[kernel-cve-report] New CVE entries this week

Masami Ichikawa <[email protected]>
Newsgroups org.cip-project.lists.cip-dev
Message-ID <CAODzB9qoH429pcuF0ODdxZFTsj2g7KA8zKz3wJKK1mU5s-ULGw@mail.gmail.com>
Hi!

It's this week's CVE report.

This week reported 23 new CVEs and 19 updated CVEs.

* New CVEs
CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in

Announce: https://www.cve.org/CVERecord?id=CVE-2022-4994

According to the .vulnerable file, this bug was introduced by commit
8370c3d in v4.10-rc1.
Fixed in v6.0-rc1.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3]

CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after*
making MMU pages available

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64561

Introduced by commit f95eec9 ("KVM: x86/mmu: Don't put invalid SPs
back on the list of active pages") in v5.9-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [2abd5287f08319fa35764566b15c6e22cb1068db]
stable/6.12: [0026dbb7de8ea76e97d6edf42fc3cc084564e2bf]
stable/6.18: [f3477a6a4164f15287444eda685b5f6405dbd1e5]
stable/6.6: [35e77467610c4a37cb0ff54ee56b85f73b1f5700]
stable/7.1: [bce0d3c26e2c761a4bf43c8949f333fc7374eb2d]

CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64562

Introduced by commit 355f4fb ("kvm: nVMX: VMCLEAR an active shadow
VMCS after last use") in v4.9-rc4.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [622ebfac01ba4f9c0060cebd41257fe46fc4a0b3]
stable/6.12: [589419470030a89f16cf19300658b6dc644ca946]
stable/6.18: [8001d2ce9d9bd09118ce523aef595aa094573ae3]
stable/6.6: [af56298e9d86e6098cd1d2e155cb2949b7c45412]
stable/7.1: [1dabef6e206568bf9d9ade74f6e56a48ea35695d]

CVE-2026-64563: rhashtable: clear stale iter->p on table restart

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64563

Introduced by commit 5d240a8 ("rhashtable: improve rhashtable_walk
stability when stop/start used.") in v4.18-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [8173f7e2ce67e6ca1d4763f3da14e5b01ce77456]
stable/6.18: [3ff7c1dbf722cf3fa538672452ba182318e0fcc3]
stable/7.1: [4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3]

CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64564

Introduced by commit 42e30bf ("[SCTP]: Handle the wildcard ADD-IP
Address parameter") in v2.6.25-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [9b2854f86f0b56e9027d68e7a3fc909d1a9b566f]
stable/6.12: [74e8f3e7114f0e26d1b2c4c048044db9fcc27603]
stable/6.18: [85aca407c560aba81b5ce9d3d6cf94c74077d19b]
stable/6.6: [fedeb4468987bcaff85fe3061de5ae052d414740]
stable/7.1: [d136b29bf91dd8e3161281b87de597b7311d9462]

CVE-2026-64565: Input: ims-pcu - fix heap-buffer-overflow in
ims_pcu_process_data()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64565

Introduced by commit 628329d ("Input: add IMS Passenger Control Unit
driver") in v3.10-rc1.
Fixed in v7.1-rc1.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [875115b82c295277b81b6dfee7debc725f44e854]
stable/6.12: [ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49]
stable/6.18: [d03a740e087de7dcb2a26dc1123377bd3d1d84ca]
stable/6.6: [40bbbf2e91fd60715525bf0405c67876af817edf]

CVE-2026-64566: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in
iptfs_skb_add_frags()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64566

Introduced by commit 5f2b6a9 ("xfrm: iptfs: add skb-fragment sharing
code") in v6.14-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [430ea57d6daf765e88f90046afbfd1e071cb7200]
stable/6.18: [d8aaf06b29f5a0b6186cf68d21c7d63678ee3891]
stable/7.1: [ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0]

CVE-2026-64567: btrfs: reject free space cache with more entries than pages

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64567

Introduced by commit 5b0e95b ("Btrfs: inline checksums into the disk
free space cache") in v3.2-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [a2d8d5647ed854e38f941741aea45b9eb15a6350]
stable/6.12: [404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2]
stable/6.18: [5e1b2ca6b34939e70fb0785e8222b53cf060016f]
stable/6.6: [33878ba25e2638bc0c61623d7a05c9ca2b74c039]
stable/7.1: [f9fef131fa3f59b857217f522fa5ea430d1b707c]

CVE-2026-64568: wifi: mac80211: fix unsol_bcast_probe_resp double free
on alloc failure

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64568

Introduced by commit 3b1c256 ("wifi: mac80211: fixes in FILS discovery
updates") in v6.7-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [1d067abcd37062426c59ec73dbc4e87a63f33fea]
stable/6.12: [ca27a81cd77b698e5eb586a011bee6800c7ee4bd]
stable/6.18: [d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae]
stable/7.1: [0ace76e410d7f7d813b605825a3e593a79c3958f]

CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on
CONFIG_INET=n

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64569

Introduced by commit 196cfeb ("net/mpls: Handle kernel side filtering
of route dumps") in v4.20-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [56d96fededd61192cd7cc8d2b0f36adfd59036c3]
stable/6.12: [ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce]
stable/6.18: [5f6e7b32bd1fbde10fd31a4143260735ea535b8a]
stable/6.6: [d6eee7cd078aaf9dd75efc801f6c9b608a37cd71]
stable/7.1: [06db79411a280707c7e4bf4b221ff4e664b51502]

CVE-2026-64570: wifi: mac80211: fix fils_discovery double free on alloc failure

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64570

Introduced by commit 3b1c256 ("wifi: mac80211: fixes in FILS discovery
updates") in v6.7-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [286e52a799fa158bdbd77da1426c4d93f9a6e7ad]
stable/6.12: [e2c55079155a953db669ca1986a985fa286bad95]
stable/6.18: [5baaa1042f71dd4b8e418f2cdd516808702d229b]
stable/7.1: [1981fba71797ec95e6755fb882cad88899a2a84f]

CVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64571

Introduced by commit 7cb7707 ("p54: move eeprom code into common
library") in v2.6.28-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea]
stable/6.12: [f46f8f9c43fd02f4dd5f716d4bda296a523c04f0]
stable/6.18: [d38f5d868a0a4770e3bcd0925e16c46acdbc9509]
stable/6.6: [25c3b85af3fc4f8043159b14e65790fc3bbdaf48]
stable/7.1: [9096e1f7014174067239a63df18ae5f28301990d]

CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64572

Introduced by commit a6c76c1 ("ipv4: Notify route after insertion to
the routing table") in v5.6-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [f2f152e94a67bc746afaf05a1b2702c195553112]
stable/6.12: [d007056868723de9c0cc3f5ffaad47a8d468b9a4]
stable/6.18: [cb8be318b4432abd88d3172ec157330f27a5f7a7]
stable/6.6: [8150b5365f026e72250cacc527ea00be30f40105]
stable/7.1: [b8d2ea75c76abcd0d72679c2f488271f573e32fb]

CVE-2026-64573: Bluetooth: qca: fix NVM tag length underflow in TLV parser

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64573

Introduced by commit 2e4edfa ("Bluetooth: qca: add missing firmware
sanity checks") in v6.9.
Fixed in v7.2-rc4.

Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/5.15 stable/6.1 stable/6.6

Fixed status
mainline: [c90164ca0f7036942ba088eb7ea8d3f6c2352020]
stable/6.12: [59fd2f075bca94f030c7c78e94878ea0803d7690]
stable/6.18: [a087ed960fce54e9302796229e9d545bbc9bcd4a]
stable/6.6: [70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24]
stable/7.1: [4fcfb5b2c736785464ff9745f94c6726c5ee2d85]

CVE-2026-64574: wifi: mac80211: tear down new links on vif update error path

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64574

Introduced by commit 170cd6a ("wifi: mac80211: add netdev per-link
debugfs data and driver hook") in v6.4-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [952c02b33f56207a160421bcd61e7ac53c9c59ae]
stable/6.12: [c57d97f381306bbfba174e8f708419e007824e0c]
stable/6.18: [0f7eaeb950adb77f71beb546e5ab30f90b41fe6f]
stable/6.6: [329589417214d3b7221432e5b266ed2bba7ff674]
stable/7.1: [901a73523e093beff123b54b1ceaf3113f18acc9]

CVE-2026-64575: bpf: tcp: fix double sock release on batch realloc

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64575

Introduced by commit cdec67a ("bpf: tcp: Make sure iter->batch always
contains a full bucket snapshot") in v6.17-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [980a813452754f8001704744e92f7aa697c53dd3]
stable/6.18: [9f27c4f0ae35b5390ce4f7a54d3501144e41a54d]
stable/7.1: [8a726e9585ffe7bfbfad2b5279277a00973970f3]

CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64576

Introduced by commit 7c37c7e ("nexthop: Implement notifiers for
resilient nexthop groups") in v5.13-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [6347c5314cee49f364aaf2e40ff15415a57a116e]
stable/6.12: [3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d]
stable/6.18: [d536bf205c71f700f6de2086038c3e1d77724715]
stable/6.6: [c0936c131a71657afc635d0db2ab096d15d473e1]
stable/7.1: [18506d7263768d76ac8e057ba55a4d9da50aad66]

CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64577

Introduced by commit 9af41cc ("gtp: Implement GTP echo response") in v5.18-rc1.
Fixed in v7.2-rc5.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [cd170f051dba9ac146fabcd1b91726487c0cb9fa]
stable/6.12: [4fc7923871d176ce0e5fecf4a9b7bb915af790ed]
stable/6.18: [961e9b1e33445f8e42859ecc020c9f60d8b69a8b]
stable/6.6: [b3c733eaae7f362601c28ac1533d47a961cd3e1c]
stable/7.1: [cf45d748e437b8dd2dd987f27ee79c8c86f95c88]

CVE-2026-64578: ksmbd: validate compound request size before reading
StructureSize2

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64578

Introduced by commit e2f3448 ("cifsd: add server-side procedures for
SMB3") in v5.15-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [15b38176fd1530372905c602fde51fe89ec8c877]
stable/6.12: [f7550a91ab211726f59cb137523b7a9eae1ac6eb]
stable/6.18: [f0e337e7db67cc1c832958bbb6c4026bdceacfdb]
stable/6.6: [2c307126ed8e7adddab82b8e31d962d3a2156ab1]
stable/7.1: [ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a]

CVE-2026-64579: xfrm: policy: preallocate inexact bins before
xfrm_hash_rebuild reinsert

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64579

Introduced by commit 24969fa ("xfrm: policy: store inexact policies in
an rhashtable") in v5.0-rc1.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [f38f8cce2f7e79775b3db7e8a5eacda04ac908e4]
stable/6.12: [94c00391a5117530188334f740ce26d3f1256190]
stable/6.18: [7acc5ed2f33608a3d83b64f50a5766843b6e2485]
stable/6.6: [d9d9cc21cc90014724a14c447e3d587be9447107]
stable/7.1: [6aa3796d18a9fda953ad76a62b57bf6c145cb9ef]

CVE-2026-64580: xfrm6: clear dst.dev on error to avoid double
netdev_put in xfrm6_fill_dst()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64580

Introduced by commit 84c4a9d ("xfrm6: release dev before returning
error") in v3.10-rc2.
Fixed in v7.2-rc4.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [136992de9bb91871084ae52d172610541c76e4d2]
stable/6.12: [43de8a49335e611adb271bbd52e84dfbc11fc185]
stable/6.18: [ff636d7b7cba6dea82ecf580415ea57f2c1a11b6]
stable/6.6: [df6856c2dda9187601d29b5fbd7a81b3b178cedf]
stable/7.1: [e078da1b4e11390cff3201c19a9a1fe70c5b934f]

CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64581

Introduced by commit 2b06cdf ("xfrm: Clear sk_dst_cache when applying
per-socket policy.") in v4.14-rc8.
Introduced by commit be8f828 ("net: xfrm: allow clearing socket xfrm
policies.") in v4.16-rc1.
Fixed in v7.2-rc4.

Bug introduced commit was backported to following branches.
cip/4.4 cip/4.4-rt cip/4.4-st

Fixed status
mainline: [c283e9ada7fcb7dd4b10592623086b2e6d2f9925]
stable/7.1: [96b678d08268b5f5c6fc99d4289d9b7e334fc683]

CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap

Announce: https://www.cve.org/CVERecord?id=CVE-2026-64582

Introduced by commit 8700e3e ("Soft RoCE driver") in v4.8-rc1.
Fixed in v7.2-rc1.

Bug introduced commit is not backported to older stable kernels.

Fixed status
mainline: [35744ab3d03c5fca8c1752f53fc8fc674e14c561]
stable/6.12: [e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e]
stable/6.18: [e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6]
stable/6.6: [665fb7d22a700c66a78db0cf88c6e6a649aba9d0]
stable/7.1: [3525987a392536f31a484833af258971af63b24c]

* Updated CVEs

CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race

stable/5.10, stable/5.15, stable/6.1, stable/6.12, stable/6.18,
stable/6.6 were fixed.

Fixed status
stable/5.10: [67aa823e3e8c229c6d374df79c804f6721cb83b6]
stable/5.15: [d8bcb28abad857f1415da7656f19b2ada90af04f]
stable/6.1: [cc35ddbc497311e0b6b9a6a6a4f4d1217d6ab1aa]
stable/6.12: [e74443f5db0037c556ef436fa64b88bf4ea08f83]
stable/6.18: [6a7ecc25abe6f0fecc6e62a05096987200edbd02]
stable/6.6: [12a891c773aeb5823d63dbd0cb2ab931d6c21c9b]

CVE-2024-42088: ASoC: mediatek: mt8195: Add platform entry for
ETDM1_OUT_BE dai link

stable/6.6 was fixed.

Fixed status
stable/6.6: [62f61129621ce7e05a6d24584660f79bf081b483]

CVE-2025-38299: ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()

stable/6.6 was fixed.

Fixed status
stable/6.6: [45bd023c7a4ec12059912a631a74723746145e7e]

CVE-2025-39901: i40e: remove read access to debugfs files

stable/6.6 was fixed.

Fixed status
stable/6.6: [ef40d9411469306e524e7887c51b709377e6ef65]

CVE-2025-40098: ALSA: hda: cs35l41: Fix NULL pointer dereference in
cs35l41_get_acpi_mute_state()

stable/6.12 was fixed.

Fixed status
stable/6.12: [19129a365d2bd019fb60662b36b2655931997f12]

CVE-2025-40307: exfat: validate cluster allocation bits of the allocation bitmap

stable/6.6 was fixed.

Fixed status
stable/6.6: [67ce8034dc0278ddd88cad93d4218a945180dddd]

CVE-2025-68299: afs: Fix delayed allocation of a cell's anonymous key

stable/6.12 was fixed.

Fixed status
stable/6.12: [bd18d2cbc9377c6b270c0b7ea44b0e6ed1d99c07]

CVE-2026-45897: netfilter: nft_counter: serialize reset with spinlock

stable/6.12, stable/6.18 were fixed.

Fixed status
stable/6.12: [48cf7918d10c66cb6b05226fa3fa5daf0c891089]
stable/6.18: [cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1]

CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path

stable/6.12, stable/6.18 were fixed.

Fixed status
stable/6.12: [d66bedfe97a2bc321fa8118e669aae988038f729]
stable/6.18: [f6410d18c1e2da325df02be989d5bca5ed38b086]

CVE-2026-46130: dm-verity-fec: fix reading parity bytes split across
blocks (take 3)

stable/6.18 was fixed.

Fixed status
stable/6.18: [d47281b9a4472cfd73122393e79fbe76b651e46a]

CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer
leak in sock_ops

stable/6.12, stable/6.18 were fixed.

Fixed status
stable/6.12: [2a2c98141e0a75f2d4a7d78b0316c88b3da784ac]
stable/6.18: [22400725de070b787cd6d806c5795370ab46d269]

CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs

stable/6.12, stable/6.18, stable/6.6 were fixed.

Fixed status
stable/6.12: [8674e2db06cff6b50f2216eed9a761d15425bb34]
stable/6.18: [ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337]
stable/6.6: [37ad2bb11e9de92cb7b94548705eeedd87f7d392]

CVE-2026-53364: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()

stable/6.12 was fixed.

Fixed status
stable/6.12: [488e808e3fa53200f3ef3324c45fcba4ae9f4972]

CVE-2026-63923: octeontx2-af: validate body pcifunc in
rvu_mbox_handler_rep_event_notify

stable/6.18 was fixed.

Fixed status
stable/6.18: [4467fa514482bbce82f73788943c815f3d126ab3]

CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF
LSM is uninitialized

stable/6.6 was fixed.

Fixed status
stable/6.6: [5337eebdf8c5d4810b1913047f078d2815d5645f]

CVE-2026-64205: i2c: i801: fix hardware state machine corruption in error path

stable/6.12, stable/6.6 were fixed.

Fixed status
stable/6.12: [ef5a347532932f58748dad485c15039f5168c377]
stable/6.6: [2ef69871b313aa0f02182795f5e0f5aa455f203c]

CVE-2026-64280: fpga: dfl-afu: validate DMA mapping length in
afu_dma_map_region()

stable/6.12, stable/6.6 were fixed.

Fixed status
stable/6.12: [b50e6cd2395cde615f59b624819998d28c0668d6]
stable/6.6: [16381bda90b261a656ded0568630c1b857b2ebc8]

CVE-2026-64290: iommufd: Break the loop on failure in iommufd_fault_fops_read()

stable/6.12 was fixed.

Fixed status
stable/6.12: [a38e0714affc5c0bbb40cba5a65d6d32a5e72a71]

CVE-2026-64542: ipv6: ndisc: fix NULL deref in accept_untracked_na()

stable/6.6 was fixed.

Fixed status
stable/6.6: [160d3f0d7a556ceae505dcab521a37057b4ce28f]

Regards,
-- 
Masami Ichikawa
Cybertrust Japan Co., Ltd.

Email :[email protected]
          :[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.