[kernel-cve-report] New CVE entries this week
Masami Ichikawa <[email protected]>
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <CAODzB9rn1J4k4qt0yQbz4wgr7CYM8cyjrht1J27qNTWaA8OiMg@mail.gmail.com> |
Hi!
It's this week's CVE report.
This week reported 226 new CVEs and 5 updated CVEs.
* New CVEs
CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53131
According to the .vulnerable file, this bug was introduced by commit
1da177e in v2.6.12.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [62443dc21114c0bbc476fa62973db89743f2f137]
stable/5.15: [4435888e1bf139d2bfe5911643d4217382136743]
stable/6.1: [063f43361e884acd7300790e90194430275d0d0c]
stable/6.12: [367abcacc13a8e2e7624408b7f593bd1e60e49d9]
stable/6.18: [5d634afb8b83b49de562792fd0d047416a43bd4d]
stable/6.6: [726abf97566867f808fec9d8a408eb9698bd570a]
stable/7.0: [cea435ea7e868ea6fdf039bc4f2090c1d829b556]
CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53132
Introduced by commit 0777061 ("virtio/vsock: don't use skbuff state to
account credit") in v6.3-rc3.
Fixed in v7.1-rc3.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1
Fixed status
mainline: [059b7dbd20a6f0c539a45ddff1573cb8946685b5]
stable/6.12: [1eca304f97a34ed5e921e1f0e06c8b241f25bf12]
stable/6.18: [9bdc637fde66b63d6cad0caacd034888bb7bf5f5]
stable/7.0: [100d5b2ffdc6468b9e48532641f29e83efdcb63c]
CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53133
Introduced by commit a808273 ("RDMA/verbs: Add a DMA iterator to
return aligned contiguous memory blocks") in v5.2-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [15fe76e23615f502d051ef0768f86babaf08746c]
stable/5.10: [2ff4b7817e5b78070c30f5fb5e678e452a2628b3]
stable/5.15: [dee2a49adeeb2a5e16a3fc858fa21b841c519802]
stable/6.1: [cc644d5608e3b0dadc970bd6e6aa26b91ea07d0f]
stable/6.12: [baf8685bcf56dc1efb44b8f6a57c42516e549068]
stable/6.18: [afd35fec9297195b759078745549c2671223f24f]
stable/6.6: [8fe0231adebe086c8a459c790944ac026cd99c6e]
stable/7.0: [ac1aad8e1281534ce936c250f68084fc79c5469e]
CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the
OIFNAME register
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53134
Introduced by commit f6d0cbc ("netfilter: nf_tables: add fib
expression") in v4.10-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ab185e0c4fb82dfba6fb86f8271e06f931d9c64c]
stable/5.10: [6744e49fe51bfba26522acc2d0e9703cb41d8e50]
stable/5.15: [eca18feed38b3377a2ec5d1f22af1170c55d0171]
stable/6.1: [d19ddef8c327a4773ff81f8e51027d1e0b4cf069]
stable/6.12: [8c84885e9790823828bb8084736ea15769b1ac16]
stable/6.18: [84d8f58cf28a0415413f43ba7148f7bacd4c1b6e]
stable/6.6: [eb8a8124484dbc3c2b543e207da39bbccb703d31]
stable/7.0: [3544210609f6d1db282bbdeca639104ef624c393]
CVE-2026-53135: drm/amd/display: Fix NULL deref and buffer over-read
in SDP debugfs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53135
Introduced by commit c7ba365 ("drm/amd/display: Generic SDP message
access in amdgpu") in v5.2-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [adf67034b1f61f7119295208085bfd43f85f56af]
stable/5.10: [ee9cfcf77a8e8af637396dc00966df5f701e661c]
stable/5.15: [b781f90a9528555c709e59789550893581ef0be4]
stable/6.1: [a2de1d71891a038a9346b2c1a72b88c8350f2479]
stable/6.12: [7ae95c0275c330b5dbae806f8e431720edad776f]
stable/6.18: [bb6f705b73b5f191f14ad004e2c8c4b615806187]
stable/6.6: [7fc4fab4acc307ad2903312c195872b2953d32c3]
stable/7.0: [c90954cdea4d6998ec345de0d840d030c145b89e]
CVE-2026-53136: drm/amd/display: Clamp VBIOS HDMI retimer register
count to array size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53136
According to the .vulnerable file, this bug was introduced by commit
1e8635e in v4.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fb0707ce00eef4e2d60c3020e1c0432739703e4a]
stable/5.15: [029571d51140650783be4fb98fe7cb4754752086]
stable/6.1: [5f8b39452fb16f507c9e4d8b4a83ce27e893307c]
stable/6.12: [d6be8e59af412623e3d874be3a048406c0edfe60]
stable/6.18: [3f32d52ec604c659725d865cf8cc6a17a33f9c6a]
stable/6.6: [4d1c3c26c2ab1842e139e61983395d64bd2e518b]
stable/7.0: [8aaa7e317fbd4beb9c6a9f77aa4cf52fae78b117]
CVE-2026-53137: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53137
Introduced by commit eff682f ("drm/amd/display: Add DDC handles for
HDCP2.2") in v5.6-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f0f3981c43b32cadfe373d636d9e9ca522bb3702]
stable/5.10: [3c4444aec06c74fbc05661f370954ac814963c38]
stable/5.15: [91fb41218c413989d8b6c837748751454b452d68]
stable/6.1: [964e50ef7b8f09815a7d05b8326af700f8d5bc96]
stable/6.12: [bfba882cfcd08f6540f72f48e786b6404f5d2c5b]
stable/6.18: [1906064d50d194a145486e5caf3db3e708b6f6ef]
stable/6.6: [79e0273272a05fb26f9b1e55bf1a52eefc3b7b35]
stable/7.0: [98cfb7530ea91d8e5e928285cdce58e1131f6e83]
CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53138
Introduced by commit 4562236 ("drm/amd/dc: Add dc display driver
(v2)") in v4.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ff287df16a1a58aca78b08d1f3ee09fc44da0351]
stable/6.12: [6173cfea2f916e01c4f98e29cd654384a05e32a3]
stable/6.18: [0e56f460bddb397fa9a8e6faf7ae7eaa86953eb1]
stable/7.0: [2645e3caf7e013189da9c6ff621d006cca5a538b]
CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53139
Introduced by commit d223f98 ("drm/v3d: Add support for compute shader
dispatch.") in v5.3-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7f93fad5ea0affc9e1505dd0f7596c0fdb496213]
stable/6.18: [9655b56b6de918e1c22b92f3880ae41b052cbd00]
stable/7.0: [11e6432836394e00d39e468cd514f9ddb66f1e49]
CVE-2026-53140: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53140
Introduced by commit 18b8413 ("drm/v3d: Create a CPU job extension for
a indirect CSD job") in v6.8-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ae7676952790f421c40918e2586a2c9f12a682b6]
stable/6.12: [0b59d0946913a0df7d1a033013e259e9b6a76546]
stable/6.18: [90b629269088a9fe24a02c032be9f08357f47873]
stable/7.0: [60ebeb23eaf3d7fd2e0551fe304309305e31d424]
CVE-2026-53141: drm/v3d: Fix global performance monitor reference counting
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53141
Introduced by commit c6eabba ("drm/v3d: Add
DRM_IOCTL_V3D_PERFMON_SET_GLOBAL") in v6.14-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6bf7e2affc6e62da7add393d7f352d4040f5bc27]
stable/6.18: [3e1947573140a57119294f0bff39ee18d93f23e1]
stable/7.0: [ed2eaf3b7b1820b690e4b896d344e00027526a25]
CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53142
Introduced by commit 44e6949 ("drm/xe/display: Implement display
support") in v6.8-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [68938cc08e23a94fd881e845837ff918de005ce7]
stable/6.18: [0f68ddfaaebfbb5581ee931779757d31f4dc9e24]
stable/7.0: [238bcdaae8f2abc65e182de7d1f69cf8f611a610]
CVE-2026-53143: drm/amdkfd: Fix buffer overflow in SDMA queue
checkpoint/restore on GFX11
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53143
Introduced by commit cc009e6 ("drm/amdkfd: Add KFD support for soc21
v3") in v5.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [352ea59028ea48a6fff77f19ae28f98f71946a80]
stable/6.12: [2c5b66c9b4057b385566940935ebc32f6e6ebfd2]
stable/6.18: [d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64]
stable/6.6: [16dad1fb0d783a4008de30e32d0038c393de05b1]
stable/7.0: [d02f05d30f35b036f7cbaf72de634affb5b38ec6]
CVE-2026-53144: drm/amdkfd: fix NULL dereference in get_queue_ids()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53144
Introduced by commit a70a93f ("drm/amdkfd: add debug suspend and
resume process queues operation") in v6.5-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2bd550b547deabef98bd3b017ff743b7c34d3a6d]
stable/6.12: [daeceb0fe2a19651c58bbfa3d9d515ecb6ca8996]
stable/6.18: [72e259a32084c42816152c346096d2edd4213e23]
stable/6.6: [62bd09e23a23da70f9aae02748eba3e6bd93095d]
stable/7.0: [e1965e8913cfbf17622ca12638e7a07f68ba0848]
CVE-2026-53145: drm/gem: Try to fix change_handle ioctl, attempt 4
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53145
Introduced by commit dc36660 ("drm: Replace old pointer to new idr")
in v7.1-rc4.
Introduced by commit 5e28b7b ("drm: Set old handle to NULL before
prime swap in change_handle") in v7.1-rc3.
Introduced by commit 7164d78 ("drm/gem: fix race between change_handle
and handle_delete") in v7.1-rc6.
Introduced by commit 5e28b7b ("drm: Set old handle to NULL before
prime swap in change_handle") in v7.1-rc3.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
stable/6.18 stable/7.0
Fixed status
mainline: [1a4f03d22fb655e5f192244fb2c87d8066fcfca2]
stable/6.18: [c0639ede2f24ac224b2079cd35ecd5fd8ad4e3cd]
stable/7.0: [1d9b93df7fc768228906e24220591ec1cddad391]
CVE-2026-53146: thunderbolt: Limit XDomain response copy to actual frame size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53146
Introduced by commit cdae7c0 ("thunderbolt: Add support for XDomain
properties") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4db2bd2ed4785dbadaeeab9f4e346b21ac5fb8eb]
stable/5.10: [c55da494dfb445fb28df3a9d293c2be6a299cd01]
stable/5.15: [7720654b4842bcdfeb64bc002f6186041849e1e7]
stable/6.1: [033dfa63bf6be2653441a1dccae4a8313a91bb9d]
stable/6.12: [a15b6d3136accb2bf84b04d9a3ddd991f7fbf1cb]
stable/6.18: [b5daa920f44cb582272fc9bfaeb67408776cbaef]
stable/6.6: [fc261397295b8ad0654cec747b0ec25ea0011995]
stable/7.0: [b2c1e5d9f1598cc1a4736d5c6bd1218f90805ee4]
CVE-2026-53147: thunderbolt: Validate XDomain request packet size
before type cast
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53147
Introduced by commit 8e1de70 ("thunderbolt: Add support for XDomain
lane bonding") in v5.19-rc1.
Introduced by commit cdae7c0 ("thunderbolt: Add support for XDomain
properties") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a504b9f2797b739e0304d537e8aa4ce883ecce39]
stable/6.1: [a770e62923090d7572f1f5a8507ae551d354a057]
stable/6.12: [79235c8add5da4bf27a12f5a5dbb579f300c059e]
stable/6.18: [46da5c3ea011e884028a91cf913db093920a915b]
stable/6.6: [0dd61ba03d05187726ecdf9c0e2175a81b9b24f6]
stable/7.0: [07cd2787cdf8942d24a1a3ef81aa89b526fb6381]
CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53148
Introduced by commit cdae7c0 ("thunderbolt: Add support for XDomain
properties") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [322e93448d908434ae5545660fcbe8f5a7a8e141]
stable/5.10: [0b334279a82d79fb4723bd4f614305de1ab69caa]
stable/5.15: [6021d39ccd979713b39b980286020d8f9a45efd1]
stable/6.1: [89ae04365e01d5ae4aae83044a8bbd2a9aaf8d0d]
stable/6.12: [05a43157676c243c248d1c6d9dcecbe6eba2f35d]
stable/6.18: [fcbd0cdab92838854a5818be7ed8a097164ef6d5]
stable/6.6: [5db10c8ad8c09f72c847dfeef3d876098257f505]
stable/7.0: [906035d5c3784570191d259cbf9a0ac1617852b5]
CVE-2026-53149: thunderbolt: Bound root directory content to block size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53149
Introduced by commit cdae7c0 ("thunderbolt: Add support for XDomain
properties") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [65423079c7420e3dbf9a7aa345c243a3f5752e5d]
stable/5.10: [5c7657d38d07268124782f03519f07c22a5814fb]
stable/5.15: [b212bc161d8a9937b42153723a4a3f2f74fab528]
stable/6.1: [1912be23daf4afc8d24ce916021ab68ca4c679db]
stable/6.12: [0a32040a48db8cf35de48b85d6115df5623e4964]
stable/6.18: [60ba6217460792356a238299edd675d91d46bab4]
stable/6.6: [4d0b1524caadb04c10a71f3f88692c63dcb39115]
stable/7.0: [cbeb68cbaa0a6f979ef428a7f2d0268c082ba166]
CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53150
Introduced by commit cdae7c0 ("thunderbolt: Add support for XDomain
properties") in v4.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cff8eb65d1eafe7793e54b4d0cf6bf831644630b]
stable/5.10: [581c2053ab4dbe27e83c9e62deb4c73aa8dc0c3a]
stable/5.15: [35d6c9252a152e756768a26dbf216b9dd9dd8e92]
stable/6.1: [99d9dbad1463afb510d42c9714f846361d1b726d]
stable/6.12: [ca11e7da4fba4b394f69e16448f4463c44c84de6]
stable/6.18: [2e0ddac549ebd713eb9f4a15b6496e3440a17d8b]
stable/6.6: [5f56bc6bddffe8710ba0ba8844023b5a44ca90e4]
stable/7.0: [3b6e68cb97f725385010264a873e14a3921b6b8a]
CVE-2026-53151: rxrpc: Fix the ACK parser to extract the SACK table for parsing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53151
Introduced by commit d57a3a1 ("rxrpc: Save last ACK's SACK table
rather than marking txbufs") in v6.2-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [333b6d5bb9f87827ac2639c737bf9613dbae7253]
stable/6.18: [566c4c1244de50fbff1f89ff93c9d7b0fc256db4]
stable/7.0: [224298450be5c04d2a6ea1c2a94669d7ebf65d00]
CVE-2026-53152: mmc: dw_mmc-rockchip: Add missing private data for
very old controllers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53152
Introduced by commit ff6f028 ("mmc: dw_mmc-rockchip: Add memory clock
auto-gating support") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.18
Fixed status
mainline: [1e9a4850afa0ceb63984fb1a9f3e86d0fc4fd18f]
stable/6.12: [b1180ff50cca48807893ecde7d1f81d573c88c85]
stable/6.18: [7f8007be13e6cc1e0a508fe461f9a91ba9a28b8c]
stable/7.0: [8d9eca906e76d3dd40e5f2c79701f066678f2e62]
CVE-2026-53153: mm/list_lru: drain before clearing xarray entry on reparent
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53153
Introduced by commit fb56fdf ("mm/list_lru: split the lock to
per-cgroup scope") in v6.13-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [98733f3f0becb1ae0701d021c1748e974e5fa55c]
stable/6.18: [c19ff4351214f059349788e13e70e74325831ff6]
stable/7.0: [2b66496d794e98f7aeec7688573051f22ec40bac]
CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb
folio copy paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53154
Introduced by commit 1cb9dc4 ("mm: hwpoison: support recovery from
HugePage copy-on-write faults") in v6.4-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [40c81856e622a9dc59294a90d169ac07ea25b0b0]
stable/6.12: [e47bf16af3c45470ea32f2241fa69aefe0dd61bd]
stable/6.18: [c72469ac0f274bde3f0df60a4584e14a123d0aa6]
stable/6.6: [8d6e1dd3ad1340cd8b6d554b7aa93d8f0a1c6d38]
stable/7.0: [45e33d43243d71d089af42f5077b8213cee6610f]
CVE-2026-53155: mm/huge_memory: use correct flags for device private PMD entry
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53155
Introduced by commit 65edfda ("mm/rmap: extend rmap and migration
support device-private entries") in v6.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [43e7f189769c512c843184a8a5892ac779a6bd90]
stable/7.0: [d7251c8d3f7cea76543abac6cf4ed15582c10846]
CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53156
Introduced by commit 7ae6478 ("nvmem: core: rework nvmem cell instance
creation") in v5.16-rc1.
Introduced by commit e888d44 ("nvmem: resolve cells from DT at
registration time") in v4.20-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5b6b6fc491899d583eaa75344e094796ae9b530b]
stable/6.12: [e0d38bf47a72da2f02c9fa6f752cd66d977cd7f7]
stable/6.18: [cb85ef5a227b3662b88f4d849a1aad43bfe7f5ae]
stable/7.0: [40e2a459c0dd1333b2343831480a0ad80dc07614]
CVE-2026-53157: net: phonet: free phonet_device after RCU grace period
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53157
Introduced by commit eeb74a9 ("Phonet: convert devices list to RCU")
in v2.6.33-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [71de0177b28da751f407581a4515cf4d762f6296]
stable/6.18: [52b8f5ef82c886f7cd24617915e4b1579ddfd001]
stable/7.0: [bff309ea51f1395c1ef8be8b75ce62d28a319113]
CVE-2026-53158: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53158
Introduced by commit f6f9279 ("misc: fastrpc: Add Qualcomm fastrpc
basic driver model") in v5.1-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5401fb4fe10fac6134c308495df18ed74aebb9c4]
stable/6.12: [4bfdf0a9855df55e9e031ca6a25b855820590c70]
stable/6.18: [d5de9cb5355db36438edc621dde3673e3f235767]
stable/6.6: [8fb4a23df5b7c02929b62e5dbc270ec7c42b8134]
stable/7.0: [d77583ca33299fede0c194744ef2284e7ba5b763]
CVE-2026-53159: misc: fastrpc: fix DMA address corruption due to find_vma misuse
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53159
Introduced by commit 80f3afd ("misc: fastrpc: consider address offset
before sending to DSP") in v5.2-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [464c6ad2aa16e1e1df9d559289199356493d1e00]
stable/5.15: [2d0f47e27c1fa718b29c69aa7c96a2c5161bc2c2]
stable/6.1: [708c17b52c60fe7a57e73b495bdee50f58feb48c]
stable/6.12: [e69e306a4cccb40a73511350cb280825a556ce3c]
stable/6.18: [53e06f8a3c2b085c31bf1284e2ebcb8036e99625]
stable/6.6: [d3e26df2e8eb361e6bef096b2fd565476a1f14c4]
stable/7.0: [7ba7b30ddb04646d4d638f4d8c4718a304bbbddd]
CVE-2026-53160: misc: fastrpc: fix use-after-free race in fastrpc_map_create
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53160
Introduced by commit 10df039 ("misc: fastrpc: Skip reference for DMA
handles") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [07ebe87915d8accdaba20c4f88c5ae430fe62fbb]
stable/6.1: [0a3b87293fbd34fda651e6aead9964f84b893962]
stable/6.12: [5b0166112019d1dce30b976ab28fd67f7f0be532]
stable/6.18: [992f121796b7ca83a5a8b93da24e971363206218]
stable/6.6: [8b080c89183196fd3e49212f2a1a1c4a29335b9c]
stable/7.0: [f20f6512ecb75c816e0debf4551a138f098615c4]
CVE-2026-53161: misc: fastrpc: fix use-after-free of fastrpc_user in
workqueue context
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53161
Introduced by commit 6cffd79 ("misc: fastrpc: Add support for dmabuf
exporter") in v5.1-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e85eb5feca8e254905ffa6c57a3c99c89a674a0f]
stable/5.10: [c6e5c2be09f814377d7f1ce97370a5b7b3e02814]
stable/5.15: [e1e3a05efe5954d5bad01157d79429d39a67a7ae]
stable/6.1: [d42679eef34dd590b694ce3b666c5e2ba10cd4bf]
stable/6.12: [ecea4967c2bff92c2fafbc59893f711b39f7b152]
stable/6.18: [5278ccd357e0d7aeeb1e76c0f3e0e02894a9897c]
stable/6.6: [df08fadcf0e5f3708365ec3b6d30b5aafd98bea1]
stable/7.0: [fbe0947420eec18a84638d29468c2d563ce4e6a3]
CVE-2026-53162: memcg: use round-robin victim selection in refill_stock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53162
Introduced by commit f735eeb ("memcg: multi-memcg percpu charge
cache") in v6.16-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c0cafe24d3f6534294c4b2bc2d47734ff7cbd313]
stable/6.18: [89bd8215e25aa6999cc51696da418e0d422bc5e0]
stable/7.0: [00731bd7e18f182a32ca54d6b176eaa470b51ed7]
CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is
not enqueued
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53163
Introduced by commit 3bfdc63 ("rtmutex: Use waiter::task instead of
current in remove_waiter()") in v7.1-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.18
stable/6.6 stable/7.0
Fixed status
mainline: [40a25d59e85b3c8709ac2424d44f65610467871e]
stable/6.18: [a388e3dfaf9538a680de5ed43a8ebb5dd45b6e53]
stable/7.0: [55363fa0a04524d11efeaadee734d2db1756ed27]
CVE-2026-53164: iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53164
Introduced by commit 433a762 ("dma-mapping: Implement link/unlink
ranges API") in v6.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6ec91df8aff77e2e8fe3179c1f3fc15b43a40ba3]
stable/6.18: [ab61c990a87d084f5565ee70340543e3a5394697]
stable/7.0: [b16f8d40bac9ced838d24c9842707af9ecae92e2]
CVE-2026-53165: iomap: avoid potential null folio->mapping deref
during error reporting
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53165
Introduced by commit a9d573e ("iomap: report file I/O errors to the
VFS") in v7.0-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2eea7f44b9c8b42fd7d3a1a87c06a7cd1b99c327]
stable/7.0: [1ad453817a4077230d1ba88eb0868f05f824449a]
CVE-2026-53166: futex/requeue: Prevent NULL pointer dereference in
remove_waiter() on self-deadlock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53166
Introduced by commit 3bfdc63 ("rtmutex: Use waiter::task instead of
current in remove_waiter()") in v7.1-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.18
stable/6.6 stable/7.0
Fixed status
mainline: [74e144274af39935b0f410c0ee4d2b91c3730414]
stable/6.18: [16f8e17184b31382076f84751db5ac51fc02733e]
stable/7.0: [1f2f3f3eacd6653ab215c5d2ea70811148d433fc]
CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53167
Introduced by commit 2d45ba3 ("fuse: add retrieve request") in v2.6.36-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4e3d1b2c48ca6c55f1e9ca7f8dccc76f120f276c]
stable/6.18: [56763afa013444a9d84ca1b74e4b7130942177ba]
stable/7.0: [1fb8735a3a4d894f8c1f90b741a3ab1d3817f9bd]
CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53168
Introduced by commit 5d7bc7e ("fuse: allow using readdir cache") in v4.20-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9c954499d43aefac01c5dfb57a82b13d2dcf4b94]
stable/5.10: [15487f98863dc7156ed43c5be26d478beb82ba35]
stable/5.15: [bd23fa0c16c5c86e5b7713224ffbb87d9db81cca]
stable/6.1: [9dbf1b2fadfc6c40805631d8a8276d1639fc9ab6]
stable/6.12: [99c317d7f8b7bbf3de16d20a01f363e390114cea]
stable/6.18: [12df4cfa738aefff21756728e91056d7defb0fe6]
stable/6.6: [dd92773d4d9cea010474eb08a5133c14ff6ab53a]
stable/7.0: [e692f0cb86204dcdb9dddc0b355407eda6394a67]
CVE-2026-53169: accel/ethosu: reject NPU_OP_RESIZE commands from userspace
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53169
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ef911805d86a05363d3ec2fa9835a41def83bb7e]
stable/7.0: [70090a32f56a4589e7e860e0f9a8fbe4417df0a1]
CVE-2026-53170: accel/ethosu: reject DMA commands with uninitialized length
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53170
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d9d021218162b6c4fe0bdf42b2b340f1aae23a12]
stable/7.0: [fb25c76a820ca8a547aa478bfb503da0a11494ab]
CVE-2026-53171: accel/ethosu: fix arithmetic issues in dma_length()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53171
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ee6d9b6e51626f259c6f0e38d94f91be4fd14754]
stable/7.0: [6bb73845d1855ceaf50e397175e5979a7bdf69bc]
CVE-2026-53172: accel/ethosu: fix IFM region index out-of-bounds in
command stream parser
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53172
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [00f547e0dfecf83014fb32bcba587c6b684c1362]
stable/7.0: [ee7bed779def61ebff1b92b0e851f412176fa416]
CVE-2026-53173: accel/ethosu: fix OOB write in
ethosu_gem_cmdstream_copy_and_validate()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53173
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c0837b9cf6eabbad8b8cbddaff1a46a6d0a2e29d]
stable/7.0: [db6cb3e35cebf487f9a78ebd4cfa4b83708ff40d]
CVE-2026-53174: ovl: keep err zero after successful ovl_cache_get()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53174
Introduced by commit d25e4b7 ("ovl: refactor ovl_iterate() and port to
cred guard") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1711b6ed6953cee5940ca4c3a6e77f1b3798cee2]
stable/7.0: [e7051909a01bfb883bfa78b27514854068ac4b85]
CVE-2026-53175: inet: frags: fix use-after-free caused by the
fqdir_pre_exit() flush
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53175
Introduced by commit 006a503 ("inet: frags: flush pending skbs in
fqdir_pre_exit()") in v6.19-rc2.
Fixed in v7.1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [32594b09854970d7ba83eb2dc8c69a2edd158c8e]
stable/6.12: [c22599cc90e1cd5f8129c8670bd68a02ff7177b4]
stable/6.18: [89b909e9704587bfecc1aab1d37e98faee03b9f9]
stable/6.6: [0e823ca0e7391630784ae7dd0981b7ad170a93d9]
stable/7.0: [010c3313a4d178dc2d3ce958d2e5cb055e2864c1]
CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53176
Introduced by commit b8d26b3 ("iser-target: Add iSCSI Extensions for
RDMA (iSER) target driver") in v3.10-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [29e7b925ae6df64894e82ab6419994dc25580a8a]
stable/5.10: [75ee6e4aa096aa9e7b2dd5c8ff98356e30aceefb]
stable/5.15: [e8a013c0c3ca2f6708341a56612a3f6d6921620a]
stable/6.1: [bd22740d7f14cb1c0289444cfd2c8d2938667c1d]
stable/6.12: [c5584e089b5af7b3bf8bd5e8ca0560cbf32b0a47]
stable/6.18: [df422fd273c96c2ee5beb80fc21adc8c70c29260]
stable/6.6: [c1234229399f4af12c553b1b0ffd978eeba65548]
stable/7.0: [1ca40b243277c9e88be5e00bd3e083f71aefb93e]
CVE-2026-53177: bnxt_en: Fix NULL pointer dereference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53177
Introduced by commit e5811b8 ("bnxt_en: Add IRQ remapping logic.") in v4.17-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d930276f2cddd0b7294cac7a8fe7b877f6d9e08d]
stable/5.15: [964b1c3eb71afe58bb61c8b984164447e000ae8a]
stable/6.1: [59c5a3e69c7630a811565937e64be70b08436761]
stable/6.12: [08e57d014ea19f303d5d57a849beb846f37788b7]
stable/6.18: [3884976f87448e269908ae61bd5d62d54ce9c0c7]
stable/6.6: [1a418ad0e5e525d1d117dd1601681f75455af320]
stable/7.0: [580844a9683afe7974856dd5b7886447435b3474]
CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before
ie_length subtraction
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53178
Introduced by commit 2038fe8 ("staging: rtl8723bs: fix spacing around
operators") in v7.0-rc1.
Introduced by commit d3fcee1 ("staging: rtl8723bs: fix camel case in
struct wlan_bssid_ex") in v5.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [88e994c57a79f62d5338231d8d37ee8dd98baffe]
stable/7.0: [542d65a6dbd9733baab96313c9fe76a76e93f484]
CVE-2026-53179: staging: rtl8723bs: fix buffer over-read in
rtw_update_protection
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53179
Introduced by commit e945c43 ("Staging: rtl8723bs: Delete dead code
from update_current_network()") in v6.10-rc1.
Introduced by commit d3fcee1 ("staging: rtl8723bs: fix camel case in
struct wlan_bssid_ex") in v5.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [514ab98364595007d4557ecc85d7e5f012c504d3]
stable/6.18: [735dabdf21561a24d8bcae456c9c32f7f961a029]
stable/7.0: [303f65af819f6d5aa302e82bce72b57a8575faea]
CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53180
Introduced by commit 7ee9887 ("timers: Implement the hierarchical pull
model") in v6.9-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d486b4934a8e504376b85cdb3766f306d57aff5b]
stable/6.12: [07b3b83587fb3012619f4439389b64a955fc7836]
stable/6.18: [1d6c2062b77be09ec15d6bf637b2e2221c4482fc]
stable/7.0: [d338e61ea94052a786aac9f58e9f0d8520afa0fd]
CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53181
Introduced by commit d021c34 ("VSOCK: Introduce VM Sockets") in v3.9-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c05fa14db43ebef3bd862ca9d073981c0358b3f0]
stable/5.10: [22c587aa3ab1ab5264daff3ec32136fd30436c13]
stable/5.15: [cf7090e255d74c4b61c51f8ede9fcacdd8393b5b]
stable/6.1: [ea0b03d52881c12a8c634ea0d6cbfa61cefdb488]
stable/6.12: [bcb275626055df7f8f947f1a349754b4004d9a15]
stable/6.18: [ba9ad6015937a5e46ba1a31370e3efdec8abbdcc]
stable/6.6: [dfd853197615d322d3a88dbcab91fc0fd2096219]
stable/7.0: [9698582a4dd9c4a05889d7db96d4c0edc9e69cac]
CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53182
Introduced by commit dbbb27e ("cfg80211: support RNR for EMA AP") in v6.4-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1
Fixed status
mainline: [4cd92957e8f8cc4ebfe8a5d4203c14c592fde6b1]
stable/6.1: [fc0ec2fc02dfe52c5821f36fbccf6a45df43f508]
stable/6.12: [30c3fa80f423613efdda3deca4af52ff7d20e4e2]
stable/6.18: [265c07c09c837621730d35f02975207a1224bf05]
stable/6.6: [688fcac7054abc680c0eef753f2bb772cfaf8cf7]
stable/7.0: [ecbf3c45add30a0857414e156bdb9c79906f0ff6]
CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53183
Introduced by commit f3589be ("mptcp: never shrink offered window") in
v5.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [da23be77e1292cd611e736c3aa17da633d7ddce7]
stable/6.1: [bf364b0f10b27679140699821f88af7f01e2a6e3]
stable/6.12: [aa3861f40ac32706d9e97bfac76984613e278788]
stable/6.18: [653245266913f03fcf21cbca68eed5c197a33e52]
stable/6.6: [b1fd13074f22105deec45aa02283e322733e0c2d]
stable/7.0: [c297a4e65c50a2b807d9309b22615080faffa8f3]
CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53184
Introduced by commit 965b57b ("net: Introduce a new proto_ops
->read_skb()") in v6.0-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3c94f241f776562c489876ff506f366224565c21]
stable/6.1: [263779a6beff03b8b06f6d25566cb0f45af361f2]
stable/6.12: [90d35188aaa92b8f8b23f66335e0e91bf60103a3]
stable/6.18: [6822eed69572000a181fa4e31fceacc60918c471]
stable/6.6: [1b585673a2249f13678e7ac443ac683ba767e0b6]
stable/7.0: [7d6d92d000ebe3a845a17c165c1d3a70c5d84fe1]
CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53185
Introduced by commit 8e654f8 ("zram: read page from backing device")
in v4.14-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [732fd9f0b9c1cdc6dfd77162ded60df005182cc0]
stable/6.12: [77a602b505ce4802915853cfc435a4722fab3e64]
stable/6.18: [c96786d6ff1acc1d54d9241e97767554c1dfdd5b]
stable/6.6: [0c2821665ff71be3f4b07ecece384669f2877f6a]
stable/7.0: [198b5a14cca27263b9c14b20114c8092de15dfcb]
CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53186
Introduced by commit aef9ec3 ("IB: Add SCSI RDMA Protocol (SRP)
initiator") in v2.6.20.16.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [13e91fd076306f5d0cdfa14f53d69e37274723c4]
stable/5.10: [3889517c2ec7f364914aea8209abfff735f7ecde]
stable/5.15: [ed77cc819ad631264787cade5ae5ec4c535ec6bb]
stable/6.1: [0b9ee09d5e849591f17d98c078033dadea967293]
stable/6.12: [2015038195939eac54a1ee83c9d98ef1a8ccbbce]
stable/6.18: [f92a285db7ff6e598591ccbfb551be155c5f4d57]
stable/6.6: [0d64bc200ebe4f275b27438c6e593903e0b16fe1]
stable/7.0: [3523e53ff95f1837ec3f57ff7558532bcb2661b7]
CVE-2026-53187: RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53187
Introduced by commit d83edab ("RDMA/core: Introduce a DMAH object and
its alloc/free APIs") in v6.17-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [323c98a4ff06aa28114f2bf658fb43eb3b536bbc]
stable/6.18: [bd5e818be7964c1689fba2dad9e6bd3a827fee74]
stable/7.0: [0efbb6b54ff56300867027d8e0800d0e32226a20]
CVE-2026-53188: RDMA/core: Validate the passed in fops for ib_get_ucaps()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53188
Introduced by commit 61e5168 ("RDMA/uverbs: Introduce UCAP (User
CAPabilities) API") in v6.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4a1b1ac2744694a2ecd66a84bdb1445f4ef24bee]
stable/6.18: [96b6e98ff12d50ed5817230c6f1188e1150d225d]
stable/7.0: [aa181287ebdcc53ee0ba5c2f8243e2d541ebc19b]
CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53189
Introduced by commit fadae29 ("thp: use mm_file_counter to determine
update which rss counter") in v4.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8d878059924f12c1bc24556a92ec56add74de3c8]
stable/5.10: [84b3212b166b446faea27ebebb7161405ffceef9]
stable/5.15: [108963978a681c0c468d279cac2b930c27672877]
stable/6.1: [459771c9cf30f378bdbd30fc65d17f7eb931bb59]
stable/6.12: [6c29a8ba084e89499ca77b947e07ae817f9c16ce]
stable/6.18: [5f5b604e1e6bde4e889199168ee80fe8306d06ad]
stable/6.6: [ae9d4caf6f133e884cf5fcda4982c493b35e5194]
stable/7.0: [ed5b030931292c94133437ac5e5ff580e498eabd]
CVE-2026-53190: drm/virtio: fix dma_fence refcount leak on error in
virtio_gpu_dma_fence_wait()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53190
Introduced by commit eba57fb ("drm/virtio: Wait for each dma-fence of
in-fence array individually") in v6.5-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3f26bb732cc136ab20176697c92f32c9c84cb125]
stable/6.12: [73524e9f96a278b521f257a78a845c49eb522bc1]
stable/6.18: [8348567a6afb24e2c9cafe8a321162d0eebe1411]
stable/6.6: [898bd0ccfed71651b881660c5d20ad73b5203174]
stable/7.0: [c0fffc874c264292e769f26194a2a5e66ce31810]
CVE-2026-53191: io_uring/net: inherit IORING_CQE_F_BUF_MORE across
bundle recv retries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53191
Introduced by commit ae98dbf ("io_uring/kbuf: add support for
incremental buffer consumption") in v6.12-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ed46f39c47eb5530a9c161481a2080d3a869cfaf]
stable/6.12: [f40570fda3f3a1f96aeaa4aef665ba274b2810b5]
stable/6.18: [0bbc9481f970b0b4ddb08cfa464db1cc93b74b56]
stable/7.0: [4973232a67e4137ab9399f504f7f2bdd847f96d2]
CVE-2026-53192: ALSA: timer: Fix UAF at snd_timer_user_params()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53192
According to the .vulnerable file, this bug was introduced by commit
3774591 in v6.12-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [053a401b592be424fea9d57c789f66cd5d8cec11]
stable/5.10: [92ad2d7f80cad43b046f093e808e11fe919d304a]
stable/5.15: [117743d62e1225e208568a3ffc2c07214f1347cb]
stable/6.1: [b2214914e461d0466548a52dfe4f4ee8ce362276]
stable/6.12: [38034d04d4a75bbca01df2b313ced0bcd0fa3242]
stable/6.18: [3d39da65b5c422c5e5afb7d5651b0698d060a827]
stable/6.6: [e2331730175f74169046d2af8db1b47243df7c7a]
stable/7.0: [306427adf9b97e29e5958cb9cf3096c6151fc9ff]
CVE-2026-53193: ALSA: timer: Forcibly close timer instances at closing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53193
Introduced by commit 3774591 ("ALSA: timer: Introduce virtual
userspace-driven timers") in v6.12-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [da3039e91d1f835874ed6e9a33ea19ee80c2cb92]
stable/6.12: [586b219a22b1032b28b8bd356b963276c5e5bf53]
stable/6.18: [f46093dd22969037beb1fce2e043f3236be41c92]
stable/7.0: [60e73ab87b84bbd6bd7ddd1d16019a3a3705ab8f]
CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53194
Introduced by commit 60b3013 ("USB: kl5usb105: reimplement using
generic framework") in v2.6.35-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [96d47e40bf9db4a9efd5c8fb53287a508d165f14]
stable/5.10: [60af1fd82983c26604102e63a3fcc822c186cceb]
stable/5.15: [0a57320f71941d4e0b1307453c9a1f0939afe666]
stable/6.1: [14147b7963685957839c76ba8094924e22777d79]
stable/6.12: [70d86e355c564b5510fde61361df014f5476c83e]
stable/6.18: [372f33ebed747d91870f57c0a2e62884a870bffa]
stable/6.6: [a1288cd700f721c1a119c4f1e8efa234e59caada]
stable/7.0: [bde742b076cbe26ecc89c8c68c76ae076a524d02]
CVE-2026-53195: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53195
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0fd2b00b2d3d05e3eaa13342b3dfb0fa85c226ae]
stable/5.10: [3e187152f44d76d7633a3855ffd0099e1588b82a]
stable/5.15: [b7faf660eefa2047ebc2959ff76da2b6eae2e9e3]
stable/6.1: [2fd64bf0ad66ab5de0c73524591d879427ba5aba]
stable/6.12: [130d6567eb148040eed1b73e1414ad6c27d22bd5]
stable/6.18: [294692d3296eee3391c348d7ea6401916d27806c]
stable/6.6: [4cb722747ed25971f35cc47ce5c0e79d7f717713]
stable/7.0: [5a79b634ee58786ca627268daefa7744f2af2e14]
CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53196
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [183c1076eca43bbb3e7bdf597456f91d81c73e74]
stable/5.10: [e168db91442b94e64fa82a7dd297983d48ea5cc0]
stable/5.15: [561edb021486e6723d841926aa4b48097da06190]
stable/6.1: [cfd634f6dfd40c49a84f9bddc2867a80e2e2623a]
stable/6.12: [b849f30d1a9e66aae6b715aaef66e427390cb081]
stable/6.18: [f96cf7bf9fbf15d7fcf0c91fec47ba8a010369ea]
stable/6.6: [d92f17af7097d10bdeddf26f66f34b354104b277]
stable/7.0: [d214d2341d4f9f447e36a7d012cdf6a6631a55f1]
CVE-2026-53197: xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53197
Introduced by commit 4b3faf6 ("xfrm: iptfs: add new iptfs xfrm mode
impl") in v6.14-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c8a8a75b733467b00c08b91a38dbaf207a08ed6e]
stable/6.18: [a13ca53e47e500854a3b9ec18b5dc83acfec863e]
stable/7.0: [822b98d354e63e8249e85473c5f3c519f3c9cecc]
CVE-2026-53198: ksmbd: fix use-after-free of a deferred file_lock on
double SMB2_CANCEL
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53198
According to the .vulnerable file, this bug was introduced by commit
e2f3448 in v5.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f580d27e8928828693df44ba2db0fffdbe11dfea]
stable/6.1: [b7063c7426ea5a4d15e01b60538718765392f49d]
stable/6.12: [89ae9df09d2c1fb4a4eb495c113a7ce1dca34147]
stable/6.18: [14d2eee0193ac3cd1bf3d014373449f0b8d35d6d]
stable/6.6: [0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd]
stable/7.0: [2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694]
CVE-2026-53199: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53199
Introduced by commit c25aaf8 ("hyperv: Enable sendbuf mechanism on the
send path") in v3.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [004e9ecfe6c5384f9e0b2f6f6389d42ec22789af]
stable/5.10: [16514afeb7d3d121072ba9a0b640d6c1c5507db0]
stable/5.15: [a82d4251918f37d9c5aab7b365157669fb885ec3]
stable/6.1: [695c59cf7bf707e6ff8cea01916ee50e86616933]
stable/6.12: [918c0c988239aa5ab96b254e504d191af6191061]
stable/6.18: [0b38870d81ab3a04c1ab0598d9d3285f5d9d0584]
stable/6.6: [09b8a7aa5a341bb345dc492aac139525efa13515]
stable/7.0: [fe7221b4346418d27ec2daccfc09df6692b76f0b]
CVE-2026-53200: KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53200
Introduced by commit d93febe ("KVM: arm64: nv: Forward FEAT_XNX
permissions to the shadow stage-2") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [49b32ddb87a3a109afecea89e55d70f73956b8bc]
stable/7.0: [b95976c2ea446044553a5f469c0bae13553d75ab]
CVE-2026-53201: Revert "drm/xe: Skip exec queue schedule toggle if
queue is idle during suspend"
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53201
Introduced by commit 8533051 ("drm/xe: Skip exec queue schedule toggle
if queue is idle during suspend") in v7.0-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fa7c84726dc217ce0c183926ef9411636c7a2213]
stable/7.0: [b69b715f48ac7e802c89ed5924795c5b055da91e]
CVE-2026-53202: accel/ivpu: Fix signed integer truncation in IPC receive
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53202
Introduced by commit 3b434a3 ("accel/ivpu: Use threaded IRQ to handle
JOB done messages") in v6.8-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d9faef564438d1e4579c692c046603e7ada7bdf4]
stable/6.12: [4788556d4dd9d717037e385de178974e9649231d]
stable/6.18: [45cb105b8642c65e9be286f7058e92314efe7ea3]
stable/7.0: [2821bf2b79e47f87e1dbdd9d25c78240965a97d6]
CVE-2026-53203: accel/ivpu: Add buffer overflow check in MS get_info_ioctl
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53203
Introduced by commit cdfad4d ("accel/ivpu: Add NPU profiling support")
in v6.11-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fb176425837693f50c5c9fc8db6fbb04af22bd0a]
stable/6.12: [d3c12ed33e8923f3090909a1738f3e59292996a6]
stable/6.18: [fa598556ecef412edcb391f144b7642e18fdfd45]
stable/7.0: [4e5047cc94bea1cc7b670b7f503358e9af0542df]
CVE-2026-53204: firmware: stratix10-rsu: Fix NULL deref on
rsu_send_msg() timeout in probe
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53204
Introduced by commit 1584753 ("firmware: stratix10-rsu: Migrate RSU
driver to use stratix10 asynchronous framework.") in v6.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bfd2eb9bba548a8f63c3339bb1fb9a2031a42d86]
stable/7.0: [6bc249d324241c64118a3018124798c28e2950f7]
CVE-2026-53205: accel/ivpu: Add bounds checks for firmware log indices
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53205
Introduced by commit 1fc1251 ("accel/ivpu: Refactor functions in
ivpu_fw_log.c") in v6.13-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [dd1311bcf0e62f0c515115f46a3813370f4a4bb1]
stable/6.12: [5961c703414048f46818be8bbb11075a9a63fb4e]
stable/6.18: [8ec70c0dbdf04392a26e03e38798a373934177be]
stable/7.0: [535da9ad8420c3b686a642403d4147ff220255fd]
CVE-2026-53206: accel/ivpu: Add bounds check for firmware runtime memory
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53206
Introduced by commit 2007e21 ("accel/ivpu: Split FW runtime and global
memory buffers") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1d0b597facdd3c0239c88e8797c1014e1ea0ef15]
stable/7.0: [f8ab60ae9309e76d9a09c601c10cc222e25b3d5b]
CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in
get_huge_page_for_hwpoison
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53207
Introduced by commit 405ce05 ("mm/hwpoison: fix race between hugetlb
free/demotion and memory_failure_hugetlb()") in v5.18-rc4.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
stable/5.15
Fixed status
mainline: [3c2d42b8ee345b17a4ba56b0f6492d1ff4c1178e]
stable/6.1: [fc3ff42cb0cbf947e4600ae9761c3783760050e2]
stable/6.12: [a33bfed648c10f5a1519981dbfad80841191edc8]
stable/6.18: [dd77a83915b07e2b0205adb284f08b39ae31dc4b]
stable/6.6: [77b73b54801ae7137479c141fd0473a491c1dc48]
stable/7.0: [bf7ba8f96c258c30393814491930ae4ecdc5fe5e]
CVE-2026-53208: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53208
According to the .vulnerable file, this bug was introduced by commit
1da177e in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dd214733544427587a95f66dbf3adff072568990]
stable/5.10: [e05c4ac575b457978a7ef441053394169084869c]
stable/5.15: [fa5823126239b3e453fac1a2fe50726c7f4a55e1]
stable/6.1: [b20e8a98dd29b121f58fcdf51e8576119aba536a]
stable/6.12: [a8335f3db15bd1e0e82e0db5d488fabc7d10d1ab]
stable/6.18: [dedc92b96dc1d8919a3bdf2495ede68922ef7ebc]
stable/6.6: [214a2042b16b3c8d798a8b9ef9f36094f13a9859]
stable/7.0: [e2b8acf9405bd9b1baf1c54dc897b0905db689bf]
CVE-2026-53209: Bluetooth: hci_sync: reject oversized Broadcast
Announcement prepend
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53209
Introduced by commit 5725bc6 ("Bluetooth: hci_sync: Fix broadcast/PA
when using an existing instance") in v6.16-rc2.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [5c65b96b549ea2dcfde497436bf9e048deb87758]
stable/6.1: [10b0e832cc05d7aef4b92bed912cbd4a395d0862]
stable/6.12: [02f50e8bb69f9b22516163a09922f5537d3b12d1]
stable/6.18: [dafc9f57140e66a10945127aa7433c3d715dc253]
stable/6.6: [1338ee049a8910ba6c9cee963920e978e6893c7d]
stable/7.0: [cdd8bbdbee763fdf5bf343e6f7d4e79347739f62]
CVE-2026-53210: tee: shm: fix shm leak in register_shm_helper()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53210
Introduced by commit 7bdee41 ("tee: Use iov_iter to better support
shared buffer registration") in v6.8-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [26682f5efc276e3ad96d102019472bfbf03833b2]
stable/6.12: [4277759906b44d923a38c8f59f5576501b187b0d]
stable/6.18: [c10c9c48b2903f41ed4c532043b0576e86228236]
stable/7.0: [dbf779db927414f5b37c1f666013e9b48a88cfde]
CVE-2026-53211: netfilter: nft_meta_bridge: fix stale stack leak via
IIFHWADDR register
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53211
Introduced by commit cbd2257 ("netfilter: nft_meta_bridge: introduce
NFT_META_BRI_IIFHWADDR support") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c7d573551f9286100a055ef696cde6af54549677]
stable/6.18: [07acb9798477535933bd658ac9fa85b6cb10d995]
stable/7.0: [f1e81d571e375d10e50e852223593493d98c1bac]
CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53212
Introduced by commit af308b9 ("netfilter: nf_tables: add tunnel
support") in v4.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c32b26aaa2f9216520a38b3f4bfeec846eb3eb8a]
stable/5.10: [349df61526d2e39decc685d246202e3e284cfe05]
stable/5.15: [55b79b1ae42372012413ce0413181d26679b17ef]
stable/6.1: [5e9ee18b27fde88cb6148202b33916c66693fe82]
stable/6.12: [fda6573a46ad24f35348e024905ee5bdf729797e]
stable/6.18: [941d7394efda5e054e2d6f3e0dd0f6a9ba19aaa3]
stable/6.6: [8767fe4079affa74314d7eb3220e700150289842]
stable/7.0: [f9a0e4b61054cde89a2a77845293c726cc07cc43]
CVE-2026-53213: drm/vc4: fix krealloc() memory leak
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53213
Introduced by commit 6d45c81 ("drm/vc4: Add support for branching in
shader validation.") in v4.8-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5d563a5da8717629ae72f9eadf1e0e340bd1658b]
stable/5.15: [30165a09f76eaf34951c818eb5d9d6e4771d76f6]
stable/6.1: [fd87d6966041e33ef7d2e5dc59f9a52b71c6ae5f]
stable/6.12: [c034aa0b1ba5f49cbdf8ef193d6ec714d74aac27]
stable/6.18: [02f5e4db57c0cdd7bac89d503b301a093a0fa95c]
stable/6.6: [e0ce103e89d61eef70edc1d1ae3bfd4c0aacbc2e]
stable/7.0: [4fc692dc6df5bc777cc1bcebf95179e28594875f]
CVE-2026-53214: ipv6: Fix a potential NPD in cleanup_prefix_route()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53214
Introduced by commit 5eb902b ("net/ipv6: Remove expired routes with a
separated list of routes.") in v6.9-rc1.
Fixed in v7.1.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [b70c687b7cf267fb08586667a3946c8851cad672]
stable/6.12: [192df376a05c2db15564640f9da7e20907c1fa24]
stable/6.18: [07d9a0870a178843cea44cfd58c27445dc94cf5f]
stable/6.6: [5f82b02b4059ddc06e4fcfd057bfb59fd6885cd2]
stable/7.0: [653a2849305708f75260b5296f17b2a759ff9cc7]
CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53215
Introduced by commit 07dd0a7 ("mvpp2: add basic XDP support") in v5.9-rc1.
Introduced by commit d652692 ("net: mvpp2: fix memory leak in
mvpp2_rx") in v5.9-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5e8e2a9624df72fca7c736b2966b2cbf6c9c3ff6]
stable/5.15: [a88b3293b556f4d8fba11db9a8061a6b0d3b69e6]
stable/6.1: [a03cdcedb2cbcc42551dc3e4746929e93c5352d5]
stable/6.12: [d0c8c4fbd22d260fe28530260656c5fb3c20ce84]
stable/6.18: [8a2126c5afe89f8ceeb60a3afb9f075b736194cd]
stable/6.6: [580f92f27cb8724bcc4be98ee89890eab524a2ae]
stable/7.0: [02e1b5c4d3b4c658b72c145427cded1bba613fc1]
CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53216
Introduced by commit 07dd0a7 ("mvpp2: add basic XDP support") in v5.9-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f3c6aa078927e6fe8121c9c591ddee8716c5305a]
stable/5.15: [a3ee9231ccec6ec3be2de89c56f897055fd9eab1]
stable/6.1: [ec8e1e5842bc0dbd4c272761f4db3651eecd0339]
stable/6.12: [994bd2b58d2bd08aa97ec0836cc813cfcb00d749]
stable/6.18: [910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e]
stable/6.6: [3b8b0c3631b19faee53f0d15a49924129b063eec]
stable/7.0: [9545cc5ef18ca22d031f2f47c157192460652359]
CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53217
Introduced by commit e192116 ("mvpp2: sync only the received frame")
in v5.5-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [180235600934bef6add3be637c296d6cf3272e67]
stable/5.10: [60412bdd1b2576659eac23a23d2d9ff96228a643]
stable/5.15: [19f8bc139e9b149d1e5bf75ae761d1bb8dd3e7d8]
stable/6.1: [a3ad9b5767c89531fc7dae951b51b0933dcf7051]
stable/6.12: [23548007b3c66d628fc7d6b80d1e23be04ea10d9]
stable/6.18: [a13199fa224e9f776f4005d5037df03aa9ea8f37]
stable/6.6: [bede0f481b9137d73d1cf64309cbe4b94818a5d6]
stable/7.0: [e302206ad84a407a7e5f3f6fe767ff5efaace689]
CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53218
Introduced by commit c078ca3 ("netfilter: nft_exthdr: Add support for
existence check") in v4.11-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [772cecf198da732faebb5dcfc46d66a505be8495]
stable/5.10: [8738b1b6d0e639ca1fc0f61516afd3557ac4ecc6]
stable/5.15: [19748967d59c31d24d21d40b728570788310b237]
stable/6.1: [46fc15a044e9938e7ea77786fb37edd2cd74f031]
stable/6.12: [67b27434c43b68a97becda98c9f0c8cf6cba2134]
stable/6.18: [78069a6d8bc86c9e036eb82c2af4a19cc1871a53]
stable/6.6: [cd513e43b4b2bd1de39e2367bc4261c699a8652f]
stable/7.0: [f08fb3d42fd3aad0b7a263da3ac3ebaf0845e265]
CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53219
Introduced by commit 71ae0df ("netfilter: xtables: use percpu rule
counters") in v4.2-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f7f2fbb0e893a0238dc464f8d8c0f5609bec584f]
stable/5.10: [b74ba3343eb44b2cbf7e9665918c287df1d52ebb]
stable/5.15: [0b35dc8527ccc16b7dc34e8a3164313e68cd4e45]
stable/6.1: [b28e2fcad3db7e8687b15bc20bced26b5b7c920e]
stable/6.12: [8d67e42ad3b1a95a152541015a07110e06992d6c]
stable/6.18: [08a3e218064db11f154ad9ad5541751ea7f34ebe]
stable/6.6: [a0d16941adf3a501956d74aefd8d6e217906e79c]
stable/7.0: [fb0521aff1e10e300d89725cc439d3ea74c828c5]
CVE-2026-53220: netfilter: revalidate bridge ports
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53220
Introduced by commit f350a0a ("bridge: use rx_handler_data pointer to
store net_bridge_port pointer") in v2.6.36-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ccb9fd4b87538ccf19ccff78ee26700526d94867]
stable/6.12: [43330a1e8aace6b5a8de9aba127e9e394ab49b0f]
stable/6.18: [4beffcd726e2a731cea4dc18e1fbc55c8d76f1a0]
stable/7.0: [d4b1301fd3c9e5e105fd3767c68bc4ba558bb228]
CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53221
Introduced by commit fbe68ee ("vti6: Add a lookup method for tunnels
with wildcard endpoints.") in v3.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a5c0359f5cbc51a2e2b114d6041e0f3c73f903e9]
stable/5.10: [c327fa4fca31415431202e063767a7ae342e19c6]
stable/5.15: [fc657ac0767c49839b3ef0b08dc0953ca30883f8]
stable/6.1: [47fb3c2b4203556308e64354b3e78f2ce221d646]
stable/6.12: [90fd4513315ca07da99cfd8549d3e553a7160f0d]
stable/6.18: [2abfb19bbb81958714ad1d43ebeb65b30394184b]
stable/6.6: [f513f308cc4bdb4530d033431592ffbc29b7fca1]
stable/7.0: [2fc7bc087cc7085368263d9d37bfe9a0bddd6a2d]
CVE-2026-53222: ptp: ocp: fix resource freeing order
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53222
Introduced by commit a60fc32 ("ptp: rework ptp_clock_unregister() to
disable events") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [627366c51145a07f675b1800fb5ea2ec960bd900]
stable/7.0: [aa03698bb28d3be5ee180adb185395054b342b04]
CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53223
Introduced by commit 8605330 ("tcp: fix SCM_TIMESTAMPING_OPT_STATS for
normal skbs") in v4.11-rc4.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1ee90b77b727df903033db873c75caac5c27ec98]
stable/5.10: [24a0d548d3a765cd4558224e4f8e06e14cba26e3]
stable/5.15: [71ff5cdd5da61d0438e902aa0fd68c28bc901abe]
stable/6.1: [ad9a0374ee6d11048e1f74cd5180bad58b9848b4]
stable/6.12: [e0665b2a8e90bb08bd205062c75662b502d31797]
stable/6.18: [3dde4fb941fa5649ab809f6cd3e20e0c424a4e31]
stable/6.6: [b903e9b5629ec8dd6db92174070045bf81ad7060]
stable/7.0: [eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a]
CVE-2026-53224: sctp: validate embedded INIT chunk and address list
lengths in cookie
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53224
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6f4c80a2a7e6d06753b89a578b710a2499a5e62b]
stable/6.18: [7560afb8cddafd829e709d7ea09230e45a825557]
stable/7.0: [512a9bb77c04ac9927648ea58af617e472be96e6]
CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53225
Introduced by commit df21857 ("[SCTP]: Update association lookup to
look at ASCONF chunks as well") in v2.6.25-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f8373d7090b745728de66308deeecc67e8d319ce]
stable/5.10: [446e0ecd845abc394b24ae2030a883572bec9d16]
stable/5.15: [928dd94db23e8ba340f83d68f7f24d831b7a4426]
stable/6.1: [d796cfd06074b579d265b28401306cadd30db945]
stable/6.12: [d6bd0bb7697ea8c0387b0d9d973453f479017b23]
stable/6.18: [f76a8b323e28e0951f979dbef20a7496383c47df]
stable/6.6: [8ce96f1182644079249a24ac7e2ffc32e0301a46]
stable/7.0: [8e86817b8af4d552f3c6fe04ca52bb0c8c57411d]
CVE-2026-53226: gpio: rockchip: fix generic IRQ chip leak on remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53226
Introduced by commit 936ee26 ("gpio/rockchip: add driver for rockchip
gpio") in v5.15-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1c1e0fc88d6ef65bf15d517853251f75ab9d18c3]
stable/6.18: [bace7b99bfa555fe833aee8827b8004c43666d02]
stable/7.0: [1f34ea5f6114011092d9a5c8b901ad6741144a1d]
CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53227
Introduced by commit 893f139 ("openvswitch: Minimize
ovs_flow_cmd_new|set critical sections.") in v3.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ee30dd2909d8b98619f4341c70ec8dc8e155ab02]
stable/5.10: [e248fb2e680deb2bd37bac551b72638fe4938a76]
stable/5.15: [0bb5b2dc1b90aa7dd1473fc8c4d813a29255ff8d]
stable/6.1: [971b1b37774f13acc5add0a2843f8598446b8598]
stable/6.12: [e3d509a1b71396e1452060dbf84a805fd1c3c549]
stable/6.18: [ecc55aad3390129a87106841f4b68bf3d70c9264]
stable/6.6: [25fdf53698535fe8790237f5a8a9626791429785]
stable/7.0: [895d1dd9057cde1687fa0f4286d47ceed0b82997]
CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53228
Introduced by commit 1490966 ("sit: Setup and TX path for sit/UDP
foo-over-udp encapsulation") in v3.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f0e42f0c4337b1f220de1ddd63f47197c7dee4de]
stable/5.10: [fddd41445a0537b093e6b3f6232c9933cad1e48b]
stable/5.15: [1132e5edc2866c3530be17622153a597095f0e43]
stable/6.1: [9c67b44edb3598d234efae6e44649eb993c03da5]
stable/6.12: [59f80c919713250fe5d25a4d9aea4e49580fa1d4]
stable/6.18: [2fa49b2715e1bad12ce3b0fa64e234d9582c8193]
stable/6.6: [0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0]
stable/7.0: [cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c]
CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX
xmit failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53229
Introduced by commit 84a0a23 ("net/mlx5e: XDP_TX from UMEM support")
in v5.3-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b69004f5a6ad32da84d8aa5b23b9c0caafe6252e]
stable/6.12: [7b3eeba50fbc3b45f279037c29a87a90e8bac1e1]
stable/6.18: [2789b74ae1f4b68333c9d5eec2f3354d07b16e61]
stable/7.0: [0aabca726b43d833721034e97d99efcc8237b22a]
CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in
mlx5_query_nic_vport_mac_list
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53230
Introduced by commit e16aea2 ("net/mlx5: Introduce access functions to
modify/query vport mac lists") in v4.5-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [894e036a24a26a6dd7b17d8d3fb5c53ab48a6074]
stable/6.12: [537d87784e81c3d7037525b99416455cee088cdc]
stable/6.18: [0f807764bb122fd63aa45f4229cb1ef2679fbd40]
stable/6.6: [41781f2789309462520a93822e946521ed78f97f]
stable/7.0: [2398e497389ed4be43f7cfbab499b49cec7dae1a]
CVE-2026-53231: net: phy: don't try to setup PHY-driven SFP cages when
using genphy
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53231
Introduced by commit bad869b ("net: phy: Only rely on phy_port for
PHY-driven SFP") in v7.0-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5a0082ec20a05ef2378410323a5089a8f1786f4a]
stable/7.0: [ef8d739eee6f85303cbecebc01eb72f063de74e0]
CVE-2026-53232: net: phy: clean the sfp upstream if phy probing fails
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53232
Introduced by commit 298e54f ("net: phy: add core phylib sfp support")
in v5.5-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [48774e87bbaa0056819d4b52301e4692e50e3252]
stable/6.12: [9326b654f90a09eadeb796c82801a5609d57f0c8]
stable/6.18: [3a254779c169954fe23328a1db51f67be374f913]
stable/6.6: [12fb84dc4dc8eb47ebe2b27f7de6255a4a205e1b]
stable/7.0: [0b27701ce93161d7bbf4b25fa20ca59963b0e20c]
CVE-2026-53233: netdev: fix double-free in netdev_nl_bind_rx_doit()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53233
Introduced by commit 170aafe ("netdev: support binding dma-buf to
netdevice") in v6.12-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c849de7d8757a7af801fc4a4058f71d481d367f2]
stable/6.12: [e055ca9205d3eb6aec3e5fe4ecc18abbbf18c599]
stable/6.18: [c299321bc6232770ce378d6fa6bc46004d2d7fdb]
stable/7.0: [9b019376cbee10c4f9184d1745fa37d156e36f30]
CVE-2026-53234: net: ibm: emac: Fix use-after-free during device removal
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53234
Introduced by commit a4dd853 ("net: ibm: emac: use devm for
register_netdev") in v6.12-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a0130d682222ae21afc395aead7cd2d87e1a8358]
stable/6.12: [cf8e14db93eaecc4c0c58299be3b3183b0e53ed5]
stable/6.18: [c09c2e236eef6f59e105f38a30f5439e6ccbcad7]
stable/7.0: [c12584cd6078085d707266be864e7e1cc91d74e3]
CVE-2026-53235: net: add pskb_may_pull() to skb_gro_receive_list()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53235
Introduced by commit 8d95dc4 ("net: add code for TCP fraglist GRO") in
v6.10-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f2bb3434544454099a5b6dec213567267b05d79d]
stable/6.12: [9e636c995b7beeb74ea882968248752821c244c4]
stable/6.18: [0cde3a004119db637b401c54e77536e4145fc0b4]
stable/7.0: [848571dcbbbea7ba44dd4f7ebe1fbb274afe08ac]
CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53236
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5d39580f68e6ddeedd15e587282207489dfb3da2]
stable/6.1: [3747de241a66ef2c7032d2cc2b826a47c5fa0f6a]
stable/6.12: [82b3e7ce10c53fc12aab8904745603efc74f8c07]
stable/6.18: [ede69b8f6670600e534591664584f810d7c385f9]
stable/6.6: [ecfe9171b26ae3eed0cd8bab7a943e9e2c9e51ba]
stable/7.0: [c68517a3e18e20997808821c5559d0cba4d776c1]
CVE-2026-53237: gpio: mvebu: fix NULL pointer dereference in suspend/resume
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53237
Introduced by commit 757642f ("gpio: mvebu: Add limited PWM support")
in v4.12-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b9ad50d7505ebd48282ec3630258dc820fc85c81]
stable/6.12: [4ef24338eda3c7e96d6f94a988266ff16ed3985d]
stable/6.18: [6136c1474db88272231573e222896e1998d34662]
stable/6.6: [7db09011ce62162d72897fc4856b4425245dfe35]
stable/7.0: [c9677a9274ffb44987ec209dc8ec9f2d34946956]
CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53238
Introduced by commit 8cc4457 ("NetLabel: Introduce static network
labels for unlabeled connections") in v2.6.25-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9772589b57e44aedc240211c5c3f7a684a034d3a]
stable/5.10: [975a84fd741440853380d37465b6e226cf47254c]
stable/5.15: [672f0f3b8f875ffe6525a37847eafa7648c4c0c6]
stable/6.1: [95bda3eac0b1454c2cee98d58d9ba6dd8391e843]
stable/6.12: [71c52da13c3737493b42d20d9f33de34e03b3156]
stable/6.18: [0c4bb32ad7fdc2dc6a8050f41eb04d4bda56b6c8]
stable/6.6: [07a18f5c90dd3d586b73242f5a5bbf0a72f2fdc6]
stable/7.0: [ccfe292a966079c61ea68a2da303b2a336170993]
CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in
xfrm_policy_bysel_ctx()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53239
Introduced by commit 6be3b0d ("xfrm: policy: add inexact policy search
tree infrastructure") in v5.0-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7f2d76c9c03257c0782afef9d95321fa04096f60]
stable/5.10: [8fc536e9f6856230f19c7d13e71af064b6a77b22]
stable/5.15: [c4c1ea36d83bf3c4569468ca5b8b614fda1bf821]
stable/6.1: [25c8c7fb3b0b9668c7d05e209f58c158d2b020c7]
stable/6.12: [88697cf980222d5906a37bf47662dac0732e2a0f]
stable/6.18: [b5316e2b8614a87d8736941972441cb47bfd4491]
stable/6.6: [42827d03f8009a6a218bacab153e21f39d6a121c]
stable/7.0: [ec82ea4eb220164d854f8734ca5a35e23e577b94]
CVE-2026-53240: xfrm: iptfs: fix use-after-free on first_skb in
__input_process_payload
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53240
Introduced by commit 3f33398 ("xfrm: iptfs: add reusing received skb
for the tunnel egress packet") in v6.14-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [eb48730bb827d1550401a5d391903f9d90b493c8]
stable/6.18: [8d9a79fbf5172d9c4c0146057af2360913265a11]
stable/7.0: [ff2ee35b6ce5fa8a8e24ea50b15733d5c8780198]
CVE-2026-53241: ALSA: seq: dummy: fix UMP event stack overread
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53241
Introduced by commit 32cb23a ("ALSA: seq: dummy: Allow UMP
conversion") in v6.10-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2b5ff4db5d7aa5b981d966df02e687f79ad7b311]
stable/6.12: [a7ef78a2c536242ccb7a4429da01580b2409bb24]
stable/6.18: [6671a46144f880c5a167930ebb14c12f3d059fe9]
stable/7.0: [6676b6063440561db600494049ce7ffb695c8cc4]
CVE-2026-53242: ALSA: PCM: Fix wait queue list corruption in
snd_pcm_drain() on linked streams
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53242
Introduced by commit 9b1dbd6 ("ALSA: pcm: fix use-after-free on linked
stream runtime in snd_pcm_drain") in v7.0-rc4.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [88fe2e3658726cb21ff2dcf9770bf672f9b9d31b]
stable/5.10: [cac5bf3500ee6422cf64e0df0b5daeecfed42917]
stable/6.1: [d842f26a167e77a36f3ed333b9fa99d36ef99fe6]
stable/6.12: [b053fcd8912f06c30f932f5b8ec41c72de474695]
stable/6.18: [cd98837db15f323463b8df07282ac723bd5c3fed]
stable/6.6: [d68b621bb5a48051932f1017a6e1bc9b18f854d0]
stable/7.0: [7c71a9522555ff137a9ca36b15d759ca04d84788]
CVE-2026-53243: rseq: Fix using an uninitialized stack variable in
rseq_exit_user_update()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53243
Introduced by commit 82f5724 ("rseq: Implement read only ABI
enforcement for optimized RSEQ V2 mode") in v7.1-rc3.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
stable/7.0
Fixed status
mainline: [6d99479799c69c3cb588fcda19c81d8f61d64ecd]
stable/7.0: [e12d20a63b61aaf9de4772effccf42cc9a003e58]
CVE-2026-53244: VFS: fix possible failure to unlock in nfsd4_create_file()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53244
Introduced by commit 64a989d ("VFS/knfsd: Teach dentry_create() to use
atomic_open()") in v7.0-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e824bbd4d224cce4b5fb59cc9dcd3447fe0b7e44]
stable/7.0: [ee1f40759a50b1800c98c1c369afd5b3e44ad987]
CVE-2026-53245: net/802/mrp: fix vector attribute parsing in
mrp_pdu_parse_vecattr
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53245
Introduced by commit febf018 ("net/802: Implement Multiple
Registration Protocol (MRP)") in v3.9-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7561c7fbc694308da73300f036719e63e42bf0b4]
stable/5.10: [ae65714d96f68bb252eb20085320bdaacab36c00]
stable/5.15: [36d259711872e3b2f6cd76a4d270c21931c0f35f]
stable/6.1: [cc98717e591a963a616fdf15ecf48eefaf45d758]
stable/6.12: [fd9c3a47c670bec6b18f44454cea023f93b5adb3]
stable/6.18: [42446ca0f3570663e87183c065e0b4def52dfba2]
stable/6.6: [6d6e42e8e17f18d61327f8653479c5b5e161ae1d]
stable/7.0: [6eea6494e542a03cdf755a593b7d74f3f7c260fd]
CVE-2026-53246: sctp: validate cached peer INIT chunk length in
COOKIE_ECHO processing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53246
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0861615c28de668669d748ef4eb913ea9262d13b]
stable/6.18: [cc272185c9a9a4b7febc2de52eeaa3d00f19091e]
stable/7.0: [edccbf3d63b0a3362bc916ea72edacc1e1ca456a]
CVE-2026-53247: net: ethernet: mtk_eth_soc: Fix use-after-free in
metadata dst teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53247
Introduced by commit 2d7605a ("net: ethernet: mtk_eth_soc: enable
hardware DSA untagging") in v6.2-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [80df409e1a483676826a6c66e693dba6ac507751]
stable/6.12: [459c6f35c58cf0fd5247e55d73ddaa29571d9b7e]
stable/6.18: [e634408d2b0cd939cfe019398a21fb47b7a8ffe3]
stable/6.6: [72775977e89c25c99ee84d2c5baa3f86a8ba5cb4]
stable/7.0: [2d86aeb46d5f69c704065a8c69822582787272a1]
CVE-2026-53248: net: airoha: Fix use-after-free in metadata dst teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53248
Introduced by commit af3cf75 ("net: airoha: Move DSA tag in DMA
descriptor") in v6.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b38cae85d1c45ff189d7ecb6ac36f41cdc3d84d0]
stable/6.18: [6f829e2c17a53a35321268339cd252aff6d6d723]
stable/7.0: [4b5a574e033e66d2131eff1c18feef8d8643c67e]
CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53249
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d3915a1f5a4bc0ac911032903c3c6ab8df9fcc7c]
stable/5.10: [4cd6e9ed49347d3a2fdaaf07e32fb524756dddc2]
stable/5.15: [2a87c3e8f03ce655ed0ef500d64d5fd924ec3691]
stable/6.1: [89343ff12b3178fc236fe531a3603e7c97c68278]
stable/6.12: [00e8845fe3428c69e980dce5071cb3da1d8f7578]
stable/6.18: [a4f3fd6516920988c47ba8d19714985c40c816a1]
stable/6.6: [8ff85dbabbbfb05e86e6cde31d91ac5782179d4d]
stable/7.0: [28f5ad1b4055405eb1616e603fe511ba5e3725e7]
CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in
xsk_skb_metadata()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53250
Introduced by commit 48eb03d ("xsk: Add TX timestamp and TX checksum
offload support") in v6.8-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [22ba97ea9cc1f63a0d0244fae38057ed452b6ac7]
stable/6.18: [0dfe05b938435892875e07771170051346412df9]
stable/7.0: [bfdfd2706d5fb2cd496a1506e680daf979309c8b]
CVE-2026-53251: Bluetooth: ISO: Fix not releasing hdev reference on
iso_conn_big_sync
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53251
Introduced by commit 07a9342 ("Bluetooth: ISO: Send BIG Create Sync
via hci_sync") in v6.13-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [5cbf290b79351971f20c7a533247e8d58a3f970c]
stable/6.12: [4bbec25f47b930101294fd310c627c3f53e9661f]
stable/6.18: [33d677d2e3713d98012c3dbd4a9207f7d785b854]
stable/7.0: [23e8eb16820b866528fb300dc67fe3f67f00ef62]
CVE-2026-53252: Bluetooth: fix memory leak in error path of hci_alloc_dev()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53252
Introduced by commit 1d61231 ("Bluetooth: hci_core: Fix use-after-free
in vhci_flush()") in v6.16-rc4.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/5.10 stable/5.15 stable/6.1
stable/6.12 stable/6.6
Fixed status
mainline: [37b3009bf5976e8ab77c8b9a9bc3bbd7ff49e37f]
stable/5.15: [5b7dfca6f852e6b9d809fd0263b5427cc9fb33fd]
stable/6.1: [c016118b9e51eeaf5bc93850d4c455a3b583c0aa]
stable/6.12: [bc2efe73c194a74839d7cf57b63880d97e21d309]
stable/6.18: [ce4b4cac3c5749b6aa75e62e2991ae2263f2f889]
stable/6.6: [0622e527a31d4b44737fed5c1a2ac1fc2cfb5184]
stable/7.0: [f82799407a50af7bcacacf09cc9b279af8fe9b81]
CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53253
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6770d3a8acdf9151769180cc3710346c4cfbe6f0]
stable/5.15: [0ef2ea86c82b2615902d085cd5a586fe9f58994f]
stable/6.1: [2b83afb19293e4de700edae306115f18966dc4f9]
stable/6.12: [d76dec1a37122bc16d83d059c08c0512ea8de909]
stable/6.18: [c893e17d2809ec9c4b3f1cdd5847cecbc27a311b]
stable/6.6: [691f14b6a48b637655755134f1e551c7c6fedc2e]
stable/7.0: [be837cd09897e9e6e1958174501d467bdcbcc2bc]
CVE-2026-53254: Bluetooth: RFCOMM: validate skb length in MCC handlers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53254
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [23882b828c3c8c51d0c946446a396b10abb3b16b]
stable/5.15: [7c15c7c2878957cbfed93bcc29c13fdace464254]
stable/6.1: [0d637136ce89f9a2309b2c3502402ce400dab0ef]
stable/6.12: [1b070ac9e99c2c2c3a8112943ca98ab6fca7f10c]
stable/6.18: [3eabc6d47a0ad22b053329997aaf0ec1e581e392]
stable/6.6: [98377e6b1a1a56561ec66a181573ea2b61b2079e]
stable/7.0: [08b9c1fbe78f4ad3f6250c6541cfaabdbeb81997]
CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53255
Introduced by commit 2bb3687 ("Bluetooth: Unify advertising instance
flags check") in v4.9-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [de23fb62259aa01d294f77238ae3b835eb674413]
stable/5.10: [13ad995071a06570668dd8daab3616c247c72080]
stable/5.15: [06fcbd79c3c360a50f9be9d370769bbd738d0976]
stable/6.1: [f7093ac233c1e7f51d125534f46067772a113175]
stable/6.12: [18fea1cb0c2599752e908c8217490f73ddd33e00]
stable/6.18: [1a3c8ffbb469859b076445af44bdfa6a711d483e]
stable/6.6: [74c08e4db35a476c3462aeb65846f955be732626]
stable/7.0: [2a3f3ed9e198ae23c15859ace2f9ca6cfdc35b57]
CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53256
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [43c441edacf953b39517a44f5e5e10a93618b226]
stable/5.10: [f5ec76bdbeb80f75ad0be204371afffee0f8fac8]
stable/5.15: [a07d741c077d4e34b16458241a94d29039386553]
stable/6.1: [1f73f92f66251065a5f39b09a47cf05ea14d3107]
stable/6.12: [b0e33e409715c617e2a20f46f99aa5403a14dfda]
stable/6.18: [8802413ce63175fb522a2bd609fb043a3550c720]
stable/6.6: [de31973ef00e5aa55496f84cf6a44bb157a34e02]
stable/7.0: [6f4462d12133106460d7c046b95aad2491e3fddf]
CVE-2026-53257: wifi: cfg80211: enforce HE/EHT cap/oper consistency
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53257
Introduced by commit 22c64f3 ("wifi: mac80211: Update MCS15 support in
link_conf") in v6.16-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cb9959ab5f99611d27a06586add84811fe8102dc]
stable/7.0: [0f5e9ddd7e8e7758771a63cdd498a2007dc8da7a]
CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53258
Introduced by commit c8cb5b8 ("nl80211/cfg80211: support 6 GHz
scanning") in v5.10-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e8694f7cc29287e843648d1075177b9a2000d957]
stable/6.18: [fb8db813eba2e56ee001c9fb5c2ce2cb78c42642]
stable/7.0: [a24134ddc18b4d440714365637d440b7121447b9]
CVE-2026-53259: ipv6: anycast: insert aca into global hash under idev->lock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53259
Introduced by commit eb1ac9f ("ipv6: anycast: Don't hold RTNL for
IPV6_JOIN_ANYCAST.") in v6.17-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f723ccaff2fb72b71ae8a9fd283f0dee4d9ae7a3]
stable/6.18: [15be7e9fdbff831fb3e89b83cc337a4f85ad3310]
stable/7.0: [3a967c498baa976b11d4800dda224c507416e97c]
CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in
reqsk_queue_hash_req().
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53260
Introduced by commit d2d6422 ("x86: Allow to enable PREEMPT_RT.") in v6.12-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e10902df24488ca722303133acfc82490f7d59ad]
stable/7.0: [b183215ff714efb747d9d5a429322ba6404b5401]
CVE-2026-53261: devlink: Release nested relation on devlink free
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53261
Introduced by commit c137743 ("devlink: introduce object and nested
devlink relationship infra") in v6.7-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3522b21fd7e1863d0734537737bd59f1b90d0190]
stable/6.12: [a9137286884703113b1c9e6403bd6d7d97b14754]
stable/6.18: [927f96861f939c0b517d13ed27bf4fabbfc1cfb3]
stable/7.0: [11324d52b0c63f4f202b35793c6507a575e9a689]
CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53262
Introduced by commit fd558d1 ("l2tp: Split pppol2tp patch into
separate l2tp and ppp parts") in v2.6.35-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a213a8950414c684999dcf03edeea6c46ede172e]
stable/6.12: [78cdfdca88cbf731a92f3b9ee5427c633dd94e28]
stable/6.18: [e251d4cdfc725c9e7d686161e3b775a0e7d95053]
stable/7.0: [62f327e287cf7b595ae3f73ba72f5cd2a9e9f39f]
CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53263
Introduced by commit 5609c18 ("6lowpan: iphc: add support for stateful
compression") in v4.6-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2a58899d11009bffc7b4b32a571858f381121837]
stable/5.10: [f24a58c72a45f4c109f3557a760cc4b60b7a6037]
stable/5.15: [da8cbb64b47e9066b40af0de170901caf17b768c]
stable/6.1: [4485d79617520d84ba5a14515e2b5136007d6deb]
stable/6.12: [dcb1bec1c32ee5c3878354e087cf5dbee2b7c7af]
stable/6.18: [c32f30ef5e66adbfa102348e2e8a23776eb007cb]
stable/6.6: [06ce6fc106b16dec9b535950db626261be865e5b]
stable/7.0: [da8808463882c3f3c357b072e25053c2121f1419]
CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for
action lifecycle
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53264
Introduced by commit d7fb60b ("net_sched: get rid of tcfa_rcu") in v4.14-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5057e1aca011e51ef51498c940ef96f3d3e8a305]
stable/5.10: [98b2e40879abf0245be5a5b7af69e0f6ff524ac3]
stable/5.15: [18af5d2ef0c4f65787fd1280c8b23286b9f2a835]
stable/6.1: [1f1b98fea6b9ea30507d0f2fbff6750292d097e2]
stable/6.12: [5dd51e09020c65aa53cf128e5e3517cd53b3c113]
stable/6.18: [b60e9391142e983fab2be53497aa8f71fdd09cd5]
stable/6.6: [8b136f18ac4b2ace5aaad3305b3f8a5d8165a009]
stable/7.0: [91d105d2cbe002f9c7b43a6183adedc37e1da1f7]
CVE-2026-53265: dm cache policy smq: check allocation under invalidate lock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53265
Introduced by commit 2d1f7b6 ("dm cache policy smq: fix missing locks
in invalidating cache blocks") in v7.1-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-st cip/5.10 cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.18 stable/6.6 stable/7.0
Fixed status
mainline: [d3f0a606b9f278ece8a0df626ded9c4044071235]
stable/5.10: [c242c7af2aecf0b538b8623bdb86b8b441da38d9]
stable/5.15: [13da856c86fb8c2ccab95034fd77da1bb2c2a17c]
stable/6.1: [d886945fcb0f8c9dc6b39928d7a96c95c587346c]
stable/6.12: [03ffe1112ed88bb3a9bd0b971549bf4d64bfc59a]
stable/6.18: [42ff6774ecd9d7f70d599cb71ff64373a1da4948]
stable/6.6: [b4892561552d671bd8c4da5ebb70e9fbb1ec446e]
stable/7.0: [c57570fba24016ec25ec046ab44db39143fb7a64]
CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53266
Introduced by commit 63137bc ("netfilter: ebtables: Fixes dropping of
small packets in bridge nat") in v5.10-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [67ba971ae02514d85818fe0c32549ab4bfa3bf49]
stable/5.10: [bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87]
stable/5.15: [76280b78cc9f23bdc6438e10ad6dff148ef8375b]
stable/6.1: [b7e91939ba9be805a62a257fa4e227dffbb88fa0]
stable/6.12: [153ea96c806aea395daba907a4f88480b6ad5093]
stable/6.18: [b18675263db1147c8e1cab625400c13a0d87bd2d]
stable/6.6: [afd64b59c3de9bbbdd3759e834fdc55cda716e0b]
stable/7.0: [c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5]
CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53267
Introduced by commit 45d9bcd ("netfilter: nf_tables: validate len in
nft_validate_data_load()") in v4.1-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3027ecbdb5fdf9200251c21d4818e4c447ef78e1]
stable/6.12: [8470f676eadeab99132708acb1a85915664d6115]
stable/6.18: [f071b0bf078146368d18e4eec386bf2ddc0ab7e0]
stable/6.6: [af80f78ce984649e1698b841cd33f4fa505ad828]
stable/7.0: [2e154b5f53f1b0b490c7b8b02499f90feb86b1d5]
CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53268
Introduced by commit 869f37d ("[NETFILTER]: nf_conntrack/nf_nat: add
IRC helper port") in v2.6.20.16.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [66eba0ffce3b7e11449946b4cbbef8ea36112f56]
stable/5.10: [4cdda7f868f48e2f81579371584fdbdce37df2c8]
stable/5.15: [8a1d6e40dedfe1068aee094d851bd69e289c9fd6]
stable/6.1: [0afc802160af0df61ed374fdb97fb34cfe5cdf2f]
stable/6.12: [ddddd8271359961e403d11c90c9ba9fc38914f7e]
stable/6.18: [9e5da2379f968a3ea5a6e38921ab6201576466dc]
stable/6.6: [7c34f91305292083253df6a9f6c8ede02d4ccaea]
stable/7.0: [573810f61bcd6b6815e2ff53bbdd2b9c9d747176]
CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53269
Introduced by commit ad49d86 ("netfilter: nf_tables: Add synproxy
support") in v5.3-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2fcba19caaeb2a33017459d3430f057967bb91b6]
stable/5.10: [0ec9ddc1bda261a2c57636c74c8b4e53000102c9]
stable/5.15: [56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389]
stable/6.1: [debc57b83d5b323df74bf010c8d50fe26ad2ed6b]
stable/6.12: [640441348258220e78daed40528b85b8afcedab6]
stable/6.18: [aaf80701dc2f7a48fe543961e21f8ca3924d587c]
stable/6.6: [0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88]
stable/7.0: [fbf0591275f50eae5733c3d7a8cd6c1e79933ffa]
CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53270
Introduced by commit 05f0050 ("ipvs: fix crash if scheduler is
changed") in v4.2-rc5.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [193989cc6d80dd8e0460fb3992e69fa03bf0ff9b]
stable/5.10: [d10730a1f2caf08088e0db1b19b242f3e6fa5f06]
stable/5.15: [e4feec3174036ba772006be74beee0efa09a9eb8]
stable/6.1: [7d4f5004511757e3984901ffb412fcf858d80ed5]
stable/6.12: [14e4689c113b4c06af1069364ade24fdd7055f33]
stable/6.18: [25918720ba97f974a4f8d433b5a0132c5b43f6f3]
stable/6.6: [c6376b9b1b4d2bad638256b1b3588e073344ae69]
stable/7.0: [19a9493faa4bf3c7bd0a386f30b60b1bb4a3da03]
CVE-2026-53271: ksmbd: fix NULL-deref of opinfo->conn in oplock/lease
break notifiers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53271
Introduced by commit c8efcc7 ("ksmbd: add support for durable handles
v1/v2") in v6.9-rc1.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [b003086d76968298f22e7cf62239833b5a3a06b1]
stable/6.12: [1ff58dcfcab434ebb51649da33774fbb8e1f7b67]
stable/6.18: [e735dbd489e3ea02be78dba991056fe1138be51e]
stable/6.6: [945a86b21b40fb17183f5b27461baa6f03e2467f]
stable/7.0: [75e33deda658c1ab3a9336cbdb1436536f9b3660]
CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53272
Introduced by commit 40452ff ("erofs: add sysfs node to control sync
decompression strategy") in v5.17-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1aee05e814d292064bf5fa15733741040cdc48ba]
stable/6.12: [86ab00cf81d44b675bb23db62b88fd76c8ac8cea]
stable/6.18: [00bf6868df65fa95b3854996246d15759fdc7070]
stable/7.0: [95caf60da33d87ed26c28993620f0d92487b0296]
CVE-2026-53273: tee: optee: prevent use-after-free when the client
exits before the supplicant
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53273
Introduced by commit 70b0d6b ("tee: optee: Fix supplicant wait loop")
in v6.14-rc4.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt cip/6.12 stable/5.10 stable/5.15 stable/6.1 stable/6.12
stable/6.6
Fixed status
mainline: [387a926ee166814611acecb960207fe2f3c4fd3e]
stable/5.10: [416259cb5bffecaaae5f76539deb535a8c1b2c34]
stable/5.15: [724d0caffd4204b46f78efe22f18f8338031c6e1]
stable/6.1: [ae847ab29ded2d7cece4d5970f0edefa4137bf2f]
stable/6.12: [d366a01475f927402c96a3fe78bfc06b924fc87d]
stable/6.18: [d5b57bb314d79e99bebb58a53588fa11dd4dbf69]
stable/6.6: [9a0dc9279d0907b198f205a693aedf696b08145d]
stable/7.0: [373152c94e57e9592b68c100e224fbd943cfd608]
CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt()
causing local DoS
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53274
Introduced by commit a6a6fe2 ("net/smc: Dynamic control handshake
limitation by socket options") in v5.18-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a3fdd924d88c30b9f488636ce0e4696012cf5511]
stable/6.1: [35a22117839602bb52283de08894c5a7dde92420]
stable/6.12: [89f6fbe0033c942cb790ffd53ca93a45eeaf1c91]
stable/6.18: [dcd90f42a33e4220385f27b515183d0c91b2fc4a]
stable/6.6: [5d27d2ffe487df89ce28fda0410eafa05dbe03a0]
stable/7.0: [94d286fa5eedc550d42bcb9c85416af8f77736ff]
CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53275
Introduced by commit 97300b5 ("[MCAST] IPv6: Check packet size when
process Multicast") in v2.6.20.16.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [791c91dc7a9dfb2457d5e29b8216a6484b9c4b40]
stable/5.15: [1354271c89d0e5fbf8b3d94097ff0216695209c7]
stable/6.1: [53baa63a4183291574483f89583dbef13677a2c4]
stable/6.12: [b2eb8886200b907fc71806869620609f0f4cacb0]
stable/6.18: [4203806f700bb44ea0b05d484d9d40044b47fb04]
stable/6.6: [2a613bf497029d555a7428406aa8cdb84a503cea]
stable/7.0: [087dbacf897c020f438f780f0a4a8aa73b6d7c5a]
CVE-2026-53276: Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53276
Introduced by commit d341370 ("Bluetooth: ISO: Add support to bind to
trigger PAST") in v6.19-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f50331f2a1441ec49988832c3a95f2edacc47322]
stable/7.0: [d324b8aa20bd3c3394e3647dc22491d88f3f4e7a]
CVE-2026-53277: KVM: arm64: Take the SRCU lock for page table walks in
fault injection and AT emulation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53277
Introduced by commit 50f77dc ("KVM: arm64: Populate level on S1PTW SEA
injection") in v6.18-rc1.
Introduced by commit be04ceb ("KVM: arm64: nv: Add emulation of AT
S12E{0,1}{R,W}") in v6.12-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f2ca45b50d4216c9cc7ffabf50d9ad1932209251]
stable/6.18: [97706097f9b851cfe55c3b00b083dfc2bcf542bc]
stable/7.0: [ec42b4ed1b072ea2d03f086061aa67bad6d8de39]
CVE-2026-53278: arm_mpam: Check whether the config array is allocated
before destroying it
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53278
Introduced by commit 3bd04fe ("arm_mpam: Extend reset logic to allow
devices to be reset any time") in v6.19-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6ccbb613b42a1f1ba7bfd547a148f644a902a25c]
stable/7.0: [8eb6dc76eeae5302c0d885906a0e469ef9630a59]
CVE-2026-53279: drm/gma500/oaktrail_lvds: fix hang on init failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53279
Introduced by commit a57ebfc ("drm/gma500: Make oaktrail lvds use ddc
adapter from drm_connector") in v6.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [657a091ab6d01d0091b77660c75cfed573c9a53e]
stable/6.1: [5fe9f505d8578852c30668567bc3ce52e776e8c7]
stable/6.12: [7877f7e231a8bd5c817af1491276550a5e195cd7]
stable/6.18: [ab9256936b58eb178caddcf5b5b1638f079909d2]
stable/6.6: [4e04b564c005c9900643c56656d751ad677889be]
stable/7.0: [f6fc44af3bbd5ab0fb6bdec6f47decca11b38425]
CVE-2026-53280: iommu: Fix NULL group->domain dereference in
pci_dev_reset_iommu_done()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53280
Introduced by commit c279e83 ("iommu: Introduce
pci_dev_reset_iommu_prepare/done()") in v7.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d769711fcddd005f1e654b3bde547140917fe696]
stable/7.0: [17194cd0dd236e732d116d50840d795ca50ef196]
CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount
corruption
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53281
Introduced by commit 60f030f ("iommu/vt-d: Avoid use of NULL after
WARN_ON_ONCE") in v6.14-rc1.
Fixed in v7.1-rc4.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [79ea2feb917b05366b49d85573c9c5331f043b2c]
stable/6.18: [9022cb9ac0c2a72a57fa8ebf92ac74f953ca0153]
stable/7.0: [cdfe3c9f2c9e28a8651ee463c88ad191ced2f840]
CVE-2026-53282: x86/kexec: Push kjump return address even for non-kjump kexec
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53282
Introduced by commit 2cacf7f ("x86/kexec: Fix stack and handling of
re-entry point for ::preserve_context") in v6.14-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [786a45757dcdf8f2beb9d4a6db605db16c18b2b4]
stable/6.18: [b0bd7a850e1f082560959707dbf57b0402071646]
stable/7.0: [7dba9631faa2ee0785e8c2bf0e3d90a05f26dd8c]
CVE-2026-53283: iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53283
Introduced by commit e874c66 ("iommu/amd: Change rlookup, irq_lookup,
and alias to use kvalloc()") in v6.16-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [07d0f496fe7ec5abe3bee7e38be709521567bb33]
stable/6.18: [f0a0f01787ecece814414b0665df879b69849d09]
stable/7.0: [79db4cbab81f07ce69a93d379ebd40d3709ecfb2]
CVE-2026-53284: btrfs: only release the dirty pages io tree after
successful writes
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53284
According to the .vulnerable file, this bug was introduced by commit
663dfbb in v3.19-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4066c55e109475a06d18a1f127c939d551211956]
stable/6.18: [9ebb7eba1237dc198768b9c76506a79f924c82bb]
stable/7.0: [df03d67dc63722845cb9fe59d815d1225b04fd54]
CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation
in DC_RUN_WITH_PREEMPTION_ENABLED
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53285
Introduced by commit 235c676 ("drm/amd/display: add DCN32/321 specific
files for Display Core") in v6.0-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [183182235f6d53bac62c6c39014738a54a68dfa6]
stable/7.0: [30bb2ec6695d62f63db4aa6179c4626834ed0cd6]
CVE-2026-53286: idpf: fix double free and use-after-free in aux device
error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53286
Introduced by commit be91128 ("idpf: implement RDMA vport auxiliary
dev create, init, and destroy") in v6.17-rc1.
Introduced by commit f4312e6 ("idpf: implement core RDMA auxiliary dev
create, init, and destroy") in v6.17-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6c77b9510829a424d1b74409b7db9456e3522871]
stable/6.18: [722b91d5086a249318c9d0e2b36aeac80ba8c808]
stable/7.0: [f319de7074e1728a9f9ff7134257360c694ec2b2]
CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53287
Introduced by commit e68b75a ("When the capset syscall is used it is
not possible for audit to record the actual capbilities being
added/removed. This patch adds a new record type which emits the
target pid and the eff, inh, and perm cap sets.") in v2.6.29-rc1.
Fixed in v7.1-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [260daaa585c43e6b37247be6bc30413c2dac589b]
mainline: [e4a640475e43f406fdfd56d370b1f34b0cbbc18d]
stable/5.10: [75bd76c9eb2de9afeca03dc5152ebca5fb8fc816]
stable/5.15: [febb4bf373ac565d3fb8d1f429827bdd983be496]
stable/6.1: [95de7bb4bf535a9288549d401ebde83cdcbf2792]
stable/6.12: [0a065c51a225854768b772a0b733a44d77162582]
stable/6.18: [e35f3550c5b4fab33103c18654c293cee9850b0a]
stable/6.6: [151ee470edc3d7ed29fe72df678f8357d2ad8ced]
stable/7.0: [d782e4d200cd9036ef353eeb29525bfbfd13a14e]
CVE-2026-53288: arm64: Reserve an extra page for early kernel mapping
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53288
Introduced by commit 5973a62 ("arm64: map [_text, _stext) virtual
address range non-executable+read-only") in v6.18-rc1.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [4d8e74ad4585672489da6145b3328d415f50db82]
stable/6.12: [a4ff33053da0a34b14abb5c96dc5a48379e26fce]
stable/6.18: [dcb89deed40ba55ff7020061712fdabf098cc2cc]
stable/7.0: [9fe9e3acaa14921b0cf0d6cc2de5b562499bf721]
CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53289
Introduced by commit 12bb018 ("ice: Refactor VF reset") in v5.8-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [54ef02487914c24170c7e1c061e45212dc55365e]
stable/6.1: [acc76b97902757b63ba5136f787d107647236a19]
stable/6.12: [4c2ac52eeeb672624b06c7a135301d7b8a21d52e]
stable/6.18: [1e9185b13ce57b86844447e092e58abb3be849b1]
stable/6.6: [3ad2471e61e9f0c4d25046d08e3d747501c3b0dd]
stable/7.0: [429024f3a407e4137aee825c2a6be0aba857937d]
CVE-2026-53290: drm/xe/eustall: Fix drm_dev_put called before stream
disable in close
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53290
Introduced by commit 9a0b11d ("drm/xe/eustall: Add support to init,
enable and disable EU stall sampling") in v6.15-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dc2d9842c67d883d3200ae33b9c3859dd9492408]
stable/6.18: [bebce43f34b5feb8a760aa832eba81e0f8a38871]
stable/7.0: [84f2bfbe6e38f8b9815ca00826e53b7f51420402]
CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53291
Introduced by commit 7aeb259 ("ALSA: hda/conexant: Fix headset auto
detect fail in cx8070 and SN6140") in v6.8-rc1.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/5.15 stable/6.1 stable/6.6
Fixed status
mainline: [b0e2333a231107adedd38c6fcfe1adc6162716fc]
stable/5.15: [49c2c5924552e1d2f8b635dee663abebbb7cf63b]
stable/6.1: [a2a33e87a2ffce3046c574d24eec4390c27c9365]
stable/6.12: [dd110cc00cf854a8ecd8d003127a4178c28574ea]
stable/6.18: [f837c7b85143a7c54140ff41ad5c076b73cd9933]
stable/6.6: [d68f753d89f4ef6e410d7e8b7e8ab2fdde921b80]
stable/7.0: [1da5c73f3793b224696617a2a21def7500ba18d6]
CVE-2026-53292: net: phonet: do not BUG_ON() in pn_socket_autobind()
on failed bind
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53292
Introduced by commit ba113a9 ("Phonet: common socket glue") in v2.6.28-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5b0c911bcdbd982f7748d11c0b39ec5808eae2de]
stable/7.0: [6db58ee730bf434d1afca91b91826e26688856ed]
CVE-2026-53293: drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53293
Introduced by commit 9e823f3 ("drm/amdgpu: Block MMR_READ IOCTL in
reset") in v6.12-rc1.
Fixed in v7.1-rc2.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [0ef196a208385b7d7da79f411c161b04e97283e2]
stable/6.12: [61957c2e467b39b528a290016367d32a433fa846]
stable/6.18: [a31c3feb54b15a90232e497ad0e27e8a82052d8d]
stable/6.6: [8c4254c8f5836e77ae83e7fc037f02b69f7a0977]
stable/7.0: [5c29d20470d4566d1b68df57097d642d01f8b427]
CVE-2026-53294: mailbox: mailbox-test: don't free the reused channel
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53294
Introduced by commit 8ea4484 ("mailbox: Add generic mechanism for
testing Mailbox Controllers") in v4.4-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [dd5648d3af2ad6bb096464773ab49d2e1df18840]
mainline: [88ebadbf0deefdaccdab868b44ff70a0a257f473]
stable/5.10: [fc0089f82c3e36060c2c79156bc2018bfb16b56b]
stable/5.15: [5d4f3d0f64f1016cb78b400a70b67df91fac99b5]
stable/6.1: [c494a11da45ad7ec9b0ff216c3e3ace351193bb6]
stable/6.12: [5c209299b0113e289e238fa5f2e8f00c59f76060]
stable/6.18: [82f6dcea46cf5de65c4ba7283f7c7b34de4a324d]
stable/6.6: [3afca89fae501dbd7421e1777b5b8f033b1d98d0]
stable/7.0: [240c71a2aea36a1a4210f911a1c32ea88777e8e4]
CVE-2026-53295: mailbox: add sanity check for channel array
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53295
Introduced by commit 2b6d83e ("mailbox: Introduce framework for
mailbox") in v3.18-rc2.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [ea3023ea2640ab9e7697514d2d5f894ed1ef0ed8]
mainline: [c1aad75595fb67edc7fda8af249d3b886efa1be9]
stable/5.10: [5cc3300fab262b26c28bc2fc06df693410c3840b]
stable/5.15: [0f11444271110d9b5bc6316a153c6431abda899c]
stable/6.1: [d44872a569b8fbacde457ff2587a775e5004bb79]
stable/6.12: [6362c4a7d7e21e68cd9aa04df7cde16befba3a4b]
stable/6.18: [9dd7489943324298bb0f385495795a82f1dd6507]
stable/6.6: [14aed0d4e58389cc6a88acf8610b12d3e476272b]
stable/7.0: [37792091ab28ba030fd8d61184c47d4d51294170]
CVE-2026-53296: mailbox: mailbox-test: free channels on probe error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53296
Introduced by commit 8ea4484 ("mailbox: Add generic mechanism for
testing Mailbox Controllers") in v4.4-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [d4b78afbb94a6cd77751771c3c2f8d38eaa94aeb]
mainline: [c02053a9055d5fdfd32432287cca8958db1d5bc5]
stable/5.10: [0ad8c4a03a358de7811ba1ab8cbd1fe76ad0ff6b]
stable/5.15: [15c4cc3850cfe1b973eb7b63c02314b267f06a64]
stable/6.1: [187069ccc3474516af32350e20d7e449160fa6de]
stable/6.12: [6c6ce2ccb4fcf1617fec83f91b21aa0265f30701]
stable/6.18: [742001919653e7313b4e91780c5d108be1692365]
stable/6.6: [81c9e7e4030e71391ab479c4c6e17b64802577aa]
stable/7.0: [02beb178e2e159daeb8f992d7abb16a37da31664]
CVE-2026-53297: net: mana: Guard mana_remove against double invocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53297
Introduced by commit 635096a ("net: mana: Support hibernation and
kexec") in v5.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [50271d7ec95144d26808025b508f463780517d3c]
stable/6.18: [a1ddfd2c0b7a48e5239fadd2a24cc4bc2cda90e6]
stable/7.0: [bbe5c3c570645a4ceb120979d3ee203a1583d775]
CVE-2026-53298: net: airoha: Move ndesc initialization at end of
airoha_qdma_init_rx_queue()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53298
Introduced by commit 23020f0 ("net: airoha: Introduce ethernet support
for EN7581 SoC") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [379050947a1828826ad7ea50c95245a56929b35a]
stable/6.12: [d36be272adda7f313e39dd118086955d993bf6a7]
stable/6.18: [4d4acfa348a1d8c0941004823662ede0fdb5dea5]
stable/7.0: [14dc48e5ba73d5c69559bf1a1a6884f7843aade7]
CVE-2026-53299: net: airoha: Move ndesc initialization at end of
airoha_qdma_init_tx()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53299
Introduced by commit 3f47e67 ("net: airoha: Add the capability to
consume out-of-order DMA tx descriptors") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [f329924bb49458c65297f1361f545816a5b90998]
stable/6.18: [90619fdedfb9cc8a80f217d882ee7a84d3703e72]
stable/7.0: [ece31f9dae0c3cd3277e66667e7b8ab2577cf34a]
CVE-2026-53300: net: enetc: fix NTMP DMA use-after-free issue
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53300
Introduced by commit 4701073 ("net: enetc: add initial netc-lib driver
to support NTMP") in v6.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3cade698881eb238f88cbbfec82acc2110440a3f]
stable/6.18: [37c8933064be714ee672b0a0523c2fd045b73b3d]
stable/7.0: [655d9ce9b1d3db0aa5271acb5e5101c66bd0d58b]
CVE-2026-53301: reset: amlogic: t7: Fix null reset ops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53301
Introduced by commit fb4c315 ("reset: amlogic: add auxiliary reset
driver support") in v6.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9797524ef2b69c6b187b55bd844eb72a8c1cbd99]
stable/6.18: [cde69482d2e6834dcd4ed675d1ef84e48627ee9f]
stable/7.0: [463a0885de665d3f36e219c5502584b99fa61c85]
CVE-2026-53302: crypto: eip93 - fix hmac setkey algo selection
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53302
Introduced by commit 9739f5f ("crypto: eip93 - Add Inside Secure
SafeXcel EIP-93 crypto engine support") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3ba3b02f897b14e34977e1886d95ffe64d907204]
stable/6.18: [fc9310d79fdb117b369a01eb00f4fd5fb4849d4e]
stable/7.0: [ec226d3e58bb9f0e26a77346085b6b4d594d53d8]
CVE-2026-53303: f2fs: protect extension_list reading with sb_lock in
f2fs_sbi_show()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53303
Introduced by commit b6a06cb ("f2fs: support hot file extension") in v4.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5909bedbed38c558bee7cb6758ceedf9bc3a9194]
stable/6.1: [d3ff0c121bbaef026df6248ab7ef6f0b068b0647]
stable/6.12: [4b3a1bf4c2ffd4c9595d900ead78c9035894a025]
stable/6.18: [d0e877810baf613b018fd9747440b9d4d9db1428]
stable/6.6: [cea15f66b7b68b2c50943a6660e0692c6635e4eb]
stable/7.0: [ea3ab43a1f3cf2c7cecd75c8be1ee99a5e94a92e]
CVE-2026-53304: scsi: sg: Resolve soft lockup issue when opening /dev/sgX
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53304
Introduced by commit 6460e75 ("[SCSI] sg: fixes for large page_size")
in v2.6.20.16.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [c42315cc48f0cd7390eab6dccb1a7b6cb6f6facd]
mainline: [d06a310b45e153872033dd0cf19d5a2279121099]
stable/5.10: [3d74e0654ac908c65a8f20373091826fe43b1363]
stable/5.15: [c47ccfb3d80dfed522ca06a5954ac97488d78c5a]
stable/6.1: [fe671d3c84ffb1b763d590c25195755adeaadaba]
stable/6.12: [9676ca7b1ef31a3a65b3e61e7ce3b54ce7364202]
stable/6.18: [1afd963fcd963db0dc5d47df6dfcf010c9c4647e]
stable/6.6: [c5f4a211e82d04ccc1809311322c47023bbe66e2]
stable/7.0: [feade299e932967de27519338d41de348fb5b061]
CVE-2026-53305: usb: typec: ps883x: Fix Oops at unbind
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53305
Introduced by commit 257a087 ("usb: typec: Add support for Parade
PS8830 Type-C Retimer") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [381133848a033c2086cf9cafb226f425bd0414ff]
stable/6.18: [37a3d1b6827783f26d2f8e6c7683e253ba79ae93]
stable/7.0: [c404d0ac0cb085cb7077ba32c334cc4042feb81a]
CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53306
Introduced by commit 44a01d5 ("[S390] s390/hvc_console: z/VM IUCV
hypervisor console support") in v2.6.29-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [ba64ed2af2d69ceef0811117ac4f4a641ab4f8b9]
mainline: [f2a880e802ad12d1e38039d1334fb1475d0f5241]
stable/5.10: [3d3b89e6ab93bdd0efd45828bda6b0e61cc46dff]
stable/5.15: [484357dff256c816d9466bda35eb765685e4dc86]
stable/6.1: [11207e42a332eb8bbcb9fe74df9edd2a807c5607]
stable/6.12: [a76511bc654819425d3b15e77b523d7f9d81f064]
stable/6.18: [3104a3f40feb107f77d7116ad9bf6c210ab7babf]
stable/6.6: [fed8b8f33a46db0ee2efdb000f4f630c86ed8ca4]
stable/7.0: [f1dc8e72de9aabe5d96767a4e97219ac26b79fe5]
CVE-2026-53307: pinctrl: pinconf-generic: Fully validate 'pinmux' property
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53307
Introduced by commit 7112c05 ("pinctrl: pinconf-generic: Add API for
pinmux propertity in DTS file") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c98324ea7849b6e5baa1774f71709b375a2c2f9e]
stable/6.18: [6476aac13805721e16439bd71f0e1703a4154517]
stable/7.0: [b7842b722169359e7ffe4b838d2496e9e72ac996]
CVE-2026-53308: power: supply: max77705: Free allocated workqueue and
fix removal order
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53308
Introduced by commit 11741b8 ("power: supply: max77705: Fix workqueue
error handling in probe") in v6.16-rc1.
Introduced by commit a6a494c ("power: supply: max77705: Add charger
driver for Maxim 77705") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1e668baadefb16e81269dbfebf3ffc2672e3a3bb]
stable/7.0: [b98e4e57e34d099a8f846fa54749654082975ea0]
CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions()
region comparison
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53309
Introduced by commit ea20344 ("ocfs2/dlm: Add message
DLM_QUERY_REGION") in v2.6.37-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [1201158265810b1f5d2a43770069798c702e190f]
mainline: [01b61e8dda9b0fdb0d4cda43de25f4e390554d7b]
stable/5.10: [760ab35040aca8399021fdb9ff1db1089feb7194]
stable/5.15: [c60a2710b73838d250cda57344c049b89abc5d52]
stable/6.1: [2a0673836f019e7c032acbf48d022d5ccf02a845]
stable/6.12: [d5403ae28085761d58b555645bc7d5feadb10073]
stable/6.18: [1fb7f356547d9688822315cd2b205ff0bd5429b4]
stable/6.6: [819d8ebad3200a53de99bd7e297bc428e41ced54]
stable/7.0: [426cd8eedac89b86148d4478990eeef16e8a2520]
CVE-2026-53310: soc/tegra: cbb: Fix cross-fabric target timeout lookup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53310
Introduced by commit 25de5c8 ("soc/tegra: cbb: Improve handling for
per SoC fabric data") in v6.17-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a5f51b04cbb3ae0f9cb2c4488952b775ebb0ccbf]
stable/6.18: [c892d0d4fe5ec05d3fdfb1616c3c0e3c12ef5abc]
stable/7.0: [8445d69a5cabd8d6cb2bf0f8b798be205f53afa2]
CVE-2026-53311: fuse: fix uninit-value in fuse_dentry_revalidate()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53311
Introduced by commit 2396356 ("fuse: add more control over cache
invalidation behaviour") in v6.16-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5a6baf204610589f8a5b5a1cd69d1fe661d9d3cd]
stable/6.18: [da3d241c5b925f17a9d8051d7a9e0d454d8e01f6]
stable/7.0: [3ac9117ba3deab8a5dd22847355f861686f4bee7]
CVE-2026-53312: iommu/riscv: Remove overflows on the invalidation path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53312
Introduced by commit 488ffbf ("iommu/riscv: Paging domain support") in
v6.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [40a13b49957937427bc23e78eb50679df4396a47]
stable/6.18: [9f0632b0d4246675fa221aa1a3bffadf9c6bd9ac]
stable/7.0: [e4b7687784153481de45fd39fb97ba3919605c0c]
CVE-2026-53313: drm/amd/display: Avoid NULL dereference in dc_dmub_srv
error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53313
Introduced by commit 2631ac1 ("drm/amd/display: add DMUB registers to
crash dump diagnostic data.") in v5.14-rc1.
Introduced by commit 71ba6b5 ("drm/amd/display: Add interface to
enable DPIA trace") in v6.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4ae3e16f4b3bf64140f773629b765d605ee079a9]
stable/7.0: [b37a978e6d8c33fbfa4abc5dcca4c7cfc6d01f22]
CVE-2026-53314: padata: Put CPU offline callback in ONLINE section to
allow failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53314
Introduced by commit 894c9ef ("padata: validate cpumask without
removed CPU during offline") in v5.6-rc1.
Fixed in v7.1-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st
Fixed status
mainline: [c8c4a2972f83c8b68ff03b43cecdb898939ff851]
stable/6.1: [65dae8b34f0810f3fa9f77c4c63650cd20820693]
stable/6.12: [3e6c08dd97dcd22a00aee469e0adfa819071d80e]
stable/6.18: [5a9f29a3e076b637d2234093e57989cf755ded5b]
stable/6.6: [a6d44f477000c6352de6b05e9e276e62083e5fbf]
stable/7.0: [9afe53f14a2aae8c4beb30e5ea51641a34f1a3d3]
CVE-2026-53315: drm/amd/ras: Fix NULL deref in
ras_core_get_utc_second_timestamp()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53315
Introduced by commit 13c91b5 ("drm/amd/ras: Add rascore unified
interface function") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2b8101cc3b34d4d80d799360d2744829d5964479]
stable/7.0: [6c84f7f0afc415691ffa7d48aa7ce1d8e6083032]
CVE-2026-53316: drm/amd/ras: Fix NULL deref in ras_core_ras_interrupt_detected()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53316
Introduced by commit 13c91b5 ("drm/amd/ras: Add rascore unified
interface function") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6b606216e03fa2b53cc179d8383b683a140fe6e1]
stable/7.0: [f2f2ed3d359509c311cc6626226e4578d7eb77d8]
CVE-2026-53317: wifi: mt76: mt7921: Place upper limit on station AID
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53317
Introduced by commit 5c14a5f ("mt76: mt7921: introduce mt7921e
support") in v5.12-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4d0bf21e3e20619d51d06c0c36207aabab8b712c]
stable/6.12: [6dbe70f9ef14d8ac1c24bf19fd9510978a3ab952]
stable/6.18: [35835ff71e6e618155578b8e3905597edd5f601c]
stable/7.0: [1a4b802afe15c5b33b2dcb37a594aba2fa215d52]
CVE-2026-53318: wifi: mt76: mt7925: prevent NULL pointer dereference
in mt7925_tx_check_aggr()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53318
Introduced by commit 44eb173 ("wifi: mt76: mt7925: add link handling
in mt7925_txwi_free") in v6.11-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [83ae3a18ba957257b4c406273d2da2caeea2b439]
stable/6.12: [28ed0b61f67386c0ba1213227d350005000240fd]
stable/6.18: [93d0694fb56de4628a921244d7f100c28acd2def]
stable/7.0: [b0332428a8d4cf93752eda9e2b0d5585525e689f]
CVE-2026-53319: blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53319
Introduced by commit 41afaee ("blk-wbt: fix possible deadlock to nest
pcpu_alloc_mutex under q_usage_counter") in v7.0-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e9b004ff83067cdf96774b45aea4b239ace99a2f]
stable/7.0: [fd7a982657077469802594a5165bc30b9a55af70]
CVE-2026-53320: nilfs2: reject zero bd_oblocknr in
nilfs_ioctl_mark_blocks_dirty()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53320
Introduced by commit 7942b91 ("nilfs2: ioctl operations") in v2.6.30-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [d91bd069a12cfefba241cdc92ccab5d07ba6717f]
mainline: [be3e5d10643d3be1cbac9d9939f220a99253f980]
stable/5.10: [e0a0c4903cbba351f0f5b5d104960d3a5b23202f]
stable/5.15: [9472d37799a0b9ff9b99639f35961ac2f0b3c9be]
stable/6.1: [65e07964b4b2daf9a54e686cf0fa72d74a9648a8]
stable/6.12: [4525658002be3ad310b16bf8db48c8adb6a55d32]
stable/6.18: [e5ff0ba4b6983cdbcc826efc201e7179ece5d46f]
stable/6.6: [b88f905d4449b70da6bda547be546e365e44352e]
stable/7.0: [94094e70fe292c9566502772d4d4d6d6a99204b1]
CVE-2026-53321: io_uring/napi: cap busy_poll_to 10 msec
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53321
Introduced by commit 8d0c12a ("io-uring: add napi busy poll support")
in v6.9-rc1.
Fixed in v7.1-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [df8599ee18c0e5fe343ffe0b4c379636b8bb839a]
stable/6.18: [39767f944a8c9e696566c37ad5b20131406c4b8d]
stable/7.0: [cb3af525f8dfb8930f0c123e5755fa967a12d5c1]
CVE-2026-53322: vfio/pci: Clean up DMABUFs before disabling function
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53322
Introduced by commit 5d74781 ("vfio/pci: Add dma-buf export support
for MMIO regions") in v6.19-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d97708701434ce72968e771976aaf9d3438fcafd]
stable/7.0: [4f1000a30f67cf7d328059242776a858611d5ef9]
CVE-2026-53323: net: dsa: remove redundant netdev_lock_ops() from
conduit ethtool ops
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53323
Introduced by commit 2bcf477 ("net: ethtool: try to protect all
callback with netdev instance lock") in v6.15-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0f99e0c3e19badaf3fdced0d3feba623e59eed41]
stable/6.18: [74d64ae4254e99ef8c8215b057a76edac82c5f99]
stable/7.0: [abe91fd045874d21834482adcd7a9693e7377056]
CVE-2026-53324: net: mana: Use pci_name() for debugfs directory naming
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53324
Introduced by commit 6607c17 ("net: mana: Enable debugfs files for
MANA device") in v6.13-rc1.
Fixed in v7.1-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c116f07ab9d22bb6f355f3cf9e44c1e6a47fe559]
stable/6.18: [34dbd7b819544c99c9d96b400fe4db613f40ac4b]
stable/7.0: [9211eb97e8f8c28bf9313ab97862d143dbbbef97]
CVE-2026-53325: agp/amd64: Fix broken error propagation in agp_amd64_probe()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53325
Introduced by commit a32073b ("[PATCH] x86_64: Clean and enhance up K8
northbridge access code") in v2.6.20.16.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b08472db93b1ccff84a7adec5779d47f0e9d3a30]
stable/6.18: [53483a9f4ee9eeb18aa866ec16cce79e136987e1]
stable/7.1: [cefe535a60a2e00e09f4b2689b0c8ffc6912459a]
CVE-2026-53326: debugobjects: Don't call fill_pool() in early boot
hardirq context
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53326
Introduced by commit 06e0ae9 ("debugobjects: Allow to refill the pool
before SYSTEM_SCHEDULING") in v6.19-rc1.
Fixed in v7.1.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [0d046ae106255cba5eb83b23f78ee93f3620247d]
stable/6.18: [44b8b03a9fb5c575548fc72c674653d6baba142a]
CVE-2026-53327: debugobjects: Do not fill_pool() if pi_blocked_on
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53327
Introduced by commit 4bedcc2 ("debugobjects: Make them PREEMPT_RT
aware") in v5.15-rc1.
Fixed in v7.1-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5f41161059fd0f1bbf18c90f3180e38cc45a14eb]
stable/6.18: [3a408cae608d9c075dd3a9e5cfc03b3cb0726863]
CVE-2026-53328: sched_ext: Don't warn on NULL cgrp_moving_from in
scx_cgroup_move_task()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53328
Introduced by commit 8195136 ("sched_ext: Add cgroup support") in v6.12-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [02e545c4297a26dbbc41df81b831e7f605bcd306]
stable/6.12: [cdff2eb97be147d2ce52ac1327841068781f25dc]
stable/6.18: [0ffcad63b19a1cadb475c9f405a93607fdcd0d7c]
CVE-2026-53329: drm/amd/display: Use krealloc_array() in dal_vector_reserve()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53329
Introduced by commit 2004f45 ("drm/amd/display: Use kernel
alloc/free") in v4.15-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [da48bc4461b8a5ebfb9264c9b191a701d8e99009]
stable/5.15: [31180638a33acad12c863132704a76536fb66211]
stable/6.1: [b15825deac1acff72638bbc8f05b89ceef8dfb13]
stable/6.12: [a914aa802669e073f014dae2e5708633b5cecd34]
stable/6.18: [e09689286385a66311ac6922af95339d7a3cef8d]
stable/6.6: [201151e120f0062bcda21cad5d007b82725ad23b]
CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in
dp_get_eq_aux_rd_interval()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53330
Introduced commit is not determined.Fixed in v7.1-rc7.
Fixed status
mainline: [e8b4d37eba05141ee01794fc6b7f2da808cee83b]
stable/6.18: [454d3b3d499c18373f8960d31aea48338a3ca9e0]
CVE-2026-53331: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53331
Introduced by commit a899d32 ("slimbus: qcom-ngd-ctrl: add Sub System
Restart support") in v5.11-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [55f2ea9ff83cc27a85526b14bc9b32f96a08d6ec]
stable/5.15: [3d1561537237c6cc1db76155183d8bbdac2339f0]
stable/6.1: [dc4d5c57e012c2c669793deb1515a57bbc6bf5dd]
stable/6.12: [aad4337a21b9ad3ae8d668fa8678d05e26ecbaa8]
stable/6.18: [9f0d45d509b434c54da10e01f4ef8086e4583401]
stable/6.6: [d54a221b0f3cd9e1f03f18104be34e02a8258fae]
CVE-2026-53332: slimbus: qcom-ngd-ctrl: Register callbacks after
creating the ngd
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53332
Introduced by commit 917809e ("slimbus: ngd: Add qcom SLIMBus NGD
driver") in v4.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2a9d50e9ea406e0c8735938484adc20515ef1b47]
stable/6.12: [fa3790c7ea98328ddc3f7d8bf40247556245a6fc]
stable/6.18: [24ec89123fc9d0d24ce719dcf7fd6c57e5b0d753]
CVE-2026-53333: mm/mincore: handle non-swap entries before !CONFIG_SWAP guard
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53333
Introduced by commit 1f20527 ("mm/mincore: use a helper for checking
the swap cache") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0c25b8734367574e21aeb8468c2e522713134da7]
stable/6.18: [a8f91ddf67f669f547bb9fb559738da6f8ee2cf3]
CVE-2026-53334: mm/damon/reclaim: handle ctx allocation failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53334
Introduced by commit 3f7a914 ("mm/damon/reclaim: use
damon_initialized()") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7e2ed8a29427af534bf2cb9b8bc51762b8b6e654]
stable/6.18: [66bc00ea37fa8ec14be5a3909d067a5967ef234b]
CVE-2026-53335: mm/damon/lru_sort: handle ctx allocation failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53335
Introduced by commit c4a8e66 ("mm/damon/lru_sort: use
damon_initialized()") in v6.18-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ab04340b5ae5d52c1d46b750538febcde9d889e7]
stable/6.18: [6d48f15659395bf1381114f01be91bc68e0be46a]
CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53336
Introduced by commit d3c0d12 ("nvmem: layouts: onie-tlv: Add new
layout driver") in v6.4-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ea41020b9018e31c2ea7e9d89021e3e6d7470883]
stable/6.12: [fd47edeabadfaa75422009dc5894e92c4c697517]
stable/6.18: [4a4d21f531ccf5bb333d99b620e0d66551f3652c]
stable/6.6: [033d498b0f473c6456be5f885be172024ad84972]
CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53337
Introduced by commit e2a7420 ("bonding/main: convert to using slave
printk macros") in v5.3-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a764b0e8317a863006e05732e1aefe821b9d8c2d]
stable/5.10: [1b7558c85493467b2ea20738866b822db6442034]
stable/5.15: [b02b2e3e876c18733b868a29064abd11cdbf8feb]
stable/6.1: [66693957bacd1c9dae6188a7312d6be69a221f2d]
stable/6.12: [c2cfe290fdb1c32a4f4eb2b8ca3f363b305d21ba]
stable/6.18: [bcb8fad90f27300add583a8371db504b766d95c7]
stable/6.6: [a629418d463fb50d132a1aa063b0105857311e5f]
CVE-2026-53338: net: airoha: Add NULL check for
of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53338
Introduced by commit 3a1ce9e ("net: airoha: Add the capability to
allocate hwfd buffers via reserved-memory") in v6.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f9f25118faa4dd2b6e3d14a03d123bbdbd59925d]
stable/6.18: [01f7d4b504580664d36faea5671cde5e3f0d8a5b]
CVE-2026-53339: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53339
Introduced by commit e517526 ("i2c: Add Qualcomm CCI I2C driver") in v5.8-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [729ac5a4b966aac42e08a94dea966f4429008548]
stable/5.10: [e8669d12da0ade52adfe0abe96cd99e708abc9bd]
stable/5.15: [4d2b4a9cda6837e5ee1de1290f2e773a713b71e9]
stable/6.1: [a50b8adb9cdb9a495b0b45583956897b7411ed7a]
stable/6.12: [4cd206c1d57a9370d5219f7b1fc45169d7bdf951]
stable/6.18: [a162a260c8c4db7501c65220e76913e8e351f823]
stable/6.6: [7107627b8b35015027201e7a095a3f6e30b4a46f]
CVE-2026-53340: i2c: imx: fix clock and pinctrl state inconsistency in
runtime PM
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53340
Introduced by commit 576eba0 ("i2c: imx: switch different pinctrl
state in different system power status") in v6.14-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8783fb8031799f1230997c16df8c8dce9fcd1841]
stable/6.18: [9fa82cf393bafc7bd7ca15c1d5cbd5b57ab9de1d]
CVE-2026-53341: fhandle: fix UAF due to unlocked ->mnt_ns read in
may_decode_fh()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53341
Introduced by commit 620c266 ("fhandle: relax open_by_handle_at()
permission checks") in v6.11-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [40ab6644b99685755f740b872c00ef40d9aa870e]
stable/6.18: [32138633e51e6db59e474765cf93268c92b42888]
CVE-2026-53342: arm64: mm: call pagetable dtor when freeing
hot-removed page tables
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53342
Introduced by commit 5e8eb9a ("arm64: mm: always call PTE/PMD ctor in
__create_pgd_mapping()") in v6.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c594b83457ccdee76d458416fb3bc9348a37592f]
stable/6.18: [95f27fcda681021ed3906d3cae7e68b6a57a1d8e]
CVE-2026-53343: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53343
Introduced by commit 44e9a3b ("ARM: 9430/1: entry: Do a dummy read
from VMAP shadow") in v6.13-rc1.
Fixed in v7.1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [77a1f6883dc6e837bb2cb30b9b02e2f94338e2c6]
stable/6.1: [c0b8c148a7754826156993ed6442d31536ec86b4]
stable/6.12: [c74990828d3c486ee44aaa68240eb3abff289d1c]
stable/6.18: [517720913bd3c17a52cd55a740064f68455ab88e]
stable/6.6: [c2e3aadc8fef7da068490597fc5582f8f362aeb2]
CVE-2026-53344: pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr
before regmap init
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53344
Introduced by commit f9f4fda ("pinctrl: mcp23s08: init reg_defaults
from HW at probe and switch cache type") in v6.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8473c3a197b57ff01396f7a2ec6ddf65383820d4]
stable/6.12: [d487a945769396cc94a8549d1fae838bd642f9a1]
CVE-2026-53345: KVM: Don't WARN if memory is dirtied without a vCPU
when the VM is dying
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53345
Introduced commit is not determined.Fixed in v7.1-rc7.
Fixed status
mainline: [8618004d3e897c0f1b71d9a9ab860461289bb89a]
stable/6.12: [66a8e7ddd901023c89a2733494d827eca3f9c1b0]
stable/6.18: [343e95c8ecc40e0738975ef4ee24c0c35e800e6b]
stable/6.6: [033d39e41fc30f484f4e4f37fb4cd76b12cbb18e]
CVE-2026-53346: rust: arm64: set uwtable llvm module flag for
CONFIG_UNWIND_TABLES
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53346
Introduced by commit d077242 ("rust: support for shadow call stack
sanitizer") in v6.12-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ac35b5580ace12e5d0a0b5e61e36d2c4e1ffa29c]
stable/6.12: [bde772ee239720af216fb0b14753971059e132dc]
stable/6.18: [d0f25a1755f2c15b1746379c8d9d7dfde85f58f5]
CVE-2026-53347: drm/virtio: Fix driver removal with disabled KMS
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53347
Introduced by commit 72122c6 ("drm/virtio: Add option to disable KMS
support") in v6.4-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f329e8325e054bd6d84d10904f8dd51137281b92]
stable/6.12: [38a5f891cda6d121c149c94cda89c31ec7024ee3]
stable/6.18: [19a6a00ff50c284f3a9818882ad2be58b33b790a]
stable/6.6: [ed3e134700a2e07caa99b9bc0683ebbe0327c562]
CVE-2026-53348: ASoC: SDCA: fix NULL pointer dereference in
sdca_dev_unregister_functions
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53348
Introduced by commit 4496d1c ("ASoC: SDCA: add function devices") in v6.19-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e4c60a1d4b6ccc66aefb3789cd908d4f9482eefd]
CVE-2026-53349: netfilter: nf_conntrack: destroy stale expectfn
expectations on unregister
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53349
Introduced by commit f587de0 ("[NETFILTER]: nf_conntrack/nf_nat: add
H.323 helper port") in v2.6.20.16.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c3009418f9fa1dcb3eb86f4d8c92583537b5faa3]
stable/6.1: [fbfde85308b99938a6092c48753214d190ece48d]
stable/6.12: [f92c90a2a3e6ff6f9f7fe88fde9004b4ca8f956d]
stable/6.18: [9d017671dcfcec23321fb7962dea624f9e71ddb1]
stable/6.6: [29d8cc44bbdf7b83a1929912214afe6643c1b4f1]
CVE-2026-53350: ASoC: wm_adsp: Fix NULL dereference when removing
firmware controls
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53350
Introduced by commit 0700bc2 ("ASoC: wm_adsp: Separate generic
cs_dsp_coeff_ctl handling") in v5.16-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7d3fb78b550301e43fdc60312aed733069694426]
stable/6.1: [5ee9bbe2af2f373e08d3017f9aef2f2eaf29fbc3]
stable/6.12: [2f1be283aa777d655525d000d16474b7e7d015ea]
stable/6.18: [12e579b889624ec54a201d98fdff975de556c731]
stable/6.6: [10def23b67b42679d5b1a356e1a6f3498bd188c3]
CVE-2026-53351: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53351
Introduced by commit 2af7c9c ("riscv/ptrace: expose riscv CFI status
and state via ptrace and in core files") in v7.0-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e3573f739e3dadab57ec80488d07e05c8f6e82d3]
CVE-2026-53352: signal: clear JOBCTL_PENDING_MASK for caller in
zap_other_threads()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53352
Introduced by commit 39efa3e ("signal: Use GROUP_STOP_PENDING to stop
once for a single group stop") in v3.0-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [90918794a4e2c3b440f8fcf3847765a8b1d81b25]
stable/5.10: [2b32b2fb241435145ea199efac024540759d2495]
stable/5.15: [391ebe74456a0f1d60b3ba4a8a64d9f44c1728fe]
stable/6.1: [f8d720bc2e35d568c18be0644e92a468de428370]
stable/6.12: [76aebd9ef20078719dfd6282d3b06c27e900a65a]
stable/6.18: [8c046f36222c6ce1e0daef2c45c891c72602f8a1]
stable/6.6: [f4aae11abb449dc536269705d0419ec69480faa9]
CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self().
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53353
Introduced by commit f266a68 ("net/hsr: Better frame dispatch") in v3.17-rc1.
Fixed in v7.1-rc7.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [afd0f17ca46258cec3a5cc48b8df9327fe772490]
stable/6.12: [0232b6fcb7615fb7fecfe0727a23065a53e228b8]
stable/6.18: [66a46e22396fd5d09606f37f73643eb20e99aa42]
stable/6.6: [271355c2ef6171dbc815e7ae653eed63444bbd58]
CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53354
Introduced commit is not determined.Fixed in v7.2-rc1.
Fixed status
mainline: [cfd391e74134db664feb499d43af286380b10ba8]
stable/5.10: [925058203229403008d77a52b1e63e2ae5f4a3cf]
stable/5.15: [8364384ae82fbffdf8968abaac3455ed854da18d]
stable/6.1: [7c3ad9365079e716b57d2363d3081ee7680cc18e]
stable/6.12: [4e7c80742e6dada9f8b9ad63f3a49c03af07ecb8]
stable/6.18: [d4fd4282204044fdedd1e42abbe70a9206f74ec0]
stable/6.6: [e717a4d08779f1a28d6e0275e75040b12c33c753]
stable/7.1: [1268c64e2bcb6e968152990e87bd10c440fcc9c0]
CVE-2026-53355: net: rds: clear i_sends on setup unwind
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53355
Introduced by commit 3b12f73 ("rds: ib: add error handle") in v4.11-rc3.
Fixed in v7.1-rc7.
Bug introduced commit was backported to following branches.
cip/4.4 cip/4.4-rt cip/4.4-st
Fixed status
mainline: [20cf0fb715c41111469577e85e35d15f099473e0]
stable/5.10: [66cccec111421a10efdc2c74499d15b93e7acae5]
stable/5.15: [2c5e5e4a5970c41f16e3ad801a78719ed5d5c71b]
stable/6.1: [29d940026dce39e3018dab6f67c9427249321270]
stable/6.12: [f16ad421a4e3e7db2d14bdf3b16f583bc4f3b30a]
stable/6.18: [1d4ec754ee3871f7e3670c67bb0298c9c5760926]
stable/6.6: [e7cf30aa5f1fc6c2a86df65df8b731df20e44d79]
CVE-2026-53356: drm/i915/gem: Fix phys BO pread/pwrite with offset
Announce: https://www.cve.org/CVERecord?id=CVE-2026-53356
Introduced by commit c6790dc ("drm/i915: Wean off
drm_pci_alloc/drm_pci_free") in v5.7-rc1.
Fixed in v7.1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d21ad938398bca695a511307de38a65889e3b354]
stable/5.10: [40f738991058eb3e3530c3006a5bd6fd5e29f035]
stable/5.15: [1ec8fc63e9cdb22da54e48e536c9204020416fc6]
stable/6.1: [14469860e2e39b7095dcd658d2bad38a11110a68]
stable/6.12: [3bd168dd835b93a3862cd05b0d13c432b115f9d6]
stable/6.18: [32d4c5d328a3ff995420f4f85163e1e403f43628]
stable/6.6: [07c33be968d9e0cab6cba38c81850a09942fcb2e]
* Updated CVEs
CVE-2026-52945: Revert "wireguard: device: enable threaded NAPI"
stable/5.15, stable/6.1, stable/6.6 were fixed.
Fixed status
stable/5.15: [18e65229a328304a7ef59899a30fd34ad73ed56b]
stable/6.1: [fb978675ccfd4a93549e49624127d8332cc61cbf]
stable/6.6: [8c9e9cd398777fd60ba202211da1110614cb5bc5]
CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
stable/5.15, stable/7.1 were fixed.
Fixed status
stable/5.15: [897d6a7247739fb1528f98c575df4f2e5de7f994]
stable/7.1: [36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed]
CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000
stable/5.15 was fixed.
Fixed status
stable/5.15: [a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d]
CVE-2026-46252: regulator: core: fix locking in
regulator_resolve_supply() error path
stable/6.18 was fixed.
Fixed status
stable/6.18: [bde74af8d4466213007bdd42cc85fa72c861dea7]
CVE-2026-53070: sctp: disable BH before calling udp_tunnel_xmit_skb()
stable/6.18 was fixed.
Fixed status
stable/6.18: [0de7db2eb27e82b983157016fa604b1ba664ae5f]
Regards,
--
Masami Ichikawa
Cybertrust Japan Co., Ltd.
Email :[email protected]
:[email protected]