026-46296: spi: s3c64xx: fix NULL-deref on driver unbind
stable/6.1 was fixed.
Fixed status
stable/6.1: [29e219a18e21258bdb4ee12cecd0e9ec87d7e6a7]
CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super()
stable/5.10, stable/5.15, stable/6.1 were fixed.
Fixed status
stable/5.10: [e890656accee4c26d932ea388eb8936a6e22184d]
stable/5.15: [6499c9c8ec437a369e7e221dad91f6122b50759d]
stable/6.1: [c554ddc87af4d4e4be42f8aed1baec9e1c7588e0]
CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent
infinite loop
stable/6.1 was fixed.
Fixed status
stable/6.1: [309abbddeca0c12714721928a819ef45e5710998]
CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp()
stable/5.10, stable/5.15, stable/6.1, stable/6.12, stable/6.18,
stable/6.6 were fixed.
Fixed status
stable/5.10: [8d03e65eb6cfbffec471a6b65416f93679bf3286]
stable/5.15: [f979971835dddbca86cf99e3b2e2b94a408a1ab2]
stable/6.1: [3f52a86a482a69294c50a5a2a097bd6f4104990a]
stable/6.12: [d68eab61944a9b0826fa2e954e42db1aa3201b7a]
stable/6.18: [e27c17346628cb56843a83f93ac63c314c00f388]
stable/6.6: [d30aac0fa00ca0afc3e08174cf7f974a66bdcf05]
CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one()
stable/5.10, stable/5.15, stable/6.1, stable/6.6 were fixed.
Fixed status
stable/5.10: [0a6f46a9332ad6958992d64d3b3a81a80b2ca940]
stable/5.15: [0e8211fcf9426f5adddf32516ba0f400ceb9544d]
stable/6.1: [e915445942af6dcea628bf66d6241641201a0c41]
stable/6.6: [5b34f9e4fe2f203724a6e893d6df0316b9670057]
CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one()
stable/5.10, stable/5.15, stable/6.1, stable/6.6 were fixed.
Fixed status
stable/5.10: [26fe549b5192536b6c1c68a2dfdc8c0dcf9fa4a9]
stable/5.15: [793385c154771603b8671dd8338927221e9d8d78]
stable/6.1: [2638a9c1521905bb5c5d1e95c8fbc09f79148ed7]
stable/6.6: [60d9c0d6cdde5420d6483c921b16fe5465eb5238]
CVE-2026-46323: net: gro: don't merge zcopy skbs
stable/6.1 was fixed.
Fixed status
stable/6.1: [3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d]
CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache
corruption
stable/6.12, stable/6.18, stable/7.0 were fixed.
Fixed status
stable/6.12: [2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b]
stable/6.18: [b198ed4e52580a7238c7c7082f03906f8b310313]
stable/7.0: [3dee9d0c198faeb95d052c1b94c2958751a28512]
Regards,
--
Masami Ichikawa
Cybertrust Japan Co., Ltd.
Email :[email protected]
:[email protected]