[kernel-cve-report] New CVE entries this week
Masami Ichikawa <[email protected]>
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <CAODzB9o-8bxd+ScpjUv=zn1dZDTZcRzD6WpfdcBg1ZZyem2J0Q@mail.gmail.com> |
Hi!
It's this week's CVE report.
This week reported 392 new CVEs and 8 updated CVEs.
* New CVEs
CVE-2026-64583: usb: gadget: udc: bdc: free IRQ and drain
func_wake_notify before teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64583
Introduced by commit efed421 ("usb: gadget: Add UDC driver for
Broadcom USB3.0 device controller IP BDC") in v3.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb]
stable/6.12: [f6fc21ec7ccd83726ba766d73d0b8cc03e726475]
stable/6.18: [dcf3e2f164435b5844706cb8eefef29ebee0eedb]
stable/6.6: [1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8]
stable/7.1: [d4964a74717107697999f48bcb4e80a9c0679a27]
CVE-2026-64584: usb: gadget: f_midi: cancel pending IN work before
freeing the midi object
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64584
Introduced by commit 8653d71 ("usb/gadget: f_midi: Replace tasklet
with work") in v5.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt stable/5.10
Fixed status
mainline: [5650c18d93a1db7e27cb5a40b394747eb4686d5b]
stable/6.12: [87bc316dd6fc90072297c635e10b9aa6075ecda1]
stable/6.18: [f45089eaad0a083d71d84ff175741d7e157d9b69]
stable/6.6: [380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9]
stable/7.1: [ac9a51d910bb7465c554c45320cb6c09f3d0b49d]
CVE-2026-64585: can: esd_usb: kill anchored URBs before freeing netdevs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64585
Introduced by commit 96d8e90 ("can: Add driver for esd CAN-USB/2
device") in v2.6.36-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c43122fef328a70045fe7621c06de6b2b8e19264]
stable/6.1: [aa1d005927db38af783c1a4a8a00a39e0229ab2d]
stable/6.12: [a3314f10369df70925140f59bbe069718f65a0b9]
stable/6.18: [765ba1c91823a296447528791b89a6504947fd5c]
stable/6.6: [a02e1d8f191324583599544d54e59e6a2b74bb0e]
stable/7.1: [5832c55b3c824ba2fe9c36ac3c411baddcce053e]
CVE-2026-64586: wifi: brcmfmac: drain bus_reset work on device removal
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64586
Introduced by commit 4684997 ("brcmfmac: reset PCIe bus on a firmware
crash") in v5.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [43b25879f004c98defa2776bedc6ca4763c51945]
stable/6.12: [e3815d1ffbb9be4f1605ddc3b427557893461683]
stable/6.18: [02d378828af8bb74f6c2f4d2bee3c77cf16c861e]
stable/6.6: [c268331845ee00dbdbccb000826bb612dff2bee7]
stable/7.1: [177a25be1195f8bdc6160ba5f1a5699f7041c985]
CVE-2026-64587: net: ethernet: arc: emac: quiesce interrupts before
requesting IRQ
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64587
Introduced by commit e4f2379 ("ethernet/arc/arc_emac - Add new
driver") in v3.11-rc1.
Fixed in v7.0-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
cip/4.19-st: [92802fae45a0a7048e60cecf20efaf8820b4fe7d]
cip/4.4-st: [0c56d53fcb25862869b4c3af6cb55858aec86a1f]
mainline: [2503d08f8a2de618e5c3a8183b250ff4a2e2d52c]
stable/5.10: [abd338da658d7faa8e26cfefc8f83f0066707564]
stable/5.15: [5f29dd540fe5ea3c826fc8ec759ba488b31f9707]
stable/6.1: [6fc7449773748c7b904235a09a67054d78ab1172]
stable/6.12: [d0f2386f529807826e7404d40a245ee428f89f62]
stable/6.18: [8efd5dcd31e22a9308b16b107a052fcd568c0a99]
stable/6.6: [81431da777924dddaefa5c9b0ca9da4a93f9df96]
CVE-2026-64588: fuse-uring: fix data races on ring->ready
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64588
Introduced by commit c2c9af9 ("fuse: Allow to queue fg requests
through io-uring") in v6.14-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [46725a0056c884cf58a6897f222892807327d82d]
stable/6.18: [b156bb9966972122b148acab8bdf415cdb8176a3]
stable/7.1: [d01a09b442cb786cd44ccc7c84d57e2856d6737c]
CVE-2026-64589: i2c: core: fix NULL-deref on adapter registration failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64589
Introduced by commit 3f8c4f5 ("i2c: core: fix reference leak in
i2c_register_adapter()") in v6.13.
Fixed in v7.2-rc1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [2295d2bb101faa663fbc45fadbb3fec45f107441]
stable/5.10: [dfccc79e5095bd0b017ae093077e3d7853b9e1e5]
stable/5.15: [9b49b2c4e39cef71819548fea841d3fe0fc0e170]
stable/6.1: [01326c7d1453f19f552b09eccb5776fbf2b91ed5]
stable/6.12: [2ce0a74bfa3acdfcdb00cf02f181f2754b451f42]
stable/6.18: [3351c5e77749a0c8a1e252b95420c143ebcf07ac]
stable/6.6: [ad4322d84ebf766914489233153b10b0519efdb4]
stable/7.1: [034e307428119b67f5f18a35e4f4e7d15a2b9774]
CVE-2026-64590: dma-buf/udmabuf: skip redundant cpu sync to fix
cacheline EEXIST warning
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64590
Introduced by commit 284562e ("udmabuf: implement
begin_cpu_access/end_cpu_access hooks") in v5.6-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [504e2b4ab97a51d56d966cd36d0997ad30b65b2d]
stable/6.12: [d6552f5cff795d60e629f37513ecf23d88fd2f82]
stable/6.18: [34696563461c9a23177feb6d8aff43f4c0510278]
stable/6.6: [0db56e7eae932f8e2f3eb44ad1a63633d8f504f8]
stable/7.1: [0449a6583c0ee76778d314e4e82f166fc97fa9d8]
CVE-2026-64591: iommu/vt-d: Avoid WARNING in sva unbind path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64591
Introduced by commit 39c20c4 ("iommu/vt-d: Only handle IOPF for SVA
when PRI is supported") in v7.0-rc5.
Fixed in v7.2-rc1.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [534b5f98ab7319d8004bbc7dab6481462243e883]
stable/6.18: [bb354384f40bb087e7c44f0f0743a23fc945f91d]
stable/7.1: [477f8dec3b5ae54e8ef3c33bdd2257e47896512e]
CVE-2026-64592: riscv: mm: Unconditionally sfence.vma for spurious fault
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64592
Introduced by commit 503638e ("riscv: Stop emitting preventive
sfence.vma for new vmalloc mappings") in v6.12-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1b2c6b56a9fa0dcbef461039937de22b1cbecc7d]
stable/6.12: [c4df24702bfc3cd2bed7746b94dc6139a3fa5428]
stable/6.18: [4d730cab96e6b75e4a07c4baf37294ebc07f795e]
stable/7.1: [ede985ff4b569ed2454024f8bb107a6729fe08aa]
CVE-2026-64593: btrfs: do not trim a device which is not writeable
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64593
Introduced by commit 499f377 ("btrfs: iterate over unused chunk space
in FITRIM") in v4.3-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1b1937eb08f51319bf71575484cde2b8c517aedc]
stable/5.10: [f41ae7e6664f3c4361129728f2c4d5f3ed995251]
stable/5.15: [210af872eafa0cf572a84cb303c0f9d2914c1226]
stable/6.1: [3d8fa4b828a86b33c60858e58aaab6df273ede05]
stable/6.12: [02c903fc6fc7e16c5d1f22d18784f1208acf43e3]
stable/6.18: [7a64521802997257b144e6edfb4e278dbeb972dd]
stable/6.6: [9c894159c5b8adc84072e3af0e55b0473a69564e]
stable/7.1: [b4af31b898a948e29861cb0bae734058f9a49d9b]
CVE-2026-64594: usb: gadget: f_fs: initialize reset_work at allocation time
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64594
Introduced by commit 18d6b32 ("usb: gadget: f_fs: add "no_disconnect"
mode") in v4.0-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3137b243c93982fe3460335e12f9247739766e10]
stable/5.10: [7fe895e0a9651518c4fc082487da770ff9c14c7f]
stable/5.15: [0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7]
stable/6.1: [cb19e54ebe9baf3c3243083ade65c937339ccb7b]
stable/6.12: [c36393b0d14e1e9783888f821ffe29381b8f46dc]
stable/6.18: [69faa3779250df14f51d5084f938a99809546e52]
stable/6.6: [d5631081be07f20e764d3cb5c98ac0a1004fba51]
stable/7.1: [ba1867999dbc4085e6d8c52ac5266005b8b2bf07]
CVE-2026-64595: HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64595
Introduced by commit d69ccfc ("HID: hid-lenovo-go: Add Lenovo Legion
Go Series HID Driver") in v7.1-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [73fde0cbff7d9d618591774a12c23434232752c1]
stable/7.1: [3e7761f7bf9f0187bb18cf52b5119bdf4940e686]
CVE-2026-64596: libfs: set SB_I_NOEXEC and SB_I_NODEV by default in
init_pseudo()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64596
Introduced by commit 1e7ab6f ("anon_inode: rework assertions") in v6.16-rc5.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6de2aeffabaafaeda819e60ec8d04f199711e11a]
stable/6.18: [b9d45d328fcda4f0d3d281b7d6f12d3f181d9381]
stable/7.1: [8e931557b317f0fb414839fa51fae1d5feb0ad97]
CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64597
Introduced by commit 4f1fffa ("cifs: commands that are retried should
have replay flag set") in v6.8-rc2.
Fixed in v7.2-rc1.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [f96e1cdcb63ed3321142ff2fcdf784e32cda8fee]
stable/6.12: [0aa97edf7c347c0f54e7e60c4740574b8120c66a]
stable/6.18: [d15d83125007f673aec4323e1bbbaaffbe87ea13]
stable/6.6: [037511726228aaf165c7067ff2bfc88eaecdf1f3]
stable/7.1: [b18ed621dbfceecea5539848cddcb9272c9a61e1]
CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64598
Introduced by commit d08089f ("cifs: Change the I/O paths to use an
iterator rather than a page list") in v6.3-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [61f28012e5650c619223decdb7970e0d3162e949]
stable/6.12: [cad756733dc3985188983f3e2eb77e2927209099]
stable/6.18: [a187883cc1dc784a4d32537f5d316f1b7b9ad76f]
stable/6.6: [aa37f5fef78dd11cbf983269da2031e12625c56d]
stable/7.1: [a1cc432cb0b0a1f74f98a0db3b94ca880c7947ac]
CVE-2026-64599: crypto: amlogic - avoid double cleanup in meson_crypto_probe()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64599
Introduced by commit 48fe583 ("crypto: amlogic - Add crypto
accelerator for amlogic GXL") in v5.5-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6d827ade51a24e18d81afb9f32756d339520a14c]
stable/5.10: [c2c48aa7a6be36d4c93da75d14d4b4f2f4168c81]
stable/5.15: [c80360b4e85099fc3835378a96a59c0a2480fb07]
stable/6.1: [5b452019a4127f63c1f2147237fc287d1581f606]
stable/6.12: [6effdbaca3cd8354540bdf42c7f5fb84412afeb7]
stable/6.18: [84a00be9b736aa5dce902a290f62cbbbdcfab9ed]
stable/6.6: [f30e2b879bda14bc3e1524fba6f8ab9ec119da90]
stable/7.1: [6dda8406d8a3da2519c8b388d443d7357839cb63]
CVE-2026-64601: ALSA: us144mkii: capture_urb_complete: redundant
usb_anchor_urb corrupts anchor list on each resubmission
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64601
Introduced by commit c1bb0c1 ("ALSA: usb-audio: us144mkii: Implement
audio capture and decoding") in v6.18-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5cff1529a2f9b3461a7f5a6e36a86682fc290534]
stable/6.18: [16f14f55141d4c55c3f321f93c328fff7cd6860a]
stable/7.1: [ab1db64912428cdf06a4f9542e16e0575e9ad59f]
CVE-2026-64602: iio: adc: spear: Initialize completion before requesting IRQ
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64602
Introduced by commit b586e5d ("staging:iio:adc:spear rename device
specific state structure to _state") in v3.16-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0]
stable/5.10: [aea8ae6c4d3ed58d9223360f758df6bd8b90c608]
stable/5.15: [67a49ab41320b3f721ce4be7447754ff040acbd5]
stable/6.1: [a50757398794aaa25f908b96c6733e045466cba4]
stable/6.12: [37077d8271b1f24894fbc21bca1c4cd337525d31]
stable/6.18: [bbfebae473ac2c8a194523b29ccb9b45f02f134c]
stable/6.6: [f3f90bc7b38ba3ff14f131cea0f8eb77624787a8]
stable/7.1: [eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4]
CVE-2026-64603: platform/x86: intel-hid: Protect ACPI notify handler
against recursion
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64603
Introduced by commit e2ffcda ("ACPI: OSL: Allow Notify () handlers to
run on all CPUs") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c085d82613d5618814b84406c8b2d64f1bc305e7]
stable/6.12: [a6402808e552e44e9c26a9fe8395ac11703d5800]
stable/6.18: [86df6499dfd232fbc1c82c0d6eb9322ca67b8cd0]
stable/7.1: [eace3b3e729d5ba11794d69acfafb58a7950217c]
CVE-2026-64604: KVM: VMX: Grab vmcs12 on CR8 interception update iff
vCPU is in guest mode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-64604
According to the .vulnerable file, this bug was introduced by commit
a7c0b07 in v3.18-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7ef78d71ca713d8c00f7c34ddcf276c808143f77]
stable/5.10: [c7cd3605244c924249dea32632e1bc3e89bda543]
stable/5.15: [9a21f1defd96c6301c5fb462a78eb51b191bd2dd]
stable/6.1: [570af5db081b87374594a00711ac5760d2ea6844]
stable/6.12: [258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4]
stable/6.18: [3dcfb04dd43b16fa1240fc6487fff578ad57264c]
stable/6.6: [ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a]
stable/7.1: [db8407b9fd06d857a4a5e8bcff1d086d13007711]
CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68480
Introduced commit is not determined.
Fixed status
mainline: [7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9]
stable/5.10: [9de1a49e8f1fbf7c372902573a27a97d4ab4d0af]
stable/5.15: [9c0b8105e919be5208c81d5516a194a28c58fe1e]
stable/6.1: [95b08cdd603fe79d2e9d5212fbb13d577c835f4f]
stable/6.12: [e262f28a69ae9e0791248f93b0173c1d1f3e1d5d]
stable/6.18: [bfe7f9993467ba431b2731437949ac1e2634e771]
stable/6.6: [608c8f5dccaaf8b8d2b28c0fbdd439d144be62b0]
stable/7.1: [61649a2d61cb0dbc673f0f232f0f0c298bf50442]
CVE-2026-68081: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails
due to invalid guest state
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68081
Introduced by commit 96c66e8 ("KVM/nVMX: Use kvm_vcpu_map when mapping
the virtual APIC page") in v5.2-rc1.
Introduced by commit 3278e04 ("KVM/nVMX: Use kvm_vcpu_map when mapping
the posted interrupt descriptor table") in v5.2-rc1.
Introduced by commit fe1911a ("KVM: nVMX: Use kvm_vcpu_map() to
get/pin vmcs12's APIC-access page") in v6.0-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2f2312c422fd2695da772cecb30c69994b795964]
stable/6.18: [7996013b85687034d2e820cef94d6404192e3a3d]
stable/7.1: [2c87a087c20632d68920272173b5d7c47f9bcf70]
CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68082
Introduced by commit d4ed4a5 ("libceph: support for lock.lock_info")
in v4.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a109a556115271ca7896dcda7b4b7e45e156c227]
stable/7.1: [a54be593d0b749161b08a1e56189b2cb9114267a]
CVE-2026-68083: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68083
Introduced by commit 265fd19 ("ksmbd: use LOOKUP_BENEATH to prevent
the out of share access") in v5.15-rc3.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1c8951963d8ed357f70f59e0ad4ddce2199d2016]
stable/6.12: [489d1ded01425c0fb33418172c0e4e588467526b]
stable/6.18: [c7c884a1305aa4540eb7942a50bd356b34120e1f]
stable/7.1: [98185b3025beeae92d1fe700d5db26b9ac4bf025]
CVE-2026-68084: staging: vme_user: fix location monitor leak in tsi148 bridge
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68084
Introduced by commit d22b8ed ("Staging: vme: add Tundra TSI148 VME-PCI
Bridge driver") in v2.6.32-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [151edde741f8bc7f2931c5f44ab376d32b0c8beb]
stable/6.1: [18be0ad31b161a8b6fbc90d14355ad40c061b6b0]
stable/6.12: [36902ab588ccc2fa07994adf6c5f51cbfe379177]
stable/6.18: [e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46]
stable/6.6: [eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6]
stable/7.1: [c6cda17e98545980e42291fc4282daa8a8ebe384]
CVE-2026-68085: Bluetooth: hci_uart: clear HCI_UART_SENDING when
write_work is canceled
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68085
Introduced by commit c1bb933 ("Bluetooth: hci_uart: fix UAFs and race
conditions in close and init paths") in v7.1-rc5.
Fixed in v7.2-rc3.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt cip/6.12 stable/5.10 stable/5.15 stable/6.1 stable/6.12
stable/6.18 stable/6.6
Fixed status
mainline: [1b0d946d6f08bd39211385bc703a440911b41e46]
stable/6.12: [d52446b3e735cfdbdc2a58342163803bc2e64249]
stable/6.18: [b9dd39cf1667e378b25a082ca796d495d578c5d3]
stable/7.1: [714d861d35d937f23375a4517569b13917bbbe51]
CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68086
The code was removed from upstream by 044925f ("mm: fs: remove
filemap_nr_thps*() functions and their users"). So, this fix is not
backported from upstream.
Bug introduced commit is not backported to older stable kernels.
Fixed status
stable/7.1: [2dfe9f5c91d0963058f8a5e46e1c2a908382cc46]
CVE-2026-68087: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68087
Introduced by commit 5e013ad ("HID: wacom: Remove static
WACOM_PKGLEN_MAX limit") in v6.15-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [55f1ad573e34abf9a0443c34bc5a63d74edba7d7]
stable/6.18: [bbe1e55629bfaabd4b2e8125b48dd3503d74ac8b]
stable/7.1: [27c4dad1b7917b747bf080792a527997e3147c69]
CVE-2026-68088: usb: gadget: function: rndis: add length check to response query
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68088
According to the .vulnerable file, this bug was introduced by commit
340600a in v2.6.13-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [95f90eea070837f7c72207d5520f805bdefc3bc5]
stable/5.10: [efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e]
stable/5.15: [bb2b4402b4571b0c989b977779f7be01107ca425]
stable/6.1: [585921866d2d7d65d4b0d89927c78f784668cf5f]
stable/6.12: [f5870777458d8be65d7cd08bc750a03f17998350]
stable/6.18: [e01e7814b4223560eab0513b7c15b8c82bdc83f3]
stable/6.6: [caea8b120604312bab2bfeb1a972f9cd17019e93]
stable/7.1: [b09716040f3fa4a252eeda3ceb5295ea0e39c1fb]
CVE-2026-68089: iio: core: fix uninitialized data in debugfs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68089
Introduced by commit 6d5dd48 ("iio: core: make use of
simple_write_to_buffer()") in v6.15-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ab92ed206d41fd171ebd37bc46360d9f2140d043]
stable/6.18: [e166a8cfb28a3d0da260dd70cae274eb8c7cec8d]
stable/7.1: [89fbd3e32dffb6227f936a9578e6eb4632aa4580]
CVE-2026-68090: debugobjects: Plug race against a concurrent OOM disable
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68090
Introduced by commit b84d435 ("debugobjects: Extend to assert that an
object is initialized") in v3.3-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b81dde13cc163450dcb402dcc915ef13ba241e01]
stable/5.10: [2d5e320b7ab9b25229ac4331541964a58b5e1d29]
stable/5.15: [203a965bf2ab43130778d8214fb0c3c8c2d19cdf]
stable/6.1: [23da32e88627e63e0864f59f4c63a2dc0ab851a3]
stable/6.12: [e2e255d07723c330dded8e576ce28a8d23a692ce]
stable/6.18: [c00164c9e7fa6145886ad666806cb5347895de5c]
stable/6.6: [d663fbf28b2eebe665bb9cf828d7d528e5a8707e]
stable/7.1: [1f4f02b336c3be125c8fcf87df73db2e0e028b8b]
CVE-2026-68091: HID: wacom: stop hardware after post-start probe failures
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68091
Introduced by commit c1d6708 ("HID: wacom: Do not register input
devices until after hid_hw_start") in v6.8-rc5.
Fixed in v7.2-rc1.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt stable/5.10 stable/5.15 stable/6.1 stable/6.6
Fixed status
mainline: [ec2612b8ad9e642596db011dd8b6568ef1edeaa1]
stable/5.10: [5a7ca028facf04921b2c1c2e4d1ee7f282510555]
stable/5.15: [3e6473a4f0596182acdda5219b4bebfbee76514f]
stable/6.1: [46d8b8c85ae0589fb85746a64e8908160e52aac3]
stable/6.12: [75eb2173b63ab41c24d80cd641af18f3c117a267]
stable/6.18: [416095e9a6037b4b39fcadd0d2bd77a8852211ec]
stable/6.6: [1a1ebdcb56ae58a0ee2c54dd15d75121e30424e3]
stable/7.1: [e2cc711a9df37f359159b21db56cea9c21f58a9c]
CVE-2026-68092: time/jiffies: Register jiffies clocksource before usage
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68092
Introduced by commit 76031d9 ("clocksource: Make negative motion
detection more robust") in v6.13-rc2.
Fixed in v7.2-rc1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [f24df84cbe05e4471c04ac4b921fc0340bbc7752]
stable/6.12: [fe9bdea65ba231fcfb155031628bb1e8491b5fe0]
stable/6.18: [cd25e9819620aa1325897912cfb4dd89303325fe]
stable/7.1: [75b478096c6bbf57fe366f7f0a8cd5365043ffaa]
CVE-2026-68093: KVM: SVM: Bump asid_generation on CPU online to avoid
ASID collision after hotplug
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68093
Introduced by commit 774c47f ("[PATCH] KVM: cpu hotplug support") in
v2.6.21-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [25f744ffa0c8e799e06250ce2e618367b166b0d4]
stable/6.12: [7508916b4b55d6f5ecc68cd09774dabd3a6b4440]
stable/6.18: [0f33b1c457c2199ed130b92cc2ff363a3f7b9415]
stable/6.6: [60283726f2845bd78b95efbd0e50b93944780477]
stable/7.1: [6b542d116acecb83a1ca34e8eace304cff6a4ec9]
CVE-2026-68094: sched_ext: Preserve rq tracking across local DSQ dispatch
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68094
Introduced by commit 7fb39e4 ("sched_ext: Save and restore
scx_locked_rq across SCX_CALL_OP") in v7.1-rc2.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [18d62044cda7a2b40f59d910659c0b0d6accad37]
stable/7.1: [97c09c9f5739b8757ee29dabb0af30069137e286]
CVE-2026-68095: fuse-uring: fix race between registration and
connection abortion
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68095
Introduced by commit 24fe962 ("fuse: {io-uring} Handle SQEs - register
commands") in v6.14-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [952b5d36f6a298f57c52a59e72076c69386a8aaf]
stable/6.18: [3bca70235a706de76fe9a81defd37d987062c686]
stable/7.1: [2cd945492bc5b472e814272e88b731bb9bb17629]
CVE-2026-68096: audit: fix recursive locking deadlock in audit_dupe_exe()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68096
Introduced by commit 34d99af ("audit: implement audit by executable")
in v4.3-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [81905b5acbe77284734438df3fbec1158e6429a3]
stable/6.12: [7d1f66c69898ffb1a718926c32a777ecc471caca]
stable/6.18: [40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8]
stable/6.6: [36eb77f14b4e6f2dc1008c1fabe31236397be27a]
stable/7.1: [3b601938314c24fcd1afb6659cad92fe96c9c2f8]
CVE-2026-68097: ksmbd: validate ACE size against SID sub-authorities
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68097
According to the .vulnerable file, this bug was introduced by commit
e2f3448 in v5.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5152c6d49e3fd4e9f2e857c57527aead752f1f87]
stable/6.12: [62d80d7c2d9428085e7458ad4c06ca8c0984039b]
stable/6.18: [337022d9dfac441c3b35e4455a51aa981996e02e]
stable/6.6: [b7cb5bf0855470799f12da825de91e48951b3876]
stable/7.1: [61fd3559199f7fa693dcbff35e59477e24af041a]
CVE-2026-68098: ksmbd: bound DACL dedup walk to copied ACEs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68098
According to the .vulnerable file, this bug was introduced by commit
e2f3448 in v5.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [58d97fcd0bf1aee694e244cc28635b9df95b543b]
stable/6.12: [b057a851129c6a084e7e393b62ca3abf6c2660bc]
stable/6.18: [f1eba60db813ec28732bf18b5f0a67ebac9c3100]
stable/6.6: [6d9d7aa4a2c99c31acfa28921c30b684110cf66c]
stable/7.1: [a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3]
CVE-2026-68099: ksmbd: restore DACL size on check_add_overflow() to
avoid malformed ACL
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68099
Introduced by commit 299f962 ("ksmbd: use check_add_overflow() to
prevent u16 DACL size overflow") in v7.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [bbf0a8e931204ecdab494a88d43b0a24a04285c5]
stable/6.12: [0bf38372821b1526f31538a7d9811844c55c7f38]
stable/6.18: [847ecd4eb3c117c3d2f13f1e7ab506543aad8183]
stable/6.6: [f4fcd0c1a243d449307b887fafee23921e9db5ab]
stable/7.1: [bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13]
CVE-2026-68100: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68100
According to the .vulnerable file, this bug was introduced by commit
e2f3448 in v5.15-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [47f0b34f6bc98ed85bfdc293e8f3e432ec24958d]
stable/6.12: [fb3dc8e6da46a1ccad1956cda57de29d9b3033e0]
stable/6.18: [b6d3cc6a524416dfdb2b47e4bba2e7e20011d056]
stable/6.6: [e31fada5143784bc05c7ae44c79eed9b7a2e147e]
stable/7.1: [5acbd3012fd4a7ccfebd91ea6f784120084eb897]
CVE-2026-68101: drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68101
Introduced by commit 9125089 ("drm/amdgpu: fix waiting for all
submissions for userptrs") in v7.2-rc1.
Fixed in v7.2-rc2.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [52f650963d8825e97a0ccdd2b616f8a01d9d3d38]
stable/6.18: [15a7cb71a5748a718453f3b01e1da3b52349c043]
stable/7.1: [be354ea7261c2fa43d2c78fc1192ddae08bdbffc]
CVE-2026-68102: drm/amdgpu: fix aperture mapping leak
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68102
Introduced by commit 9d0af8b ("drm/amdgpu: pre-map device buffer as
cached for A+A config") in v5.13-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ea772a440d56b285f4d491affac50ecd41f6b402]
stable/6.12: [a343d028ad6c174da8dc6af560c51e6d140a6727]
stable/6.18: [6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa]
stable/6.6: [67bc3647e418e23dc0d17604bdba634a73de809f]
stable/7.1: [f5988b5c300a32ff751724ffd33d5a8d5873e4a7]
CVE-2026-68103: drm/amdgpu: reject mapping a reserved doorbell to a new queue
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68103
According to the .vulnerable file, this bug was introduced by commit
8949843 in v6.16-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a609b6278bf3cde17eeee6620091465521e4b02c]
stable/7.1: [1050d258c7c56066d2dcaedf8d0ef66364062adc]
CVE-2026-68104: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68104
According to the .vulnerable file, this bug was introduced by commit
2503032 in v4.6-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [28c9b3c5dc35cc790d11e26ca3fc6e068be63998]
stable/6.12: [5c0a82283271759fff445ac27182072f200a888c]
stable/6.18: [08fee493e0261f9e4120a5c8e7e42e8a723574e8]
stable/6.6: [bdfc7f1e0900ef1361b828c4f69b72701f8a0a86]
stable/7.1: [930a5dc3df4aa5e10393134bd5313d616dbebaf6]
CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68105
According to the .vulnerable file, this bug was introduced by commit
52cb80c in v6.11-rc1.
Fixed in v7.2-rc2.
The gfx_v12_0.c was added by 52cb80c ("drm/amdgpu: Add gfx v12_0 ip
block support (v6)") in v6.11-rc1. The gfx_v12_1.c was added by
ad5f1ee ("drm/amdgpu: Add initial support for gfx v12_1") in v7.0-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a279bd143b3c184358b658e43a057e31ee8c4de5]
stable/7.1: [5bc93f907bad7e076d814664dfab8fc230efca3d]
CVE-2026-68106: drm/amdgpu: fix division by zero with invalid uvd dimensions
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68106
According to the .vulnerable file, this bug was introduced by commit
d38ceaf in v4.2-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0c01c811be47e6b146552dd59bfedbea8f09b8f4]
stable/6.12: [a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf]
stable/6.18: [ffb33d466a68cea3e8a3dbed04d79037a3cbabd1]
stable/6.6: [52f9a588296432accf2982f7d258192a37562f4f]
stable/7.1: [be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc]
CVE-2026-68107: drm/amdgpu/vcn4: avoid rereading IB param length
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68107
According to the .vulnerable file, this bug was introduced by commit
2b10cb5 in v6.17-rc6.
Fixed in v7.2-rc2.
The vcn_v4_0.c was added by 8da1170 ("drm/amdgpu: add VCN4 ip block
support") in v5.19-rc1.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.6
Fixed status
mainline: [3b4082fabc67c9780b06eb959e59dd92fa79c0f0]
stable/6.12: [ff6aa542d91d76a185f69bd1997b94a560ff5f6b]
stable/6.18: [bd868c077f67589ed2a714307ceaade5f246e302]
stable/6.6: [bbbe6a2a8d8dc87243438d3ffea2083b52d882d9]
stable/7.1: [c309626bf91fa0a0b583575654e6e14e81f818a3]
CVE-2026-68108: drm/amdgpu/vce: fix integer overflow in image size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68108
According to the .vulnerable file, this bug was introduced by commit
f1689ec in v4.2-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [186bfdc4e26d019b2e7570cb121964a1d89b2e5b]
stable/6.12: [a6d7065b91a14790980ce6f4960db0ca8c3c9940]
stable/6.18: [7eebef042c12dfe0568593ee6a8926d16505925e]
stable/6.6: [a07430abd556de3707adfcadcc60db3fa64e4b2b]
stable/7.1: [00c311a13d225266800c712f2b7db2711c6897de]
CVE-2026-68109: drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68109
According to the .vulnerable file, this bug was introduced by commit
4ed5116 in v7.0-rc1.
Fixed in v7.2-rc2.
Affected file was added by 4ed5116 ("drm/amdgpu: Add sdma v7_1_0
support") in v7.0-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [767648c18d7872bbf54481ba846e055f7e1c0213]
stable/7.1: [253b1401862b9eb2be54f63546505a40a14672dd]
CVE-2026-68110: drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68110
According to the .vulnerable file, this bug was introduced by commit
7138fc8 in v6.4-rc1.
Fixed in v7.2-rc2.
Affected file was added by 7138fc8 ("drm/amdgpu: add sdma v4_4_2
support (v4)") in v6.4-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [40cdbe9fa424cc6264a7aed93a04bd7d69109d9e]
stable/6.12: [ca50e541191fab519ed628182e1472e21d60e2ce]
stable/6.18: [dc3f5da1ba8e280d31676ce15b937e4302235b03]
stable/6.6: [256d6f4803a93df96579c1ffdcb56518b9304f76]
stable/7.1: [cbe3b293d0ee926e595f53513d7c027d1c3e5be5]
CVE-2026-68111: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68111
According to the .vulnerable file, this bug was introduced by commit
b102357 in v4.12-rc1.
Fixed in v7.2-rc2.
Affected code were added by b102357 ("drm/amdgpu: implement GFX 9.0
support (v2)") and 72408a4 ("drm/amdgpu: enter rlc safe mode before
set cgpg").
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6302be10b521f5106ce01eb5a724b9e7945a5061]
stable/6.12: [d74a6351d3f64e1f8a0fba28b369c0eeecf517f1]
stable/6.18: [042c047e8bc9c9ada7574028a8e4592102e2e1fd]
stable/6.6: [6c8b9c1f03c7169c9577098b0c3035617606f8d4]
stable/7.1: [43768ad42b8f1a91652b86e0731ac14d6853cebb]
CVE-2026-68112: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68112
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 8630112 ("drm/amdgpu: split gc v9_4_3
functionality from gc v9_0") in v6.5-rc1.
Fixed status
mainline: [00f4050f7c367d7bdce347ca279ce467c434cf15]
stable/6.12: [cfb02825277526bd216b56be555a97a9e8612682]
stable/6.18: [05aea3344c422fe95299bb1b21a04de30c7ea198]
stable/6.6: [c59b57c2e0c8cced4350ff7792361ba2a79ee85c]
stable/7.1: [ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7]
CVE-2026-68113: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68113
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 52cb80c ("drm/amdgpu: Add gfx v12_0 ip
block support (v6)") in v6.11-rc1.
Fixed status
mainline: [cd3b3efa1ced05528d9128755338baa62a6b562d]
stable/6.12: [eef69b826b2036314b59020dfa6083fc859bfcc1]
stable/6.18: [987bedd3ea89d747d1c5ab708ce3293e2f033b6c]
stable/7.1: [81597685c0d73b9c2e1a89c12c576ab80d1c00f4]
CVE-2026-68114: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68114
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by ad5f1ee ("drm/amdgpu: Add initial support
for gfx v12_1") in v7.0-rc1.
Fixed status
mainline: [6560e6bd76127844e39f09fa591c2791dc7932e8]
stable/7.1: [1c27e889fa162bc3590de0942237d2ccec96b765]
CVE-2026-68115: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68115
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by a644d85 ("drm/amdgpu: add gfx v10
implementation (v10)") in v5.3-rc1.
Fixed status
mainline: [d06c4173a7c38c7a39e98859f839ce714c7af2c9]
stable/6.12: [6c8cfdc2321c1284dc4320ac148867ea8f6419bd]
stable/6.18: [7e22de67e545d0f72595514d3a66675e9d074adc]
stable/6.6: [793cdf17ddf9dc662a94cae86ce005565ef3c1c2]
stable/7.1: [2929a932b0d70f481dbcb6994181544b07913de0]
CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68116
Introduced by commit a3a48de ("vxlan: mdb: Add MDB control path
support") in v6.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dcd9b465965422b9654f6026e8a2fa8984f74c3c]
stable/6.12: [2c54dff57606590fa4abec46bab6bea3133f1539]
stable/6.18: [79370b573e92e8f190eb5f9a511fa5398340d8b2]
stable/6.6: [5bc8fc1d2ff802eec839e03adef5df597421898d]
stable/7.1: [54a3c27b357dfb34f327f89bfadeb998bef8051e]
CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in
tipc_sk_create()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68117
Introduced by commit 00aff35 ("net: tipc: fix possible refcount leak
in tipc_sk_create()") in v5.19-rc5.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt stable/5.10 stable/5.15
Fixed status
mainline: [ba0533fc163f905fe817cfabdf8ed4058da44800]
stable/6.12: [dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea]
stable/6.18: [5f5a41a48dbf9eda57b67ce23e548602cf7195a6]
stable/6.6: [b07d87b31631edb6529e6cdcca790a7489d1250d]
stable/7.1: [f9596b1566616a8be0592dbceccb6344a7c6f6bb]
CVE-2026-68118: tcp: challenge ACK for non-exact RST in SYN-RECEIVED
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68118
Introduced by commit 282f23c ("tcp: implement RFC 5961 3.2") in v3.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a28c4fcbf774e23b4779cae468e3497a5ad1f4a1]
stable/6.18: [234f9ffbd9b2c1b24ec67200ea3cff07401bec48]
stable/7.1: [22cec809b048495310f206d9abbcdbbfbdce3ae3]
CVE-2026-68119: tcp: initialize standalone TCP-AO response padding
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68119
Introduced by commit decde25 ("net/tcp: Add TCP-AO sign to twsk") in v6.7-rc1.
Introduced by commit da7dfaa ("net/tcp: Consistently align TCP-AO
option in the header") in v6.7-rc5.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e1a9d3cc11829c5414a75eb39c704f461936eb24]
stable/6.12: [bbb7db8c74b0b5d17a695136f0f0806ecd0118f6]
stable/6.18: [fadaff3f66e124c3a62237f9c881819a8ac90309]
stable/7.1: [a859b280441fb02f64ed4037f03d5c0c34a7a595]
CVE-2026-68120: rtase: Workaround for TX hang caused by hardware packet parsing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68120
Introduced by commit d6e882b ("rtase: Implement .ndo_start_xmit
function") in v6.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1c50efa1faf3a1a96e100b07ec7a2f3164d90bee]
stable/6.12: [fe3a7320711eec6537e4890892f7ab9776d8618f]
stable/6.18: [4a4f3aa6af205bee539b5670afa2cd4e4953750e]
stable/7.1: [0f54f5048615e4e2802697855ea6374613548301]
CVE-2026-68121: pppoe: reload header pointer after dev_hard_header()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68121
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e9c238f6fe42fb1b4dba3a578277de32cb487937]
stable/6.12: [7e9fbd7f96bcde63a7c798fe16b38cedee7a1501]
stable/6.18: [6866abf59976d273164a6624234d96a967280223]
stable/6.6: [e6493a4d1ee17595766165fa446d45b7e0c318d0]
stable/7.1: [bed4caecd723693f750e13adbb2c42ca1249a3fd]
CVE-2026-68122: ovpn: fix peer refcount leak in TCP error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68122
Introduced by commit a6a5e87 ("ovpn: avoid sleep in atomic context in
TCP RX error path") in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [63bbe18fc03062f483c627838a566a707b62da79]
stable/6.18: [b08526bf0bbf84ceebd29033783e8e0c9f451286]
stable/7.1: [f08f39c1f43f3980d46b06af8ed99ffe84ac294a]
CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68123
Introduced by commit f2a4d08 ("openvswitch: Add packet truncation
support.") in v4.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4032f8ed10fcb84d41c508dfb04be96589f78dfe]
stable/6.12: [fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc]
stable/6.18: [100a23b1613e9218e0af654ef102352c713f0263]
stable/6.6: [a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855]
stable/7.1: [ea85dbcbe8d4056ecb54352f97743d138ea4c407]
CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx
buffer overflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68124
Introduced by commit a0c2ccd ("mctp: Add MCTP-over-serial transport
binding") in v5.17-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [793b9b729f1e8de57be8c8daf1a9838be96cabed]
stable/6.12: [68819427bc07eca7963a9e8be19e5272cc29186c]
stable/6.18: [f80ba170d7b3a44e3d244a2c8e06031d61bf3b23]
stable/6.6: [36dc6d6964a3b90411cc7944cd9b8b6f67b9807b]
stable/7.1: [06a6b606129c8a25cd457760f5370f3ff01fe05d]
CVE-2026-68125: mac802154: llsec: reject frames shorter than the
authentication tag
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68125
Introduced by commit 4c14a2f ("mac802154: add llsec decryption
method") in v3.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fd3a3f28ed60c6af4b2a39933b151d6b27842c3b]
stable/6.12: [de80808f37d99c6dc67bb6f97eea00c8f57a8821]
stable/6.18: [f20dedce0429b293d4bad604e0d3f65d8ac96c83]
stable/6.6: [5bbf0cd9b6a7076af86c75e87e180099be2e11ae]
stable/7.1: [e09e0301d616c1ef38a5e64e8e4326fd39df13cc]
CVE-2026-68126: mac802154: hold an interface reference across the scan worker
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68126
Introduced by commit 57588c7 ("mac802154: Handle passive scanning") in v6.3-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [234e5e898b713bc0b3a631b6f002897f43d046c8]
stable/6.12: [dd4754194a706163294b6141460101b99082c8c7]
stable/6.18: [59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b]
stable/6.6: [bd7110f0caa32426140ff302a209c53294ef2cfd]
stable/7.1: [5f303f622f6bb8907c405e5123a0ab0f70fb0065]
CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68127
Introduced by commit 33f11d1 ("ila: Create net/ipv6/ila directory") in v4.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [92d3817649df2b0b6a008a686c8275c88d7ef594]
stable/6.12: [7097a0280b178237265681be66d1bef11d15894b]
stable/6.18: [472aba2603ca74c4f7722cb0c0296942b0776b8d]
stable/6.6: [896a9512d0d83c2a4b357e5585b7b62a8e3f95c1]
stable/7.1: [c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc]
CVE-2026-68128: ice: reject out-of-range ptype in ice_parser_profile_init
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68128
Introduced by commit e312b3a ("ice: add API for parser profile
initialization") in v6.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [59abb87159c53605c063f6e2ceb215b5eba43ee6]
stable/6.12: [fe2f8d5a77adea38e889fe3d6cde1b76d4a635bf]
stable/6.18: [5e496f2b615cec4b45537cfb5b54f36a51dc8753]
stable/7.1: [33cc15aaf2491166dddc018b24b3b7db53ec01b2]
CVE-2026-68129: gve: fix Rx queue stall on alloc failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68129
Introduced by commit 9b8dd5e ("gve: DQO: Add RX path") in v5.14-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b65352a1bac64442ad95e64f385b40ccb9f1b0db]
stable/6.12: [0c317349b4baa5038d1fc373bf46d5a2419d1710]
stable/6.18: [91e0249f3ef62b75fe8c9c9372eaba32876e4b3a]
stable/6.6: [299d5728a7312fdd02059b074aebbe4ebbd391e4]
stable/7.1: [689b9f588d2d7323dc66293fe594a68d030f400f]
CVE-2026-68130: ksmbd: defer destroy_previous_session() until after
NTLM authentication
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68130
Introduced by commit e2f3448 ("cifsd: add server-side procedures for
SMB3") in v5.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c74801ee524f477c174a1899782b6c3b6918d407]
stable/6.12: [243f1614ef2aca2d62a744575f1c24b07cd42757]
stable/6.18: [18705cace0619fd2123737dcd028147774f38181]
stable/6.6: [5c833074b549e5db125436a6f681af682261f785]
stable/7.1: [0ff12308c8a6c16ab68f0a487ffa93d69001dc18]
CVE-2026-68131: rbd: Reset positive result codes to zero in object map
update path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68131
Introduced by commit 22e8bd5 ("rbd: support for object-map and
fast-diff") in v5.3-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4]
stable/6.12: [2419aa74081007dc4d14ff5640659052dfdfd69a]
stable/6.18: [34f2a2f32af570dfcc532ad70c080629ee1c32b0]
stable/6.6: [14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b]
stable/7.1: [b1a61366933224b3ad80975c4d01ac2cc6931ecf]
CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68132
Introduced by commit 08fdc8a ("buffer.c: call thaw_super during
emergency thaw") [1] in v4.17-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [749d7aa0377aae32af8c0a4ad43371e7bf830ab5]
stable/6.18: [63d78b546eefc38ad9898dc839bfc94811ede547]
stable/7.1: [4c483644d1a7709efe7d1be7dbf88cf4008a7864]
CVE-2026-68133: ice: fix PTP Call Trace during PTP release
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68133
Introduced by commit 8293e4c ("ice: introduce PTP state machine") in v6.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f6a7e00b81e35ef1325234925f2fe1e53b466f92]
stable/6.12: [7d517b255f669cedd09830214d55f2f413b34481]
stable/6.18: [e4406cbdd915f702d2ed9ee8b30683a16b06c6ac]
stable/7.1: [14fceda28069fdbe1bb49cdb6e1774892b583348]
CVE-2026-68134: ptp: ptp_s390: Add missing facility check
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68134
Introduced by commit 2d7de7a ("s390/time: Add PtP driver") in v6.13-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e78f1ac37afcb16cb6fef8a2c92591eab6558956]
stable/6.18: [b3efb4744abf493c9782eae713b861a80d9bbeca]
stable/7.1: [545a7fdbc110c82933d448db2695abff07536f08]
CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68135
Introduced by commit 701a0fd ("hip04_eth: fix missing error handle for
build_skb failed") in v4.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [14fa65d10f5696b063a7d8d26e8291ea84a2c6ed]
stable/6.12: [67a7614bde310da006ab259f4f163d3fb0f9e253]
stable/6.18: [80d977f280b4eccd4ac5369871d0ecb2b9c9a49d]
stable/6.6: [e054dcd990d8180cde529ea28ce0838e76a5ad5e]
stable/7.1: [a0f247d63489a107bbc3b712a77b302af2a2a173]
CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68136
Introduced by commit 3a1296a ("net: Support GRO/GSO fraglist
chaining.") in v5.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e751256486d0ded20f5a9f9863467f1dce65142f]
stable/6.12: [107e1a469f53a2a70874f3f12bf6fcd23925da1d]
stable/6.18: [a4dfd46cc8f08a29c6183794790547d0945f3d45]
stable/7.1: [fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0]
CVE-2026-68137: net/x25: fix use-after-free in x25_kill_by_neigh()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68137
Introduced by commit 7781607 ("net/x25: Fix null-ptr-deref caused by
x25_disconnect") in v5.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/4.4 cip/4.4-rt cip/4.4-st
cip/5.10 cip/5.10-rt stable/5.10 stable/5.15
Fixed status
mainline: [5499e0602d2faafd42c580d25f615903c3fbe11b]
stable/6.12: [610678d4be94b619c751572e8a58de705592cd07]
stable/6.18: [ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a]
stable/6.6: [3f4fe26c20c30bd5a2e2583e80685def0b27858c]
stable/7.1: [9aabda553184346f74810e2ee1d96920b4612e3f]
CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68138
Introduced by commit 470502d ("net: sched: unlock rules update API")
in v5.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f43ee0c0730d6191629b5ee1ceae27b1ebfdc047]
stable/7.1: [fb29e1b41052488ee3f2d115d4a870497ebd7f7d]
CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68139
Introduced by commit bf11485 ("net/mlx5: Register mlx5e priv to devcom
in MPV mode") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e32649b4bad90a6216d8e93cd7dd050af8ac9740]
stable/6.12: [c698b2735613f1f35c55688bd2252f75f31c49ad]
stable/6.18: [40f9a124ebbe0d60fe165fb3f87515c35b2d72f5]
stable/7.1: [a60c81f168c9fe4f5d84302d1e32b717f5a8a933]
CVE-2026-68140: net/iucv: fix use-after-free of a severed iucv_path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68140
Introduced by commit f0703c8 ("[AF_IUCV]: postpone receival of
iucv-packets") in v2.6.24-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a]
stable/6.12: [a5bbaddf69853117f28173c3f5c8fc14c6b2ec82]
stable/6.18: [900cd6d8119b7f3ae5c4bf82f922ff5957df43db]
stable/6.6: [23658b350b4107e8292045c2044983fd426fa15d]
stable/7.1: [f579582c03ed526281a8450159baf1d35099a85f]
CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68141
Introduced by commit 3881ac4 ("af_iucv: add HiperSockets transport")
in v3.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [47a5116e56a6b6fe1e909f244e39cd0fc26ceee4]
stable/6.12: [46453b16f38ec7147351f7447e2aec6ea330f7b3]
stable/6.18: [33736ff5e7c97d3348ce812e8bd2e125d840743c]
stable/6.6: [8bb111f87ded6acb9837ec9b45d6f02cda94c51f]
stable/7.1: [0e857185591fe79934427c9c0c1c31dc776be134]
CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68142
Introduced by commit 5b861f6 ("geneve: add rtnl changelink support")
in v4.14-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01]
stable/6.12: [9de5518fc1fab583526a8f66b8e505c4864dc60a]
stable/6.18: [f8c498585d2a08aa623748353c3e61467b7e9fd2]
stable/6.6: [2abdacc927c92fa6a9cc8341e8c9b88dcb561553]
stable/7.1: [95f45e20f1b2cec13823f0f68060ab4b2261b2c1]
CVE-2026-68143: net: slip: serialize receive against buffer reallocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68143
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d]
stable/6.12: [44401f7dd9940ced7098930ef64f5a332f279fc2]
stable/6.18: [5d07b178bef511d69558cfc89fe1129258dc39f8]
stable/6.6: [eb3836eab47487823f362e6985e170a1e15f20fd]
stable/7.1: [0e37bbd6d617eb52bace49390e99eaedc1af73ce]
CVE-2026-68144: phonet: pep: fix use-after-free in pep_get_sb()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68144
Introduced by commit 9641458 ("Phonet: Pipe End Point for Phonet Pipes
protocol") in v2.6.28-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0f71f852a96af9685858ce59fda34ecbf85c283d]
stable/6.12: [17f78c0c0d41d738ee236eb6e841e39395188054]
stable/6.18: [a48a889b60f73edb0399a8b08284a2ab0bd0295f]
stable/6.6: [8d931a75a38b9bb584a4071f5ebbd52755fc35ee]
stable/7.1: [25e3641beb51333bfbb155af2fd2573a61113af2]
CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68145
Introduced by commit 4ce02c6 ("iomap: Add per-block dirty state
tracking to improve performance") in v6.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9c7d8f7c8994c790fca501dc45ce66e7356cbe05]
stable/6.12: [fb4fad9105c88b1d82f1b3c39e3b6abea8249af6]
stable/6.18: [7037e7bdcd26f46c080b8ce307dee5cb471c4b7c]
stable/7.1: [c5b6a48a8a716a7730e39af1cad083dc4ec955ce]
CVE-2026-68146: ftrace: Add global mutex to serialize trace_parser access
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68146
Introduced by commit e704eff ("ftrace: Have set_graph_function handle
multiple functions in one write") in v4.11-rc1.
Introduced by commit 689fd8b ("tracing: trace parser support for
function and graph") in v2.6.32-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7720b63bcef3f54c7fe288774b720a227d54a306]
stable/6.12: [90be137813e1a5bdfd671e40fe28004fb959d3e4]
stable/6.18: [65bf73bee1a4f3722208ae46afc0fa5de76b9a0a]
stable/6.6: [3d0dd138a06c782f8b755cd1b6f9909494514ce1]
stable/7.1: [e807c9193d9493c7a0d039158ebb955050a76df1]
CVE-2026-68147: fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68147
Introduced by commit 22e9947 ("fscrypt: stop holding extra
request_queue references") in v6.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6fe4e4b8259e1330945b5f3c9476e08473b8e0e8]
stable/6.12: [97a688563be71ec6fefc071aff69a66c69dbe244]
stable/6.18: [81ea8e8221853950c47dac7164f27c63a96f8f86]
stable/6.6: [4462ac3d90e897dda52ce4b6af2d526ddae835a8]
stable/7.1: [bc2d630296e0e049210ec05ff08459a6893ae749]
CVE-2026-68148: fscrypt: Add missing superblock check in
find_or_insert_direct_key()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68148
Introduced by commit 22e9947 ("fscrypt: stop holding extra
request_queue references") in v6.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b5fa40226e71c17847b9ff2816c6ca4133d0d994]
stable/6.12: [deff41898a5ae3a47db5fa1896a494aa95efda5d]
stable/6.18: [95376fe9c145be35566991df99c53134943d992f]
stable/6.6: [330249609b70778094a7a36f5b6bcfa6362121d4]
stable/7.1: [466f187b501a5ac8e1ea2ccf3ccd5c46108d8830]
CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68149
Introduced by commit facd610 ("fuse: fixes after adapting to new posix
acl api") in v6.2-rc6.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4b9a5458d02e214ef2b384124ca626e3e381d778]
stable/6.12: [834ddf899484a2f23129080e8773bc04f4691d07]
stable/6.18: [a019b074903b3ad0a9726087efd0e8291452023b]
stable/6.6: [b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf]
stable/7.1: [ca03a7984a34f48085fd013e0d2cf4e6420b4acf]
CVE-2026-68150: fs/super: fix emergency thaw double-unlock of s_umount
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68150
Introduced by commit 2992476 ("super: use a common iterator (Part 1)")
in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [503d67fbaec6fdeaba391cb497675071db9d16ea]
stable/6.18: [c78e38745ff1b0457c4551e7f75ea15842df1169]
stable/7.1: [64017df6e61a3ce7159cee284109b92009985361]
CVE-2026-68151: binfmt_elf_fdpic: only honour the first PT_INTERP
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68151
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3349ef6a366a61d631f6a263d12cea240957719d]
stable/6.12: [21eaf5594a33d16343a011c752624099c30e918f]
stable/6.18: [89b9121c3b0162655fc2f190b714ae64f1aa8cae]
stable/6.6: [e4563e07ef5c938d5332c5c44721db976f214bc6]
stable/7.1: [69ecc199880bf7e8d06224c82dc411d18f9285f8]
CVE-2026-68152: amt: fix use-after-free in AMT delayed works
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68152
Introduced by commit cbc21dc ("amt: add data plane of amt interface")
in v5.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ea20c44935d6142daecfa9b39d635033a7553e1b]
stable/6.12: [a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2]
stable/6.18: [1a644db2cf59f164cdf3c75995bab5aadc097528]
stable/7.1: [006340cf06881b6ff49767d8b6f3c4f7b892670c]
CVE-2026-68153: libceph: remove debugfs files before client teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68153
Introduced by commit 76aa844 ("ceph: debugfs") in v2.6.34-rc2.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e4c804726c4afce3ba648b982d564f6af2cfa328]
stable/6.12: [d3dc8889d39a676bf840132bd5c5c48cb0daba23]
stable/6.18: [8f5a3abc54ba24dbceb14cc3a719908c4f688091]
stable/6.6: [fc1010e7e0204ece6cc0f9af4f473e9553535eab]
stable/7.1: [b9fedda2f628e030384228de0dafc574b7fb0c2f]
CVE-2026-68154: libceph: reject zero bucket types in crush_decode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68154
Introduced by commit f24e998 ("ceph: OSD client") in v2.6.34-rc2.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [05f90284223381005d6bcddab3fda4a97f9c3401]
stable/6.12: [826cd1de5802fd392922785f9b64d76e65d2a100]
stable/6.18: [3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56]
stable/6.6: [b8a9fb6bf806f9c4891e71ae1beab0c07c23a877]
stable/7.1: [70998f91030ee083ecb336a1dff0701c20a38081]
CVE-2026-68155: libceph: Reject monmaps advertising zero monitors
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68155
Introduced commit is not determined.Fixed in v7.2-rc5.
Fixed status
mainline: [40480eee361ed9676b3f844d532ac28b47251634]
stable/6.12: [cd0d41bc569632eaaeccde9d2a6bc919ec00c407]
stable/6.18: [e67e8b694872c9bc66996040f9de9242f6236ed9]
stable/6.6: [0591a15815b498be628a937146e44487d599ba33]
stable/7.1: [3b249546f59c3d6d3592c10657f82bc3f1faa07c]
CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after
authorizer update
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68156
Introduced by commit 0bed9b5 ("libceph: add update_authorizer auth
method") in v3.10-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [937d61f86d377a3aa578adae7a3dfcecdddf9d89]
stable/6.12: [75e82e8944ac1efe9fdb88bd2f14d9a031282bdf]
stable/6.18: [0060ec912292a550198d8d18ac95b433c92a7091]
stable/6.6: [9d37aec9ffe4e743dabc3f84502e9723e17a30d4]
stable/7.1: [5ecfcd5c05866f185357700b81b461dae4f5ebb2]
CVE-2026-68157: libceph: guard missing CRUSH type name lookup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68157
Introduced by commit 117d96a ("libceph: support for balanced and
localized reads") in v5.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bbeae12fda3384a90fbebc8a19ba9d33f85b5361]
stable/6.12: [3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50]
stable/6.18: [4716a64b7cc2797741f7be4e283ace78a9dff37d]
stable/6.6: [c46d82c47afc968d6ee8ef4470fa2dd35b765c21]
stable/7.1: [db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d]
CVE-2026-68158: libceph: Fix multiplication overflow in
decode_new_up_state_weight()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68158
Introduced by commit 930c532 ("libceph: apply new_state before
new_up_client on incrementals") in v4.7.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.4 cip/4.4-rt cip/4.4-st
Fixed status
mainline: [98917a499ec7064c14fc56d180a4fd636fc2784c]
stable/6.12: [143ba49ead77ec483c0326f8aaad8649874e99c4]
stable/6.18: [1732d89dfcd74f6fde9ce70900d316c4a151c153]
stable/6.6: [05c90e059269f087becfcce23348496085835c29]
stable/7.1: [bee4b5b53e7bff0467fd916cc44c9b190733c6bd]
CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to
CEPH_PG_MAX_SIZE
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68159
Introduced by commit a303bb0 ("libceph: introduce and switch to
decode_pg_mapping()") in v4.13-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9f00f9cf2be293efe899db67dc5272e3a9c62717]
stable/7.1: [e36663145abd7024f0281dfb22fdef65f185845b]
CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in
ceph_handle_caps()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68160
Introduced by commit a8599bd ("ceph: capability management") in v2.6.34-rc2.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02]
stable/6.12: [03b417afce19ee6b6e61f1bbbbebac924c9f36d1]
stable/6.18: [a4228b93706fb74a484e6ffb271c1cc2af3a2ddb]
stable/6.6: [9081c71796724ffe96cba253f68fbe42363c5295]
stable/7.1: [71893c342a26bcff92eaab0b2b75d64aed19308a]
CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68161
Introduced by commit 046c052 ("sctp: enable udp tunneling socks") in v5.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ffb2bd7ade36ec4da32c46a6eddbf4515316d08c]
stable/6.12: [8ff78591d309c50a4fdab683b68dd8d512a270dd]
stable/6.18: [3bf0e349cbb4f975f35eb22753acc346b89c66a0]
stable/6.6: [c6eb2d615210b80339548ab07c0230edaab9a6c7]
stable/7.1: [37ff9794be48d0caa37687e04d09675f9c849121]
CVE-2026-68162: sctp: avoid auth_enable sysctl UAF during netns teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68162
Introduced by commit 15649fd ("sctp: sysctl: auth_enable: avoid using
current->nsproxy") in v6.13-rc7.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/4.4 cip/4.4-rt cip/4.4-st
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [f8d5e7846025f4ab15a461235f8ebae9094a361a]
stable/6.12: [626bda8cfe43dff19a9833ff6ba055a817b5455c]
stable/6.18: [be6aae9d1b91c603adb35872d37d40e83daf8758]
stable/6.6: [66700c0719675e0e118ae83b2d7168dacd69dd3d]
stable/7.1: [a50e73488e0bbdd262b3be3c9a1d8dd078382381]
CVE-2026-68163: mm/page_vma_mapped: fix device-private PMD handling
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68163
Introduced by commit 65edfda ("mm/rmap: extend rmap and migration
support device-private entries") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f84ca9b1888d8fce7dfefe0e750fa971f8797486]
stable/7.1: [ab6209f4b48a98ef14d6766acdb62aa9bb32e670]
CVE-2026-68164: mm/damon/core: disallow overlapping input ranges for
damon_set_regions()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68164
Introduced by commit 97d482f ("mm/damon/sysfs: reuse
damon_set_regions() for regions setting") in v5.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [954157679ec34661c2e87e7eb796104a797c32db]
stable/6.12: [06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd]
stable/6.18: [6ce0db97fb37ab8cf8596edca0e3de8618ab009a]
stable/6.6: [4b4a3e7ef7bb622237495db9ba4dfd7417d6530e]
stable/7.1: [e33adf96afb5883f84b0d98747976bde293e33cb]
CVE-2026-68165: mm/damon/core: validate ranges in damon_set_regions()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68165
Introduced by commit 43b0536 ("mm/damon: introduce DAMON-based
Reclamation (DAMON_RECLAIM)") in v5.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1292c0ecb1caefb8ca064a3639d5673991e8810c]
stable/6.12: [c927b73a5694c735314ea10e7c81c07f9bd51ad7]
stable/6.18: [4b6f1d6d5d07855bd1bb9e64922b049062138bfa]
stable/6.6: [b585facbafbb5cf117b37b1c75819ac046646c27]
stable/7.1: [43aaddd0fa92010a68adeda7744c7cf497a1c8e9]
CVE-2026-68166: userfaultfd: prevent registration of special VMAs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68166
Introduced by commit 54007f8 ("mm: Introduce VM_SHADOW_STACK for
shadow stack memory") in v6.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3c58f641e813c3c71039f8fd4d4e2a3aab713288]
stable/6.18: [165613191ad9d034bf17c00e3a142f9561597ec5]
stable/7.1: [0c26202b157f1efc3cd2f26f5c30f59b508a6a5d]
CVE-2026-68167: btrfs: do not try compression for data reloc inodes
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68167
Introduced by commit 3eaf5f0 ("btrfs: extract inlined creation into a
dedicated delalloc helper") in v7.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ae4316f332e03e628712e9dfb89f2b7d3c70c21a]
stable/7.1: [31a62e4ad66313cf1ebaa00c2a17d644a4b87d22]
CVE-2026-68168: afs: Fix afs_edit_dir_remove() to get, not find, block 0
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68168
Introduced by commit a5b5bee ("afs: Use the contained hashtable to
search a directory") in v6.14-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [62d9853aa4ce6e9797b6949804891be14b219752]
stable/6.18: [f2b293359924117736218701ebd8b40618d73e6f]
stable/7.1: [bfdfc7782ada6f3a4df7182889b66039f8e4131c]
CVE-2026-68169: mptcp: pm: userspace: fix use-after-free in get_local_id
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68169
Introduced by commit f012d79 ("mptcp: check addrs list in
userspace_pm_get_local_id") in v6.8-rc5.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1 stable/6.6
Fixed status
mainline: [9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9]
stable/6.12: [31ce5af66891f79998fb2e8b8df08e3c98fd72e3]
stable/6.18: [d64f6c02495f3fad674038cfa7ec049671b59e7b]
stable/6.6: [d2c3760b45f2f481a4dd4c5adef4a29dfabd948f]
stable/7.1: [40dde4b5d98279471a70e5c8bb713182738c00d9]
CVE-2026-68170: mptcp: fix stale skb->sk reference on subflow close
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68170
Introduced by commit ee458a3 ("mptcp: introduce mptcp-level backlog")
in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bd7aae448f6ee9d82599a4474664de1e6e91a535]
stable/7.1: [625fc6060864889fe3d370cdeffbbab762af3cb4]
CVE-2026-68171: [REJECTED]: arm64: syscall: Ensure saved x0 is kept
in-sync with tracer updates
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68171
This CVE was rejected. Introduced by commit a5cd110 ("arm64/ptrace:
run seccomp after ptrace") in v4.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e057b94772328221405b067c3a85fe479b915dc8]
stable/6.12: [b7afd2a80593dde3f4a68c9a9f73752f9c340e85]
stable/6.18: [64ab0964c7db949abbd3c56268a220e2b77f7b9e]
stable/6.6: [8000a5f4d1d192f5bb3e4f29e7606a9460d376df]
stable/7.1: [e59c2476ef755221da31f4e26f6b89712ecf50f1]
CVE-2026-68172: arm64: make huge_ptep_get handled unaligned addresses
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68172
Introduced by commit 29cb805 ("arm64: hugetlb: Cleanup huge_pte size
discovery mechanisms") in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f73a8edc2ccc6ec72c37d5c578e7592d2e1f9922]
stable/6.18: [9cd4b1a52eff330798d668c1775f8bc450776280]
stable/7.1: [f3530aec26563f4d483ff31402392961362e9bc6]
CVE-2026-68173: ublk: wait on ublk_dev_ready() instead of ub->completion
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68173
Introduced by commit 728cbac ("ublk: move device reset into
ublk_ch_release()") in v6.15-rc3.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [432a9b2780c0a01caf547bd1fc2fcf28aeb8d173]
stable/6.18: [7dd26adf7e7d482af524e3a0cca4a81ef7c159d0]
stable/7.1: [8f188dd11a1c2ad94caeaee36ef68bb8221d4a12]
CVE-2026-68174: tracing: Fix union collision of module and refcnt for
dynamic events
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68174
Introduced by commit 4c86bc5 ("tracing: Add :mod: command to enabled
module events") in v6.14-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b4eb07bde606c2096b24252be589e735eff6d413]
stable/6.18: [b6a4575f22925da7e6aa00171e9fc0e5029c0bc9]
stable/7.1: [43a23dfe0024afd3d2b0232e987d0292919a9b24]
CVE-2026-68175: tracing: Fix resource leak on mmiotrace trace_pipe close
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68175
Introduced by commit c521efd ("tracing: Add pipe_close interface) in
v2.6.33-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c1d87e724ae55e781b7cc7ccafb34d9e668582b2]
stable/6.12: [594e1cf3f736779a535873fd5988162d827bfe4f]
stable/6.18: [cf5a82bef623b969a609f2b7e392d06dbae34aa6]
stable/6.6: [f9e6dfe341fb31c95b9655eb6b1db8b3ae090817]
stable/7.1: [cb459fec4f7b13caf646101ff076e94ef38434d8]
CVE-2026-68176: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68176
Introduced by commit f984b51 ("ftrace: add mmiotrace plugin") in v2.6.27-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [144f29e85702234b23d2a62abf723e6a17eb5427]
stable/6.12: [201a01102c529772168181190cb084471082cf5c]
stable/6.18: [8464427e1c177809a9488a97dfa2807d9dcf323b]
stable/6.6: [faaf95135184208ee3ac6f33175c8d1800669dfc]
stable/7.1: [724cd84b0546c07806840fa658714488553d13a2]
CVE-2026-68177: tracing: Delay module ref count for "enable_event" trigger
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68177
Introduced by commit 61d445a ("tracing: Add bulk garbage collection of
freeing event_trigger_data") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e091351b38818ef620d27f44f4bfd625f13afbff]
stable/7.1: [159fdc3e01dca5fdbc412fcd8b239895733a270d]
CVE-2026-68178: misc: nsm: pin the module while the device is open
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68178
Introduced by commit b987375 ("misc: Add Nitro Secure Module driver")
in v6.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3b231f1e9990f4c21220d0a69733ce2105891ff9]
stable/6.12: [1996639f824ce9468395cdb7bcb8f467fa787e77]
stable/6.18: [1da310b94504d42001e9c32c43c5dc105b777e5f]
stable/7.1: [9e9a82d00c3d10129fc310a7547b24a679d5d920]
CVE-2026-68179: misc: nsm: only unlock nsm_dev on post-lock error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68179
Introduced by commit b987375 ("misc: Add Nitro Secure Module driver")
in v6.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ce1fed11d18e163baf7f875152a33bf80f625c1a]
stable/6.12: [4aa3f7d48e91eb74a363c1b4d7dbdd28f5b341fb]
stable/6.18: [8f068342096b027181b168d91fef7ac7a2c64b25]
stable/7.1: [f318f5a872cb9096536e759b23ae5c9873bb80ed]
CVE-2026-68180: intel_th: fix MSC output device reference leak
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68180
Introduced by commit 95fc36a ("intel_th: fix device leak on output
open()") in v6.19-rc7.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt cip/6.1 cip/6.1-rt cip/6.12 stable/5.10
stable/5.15 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [761b785a0cfbce43761227bc42a7f984f31f8921]
stable/6.12: [26e27b8dcef1e4df6f30d8f25b3304a506d482b3]
stable/6.18: [caba30eb8bd321c465ecfc7d850ee85f5b353496]
stable/6.6: [ddcf2064d7ec5a8c9afa7cb74442320e443502bc]
stable/7.1: [c3a28f9cb82425fe0835048ed3677f321e780691]
CVE-2026-68181: mei: bus: access mei_device under device_lock on cleanup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68181
Introduced by commit 35e8a42 ("mei: bus: Check for still connected
devices in mei_cl_bus_dev_release()") in v6.17-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [f112ea910e554d58b4b39a4492b7d302f0f4204f]
stable/6.12: [c88c030a324c9018b77894a19b2564eb66862020]
stable/6.18: [59dd34854202d9a3faaa87a85205e553fe7150e1]
stable/6.6: [441559d4c595f839b39f0ab6a4ae628427c2fd9e]
stable/7.1: [7cf79e8d682fe93777268f029668ce5e214237fd]
CVE-2026-68182: comedi: comedi_parport: deal with premature interrupt
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68182
Introduced by commit 241ab6a ("Staging: comedi: add comedi_parport
driver") in v2.6.29-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [17221216ae8ce6a24e8a4e787382e3ebc81b88a8]
stable/6.12: [086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1]
stable/6.18: [cf26dd2d841583c54a87005c4934b92fddb930c3]
stable/6.6: [b061bb4dca49fd93063359d3805387235818778c]
stable/7.1: [5d059ce0e6a2f6f8b97273499d47b8f917097b48]
CVE-2026-68183: firmware: stratix10-svc: fix memory leaks and list
corruption bugs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68183
Introduced by commit 7ca5ce8 ("firmware: add Intel Stratix10 service
layer driver") in v5.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9119ceb76e987c2ec2b549ea100e3268ce3a1c7c]
stable/6.12: [fff6e5ff0318315998b540896537eaaa2ebf9f7b]
stable/6.18: [4f2db41a09eba7a45abd140bb86ffc519c191886]
stable/6.6: [95f702e372964aff486338783f49e28a40a53127]
stable/7.1: [8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47]
CVE-2026-68184: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68184
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b27e195d4db8dea263050bdbeb11881b2999c9c6]
stable/6.12: [35b68e24c5a69fa4545f46f05f6c849223034cb6]
stable/6.18: [d43c5c0c935522deae7339e0c2399365f3bf0016]
stable/6.6: [7344c84e32413e5c8832f74b8a612b0194e5c051]
stable/7.1: [f3e2715a150066f09aa82c30fa983fb184ad6dd5]
CVE-2026-68185: LoongArch: Move jump_label_init() before parse_early_param()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68185
Introduced commit is not determined.Fixed in v7.2-rc5.
Fixed status
mainline: [ea68d444a658783234a06f05414e41cf93a18fb2]
stable/6.12: [4b40e590efb350c54480d7e883f054d3609a94c6]
stable/6.18: [38b025fcdc45bdf5140a5726a1fbb2e694ea047b]
stable/7.1: [881e9f3c4e117b100880b1c5de3a0da8e455a78f]
CVE-2026-68186: binfmt_misc: set have_execfd only once the interpreter is opened
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68186
Introduced by commit bc2bf33 ("exec: Remove recursion from
search_binary_handler") in v5.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bbf5f639918dc011aaf60aab8480218758ee68c5]
stable/6.12: [2dd0298905e97795a9c5ec30cf5b41975f821632]
stable/6.18: [1cd4e9b7967dab48c9f79a00b06ffff7208c0993]
stable/6.6: [0f19d54e2524f0bf183b82f365ae4e49b4a2f788]
stable/7.1: [5ccc99d58f94fad258c9c375715b3974e48620e8]
CVE-2026-68187: exec: fix unsigned loop counter wrap in transfer_args_to_stack()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68187
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [16cc4f5c1c4b9e45eca7f7deefa5410a292db599]
stable/6.12: [dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e]
stable/6.18: [2bc6bf70d41055377f390d06f0f3521deb62fd3b]
stable/6.6: [c62bb00caba66e01fb578d5f0302f247dc64930a]
stable/7.1: [55fa2c7f2b15583d1a2fe1b5abcc24377359339f]
CVE-2026-68188: Bluetooth: RFCOMM: Fix session UAF in set_termios
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68188
Introduced by commit 3a5e903 ("[Bluetooth]: Implement RFCOMM remote
port negotiation") in v2.6.20.16.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c783399efc22d035443f1dfbf2a09bf9562aaa5e]
stable/6.12: [a82a9d3891f5607030b0672c255087a12bb9837b]
stable/6.18: [780b04d09c941262ee2a2b4a09906451b69df8a6]
stable/6.6: [2894bd8c68e97accd758ca6e5fc375d7e9e8882c]
stable/7.1: [98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea]
CVE-2026-68189: Bluetooth: hci_sync: Protect UUID list traversal
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68189
Introduced by commit 161510c ("Bluetooth: hci_sync: Make use of
hci_cmd_sync_queue set 1") in v5.17-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e9027ffbf5a0f3c12ca8900822e884eae9f0821b]
stable/6.12: [a351f68fb24828b23a971e00b8238ee0e8a40380]
stable/6.18: [a42f5536ea9c00e13f0c0fbb330feed95e2365ca]
stable/6.6: [e4fa2c5c261d736b8e58759fdef3a968d510630c]
stable/7.1: [fe13adc258df88d95789e5673c7ba5178b5f8b28]
CVE-2026-68190: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68190
Introduced by commit 554c0a3 ("staging: Add rtl8723bs sdio wifi
driver") in v4.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0e95ff792ae0aa6fbad9455943e9e1e4062670e9]
stable/6.12: [630fdca3f2437fee3ffd437c4b646ccf84c7be87]
stable/6.18: [875479f18835ac11e21a83e88f3d4dc7ccdcd0c4]
stable/6.6: [b9d9a4cd2e59df7281992a076464d2536e80c674]
stable/7.1: [23c31f107b4f8f420a754a45d12599bdb78f9bb8]
CVE-2026-68191: wifi: ath12k: fix NULL pointer dereference in rhash
table destroy
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68191
Introduced by commit 57ccca4 ("wifi: ath12k: Add hash table for
ath12k_link_sta in ath12k_base") in v7.0-rc1.
Introduced by commit a88cf5f ("wifi: ath12k: Add hash table for
ath12k_dp_link_peer") in v7.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [70231dcd782201579990ded73e0435d18bb524ca]
stable/7.1: [17a4298f7794843af0094035723dc5e7311c7453]
CVE-2026-68192: wifi: brcmfmac: make release_scratchbuffers idempotent
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68192
Introduced by commit 4684997 ("brcmfmac: reset PCIe bus on a firmware
crash") in v5.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [538c51e9d124cf656f2dd0c0394a8545efc7102d]
stable/6.12: [5a045c2f0fbf029873d2295178fa0785ade35af0]
stable/6.18: [044fca8f45ba9ab6ca526163155234cf88287ff5]
stable/6.6: [b7d1d8cb1bdca56aecebacd2896615da0acc126a]
stable/7.1: [0ca80328df23f851c86866720d4977783c919ee6]
CVE-2026-68193: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68193
Introduced by commit c948b5d ("wifi: mt76: mt7925: add Mediatek Wi-Fi7
driver for mt7925 chips") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [feeff151c83e7f0ffcdedcad5343852d23d1f6e1]
stable/6.12: [0c8c4cd0ca60b45c4b05a39e3769b8473d6836eb]
stable/6.18: [9cb72f67e1502aabba51aab9ac04ae7c386ee194]
stable/7.1: [9677e86a5f7d680fe280a5f8999bc57353e360d7]
CVE-2026-68194: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68194
Introduced by commit 48fab5b ("mt76: mt7921: introduce mt7921s
support") in v5.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [da4082e91acabc1498611ed8ccc53f0610baefc6]
stable/6.12: [ecf995b828191829ba4a87169bccabcbeb5c9c32]
stable/6.18: [263816e92e8d66c81c98ccab2b5d2191ed08ec71]
stable/6.6: [ef2ee5f820c3ef87643b51e960c20b4a14d8336b]
stable/7.1: [24475d2ddc8d8dfd82f4d2be0d951401f86911a6]
CVE-2026-68195: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68195
Introduced by commit eb99cc9 ("mt76: mt7615: introduce mt7663u
support") in v5.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [39afc46c0243d10b7795e6e6cf4ae91f41732120]
stable/6.12: [88c98ef247a3126fea9bbbda953a18a2f36c3ea7]
stable/6.18: [ab4d213393e846baa6437497f94dda7553cbeda7]
stable/6.6: [f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5]
stable/7.1: [b2ab73b8123ce6cf2bc32634bfee4928676ffa66]
CVE-2026-68196: wifi: wilc1000: validate assoc response length before
subtracting header
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68196
Introduced by commit c5c77ba ("staging: wilc1000: Add SDIO/SPI 802.11
driver") in v4.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de]
stable/6.12: [4d410320e8ae5933e651660c9fadc1d380309e23]
stable/6.18: [e511e93abd6eeedcd5b3c55516241f414fbde64a]
stable/6.6: [584c8954ad55f8b09b475be6db710fe40ceb988c]
stable/7.1: [8ccdf8c8de87a9580df37c3c1ec53ba88cedef65]
CVE-2026-68197: wifi: mwifiex: fix NULL dereference when the AP has
HT-cap but no HT-oper
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68197
Introduced by commit 396939f ("mwifiex: add HT operation IE in TDLS
setup confirm") in v3.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c3d68e294cbb6a4090bb219d3dcaca85a011809b]
stable/6.12: [45011e4d9ba3f2182e5df64be65888044fa20771]
stable/6.18: [9375a4ea4121625ef27a46b74781cda66a5cc61b]
stable/6.6: [eb42c3c8fd479166c42984728754cd779c71fd60]
stable/7.1: [cca4398aa305c22016d1714f388e2fa6ea4e5ad4]
CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68198
Introduced by commit bdcd817 ("Add ath6kl cleaned up driver") in v3.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ba7debb4dd6427386862220e8335a53a4bfc235d]
stable/6.12: [b5d618fd61b9069b4c0a6b487022dd3117ad5acc]
stable/6.18: [18965470d41e69d3fc10eb62afae29d10f4cdfd1]
stable/6.6: [64af6534a085f49d6ed33338a19ab9cf0d0523c9]
stable/7.1: [a3313111b5d9046af60b370c93eec105b27380c1]
CVE-2026-68199: wifi: ath6kl: fix OOB access from firmware ADDBA window size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68199
Introduced by commit bdcd817 ("Add ath6kl cleaned up driver") in v3.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [44126b6994eeb28f2103b638e698f40a1244f327]
stable/6.12: [5a65fd4722416061698b0a3277222381efbc4882]
stable/6.18: [58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c]
stable/6.6: [d4558c140782180e2c80a7588a4af9f8675adfc4]
stable/7.1: [cec0a487cf38ac1f9bca240ffe8a94c5014b72f2]
CVE-2026-68200: ALSA: timer: don't re-enter an instance callback that
is still running
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68200
Introduced by commit 3774591 ("ALSA: timer: Introduce virtual
userspace-driven timers") in v6.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [70d28bfcd6224eed75986b3b987b997e59643fa4]
stable/6.12: [996c24377eea4d4506b7c3ccbbf1e490440b5e0b]
stable/6.18: [1395327a96614885552bae5fbb650e6dd182d49b]
stable/7.1: [c1078130a4cd7e738f4b73afe99b3e68cbfbf884]
CVE-2026-68201: ALSA: timer: drain a slave's callback before its
master detaches it
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68201
Introduced by commit 3774591 ("ALSA: timer: Introduce virtual
userspace-driven timers") in v6.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bdefe1346a8e6b8dc8593406dc2617e985fcbcab]
stable/6.12: [cd461bcfcdf8d6b6b5365941c1d3859f8bc77aa0]
stable/6.18: [426c0ff1c433d6030610ad4f9375746dfe931caa]
stable/7.1: [2b298997786876b225cff2446e11a0fa6f602f6d]
CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68202
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9]
stable/6.12: [24f0cabf173539f048946c8fc221131dc221f277]
stable/6.18: [6a10025c7fd09a7d2af37a3ae1da188569fce470]
stable/6.6: [fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07]
stable/7.1: [31a6163e301d832060f8236f1ed17cbc1ca198df]
CVE-2026-68203: media: vivid: fix cleanup bugs in vivid_init()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68203
Introduced by commit f46d740 ("[media] vivid: turn this into a
platform_device") in v4.1-rc1.
Introduced by commit d7c969f ("media: vivid: Add 'Is Connected To'
menu controls") in v6.11-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a07c179a92e949172ca52f6d4a13202ea88cd4b7]
stable/6.12: [4385092a86b94e1f332db35a3766108978c0722f]
stable/6.18: [1349af7f87df57940619f5b87990b799dac9ed8a]
stable/7.1: [6d51ad8f1c50c50d1abcc97fd243179967184c6a]
CVE-2026-68204: media: vivid: check for vb2_is_busy() when toggling caps
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68204
Introduced by commit 73c3f48 ("[media] vivid: add the control handling
code") in v3.18-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c2d1a2130c93f6d758af58590b86b2254c7a1dec]
stable/6.12: [abaec6747304581f8d4a9936352fa10e13325f07]
stable/6.18: [492c97cb50feaa60ccd7792d3d6b904ed8ec61bf]
stable/6.6: [a9cd0e8fb0b21faaa71199d9d3feb305c18ff576]
stable/7.1: [daf2d92669b4a659d805d88d811161c70cd325ee]
CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in
v4l2_async_register_subdev_sensor()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68205
Introduced by commit aef69d5 ("media: v4l: fwnode: Add a convenience
function for registering sensors") in v4.15-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [06cb687a5132fcffe624c0070576ab852ac6b568]
stable/6.12: [caea6bc68c925d63ca33d21b2255f47181943d61]
stable/6.18: [cf9732fd6c4f2f803ccfc46d89489b6635590270]
stable/6.6: [47ef04cd13d38010b580056a9d8840aaab944841]
stable/7.1: [067887ff93fddbb3a3fb84c900bc654ecfe5ba61]
CVE-2026-68206: media: v4l2-ctrls: validate HEVC active reference counts
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68206
Introduced by commit d395a78 ("media: hevc: Add decode params
control") in v5.14-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [afbe4bc252d90a6f8fad869b06d5430f615f22f9]
stable/6.12: [dbaf0e0023e2f9332c5164822def7f80b7d2c5ef]
stable/6.18: [3068ab802fc98b121dcb451e1f7f4d338ffc7a19]
stable/6.6: [9a998cc1c348769262d433acb7d238c5fac4b2e0]
stable/7.1: [b01df98a6669d2b67d8aed816021b327fd905998]
CVE-2026-68207: media: ti: vpe: unwind v4l2 device registration on probe error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68207
Introduced by commit 4d59c7d ("media: ti-vpe: vpe: Add missing null
pointer checks") in v5.5-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e0f1c9a90ef665f2587c274a8fed59f2dfc575a6]
stable/6.12: [7d383357905de975e1dbde639e5fa7477075d104]
stable/6.18: [7e6521dd747eca3cb3d4cd3ddcf20f266494f63d]
stable/6.6: [4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9]
stable/7.1: [fcbbaf9cb9722a82f0221c56114037fc537f4ada]
CVE-2026-68208: media: ti: vpe: Fix the error code of devm_kzalloc()
in vip_probe_slice()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68208
Introduced by commit fc2873a ("media: ti: vpe: Add the VIP driver") in v7.0-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e8f319eae96a3d718e810d52432020a2b77f5f60]
stable/7.1: [956879b173c2cf782fbc3d18947fd1da286359cf]
CVE-2026-68209: media: sun4i-csi: Return queued buffers on
start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68209
Introduced by commit 577bbf2 ("media: sunxi: Add A10 CSI driver") in v5.4-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bbba3e260a62810a717b4442a3bb96d0ec0f6309]
stable/6.12: [a8abecc638a7feb20b78fabd563b05e30c071331]
stable/6.18: [b5184b3f0e9d4cc47059ba1138c9a73d43d2493f]
stable/6.6: [4872161e6fbe4e1783daea8bff79caddfae0fb82]
stable/7.1: [668face37fdb6b6900645dc8777195498541c9a7]
CVE-2026-68210: media: stm32: dcmi: unregister notifier on probe failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68210
Introduced by commit d079f94 ("media: platform: Switch to
v4l2_async_notifier_add_subdev") in v4.20-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [084973ebd67b28f0945c5d45408f86c58b540110]
stable/6.12: [6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7]
stable/6.18: [931abe1deb65b919d23fa203d7f6d6fbd4fccd8e]
stable/6.6: [37ff63c5d7119cbc5c6bacdcc658add6008a8e1f]
stable/7.1: [4b7ee504969e074725e439c949f2483e5fa5572a]
CVE-2026-68211: media: stm32-dcmipp: Return queued buffers on
start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68211
Introduced by commit 28e0f37 ("media: stm32-dcmipp: STM32 DCMIPP
camera interface driver") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ffc8eec06378a340d708c889184ab3e14b57d540]
stable/6.18: [ed342a86bb2f9c1b44a0fc4f6b08c14073946e4f]
stable/7.1: [624af2d4b5e9d3dd366538e4fb4a2a037792a7e3]
CVE-2026-68212: media: saa7134: Fix a possible memory leak in
saa7134_video_init1
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68212
Introduced by commit a00e688 ("[media] saa7134: move saa7134_pgtable
to saa7134_dmaqueue") in v3.16-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f86ed548386e3050e5f8f25b450d09dc009d9a88]
stable/6.12: [e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23]
stable/6.18: [b7936e8cbec1b96b126058eeb005e5b9111df38e]
stable/6.6: [134c979dd721e22f196d71026432ee37d1f5cc38]
stable/7.1: [1731dd61b6c0b7435c139951d2b7eada6c9667a8]
CVE-2026-68213: media: rtl2832_sdr: Return queued buffers on
start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68213
Introduced by commit 7711389 ("[media] rtl2832_sdr: Realtek RTL2832
SDR driver module") in v3.15-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [33ca0aab6f4bd90921fc1395478f38f72c4d19af]
stable/6.12: [0b08c0403cf672a121ace4eff647a9b240bd4e1b]
stable/6.18: [894e83509c66910112b9eaeaa8cd66cd9806db91]
stable/6.6: [465dc8e71d2db2ed603e749fa71392bcdccf07eb]
stable/7.1: [fc0b18782aab4e35078efe72863df8eab46560a8]
CVE-2026-68214: media: rtl2832: fix use-after-free in rtl2832_remove()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68214
Introduced by commit cddcc40 ("[media] rtl2832: convert to use an
explicit i2c mux core") in v4.7-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [680daf40a82d483949f87f0d8f98639dc47e610c]
stable/6.12: [24bef237eef8dd1ebcffb129ba21891ddad0d309]
stable/6.18: [2c71bda6edc630a1f8c3c45d8df5fc22d234e042]
stable/6.6: [9acd5bbbe1df8e487e49488692c224496d4c9e16]
stable/7.1: [90d781711418881f8c836c2a859cc2886625d750]
CVE-2026-68215: media: radio-si476x: Unregister v4l2_device on probe failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68215
Introduced by commit b879a9c ("[media] v4l2: Add a V4L2 driver for
SI476X MFD") in v3.10-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [436a693af04ffb889aaf87cb69ec1f2b21d3569c]
stable/6.12: [7ef9f1659404544a8dddd68842bafcb4a38197af]
stable/6.18: [64cb15878b35e5574ff4f80a0b613a79e47867ba]
stable/6.6: [4ca9c9f12b1bc341a0a3bbbd2090fd182db53771]
stable/7.1: [730c235d7d2c80a401dac56b0f5066c889aa442d]
CVE-2026-68216: media: pwc: Return queued buffers on start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68216
Introduced by commit ceede9f ("[media] pwc: Fix locking") in v3.5-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [975b2ee20e569d47821e4f6c9761b4664d48a6a4]
stable/6.12: [5d7cc2634c3843a1414a0f6407aa17f1f91dee60]
stable/6.18: [cb16b79a2be2cec9c3ebe4147490817c4d8b1de3]
stable/6.6: [f2f9fcacd81953dde6cb86312ab13ca13e689664]
stable/7.1: [a4f8f629983f643333e49df90557805469bcbb25]
CVE-2026-68217: media: pwc: Drain fill_buf on start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68217
Introduced by commit 885fe18 ("[media] pwc: Replace private buffer
management code with videobuf2") in v3.1-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [906e410dcffbbd99fb4081abab817a830033aa28]
stable/6.12: [acc789b2173070638cad89c2b61d33ed338be0dd]
stable/6.18: [9afd605dcd96c7a45f338eded1de16679b30e1df]
stable/6.6: [a56e7641e09bd80b976e944ae759109b86fd5b38]
stable/7.1: [5d4812668b03f823b5044789d6aa77fe56b42587]
CVE-2026-68218: media: pci: dm1105: Free allocated workqueue
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68218
Introduced by commit 519a4bd ("V4L/DVB (11984): Add support for yet
another SDMC DM1105 based DVB-S card.") in v2.6.31-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1a65db225b25bb8c8febf16974c060e0cc242eb9]
stable/6.12: [8d753c8c37afc0910ed5ddc014645b05d6266add]
stable/6.18: [08ddfd628a2dbd9d385da677afccd893d0ab37e1]
stable/6.6: [46715fecc38a2d341c3ff680f295de6e8aec72c0]
stable/7.1: [0c2b4c45fce012e88904b8c66b5cd786535c0b8c]
CVE-2026-68219: media: nxp: imx8-isi: Fix potential out-of-bounds issues
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68219
Introduced by commit cf21f32 ("media: nxp: Add i.MX8 ISI driver") in v6.4-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf]
stable/6.12: [ba7e1b06cbdad3b7c3314390cca22aff42f655d4]
stable/6.18: [28ae75dba701d7aa69a36802c398582933d3e0e6]
stable/6.6: [690cdda752f3dc6b7a8b2d4a243e0207b66a1f37]
stable/7.1: [75cdfaa7c908ca06d564170da9c80fb579f149a5]
CVE-2026-68220: media: nxp: imx8-isi: Add missing
v4l2_subdev_cleanup() in crossbar and pipe
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68220
Introduced by commit cf21f32 ("media: nxp: Add i.MX8 ISI driver") in v6.4-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [567418eedd25b3d86d489807682030b4b98b73d9]
stable/6.12: [f04ec98605420e7c2c1ad6d2f6fb26692d4f218a]
stable/6.18: [9e61258fbc3cfc053e4c2ed72254c2de76772354]
stable/6.6: [549dd1afce2cf79a826d1f9742effb4565d52871]
stable/7.1: [9c5ddbabc31fda93a508d9b8f0c776a4a08e49f5]
CVE-2026-68221: media: nuvoton: npcm-video: fix memory leaks in probe and remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68221
Introduced by commit 46c15a4 ("media: nuvoton: Add driver for NPCM
video capture and encoding engine") in v6.7-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [50cc0e547da50b887e63dfa1ad203cd5b735d01e]
stable/6.12: [b092d690a9b28795ab2db083023e8a5368cddb22]
stable/6.18: [181a0aeefd56f9285325b84789aa348aba0508bf]
stable/7.1: [65ddc021d39d6383635ee8b0970b2d1c7947e447]
CVE-2026-68222: media: msi2500: Return queued buffers on
start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68222
Introduced by commit 977e444 ("[media] Mirics MSi3101 SDR Dongle
driver") in v3.12-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7201c17786a498497bca57752883b90914d405ac]
stable/6.12: [bab9d5a67d4db96ae8c187b92b37979911302a10]
stable/6.18: [264b5380c4f8aa92dbc2983ecd2b627f1d5e0061]
stable/6.6: [1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a]
stable/7.1: [3673cb0a5711e910074d69201da9e1535c03f97a]
CVE-2026-68223: media: meson: vdec: Fix memory leak in error path of vdec_open
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68223
Introduced by commit 3e7f51b ("media: meson: add v4l2 m2m video
decoder driver") in v5.3-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [940f161f734b25f175a95d2684c2021f6323693a]
stable/6.12: [2cf0171ad594860e31723c671e37824ce12c01ea]
stable/6.18: [1391b75bf0119b5d37f1c1c3078d452a01967f9b]
stable/6.6: [c6cd08a71a630f19b10c318e76e3c56e1dd10e00]
stable/7.1: [99f3527bd1a27ff798d59177ed045b0dd87deaef]
CVE-2026-68224: media: mali-c55: Fix possible ERR_PTR in enable_streams
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68224
Introduced by commit d5f281f ("media: mali-c55: Add Mali-C55 ISP
driver") in v6.19-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [94c6402e423d36a2bd6f62055a65a0d439d84da7]
stable/7.1: [65d4424275845e9f9012b40b5cbff4572771d768]
CVE-2026-68225: media: i2c: alvium: fix critical pointer access in
alvium_ctrl_init
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68225
Introduced by commit 0a7af87 ("media: i2c: Add support for alvium
camera") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4f6f28ff24709710c08557c127b3e4c3fb1b4159]
stable/6.12: [4bacfda44d36f165f6cb57bea408912886400ffa]
stable/6.18: [7337c88205ed0ffc654f40266be0d3c3eb15fb29]
stable/7.1: [eb2f934646aefb06314cecd1deb020794829b207]
CVE-2026-68226: media: cx23885: add ioremap return check and cleanup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68226
Introduced by commit d19770e ("V4L/DVB (6150): Add CX23885/CX23887
PCIe bridge driver") in v2.6.24-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a0701e387b46e2481c05b47f1235b954bfc2af3e]
stable/6.12: [83540d86d717735b52a43e4ba1b784da5cc2310a]
stable/6.18: [c68c4ce72feb6fcccc843eb3baa7af60189ed567]
stable/6.6: [8fbdca4c99f68734e9b6c030973fb61a11bede15]
stable/7.1: [ff3c670a1de3a714f5644e37b9446fe7c3299fd3]
CVE-2026-68227: media: cx231xx: fix devres lifetime
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68227
Introduced by commit 184a827 ("[media] cx231xx: use devm_ functions to
allocate memory") in v3.17-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7d6358ab02866e5b7ed8d3a00805297617bbb0ec]
stable/6.12: [c5ccb01eb1107acb6aab8ce8fe5a523f215c837e]
stable/6.18: [f468b7ee5d6332b01e6c538179a4c720e6dae93b]
stable/6.6: [a373f1a5137e96549a795e7fb9efb5de0ae1d065]
stable/7.1: [e797e252bfb3d0d4b3d38e4faef817e05869c240]
CVE-2026-68228: media: chips-media: wave5: Move src_buf Removal to finish_encode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68228
Introduced by commit 9707a62 ("media: chips-media: wave5: Add the v4l2
layer") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b20157147089a9c16a38c7810e2fe6f2df8e3277]
stable/6.12: [1ee2b2b189ddc7b23c8eee1145de42b8bd19fb06]
stable/6.18: [f24ca8b53fe15db40957bdaa40c9aa68e1557bbe]
stable/7.1: [d681227ce43bfd74b6eb69beecd9b0bec1fd8b48]
CVE-2026-68229: media: cedrus: skip invalid H.264 reference list entries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68229
Introduced by commit e000e1f ("media: uapi: h264: Update reference
lists") in v5.10-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [10358ea986c3c85516d1c8206486464f79d36e76]
stable/6.12: [0af8945fcae742d099f59f3c725eb67235953a31]
stable/6.18: [9924cb548ee7753a6473997949c3ec48092de0b0]
stable/6.6: [2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a]
stable/7.1: [e53112c2de88982e66c369aee2120d5efd78df30]
CVE-2026-68230: media: amlogic-c3: Add validations for ae and awb config
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68230
Introduced by commit fb2e135 ("media: platform: Add C3 ISP driver") in
v6.16-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9724164f71974a2a44a5e026614fbcc05bab6d91]
stable/6.18: [391fe3e36e59f3c6e3d46edfb3a5de51e00cd216]
stable/7.1: [32cbe5474e74817aa8a576b94135cc45e59f5e07]
CVE-2026-68231: media: airspy: Return queued buffers on
start_streaming() failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68231
Introduced by commit 634fe50 ("[media] airspy: AirSpy SDR driver") in v3.17-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [04344d0b4929caa94c0df72f767752aa0935ef5d]
stable/6.12: [cd42623d698b59f1fe5768f78a4101c28d5feb2e]
stable/6.18: [73bd2779865372b1017d4f555b45270aa2d0d710]
stable/6.6: [877686a74ecdc93dcaee09dbac566e819059c9e7]
stable/7.1: [170fcc945bc094b1c956bf555c070692826a3eff]
CVE-2026-68232: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68232
Introduced by commit 99624bd ("drm/gpusvm: Add support for GPU Shared
Virtual Memory") in v6.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [847b371debf3c8c72384ab7b9a0c4123a74cc925]
stable/6.18: [a2212fef8e18724e06432fce01fa257296d9f053]
stable/7.1: [adf0542659c783c962f4a8f2adcb3532ed54821c]
CVE-2026-68233: drm/vc4: Shut down BO cache timer before teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68233
Introduced by commit c826a6e ("drm/vc4: Add a BO cache.") in v4.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6273dd3ffb54ec581855b82ae77331b66028249c]
stable/6.18: [a38f2724eb93a78ba250b01e0caf3468df4d3956]
stable/7.1: [bac4c1a9af690b8635c6924872075c41d8763ed9]
CVE-2026-68234: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68234
Introduced commit is not determined.Fixed in v7.2-rc4.
Fixed status
mainline: [a2f895f3c852063258d62e9f74b081de07ca95df]
stable/6.12: [2f390b4c83011452753fd84972f657d2b00a952b]
stable/6.18: [ba7b6444097a73ccd3d3ac9e2be4ebb73d226460]
stable/6.6: [51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc]
stable/7.1: [9743f60013273987abf415dc47474683d22aaee9]
CVE-2026-68235: drm/amd/display: dce100: skip non-DP stream encoders for DP MST
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68235
Introduced commit is not determined.Fixed in v7.2-rc4.
Fixed status
mainline: [d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5]
stable/6.12: [bfe28ce019c2d667d98071262da33d8bba122919]
stable/6.18: [51ea665c30c424c98959101f3bf6f48ab42949c8]
stable/7.1: [ed2d86aef9fa4c43f82da0fca91a60f7326d7d03]
CVE-2026-68236: drm/amd/display: set new_stream to NULL after release
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68236
Introduced by commit 9b690ef ("drm/amd/display: Avoid full modeset
when not required") in v4.15-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9fa26b9eed6195bf840f39ac183b9a6237548755]
stable/6.12: [5182e442e61397d446c36995b8f5676942d35b82]
stable/6.18: [679f23f0a3606afcef1ffabd72222f00a54ad9e3]
stable/6.6: [ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76]
stable/7.1: [0676fecbb5242aa22c057e78326d6d6041db034c]
CVE-2026-68237: drm/amdgpu/userq: fix indefinite fence wait during GPU reset
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68237
Introduced by commit 290f46c ("drm/amdgpu: Implement user queue reset
functionality") in v6.19-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5d75ec2e5f1736c2f10c7d6f4565bf1bf29f29a7]
stable/7.1: [3085ae8695e025b39d208f288c6265edc75abbe8]
CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68238
Introduced commit is not determined.Fixed in v7.2-rc4.
Fixed status
mainline: [65bff26617607c1331283232016c0e89088c5b78]
stable/6.18: [312278b3091912fa56a6a587609f17dcb33465c2]
stable/7.1: [9b7de3ee5d2c5ee2a706e5f7ca0126f4fbea4da8]
CVE-2026-68239: drm/ttm: Account for NULL and handle pages in ttm_pool_backup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68239
Introduced by commit b63d715 ("drm/ttm/pool, drm/ttm/tt: Provide a
helper to shrink pages") in v6.15-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5b7b3b6595ee77d01c7463757baed114786094dd]
stable/6.18: [22aa7fb4e7d0b3ab41d1240ed743167980912970]
stable/7.1: [9ddaabf38f7a45b329e34358b98d2968d8649d21]
CVE-2026-68240: drm/gpusvm: publish dpagemap early to avoid device
mapping leak on error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68240
Introduced by commit f70da6f ("drm/gpusvm: pull out drm_gpusvm_pages
substructure") in v6.18-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7f708f51e3955bda0d77a0b67ab9bea6c97fea99]
stable/6.18: [e8362523fd1b61712f7d996802f9b5dee545c7e6]
stable/7.1: [72e4fca5529e45b5beebad79d804de442f632324]
CVE-2026-68241: drm/i915/mst: limit DP MST ESI service loop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68241
Introduced by commit 3c0ec2c ("drm/i915: Flatten
intel_dp_check_mst_status() a bit") in v5.8-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [005771c18c5b2c98cb4e7517661aea460990fd3f]
stable/6.18: [e3bcd3bf7eeca9570b9fa0b2f8a602c7bcc6b0d0]
stable/7.1: [9061fbf2230b6fcef042a6f637beae57c2fc93a5]
CVE-2026-68242: drm/i915/gt: Fix NULL deref on sched_engine alloc failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68242
Introduced by commit 3e28d37 ("drm/i915: Move priolist to new
i915_sched_engine object") in v5.15-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [82ec992c404c3dc774c5e9f3d4aa858e97187675]
stable/7.1: [edd4804f07b8369ed472de19272974e2bf2a6271]
CVE-2026-68243: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68243
Introduced by commit d4433c7 ("drm/i915/gem: Use the proto-context to
handle create parameters (v5)") in v5.15-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2b56757a9a7456825eb668fde92299e01c5e2721]
stable/6.12: [9923c223d38fcd9602f41cc31d480e5299d9a38e]
stable/6.18: [726f27bca93e6c83b263542669132ee1d0eb693e]
stable/6.6: [edd2edaca52ada833c341c8b264aaea9dd93369c]
stable/7.1: [97f236379f06a5082d37c6a764edd56bb58a94cd]
CVE-2026-68244: drm/i915/gem: Do not leak siblings[] on proto context error
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68244
Introduced by commit d4433c7 ("drm/i915/gem: Use the proto-context to
handle create parameters (v5)") in v5.15-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [eed3de2acf6aa5154d49098b026710b646db67ee]
stable/6.12: [8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5]
stable/6.18: [37951ce1567ccf8c86c7a1b8fb7d55a32c821b87]
stable/6.6: [f014702fbd48d06a3d7a06e4bb4075d406376cf0]
stable/7.1: [6cdbef8f60f313684e641628d64aa85960080d3f]
CVE-2026-68245: drm/amdgpu: fix lifetime issue of
amdgpu_vm_get_task_info_pasid()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68245
Introduced commit is not determined.Fixed in v7.2-rc3.
Affected code was added by b8f67b9 ("drm/amdgpu: change vm->task_info
handling") in v6.9-rc1.
Fixed status
mainline: [04cc4aa3617b0ed67e859f91f09de5d896a46f3a]
stable/6.12: [fe16a7e5336ae888751984e30c451fbf7cfa5df7]
stable/6.18: [1173190412fb9d12e7efce76734118d9712ff970]
stable/7.1: [5d5fb9124a2bba96a7807086d8fe0f7ce810d546]
CVE-2026-68246: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68246
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 3d879e8 ("drm/amdgpu: add init support for
GFX11 (v2)") in v5.19-rc1.
Fixed status
mainline: [0eebcab1ea2a77f086a04108f386f82ee3496022]
stable/6.12: [7aeef42b657d930f3b639220e62120ac1bf058a1]
stable/6.18: [dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f]
stable/6.6: [96b6d68f2b5a208e4d8f1e4a932ec424655e1267]
stable/7.1: [625f301e01bf89694466fdaa1f9904e2c62eb8f2]
CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68247
Introduced by commit 6434cf6 ("drm/i915/bios: calculate panel type as
per child device index in VBT") in v6.0-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2084503f2d087bf956198e7f6eb25b03a7049cb2]
stable/6.12: [e7b5694645b03e80830dc141b59fc65aac693c70]
stable/6.18: [8b2da44446f9dce2ae50fee78bac2734d4277143]
stable/7.1: [8887b94d2fc93071bf6ff09c39d474510e6f582f]
CVE-2026-68248: drm/i915: Return NULL on error in active_instance
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68248
Introduced by commit bfaae47 ("drm/i915: make lockdep slightly happier
about execbuf.") in v5.13-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1e33f0de5fdcd09e51fdec1e5822448970b6420f]
stable/6.12: [b238d86e7f43afde8e830ef5b8d89ffedbbc7613]
stable/6.18: [cbec6a57959ab503e3ad4ad6edd51efb585dce92]
stable/6.6: [32c1a2afa90dd07df931f0b12578de1dbb751f0c]
stable/7.1: [58b7e63ca0cd964190957ddd169c899256acaee9]
CVE-2026-68249: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68249
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by fef6e24 ("drm/amdgpu: add initial support
for sdma v5.0 (v6)") in v5.3-rc1.
Fixed status
mainline: [9e98ed3113943257ad6e5c1e6beddbdb482a70ad]
stable/6.12: [28337e5d7df429bac7de64b17f1a595147778caa]
stable/6.18: [d20b5c139b2906bcd8ab4bfe5b8be500318161d1]
stable/6.6: [f6212bc1bbd936fd9f7d77168b0c8b0019477b64]
stable/7.1: [0027cb19b0449ad6babedb1af285a713ab05c97f]
CVE-2026-68250: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68250
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 157e72e ("drm/amdgpu: add sdma ip block for
sienna_cichlid (v5)") in v5.9-rc1.
Fixed status
mainline: [b9dd618a635d39fbb211454b6e8837b2a7f10fb0]
stable/6.12: [b665c1845488c6cd869da3d31b5978015977f898]
stable/6.18: [09da54636bac146c1a3c461c4e7eb08d355bb86e]
stable/6.6: [01dfea84df919cfbec4064151d327480ae5c120d]
stable/7.1: [2051bbbfbd44ff51637b01a5a3dbee6630f90d57]
CVE-2026-68251: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68251
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 61a039d ("drm/amdgpu: add initial support
for sdma v6.0") in v5.19-rc1.
Fixed status
mainline: [ec42c96c322e5cc48099ab5e67b5cbe236cb1949]
stable/6.12: [e7f31c9a61533062a704f90b9f63064045249693]
stable/6.18: [51fd52087165180967cf7d5ee99badee7e172ea0]
stable/6.6: [2eb06c88426b6c8de602c608959f3a56ac51861e]
stable/7.1: [9df8a7f09e305249872b536555793b28e77b7de9]
CVE-2026-68252: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68252
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by b412351 ("drm/amdgpu: Add sdma v7_0 ip
block support (v7)") in v6.11-rc1.
Fixed status
mainline: [e80e28f398f5d9f6e361ffb56382d2e74fc87556]
stable/6.12: [395bf099ef7153227600a2d8cb087f45c4a277b6]
stable/6.18: [4c09483325360373656214cc7a2fd29dc73037a5]
stable/7.1: [bcbd53d25da879bbce75faad9888c9a56e942fec]
CVE-2026-68253: drm/i915/hdcp: check streams[] bounds before overflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68253
Introduced by commit e03187e ("drm/i915/hdcp: MST streams support in
hdcp port_data") in v5.12-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bbb15a6b042d02e5508a02b4847e02d2579ee7bc]
stable/6.12: [2106fb490b2c6003e23ad6ff36ce823a2170e138]
stable/6.18: [3d2ef8d389495e7889c6062d8bddc46d2a5fbdef]
stable/6.6: [84351f12390349ba010920fc247e1a0b12e41eb3]
stable/7.1: [984085c5b53572e2e03fd5fc4817e86ef1effc6e]
CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68254
Introduced by commit 117cd09 ("drm/i915/display/dp: Compute VRR state
in atomic_check") in v5.12-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f8a9262c7a6fc2de9802e14b0228114f0333869e]
stable/6.12: [f16218689b41efcbc491207cd7716477b1223879]
stable/6.18: [df1582c0a101e2e2f133dd331d2a3258bb6a7518]
stable/6.6: [6598ac1721c3a5543efdbcab579a8561268d7ce1]
stable/7.1: [c726c8bbee5115dad37fa7867136ebaa50690331]
CVE-2026-68255: drm/virtio: bound EDID block reads to the response buffer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68255
Introduced by commit b4b01b4 ("drm/virtio: add edid support") in v5.0-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd]
stable/6.12: [2757e6e803092cf0aeaf4b735e16b5d3bdc705c5]
stable/6.18: [35be0e2c6862abcd5e5f5445261f1fd910d4a9b4]
stable/6.6: [9fc2a017c5d597937e0c28b9a9669844aa796c42]
stable/7.1: [375c1934ef0196d3b6d3a1eae3232bef8dae7bf7]
CVE-2026-68256: drm/amd/display: detect_link_and_local_sink: DP alt
mode timeout path leaks prev_sink reference
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68256
Introduced by commit 5461888 ("drm/amd/display: break down dc_link.c")
in v6.3-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a6e14b976be48eebd8769cb5b883a6af7fc5ade1]
stable/6.12: [a59e493567d18ef3858be9368acd132a01ebfa09]
stable/6.18: [4ee77643e6194f2deb62fe62f04396f9825e27d8]
stable/6.6: [f9922828a4ebd26286fbe0286cc61695e7d9b07b]
stable/7.1: [58ea24dd96848626039296e9e8510270ec8dc4bf]
CVE-2026-68257: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68257
Introduced commit is not determined.Fixed in v7.2-rc4.
Fixed status
mainline: [2b0386d4293920e690c0e017708f999b93cc729b]
stable/6.12: [b88ffe6593607364a8c06a48c6f29e55437cdf8e]
stable/6.18: [abce3276c57e36c955627307469b9f009057a467]
stable/7.1: [865532d54eb57b660b1cb1b0e1755776ce21b849]
CVE-2026-68258: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68258
Introduced commit is not determined.Fixed in v7.2-rc3.
Fixed status
mainline: [47ea05f246bebc81c7796f56265cffd812cf0601]
stable/6.18: [fd1691ec62701c982ea32e749678988c67fd4c21]
stable/7.1: [cc10a5839756982504ee8568fc1e1625962ab7f8]
CVE-2026-68259: drm/amdkfd: Check bounds in allocate_event_notification_slot
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68259
Introduced commit is not determined.Fixed in v7.2-rc3.
Fixed status
mainline: [bb52249fbbe948875155ccd45cd8d74bf4ae747b]
stable/6.12: [4622214f0542f64b02c250db0f9c677eeb032d9b]
stable/6.18: [50319efb865f72db45f191c8709511746d58ee0a]
stable/6.6: [85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53]
stable/7.1: [abeeb1947d81610c65349db4d89c6151f270e136]
CVE-2026-68260: drm/imagination: acquire vm_ctx->lock before mapping
memory to GPU VM
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68260
Introduced by commit ff5f643 ("drm/imagination: Add GEM and VM related
code") in v6.8-rc1.
Introduced by commit 4bc736f ("drm/imagination: vm: make use of
GPUVM's drm_exec helper") in v6.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [17e2030f37600994440f875dc410615d5c66ee6d]
stable/6.12: [1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf]
stable/6.18: [6253bb56bb2ebdf317d8b599ce737a2510cc2e17]
stable/7.1: [15f58d44c24477a6ebffa44ec05207b81cfa55d9]
CVE-2026-68261: drm/imagination: fix error checking of pvr_vm_context_lookup()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68261
Introduced by commit d2d79d2 ("drm/imagination: Implement context
creation/destruction ioctls") in v6.8-rc1.
Fixed in v7.2-rc3.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cf385cf6e713eba0720651174dac0b2d2f5bb8f8]
stable/6.12: [ce97192087c659f2e0c0c2a627330c7edcc9eeb3]
stable/6.18: [c45fafa69fe3f79e319369cf665da89868e3ef98]
stable/7.1: [401fbe3b6bbb6c94c24ee8843b7beed5111491ac]
CVE-2026-68262: drm/imagination: Fix user array stride in pvr_set_uobj_array()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68262
Introduced by commit f99f5f3 ("drm/imagination: Add GPU ID parsing and
firmware loading") in v6.8-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a]
stable/6.12: [bbebc39a70f6fc9b02637c8624349e30325873cb]
stable/6.18: [b983a35dad3701399c692d7c6eb57d8b6ffc0929]
stable/7.1: [09beaf4aec05b0525f2153dce693f3eb3166697a]
CVE-2026-68263: drm/imagination: Fix double call to drm_sched_entity_fini()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68263
Introduced by commit eaf01ee ("drm/imagination: Implement job
submission and scheduling") in v6.8-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4af24c27a39ba147a613a09e10b9e0f7294524c0]
stable/6.12: [9be3f4bd6f514f69c51a8c77ea64fce2729dc7f4]
stable/6.18: [c88fdbf3da26e0179629530cae7768cd3d4ead85]
stable/7.1: [c1136d907fd04ca5c62ba11c1159b5fe65a1760c]
CVE-2026-68264: drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68264
Introduced by commit e8babb2 ("drm/xe: Convert multiple bind ops into
single job") in v6.12-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6384271ac1ac0099198d15df79212a19ebdb929d]
stable/6.12: [be5c39730ab8f1dfe59983bf7d8e3705541d1fee]
stable/6.18: [157b1e3384d7d37f59c0c2b2ff2af8f557db1daa]
stable/7.1: [90e4fd331b980259c40118d05b89b0ec514e7c48]
CVE-2026-68265: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68265
Introduced by commit c1bb69a ("drm/xe/svm: Consult madvise preferred
location in prefetch") in v6.18-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7bc597ce74bab4153b2009c92eccf889e9d74044]
stable/6.18: [d256dac008d1d9e6378aa1a5454e89a8292d174c]
stable/7.1: [c4affa4e8bc8086b4d3e8d6cf1055a624f813d72]
CVE-2026-68266: drm/xe: Hold a dma-buf reference for imported BOs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68266
Introduced by commit dd08ebf ("drm/xe: Introduce a new DRM driver for
Intel GPUs") in v6.8-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [62775525a27c3b0d56382e08ba81ee2d322058b6]
stable/6.12: [c22d65d62b3318e237c0e5b1177d90ab83d9fe06]
stable/6.18: [c1954c66662de477a8f4309335b775f7b07bd28b]
stable/7.1: [ba8c4cbb31c6f81fa5b12d6e28f1f706040aff48]
CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68267
Introduced by commit 828a8ea ("drm/xe/oa: Add MMIO trigger support")
in v6.11-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e70086a3a06d276b4a5d9a2c51c9330c6cf72780]
stable/6.12: [9852aa87ecba95d7bf9fb94a9d6c4f69312c9682]
stable/6.18: [7982678fa21eda02a9111d2646be6762b5e3a64d]
stable/7.1: [1e6d07abbc0c41cb3259042794ad3deca79dd14e]
CVE-2026-68268: drm/xe: Return error on non-migratable faults requiring devmem
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68268
Introduced by commit 4208fac ("drm/xe: Add more SVM GT stats") in v6.18-rc1.
Fixed in v7.2-rc2.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [136fb61ba8571076dc5d49350a0e6d002d740b74]
stable/6.18: [90a8a938e0caecc9ee9dec3eb9eda92d66ba02a3]
stable/7.1: [7445e1b85159baf40d56b9557f344f131f924dd0]
CVE-2026-68269: drm/i915/gem: Add missing nospec on parallel submit slot
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68269
Introduced by commit e5e3217 ("drm/i915/guc: Connect UAPI to GuC
multi-lrc interface") in v5.16-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [914a76a9f08366434bf595700f62026b7a19a9cc]
stable/6.12: [be393175306694de5da1d1a23a8ea4149baa09f1]
stable/6.18: [45db277b2e1e34bcc99a0852026791108339ec3e]
stable/6.6: [4a27275d275971c9ea29d3d240ea4a224ad368a2]
stable/7.1: [c41a54619e95f860bf2950dd679ab353380ecd2b]
CVE-2026-68270: drm/sysfb: Avoid possible truncation with calculating
visible size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68270
Introduced by commit 32ae90c ("drm/sysfb: Add efidrm for EFI
displays") in v6.16-rc1.
Introduced by commit a84eb6a ("drm/sysfb: Add vesadrm for VESA
displays") in v6.16-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b771974988ec7ce077a7246fa0fa588c246fe581]
stable/6.18: [154795885e8f0033c918c815aece543168bee670]
stable/7.1: [9d58a811739a365cd693192f4b5344d736967a88]
CVE-2026-68271: drm/nouveau: fix reversed error cleanup order in ucopy functions
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68271
Introduced by commit b88baab ("drm/nouveau: implement new VM_BIND
uAPI") in v6.6-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ab99ead646b1b833ecd57fe577a2816f2e848167]
stable/6.12: [e15c25c7972d38a9f6bf8c3f7f29179a67263eba]
stable/6.18: [4e109faa9ea2b6c04cc5a99e76db3126575a59d1]
stable/6.6: [2473ac314387a5def7244eb6d6a345934ed140bf]
stable/7.1: [ebbaf64d2635d1e78196c067fa8fa582a7dc17f7]
CVE-2026-68272: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68272
Introduced by commit ac92870 ("drm/amdgpu: add gfx shadow CS IOCTL
support") in v6.5-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [84c4c36acd5c4b2558b5069f869a165b2c655c84]
stable/6.12: [2aa9ea2bd5146d237c8cc16d8737d878b0298a94]
stable/6.18: [315d2e5741a81b0be763e80413a2677e22b7e596]
stable/6.6: [3f190956404da55560056ce20606010e18bc059c]
stable/7.1: [24668ca3ec19434d7a9574bf9112f2b0614c3a4e]
CVE-2026-68273: drm/amdgpu: Fix context pstate override handling
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68273
Introduced by commit 79610d3 ("drm/amdgpu: fix pstate setting issue")
in v6.1-rc3.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c1dc4ccb82c9e56325d8e7514ca4c90bd1efb351]
stable/6.12: [23a8726e1d7597fe7c9a59d5dc42ba8b7d345b8a]
stable/6.18: [e06c39cc1c48dca68a5ffd971c23025a52d46634]
stable/7.1: [9f9c88eb298c54348be3ca4087f4f4c615065b87]
CVE-2026-68274: drm/xe/guc: Fix buffer overflow in steered register
list allocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68274
Introduced by commit b170d69 ("drm/xe/guc: Add XE_LP steered register
lists") in v6.13-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0]
stable/6.18: [b485bfb45555163bfa5f565d6a3415fcb3035b02]
stable/7.1: [a9a020f3c11eba6573b699f9cf9245a51b025ade]
CVE-2026-68275: drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68275
Introduced by commit 4d82724 ("drm/amdgpu: Add mapping info option for
GEM_OP ioctl") in v6.18-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [93475c34111916df71c63e510fc52db01351f809]
stable/6.18: [ddba17b3dfa0efc80d6c98621c2fb7af66adb622]
stable/7.1: [9faf4c66edb6bcb8ca0465c3a4868bb7f278cd31]
CVE-2026-68276: drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68276
Introduced by commit d361ad5 ("drm/amdgpu: Add sysfs interface for
running cleaner shader") in v6.12-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3]
stable/6.12: [201633f47b542a99bb7baafdfcda7781249fb3d9]
stable/6.18: [e28420e36542ae8b66a5bdcec419525f521bddf8]
stable/7.1: [9cd9a983769a4d0e9cc80a287316ee79685d38b3]
CVE-2026-68277: drm/dp/mst: fix OOB reads on 2-byte fields in sideband
reply parsers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68277
Introduced by commit ad7f8a1 ("drm/helper: add Displayport
multi-stream helper (v0.6)") in v3.17-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6b89ba3dba2f583626fb693e47e951ffb8bf591f]
stable/6.12: [0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df]
stable/6.18: [d5c70523cafa26ad2c7a37b612849abe2683baa8]
stable/6.6: [bdf0508b1e6785d4a8982c637e97e68d60b47d7b]
stable/7.1: [68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73]
CVE-2026-68278: drm/dp/mst: fix buffer overflows in sideband chunk accumulation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68278
Introduced by commit ad7f8a1 ("drm/helper: add Displayport
multi-stream helper (v0.6)") in v3.17-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [55bd5e685bda455b9b50c835f8c8442d52a344a3]
stable/6.12: [ef0dbcc200c3389f1f781ab181932a97e54b51af]
stable/6.18: [1e5827839ad0ceb0079d1560c321fa3656b54f21]
stable/6.6: [53937a2787d29c7a460e984dc4f20ff6ac91dc65]
stable/7.1: [a6366b551079c79bf7bdbadd74c97358bcfe2d58]
CVE-2026-68279: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband
reply parsers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68279
Introduced by commit ad7f8a1 ("drm/helper: add Displayport
multi-stream helper (v0.6)") in v3.17-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1a8f537f5a1eeac941f262fe73078d6b08ba83c0]
stable/6.12: [04d953f50d61e542e94a5977822cc53735f8c0ce]
stable/6.18: [533d9e2bede4aeefdc2a0561d7071cfede95958f]
stable/6.6: [22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2]
stable/7.1: [e6ef5455b06cb4e5d181aabcd723791587c79f12]
CVE-2026-68280: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68280
Introduced by commit e192339 ("drm/bridge: Add Cadence DSI driver") in
v4.18-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d8b08844c0ecc6f2002fa68711e779aa18c8585]
stable/6.12: [347bc3a6a4d968c403d2292e5ad986294d919dfc]
stable/6.18: [c0384d6872f4dc2701960048a0be1a12a8d2dc6e]
stable/6.6: [c18d46d9830c29677be5213a067daafe1ac80e43]
stable/7.1: [1f9c6b74e79639179e90ad0c0fbeae26e31e044b]
CVE-2026-68281: drm/imagination: Count paired job fence as dependency
in prepare_job()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68281
Introduced by commit eaf01ee ("drm/imagination: Implement job
submission and scheduling") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9cd74f935306cd857f46686975c43383e1d95f94]
stable/6.12: [02b0da249c8f78d2bbf9f498bbd371c66142b0af]
stable/6.18: [943fa73ea0efa335d9c1800fcfac47915de4ff89]
stable/7.1: [a673171502e87acb5a9e2923f4cf9dce521fd05e]
CVE-2026-68282: drm/rockchip: analogix_dp: Add missing error check for
platform_get_resource()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68282
Introduced by commit 718b3bb ("drm/rockchip: analogix_dp: Expand
device data to support multiple edp display") in v6.15-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [45895f4d4d5f222d07412f90664f88b059627859]
stable/6.18: [6ab29a86835721566f0c26bd7bebcdcdcb0cb093]
stable/7.1: [ba34d197ebf2552cf10d279e076c58a22c9ecf73]
CVE-2026-68283: tracing: Fix use-after-free freeing trigger private data
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68283
Introduced by commit 61d445a ("tracing: Add bulk garbage collection of
freeing event_trigger_data") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [79097812153b826fc156a2930ec8a90ed9edf4a2]
stable/7.1: [b9c8a1400a3bf633f32820d184f3e05fed0f4af7]
CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68284
Introduced by commit 604326b ("bpf, sockmap: convert to generic sk_msg
interface") in v4.20-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2d66a033864e27ab8d5e44cb36f31d9d2413bee4]
stable/6.12: [cde4d6bcd9b73073c66498f6723c7b364c4dbc18]
stable/6.18: [786d690257ec7a0c839f8710456e444ce3f1348b]
stable/6.6: [ee762f684eefa59de34d9ed93cab08336e834f47]
stable/7.1: [752b1159ed5d0c48fe169a3721b96660a9822aa1]
CVE-2026-68285: LoongArch: BPF: Fix memory leak in bpf_jit_free()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68285
Introduced by commit 4ab17e7 ("LoongArch: BPF: Use BPF prog pack
allocator") in v7.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [47e20d4b3da97ef3881d1e55e43545c22424f3fc]
stable/7.1: [f1557e0a64736b63aed24e285108a7bc3b7de294]
CVE-2026-68286: drop_monitor: perform u64_stats updates under
IRQ-disabled section
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68286
Introduced by commit e9feb58 ("drop_monitor: Expose tail drop
counter") in v5.4-rc1.
Introduced by commit 5e58109 ("drop_monitor: Add support for packet
alert mode for hardware drops") in v5.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fd098a23bf8fda7eae48db9b06e7c34fc4d228fa]
stable/7.1: [d5e2cd2bc8ae36617346b3a54ee9da61d866bf92]
CVE-2026-68287: drop_monitor: fix size calculations for 64-bit attributes
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68287
Introduced by commit ca30707 ("drop_monitor: Add packet alert mode")
in v5.4-rc1.
Introduced by commit 5e58109 ("drop_monitor: Add support for packet
alert mode for hardware drops") in v5.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7089f7ab99c89f443c92d8fcc585e63f2727f0b3]
stable/7.1: [4a9e30764e80693bcf875c776170edce20f94fe0]
CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68288
Introduced by commit ca30707 ("drop_monitor: Add packet alert mode")
in v5.4-rc1.
Introduced by commit 5e58109 ("drop_monitor: Add support for packet
alert mode for hardware drops") in v5.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5e9c8baee0329fbefe7c67aea945e2a07f15e98b]
stable/7.1: [8fd6975d2aecc36b25ee82b6aef88e62a3527ccb]
CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and
tipc_recvstream()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68289
Introduced by commit e9f8b10 ("tipc: refactor function
tipc_sk_recvmsg()") in v4.12-rc1.
Introduced by commit ec8a09f ("tipc: refactor function
tipc_sk_recv_stream()") in v4.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [47f42ff521b4eeb46e82f9a46a4783a99f7570d7]
stable/7.1: [fe9bf32bb18f2d35789d4960fb007d1059bbaa38]
CVE-2026-68290: rds: tcp: unregister sysctl before tearing down listen socket
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68290
Introduced by commit 7f5611c ("rds: sysctl: rds_tcp_{rcv,snd}buf:
avoid using current->nsproxy") in v6.13-rc7.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [167e54c703ccd4fa028feb568b0d1002020cff86]
stable/6.12: [80fffed08dc1c10e971066941d2daa56253f1552]
stable/6.18: [16df2d154ec82e2f7e7585b4fa154751ba37729a]
stable/7.1: [3aa13fe0c1bb7bc5312f878e61523e5d8cf3f85d]
CVE-2026-68291: idpf: fix max_vport related crash on allocation error
during init
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68291
Introduced by commit 0fe4546 ("idpf: add create vport and netdev
configuration") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [237f1f7653b8729169af11fae79f01b90d00b87e]
stable/7.1: [9fbe22b7aff0a65984d78ee6b93e2f8179abd1f5]
CVE-2026-68292: ice: prevent tstamp ring allocation for non-PF VSI types
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68292
Introduced by commit ccde82e ("ice: add E830 Earliest TxTime First
Offload support") in v6.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [144539bbfd3cea1ab0fb6f5216d6004c1f4f029b]
stable/6.18: [684d4d0bda95a3fb21b3e29ff0f668f657707b54]
stable/7.1: [d0a21604c6abfa4956f3a511a1de174cec77a812]
CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68293
Introduced by commit 271907e ("net/mlx5: Query the maximum MCIA
register read size from firmware") in v5.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [11c057d23465c7a5817a7284c896d19d54c0b616]
stable/6.12: [5be4eebd5a3a198dab0adcd550e1cadca79bdfed]
stable/6.18: [87b39a8c875ca744b7de69af0a8ef8874cffccf1]
stable/7.1: [88b2a16ddac3357e3f1d528e758b51e2c945d546]
CVE-2026-68294: net: qrtr: restrict socket creation to the initial
network namespace
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68294
Introduced by commit bdabad3 ("net: Add Qualcomm IPC router") in v4.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3b536db8fb32da9e9c62f2bb45e2e319331f0426]
stable/6.12: [f488116df769bdaf89c93371350e49e12133e70f]
stable/6.18: [8150c48fb978e01689f94ed80148f8a7499ae571]
stable/6.6: [4b95e1f0d6e6342c427cb341ee18a894b146b789]
stable/7.1: [659b9b4f194bb56b9903cc95e786ef1d438baa7d]
CVE-2026-68295: LoongArch: BPF: Zero-extend signed ALU32 div/mod results
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68295
Introduced by commit 2425c9e ("LoongArch: BPF: Support signed div
instructions") in v6.7-rc1.
Introduced by commit 7b6b13d ("LoongArch: BPF: Support signed mod
instructions") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dacd348b8a993373576fe2ee2d8b114740ba57a6]
stable/7.1: [716cb29dbed4d62e9e108950a1a82bcba4cc2d45]
CVE-2026-68296: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68296
Introduced by commit 00d066a ("netdev_features: convert NETIF_F_LLTX
to dev->lltx") in v6.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [675ed582c1aa4d919dd535490de08c015005c653]
stable/6.12: [9f948e9aede9678f4103457daf2bc9dd54c65a06]
stable/6.18: [15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3]
stable/7.1: [2bffe379023512d280337c70faeb6a8cc435db5e]
CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68297
Introduced by commit 901271e ("tipc: implement configuration of UDP
media MTU") in v4.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8]
stable/6.12: [f4013598b69457dbea350df52e52daea6faef8eb]
stable/6.18: [1b8fb5a20508bfb0db854e01214888c761b3a911]
stable/6.6: [f02334a9e378f7e07232b26dc3d2ab353339f040]
stable/7.1: [c1cda72f6acec02ebd45d913bf8527ff77336ba6]
CVE-2026-68298: drm/xe/vm: Fix SVM leak on resv obj alloc failure in
xe_vm_create()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68298
Introduced by commit 9e97874 ("drm/xe/userptr: replace xe_hmm with
gpusvm") in v6.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d2c6800ad1802bed72a6de1416536737f114f1d6]
stable/6.18: [279339aa8bdcf9db40094cf2bcbd495c53dbe817]
stable/7.1: [9ac92736030f3395d970c300eaeb59ac258a0c3e]
CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68299
Introduced by commit 45dac1d ("vmxnet3: Changes for vmxnet3 adapter
version 2 (fwd)") in v4.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [34a71f5361fc3adb5b7138da78750b0d535a8252]
stable/6.12: [28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8]
stable/6.18: [4fdb0f162ccdbe9626863b10003855703253fa29]
stable/6.6: [667b6e52048eaf4dbcf1707ed87ffd44abb9cb38]
stable/7.1: [b28596baf87e25a078789f1c05817c8a3bf71257]
CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68300
Introduced by commit bbd0d59 ("[SCTP]: Implement the receive and
verification of AUTH chunk") in v2.6.24-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8e04823c120b376ef7dab14b60ebf6823aa16c14]
stable/6.12: [28c5fdce9dd955d2baf5e28987819b6d7cfaf646]
stable/6.18: [18957373920caf5cdaf5cf32e5d1d7a99ca7700a]
stable/6.6: [ec2e157fc9678a9bc411305a25aec3fd337d7efb]
stable/7.1: [83f5031f2a6a49d696eb4cc0898345d12f9c6451]
CVE-2026-68301: net: hsr: fix memory leak on slave unregistration by
removing synced VLANs
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68301
Introduced by commit 1a8a63a ("net: hsr: Add VLAN CTAG filter
support") in v6.13-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/5.15 stable/6.1 stable/6.12 stable/6.6
Fixed status
mainline: [dcf15eaf5641812f1cfc5e96537380132a7da89d]
stable/6.12: [21d48408479a17eb65568a765930adea37e4d804]
stable/6.18: [b5ded444621b6180df9f3d4e07045fc1fc1e8cd9]
stable/6.6: [f72c312af6c7897ab0f8a2b5a63f917a207a4143]
stable/7.1: [ae995b8002d3af134560a706c0e111a89e26317c]
CVE-2026-68302: amt: re-read skb header pointers after every pull
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68302
Introduced by commit cbc21dc ("amt: add data plane of amt interface")
in v5.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3656a79f94c471827a08f2cacce5f94ad5e52c24]
stable/6.12: [7746d588d42a4ac0117b68ed8e9b22a9da53dfb7]
stable/6.18: [ca0e8b661957f777591efe874cd9d9a63619cd99]
stable/6.6: [9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e]
stable/7.1: [7f48e3ddad8e97545b25788b8203b3a539df1621]
CVE-2026-68303: drm/vc4: hvs/v3d: Fix null dereference in unbind
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68303
Introduced by commit d3f5168 ("drm/vc4: Bind and initialize the V3D
engine.") in v4.5-rc1.
Introduced by commit c8b75bc ("drm/vc4: Add KMS support for Raspberry
Pi.") in v4.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7dc3680b7ffe01add3e9299fde8471d2dd53a8ae]
stable/7.1: [261f0a3f0ac03248284f5116d3258f89c9642215]
CVE-2026-68304: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68304
Introduced by commit 2526ff2 ("brcmfmac: support 4-way handshake
offloading for 802.1X") in v4.13-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7cb34f6c4fe8a68af621d870abe63bfca2275dd6]
stable/6.12: [d3ac5b35ec85c41ccf8ec524d47b520e72edaca1]
stable/6.18: [00ebbf030d8c4a1cb89cbbae15e28332373649db]
stable/6.6: [137e4710da626290495b174e2eb1d5e889a4b165]
stable/7.1: [bd4fac033bb95fcad898cf6734e869991b2561cb]
CVE-2026-68305: drm/xe/vf: Add drm_dev guards when detaching CCS
read/write buffers
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68305
Introduced by commit 864690c ("drm/xe/vf: Attach and detach CCS copy
commands with BO") in v6.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4c92afb4c143526d340545ca581e88e6952ea511]
stable/7.1: [523ed2831ee55b2a1edabdea96781651f9df9685]
CVE-2026-68306: wifi: mt76: mt7996: fix possible NULL-pointer deref in
mt7996_mcu_sta_bfer_eht()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68306
Introduced by commit ba01944 ("wifi: mt76: mt7996: add EHT beamforming
support") in v6.3-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2fffc472bec490c8357defcee9c075ca74467352]
stable/6.12: [3e4f848f4a620e1d77c38459e73cf3b362f7bc6b]
stable/6.18: [d5628f39fccc107dca00b98a491d9848898599f7]
stable/6.6: [2b1882cf313ae44181146629b3578a7826c672c9]
stable/7.1: [45c496756c6f6df6c3aeb5b2cb996993d2f14687]
CVE-2026-68307: wifi: mt76: mt7925: fix crash in reset link replay
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68307
Introduced by commit 1406199 ("wifi: mt76: mt7925: add link handling
in mt7925_vif_connect_iter") in v6.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bd8b2ec838184236c3fcbf738a926328836adf12]
stable/6.12: [d9326796a378f80be5f9fd60983c62fdccdf2f0b]
stable/6.18: [95b0cf02731c74e073ef8937f5526bd4442a0326]
stable/7.1: [89d03bda560d635f66d495f37b46a187fd4edfdf]
CVE-2026-68308: wifi: mt76: mt7996: check pointer returned by
mt76_connac_get_he_phy_cap()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68308
Introduced by commit 98686cd ("wifi: mt76: mt7996: add driver for
MediaTek Wi-Fi 7 (802.11be) devices") in v6.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e858cf6bf99880343348ff1e8c942aaff1d9d592]
stable/6.12: [8b8a079e22ce9fc3c0d05b148ef67e4c6e576678]
stable/6.18: [d14238523ca4c6f5fcb54d1920eb2f8525a7711f]
stable/6.6: [4fd85fd2373501b7386e93a5ce4a549d7c4e64e3]
stable/7.1: [8bc7167e8a86489b7cb96a69cf1fb671d6df014b]
CVE-2026-68309: wifi: mt76: connac: fix possible NULL-pointer deref in
mt76_connac_mcu_uni_bss_he_tlv()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68309
Introduced by commit d0e274a ("mt76: mt76_connac: create mcu library")
in v5.12-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2c1fb2335f5e3afb34f91bc07ecb63517c328090]
stable/6.12: [2afc2d5098866518a5c446a2e647b1b3f43daaf4]
stable/6.18: [c058786b09cfab080125bc3ee7928a181dcbd37a]
stable/6.6: [b09508dd7bc4a8948ea00603041a918c09788502]
stable/7.1: [8709c66e665a2a09192853d4f3d0fb4bd0f76403]
CVE-2026-68310: wifi: mt76: mt7915: guard HE capability lookups
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68310
Introduced by commit e6d557a ("mt76: mt7915: rely on
mt76_connac_get_phy utilities") in v5.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8e9db062654a388d0fa587acbeeae68dd33eba41]
stable/6.12: [a031f454f14e3e76ad03bcb23918e1a82b4b0869]
stable/6.18: [871549814eb4da081f1e93cc0c7ea626a310a966]
stable/6.6: [23a2b98e754da04e0e90314d5fa8ca44349590fb]
stable/7.1: [6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e]
CVE-2026-68311: wifi: mt76: mt7925: guard link STA in decap offload
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68311
Introduced by commit b859ad6 ("wifi: mt76: mt7925: add link handling
in mt7925_sta_set_decap_offload") in v6.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [96ea44f2269f30364cffa054ee3a87e595bef0d4]
stable/6.12: [1e608cae1ba0b4a600b752efa223fd2be376b143]
stable/6.18: [f1ee53e08fdd2906e90c6a6d71e1368fcd52bfc3]
stable/7.1: [d86883f7e8f03a5b81b4e59f2c0b6c05f79e01fd]
CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in
deferred close drain paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68312
Introduced by commit e3fc065 ("cifs: Deferred close performance
improvements") in v5.15-rc3.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c2f2e83e3bbc5483730fd4ee903182761f1ae50f]
stable/7.1: [32390b3f06f26e366cfb27dbac4bc0196c321535]
CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68313
Introduced by commit d0796d1 ("tipc: convert legacy nl bearer dump to
nl compat") in v4.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [22f8aa35964e8f2ab026578f45befc9605fd1b28]
stable/6.12: [1ab78af2140189b735b8d3b889b0284128cb2013]
stable/6.18: [e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef]
stable/6.6: [f9c669d9f4cac832fe31193cdbc24c6a9d99398b]
stable/7.1: [b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48]
CVE-2026-68314: net: mctp i3c: clean up notifier and buses if driver
register fails
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68314
Introduced by commit c8755b2 ("mctp i3c: MCTP I3C driver") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [03d1057305ef17ac3f5936ac1580bc9a1a826e14]
stable/6.12: [49d15cfab247c0f60ce1800bdcd66850beea7b3a]
stable/6.18: [a8bd8c109da5a87f0c5db0c23cf550d039fde77c]
stable/7.1: [a40e83a34eaa2be64372286040696f04eabcd09f]
CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68315
Introduced by commit 7f9d68a ("sctp: implement sender-side procedures
for SSN Reset Request Parameter") in v4.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [18ae07691d43183d270de8be9dc8e027906015d9]
stable/6.12: [6f0e39d180cd7cced647381b6fa14fd83d261047]
stable/6.18: [1a10fe1aa9c01f41b389a31906a77d538637c9d9]
stable/6.6: [b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b]
stable/7.1: [00ae679cb21a035491fdad8d58dc6d79cc68b675]
CVE-2026-68316: accel: ethosu: Fix element size accounting for cmd
stream validation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68316
Introduced by commit 5a5e9c0 ("accel: Add Arm Ethos-U NPU driver") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [18a551482a4a326790698b273e76d7575a51a57d]
stable/7.1: [b4ae748f8e6cb65bb86e5a281bbb5b5e5f106527]
CVE-2026-68317: pds_core: fix auxiliary device add/del races
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68317
Introduced by commit b699bdc ("pds_core: specify auxiliary_device to
be created") in v6.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.6
Fixed status
mainline: [bfa33cd513c7ceb93c5a4c30e5662acd73c0a916]
stable/6.12: [ef194751fed50cf3452017b63f00142a0ab40c70]
stable/6.18: [cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518]
stable/6.6: [646b58b543f3bb1641e9123b75ff7799fe7b42f1]
stable/7.1: [bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454]
CVE-2026-68318: pds_core: fix use-after-free on workqueue during remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68318
Introduced by commit 01ba61b ("pds_core: Add adminq processing and
commands") in v6.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0ad134881508c36b65c1a8864f8bec53adbd3327]
stable/6.12: [224214eb4182ff20a665b615a90b66017539dd75]
stable/6.18: [9e0f80fac50ab95dd75537c8ecaf5051d01f19b5]
stable/7.1: [ecc7a7d7569ec1d6a61e18372696b9de97635156]
CVE-2026-68319: pds_core: fix deadlock between reset thread and remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68319
Introduced by commit 81665ad ("pds_core: Fix pdsc_check_pci_health
function to use work thread") in v6.9-rc4.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ab0eec0ff0a421737a37f510ceab5c6ea59cd05a]
stable/6.12: [90d9f3ef28843e6c35149324b8eefb427a7435c2]
stable/6.18: [19ef775c91c6bf4bd2b60f6616f4e28b621cdd6a]
stable/7.1: [54f905821f26d385fba407a920b51f0a752c76dc]
CVE-2026-68320: sctp: fix auth_chunk_list capacity check in
sctp_auth_ep_add_chunkid
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68320
Introduced by commit 1f48564 ("[SCTP]: Implement SCTP-AUTH internals")
in v2.6.24-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ff04b26794a16a8a879eb4fd2c02c2d6b03850e9]
stable/6.12: [886e28e14ab655012779016d251fef53d103aa12]
stable/6.18: [11092d79eb2b7c0068382f72fc2416d1786bb2e0]
stable/6.6: [5a365f1e423444c5da7eb689a8661633dad43e48]
stable/7.1: [b6ea3dda09eb4d5caf7bbc00f857688cf9e98255]
CVE-2026-68321: net: txgbe: fix FDIR filter leak on remove
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68321
Introduced by commit 4bdb441 ("net: txgbe: support Flow Director
perfect filters") in v6.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ecaa37826340520664a4e5522f803ff48fc3f564]
stable/6.12: [5c2f04258be2645cdd8f87553990948e7054e7fb]
stable/6.18: [2d34421bfa261f7e83bea2f2f75fa75e0c3037d1]
stable/7.1: [4946dea2386333e5d93bfb36df803fefb5a8c635]
CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68322
Introduced by commit eee2fa6 ("rds: Changing IP address internal
representation to struct in6_addr") in v4.19-rc1.
Introduced by commit 1e2b44e ("rds: Enable RDS IPv6 support") in v4.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9c805e592a29be9e4e61ff1bd567da04aa8fd6f9]
stable/6.12: [a8302e758050e6a922765aee8d220a4fd350f52d]
stable/6.18: [f6787fdffcae5490c779f0f3f33b11597525d1ae]
stable/6.6: [8e48d7ab1e01936a172ff31531904b003895fd8c]
stable/7.1: [00d5707217b5972554898ff734ae7b71bce704e6]
CVE-2026-68323: tipc: serialize udp bearer replicast list updates
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68323
Introduced by commit ef20cd4 ("tipc: introduce UDP replicast") in v4.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [350e592ff4e30e48ffb55e142d11a73e63f4869c]
stable/7.1: [d70c81001df9320d3445e664428a1d408b5ba896]
CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68324
Introduced by commit 55ee5e6 ("iommu/vt-d: Add common code for dmar
latency performance monitors") in v5.14-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [754f8efe45f87e3a9c6871b645b2f9d46d1b407b]
stable/6.12: [866a35735e56b9dc81cbc33899255134adf6d8b3]
stable/6.18: [d06fea9b85f038690f55e72fe0c45e113715a85a]
stable/6.6: [3078d82e7fe9048a2b90a992e71af7cd7ef881fa]
stable/7.1: [0e28ca1c3204b51068579defc904a0dfba5e5c57]
CVE-2026-68325: iommu/amd: Bound the early ACPI HID map
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68325
Introduced by commit ca3bf5d ("iommu/amd: Introduces ivrs_acpihid
kernel parameter") in v4.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [fb80117fddb5b477218dc99bb53911b72c3847f8]
stable/6.12: [abe5d7962f09adada9c4fb25b816dddd3f97c55d]
stable/6.18: [e5ebe8544df1a1c3611739a8622156094fe470df]
stable/6.6: [1e31d2394e0db69541b1591d46c5ad6431c81db3]
stable/7.1: [030a8e84f8f1b6e96f469c84a13a225c3699910b]
CVE-2026-68326: wifi: mwifiex: bound uAP association event IEs to the
event buffer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68326
Introduced by commit e568634 ("mwifiex: add AP event handling
framework") in v3.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f0858bfc7d3cab411a447b88e3ef970e575032c9]
stable/6.12: [ad26c75ae25749313248f06510ebe43b5bf4adcc]
stable/6.18: [d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c]
stable/6.6: [a3f47d7c75ddad1a14621a309286f9fae3cba191]
stable/7.1: [b6766d7ea43edf5de9d5a572bc58b631d09efe4b]
CVE-2026-68327: wan: wanxl: Only reset hardware after BAR mapping
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68327
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [91957b89da995607cb654b1f9a3c126ddbaee10f]
stable/6.12: [b9e2ff70e96acf83693b27987e0390bad9f83efa]
stable/6.18: [59cbe6cfa0fa23c192351cc284e30707309f6741]
stable/6.6: [f4834132773f15ffb255127499c8443947fa7d0f]
stable/7.1: [2fe22d58b3797d741570f9873b26653fd511576c]
CVE-2026-68328: nfp: Check resource mutex allocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68328
Introduced by commit f01a216 ("nfp: add support for resources") in v4.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc]
stable/6.12: [cfa119aa781c4044dab5b4c1e5864600f53a26bc]
stable/6.18: [3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3]
stable/6.6: [6dbd428119cb1fd1b73cf6968c711f4ea964dc8b]
stable/7.1: [a7dc30b6828c3a30252892827b12b676749f250f]
CVE-2026-68329: iommu/amd: Wait for completion instead of returning
early in iommu_completion_wait()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68329
Introduced by commit 815b33f ("x86/amd-iommu: Cleanup completion-wait
handling") in v3.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1e75a8255f11c81fb07e81e5029cfd75804350a0]
stable/6.12: [93494bd446396c257fb589f59894577e96e406e2]
stable/6.18: [d053eb7e09e10cbdca3fca8b35c1017d438091b2]
stable/6.6: [ab7faf5a172ebfdc423ebb3eea4d472740de82f9]
stable/7.1: [02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb]
CVE-2026-68330: net: airoha: Fix DMA direction for NPU mailbox buffer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68330
Introduced by commit c529187 ("net: airoha: npu: Move memory
allocation in airoha_npu_send_msg() caller") in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6f884eb87a79e0c482baef2ad96c96b81d024235]
stable/6.18: [76fc5604308a109bf5838c2a0a0eb3ac6819f1ea]
stable/7.1: [4c4d866a64f36718cbcdf20add372a599dd44311]
CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68331
Introduced by commit 7194792 ("dpaa2-eth: add MAC/PHY support through
phylink") in v5.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b4b201cc93ff70150853aba03e14d314d1980ca0]
stable/6.12: [e23e4a3b9dfd893469c731318d409cdf04fb1ddf]
stable/6.18: [f112df0744e2d77baa68eeebb860021bbaaa022a]
stable/6.6: [915012e923316b8b5d5bf8fc771617b47bd7572d]
stable/7.1: [a3cecf169cc652b558d08661bb6ce55e4c933ec0]
CVE-2026-68332: net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68332
Introduced by commit 6abcf75 ("net: airoha: Fix schedule while atomic
in airoha_ppe_deinit()") in v6.19-rc5.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
stable/6.18
Fixed status
mainline: [2484568a335cd7bda951c75b3a7d95ea36161ae7]
stable/6.18: [46e3bed4b071095ecc9384a7b349e1908728531f]
stable/7.1: [ad28c4f9e0eae4993cb3fde3e7cea330acd8b97c]
CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68333
Introduced by commit 84cba72 ("dpaa2-switch: integrate the MAC
endpoint support") in v5.15-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4c1eabbef7a1707635652e956e39db1269c3af2b]
stable/6.12: [680eecc850d36a280df9780496bc603fec17b2d6]
stable/6.18: [26ac2d3602347f0377fbcd5214bc28a9d735ae68]
stable/6.6: [1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38]
stable/7.1: [c27694ff6748e08fcd2fdba89018439d75b8198f]
CVE-2026-68334: rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68334
Introduced by commit 5800b1c ("rxrpc: Allow CHALLENGEs to the passed
to the app for a RESPONSE") in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [745fb794c3e933c023af9dbb5876a5e16ad2dc71]
stable/6.18: [c9165e199f56997f2f2deb5d3ec2dfab98dfa288]
stable/7.1: [092b42cf3f6013eec43607ecbcad674723649514]
CVE-2026-68335: rds: drop incoming messages that cross network
namespace boundaries
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68335
Introduced by commit c809195 ("rds: clean up loopback rds_connections
on netns deletion") in v4.18-rc4.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5521ae71e32a8069ed4ca6e792179dc57bc43ab2]
stable/6.12: [cfb3ce07b705e486e022a2f2b1242b48f13981ff]
stable/6.18: [9591042533140dfe6608d9344806d567dcd39d02]
stable/6.6: [1e2e2d9806944fe485824d617c8b7c78116c22db]
stable/7.1: [0f8690e3869109cd5803ccb400889d20a0b54e0e]
CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68336
Introduced by commit 4e24be0 ("bonding: add new parameter ns_targets")
in v5.18-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1c975de3343cdef506f2eecc833cc1f14b0401c4]
stable/6.12: [690ce66782778e8c4b1fdd79c0b0890a100e9522]
stable/6.18: [992dce02bdabbd9883255ea9b36494e34a7821d7]
stable/6.6: [2a4bad24ac5296b262ad821aa5e08bb265e6b154]
stable/7.1: [738039ad21e20ca2c5bbde2f5a4f5ad5fb718038]
CVE-2026-68337: bpf: Reject redirect helpers without a bpf_net_context
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68337
Introduced by commit 401cb7d ("net: Reference bpf_redirect_info via
task_struct on PREEMPT_RT.") in v6.11-rc1.
Introduced by commit 3625750 ("net: sched: Introduce helpers for
qevent blocks") in v5.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3f4920d165b29052255527d8ae7619e7ec132ece]
stable/7.1: [cabfacbd5af09d3ae898ca224c4a1459e9bba15d]
CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68338
Introduced by commit dc99f60 ("packet: Add fanout support.") in v3.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [50aff80475abd3533eef4320477037e6fcc6b56e]
stable/6.12: [0a052e0808e015e68144a9877e6ef42b952c49fa]
stable/6.18: [1bc55c29cd85818e9052f17deb287d5a11fb817f]
stable/6.6: [80ec024d53a05c60ad1d08968dcf745f10c1665c]
stable/7.1: [a885387dae7986a55bae5c77a15bdd447f64e9b9]
CVE-2026-68339: Bluetooth: btusb: validate Realtek vendor event length
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68339
Introduced by commit 044014c ("Bluetooth: btrtl: Add Realtek
devcoredump support") in v6.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [df541cd485ff80a5ddc579d99687bc7506df9851]
stable/6.12: [400267bab0f4076088e163e58cad2bb41c3cf5e7]
stable/6.18: [8881daaafadbe7fb2b7341d16a3949114409c90c]
stable/6.6: [8de58bfa26e028f99271dde5a92107cd07f5e063]
stable/7.1: [24b0758193d70da47ef8b979153d2a181dbdf34e]
CVE-2026-68340: hwmon: occ: validate poll response sensor blocks
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68340
Introduced by commit aa195fe ("hwmon (occ): Parse OCC poll response")
in v5.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [70e76e700fc6c46afb4e17aec099a1ea089b4a22]
stable/6.12: [54cb78eceb4e286ccd5a5c01a4632157860d47f0]
stable/6.18: [538d862cc0dbd5c732fe26d5aad98eae039e6676]
stable/6.6: [112525534ab5cff482d35897ca4ca11fd3a76f46]
stable/7.1: [b042e538e98b939fccfffc464e2c34c29f0e96ef]
CVE-2026-68341: ovpn: fix use after free in unlock_ovpn()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68341
Introduced by commit 80747ca ("ovpn: introduce the ovpn_peer object")
in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e1ad6fe5db719874efa45b2caf9934552e09fc43]
stable/6.18: [5b96227c0e8b212b74838424c929fc889aedb555]
stable/7.1: [4cdb209f12a89c5faf9be0c45edb90ccdf65db0c]
CVE-2026-68342: ovpn: avoid putting unrelated P2P peer on socket release
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68342
Introduced by commit f6226ae ("ovpn: introduce the ovpn_socket
object") in v6.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b52c5103f64ee825996ca1ab8df7283cde8c5f86]
stable/6.18: [c5bf6b39be235ef578af4d39872f0c68cda3b937]
stable/7.1: [016a50379d17b886d12a4efa5211a418e035fe70]
CVE-2026-68343: smb: client: validate DFS referral PathConsumed
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68343
Introduced by commit 4ecce92 ("CIFS: move DFS response parsing out of
SMB1 code") in v4.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f6f5ee2aa33b350c671721b965251c42cebb962e]
stable/6.12: [285bd4a5f3f156aa5869843b47a1b1380b774241]
stable/6.18: [2fdd6d196c656b376cc251e1e9ff110b3ed522e1]
stable/6.6: [5b439f39f33ec15d319ced3b025e122346fba987]
stable/7.1: [9f88a99ed511651b2dc2177d6854b2d1b8322e75]
CVE-2026-68344: usb: atm: ueagle-atm: reject descriptors that confuse
probe and disconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68344
Introduced by commit e2674df ("usb: atm: ueagle-atm: wait for
pre-firmware load in .disconnect()") in v7.2-rc3.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/5.10 cip/6.1 cip/6.12 stable/5.10 stable/5.15 stable/6.1
stable/6.12 stable/6.18 stable/6.6 stable/7.1
Fixed status
mainline: [71132cedd1ecbc4032d76e9928c18a10f7e39b80]
stable/6.12: [9904a46401198872ab3de34fd11f383831ef3428]
stable/6.18: [d0a57f19fe2865b9747484f5f9c631f944ed9a0f]
stable/6.6: [c035b1198906dd5bd3df9a3045b59254bad1ea7a]
stable/7.1: [0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce]
CVE-2026-68345: arm_mpam: guard MBWU state before adding it to garbage
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68345
Introduced by commit 41e8a14 ("arm_mpam: Track bandwidth counter state
for power management") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [977f52909c624210178a1247fab0b02b110c1106]
stable/7.1: [ca1f96334267ab8d47b2c9d535cdc9920fdde269]
CVE-2026-68346: ALSA: hda: cs35l41: validate and free ACPI mute object
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68346
Introduced by commit 447106e ("ALSA: hda: cs35l41: Support mute
notifications for CS35L41 HDA") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3b597d24dc0455ae926f1053f97c2725038fc3cd]
stable/6.12: [7fea0c89ed39a13d9a31163a74f8c62de30a4ffc]
stable/6.18: [08433c71f15984ddd5f5a307cf3f0aa9b84583aa]
stable/7.1: [d5dfdf43259ad9d054052012095b1630e7366dcf]
CVE-2026-68347: iommu/amd: Fix IRQ unsafe locking in gdom allocation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68347
Introduced by commit 757d2b1 ("iommu/amd: Introduce gDomID-to-hDomID
Mapping and handle parent domain invalidation") in v7.0-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0db3a430d9681fdb29890bef6934cd89cd1745d0]
stable/7.1: [e0c78cdf35af3ada05f9309f4641e9f83c945dbd]
CVE-2026-68348: ASoC: tas2781: bound firmware description string parsing
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68348
Introduced by commit 915f5ea ("ASoC: tas2781: firmware lib") in v6.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bc889dfcea9294a1eae7f8e2f3573a90764ae4d0]
stable/6.12: [0ec45e80a82785ee147516fdecf5c93707dec119]
stable/6.18: [41ae2b7d37c3dd82302167496836cca9f0328374]
stable/6.6: [3ddb0d3e36507615e5ef010a879357a54870adf5]
stable/7.1: [e75ef37d83c90b09bedb601624b47e168202b226]
CVE-2026-68349: wifi: carl9170: fix buffer overflow in rx_stream failover path
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68349
Introduced by commit a84fab3 ("carl9170: 802.11 rx/tx processing and
usb backend") in v2.6.37-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a1a21995c2e1cc2ca6b2226cfe4f5f018370182a]
stable/6.12: [b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78]
stable/6.18: [4503829843353dbb18b879c35be1cdfc9af677b7]
stable/6.6: [5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e]
stable/7.1: [21f59906ea75618fdd46a7e32754d54fbee083ea]
CVE-2026-68350: wifi: carl9170: fix OOB read from off-by-two in TX
status handler
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68350
Introduced by commit a84fab3 ("carl9170: 802.11 rx/tx processing and
usb backend") in v2.6.37-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a3f42f1049ad80c65560d2b078ad426c3134f78d]
stable/6.12: [e8a862a3da457ddc50633c346dc645d559da09ae]
stable/6.18: [fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59]
stable/6.6: [7ed0dce8613c92111d2a3836ced2ab03190ba20e]
stable/7.1: [423c836f934814b8fdbe53b24a79d021a0ee8454]
CVE-2026-68351: wifi: carl9170: bound memcpy length in cmd callback to
prevent OOB read
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68351
Introduced by commit a84fab3 ("carl9170: 802.11 rx/tx processing and
usb backend") in v2.6.37-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4cde55b2feff9504d1f993ab80e84e7ccb62791c]
stable/6.12: [500c36649f270de05a56591fcc1aaaa36687958e]
stable/6.18: [9aee949c68dc6dccbc54333537b109c53fe2079f]
stable/6.6: [f74e34e66379e487a09009a4f2d42470051672bd]
stable/7.1: [cb7a38810cf25738176dac32dec7a146b3f959cf]
CVE-2026-68352: wifi: ath6kl: fix OOB read from firmware IE lengths in
connect event
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68352
Introduced by commit bdcd817 ("Add ath6kl cleaned up driver") in v3.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6b47b29730de3232b919d8362749f6814c5f2a33]
stable/6.12: [d70c0a850c21b57a6f46ce363860203389bbeaa6]
stable/6.18: [33b5342d2080657054ddf89ef1199b426a37dae8]
stable/6.6: [1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e]
stable/7.1: [94e1bfcefe8264a207c2fda2febb954e70a34b42]
CVE-2026-68353: wifi: ath6kl: fix OOB read from firmware num_msg in TX
complete handler
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68353
Introduced by commit bdcd817 ("Add ath6kl cleaned up driver") in v3.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495]
stable/6.12: [289edc3c71344b89e6522891147cfb8f61b088bb]
stable/6.18: [eb636fbc443149b3501c3f97e26225ddcb314a0f]
stable/6.6: [69ac7ba3a3df6654e7daa82674575a8c4a1a63ea]
stable/7.1: [c38b0d5c661951b5dd082bdf31f8a57a0ce6e540]
CVE-2026-68354: firewire: net: Fix fragmented datagram reassembly
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68354
Introduced by commit c76acec ("firewire: add IPv4 support") in v2.6.31-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d52a13adbb8ccbab99cd3bad36804e87d8b5c052]
stable/6.12: [22e05b8ddbcf7d22c7f1598786e86635547e554d]
stable/6.18: [0177e578d7a885037b0fb82286c12e9d0360cc10]
stable/6.6: [b7d633c7c92321be98724b1d365e8ce507f2f349]
stable/7.1: [2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999]
CVE-2026-68355: wifi: ath11k: fix potential buffer underflow in
ath11k_hal_rx_msdu_list_get()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68355
Introduced by commit d5c6515 ("ath11k: driver for Qualcomm IEEE
802.11ax devices") in v5.6-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7f11e70629650ff6ea140984e5ce188b775b2683]
stable/6.12: [904367381a922aa2dc3e8bd2488e6c9180516c7a]
stable/6.18: [a154ca3c441a67d36b3a9ea63a4f11b06abe6223]
stable/6.6: [69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a]
stable/7.1: [725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5]
CVE-2026-68356: watchdog: airoha: Prevent division by zero when clock
frequency is zero
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68356
Introduced by commit 3cf67f3 ("watchdog: Add support for Airoha EN7851
watchdog") in v6.13-rc2.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bcfcd7619f277842430d197556463b401b839ee9]
stable/6.18: [8681e5addf7171602616e256a09057697dcc75ca]
stable/7.1: [57c3f5bd5be008cd5b4ff6a45b7cb90f5ca45a37]
CVE-2026-68357: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68357
Introduced by commit da0d12f ("watchdog: pretimeout: add panic
pretimeout governor") in v4.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661]
stable/6.12: [0ca252720f0e38411cfec3431db9bb1aed0a412c]
stable/6.18: [7d1658b066de30f4b23afc14814d22416a971e6e]
stable/6.6: [2e47b91b9b4020fcc01def14d6b6556d66074cf4]
stable/7.1: [7993d626983cc58fbde9607333cfd2d57725c197]
CVE-2026-68358: hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68358
Introduced by commit f3b4b14 ("hwmon: Add driver for NZXT Kraken X and
Z series AIO CPU coolers") in v6.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f151d0143ac4e086f92f52328ebdbdc50933d8ef]
stable/6.12: [8cb282c34d582afcca7b1bae7c7bcd5204fd03d6]
stable/6.18: [305c23993e43db9a3681978691b1f9f2a1b26299]
stable/7.1: [dc73b0dfeab8dc0fe73e29c4401d032279e23efd]
CVE-2026-68359: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68359
Introduced by commit 53e68c2 ("hwmon: add driver for NZXT RGB&Fan
Controller/Smart Device v2") in v5.17-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e]
stable/6.12: [a2a15de020597efbff84b4281dd472e5860b7e3e]
stable/6.18: [205cff797a94757ec88ba299c8e2bf2e1e3f4bbf]
stable/6.6: [185c0880397aee9def0af5a59ea65f22f37ad658]
stable/7.1: [18d7c523891004226bccdba39dd681eca22ceb8a]
CVE-2026-68360: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68360
Introduced by commit 40c3a44 ("hwmon: add Corsair Commander Pro
driver") in v5.9-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [94c87871b051d7ad758828a805215a2ec194512a]
stable/6.12: [c7757db58957ac20cdec6ce575dbd44a6375664e]
stable/6.18: [56d2deb6448378118dbe68c4fbb3fbae5f65b18c]
stable/6.6: [0975c42ed2a3bf32125a920e5d19194289126210]
stable/7.1: [1a634f464d6153dfa4d7e73a3d78236b65a64ee9]
CVE-2026-68361: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68361
Introduced by commit d115b51 ("hwmon: add Corsair PSU HID controller
driver") in v5.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9ab8656548cd737b98d0b19c4253aff8d68e97f4]
stable/6.12: [c0aae8d24f5e52d6910f97d59bc624e131f3ae1a]
stable/6.18: [ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e]
stable/6.6: [e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a]
stable/7.1: [bb25bd980f2d9bd34558e1b1d16636e4945baf14]
CVE-2026-68362: wifi: ath11k: fix NULL pointer dereference in
ath11k_hal_srng_access_begin
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68362
Introduced by commit 6fe62a8 ("wifi: ath11k: Add cold boot calibration
support on WCN6750") in v6.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e8d85672dd7e2523f774caafba8f858384e18df7]
stable/6.12: [d6bba659ac30d862ee7bab92862cd6e514f07521]
stable/6.18: [e5394605f9a985cc3a8263e610ba84b33cbe7b0c]
stable/6.6: [e517e207300edcf7f3a8f6c45f9155c0e419ffb9]
stable/7.1: [4abb4e284d8897176e91d7a3168ee29ed876bb41]
CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after
re-arming firmware request
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68363
Introduced by commit e904cf6 ("ath9k_htc: introduce support for
different fw versions") in v4.4-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dad9f96945d77ecd4708f730c06ef54dcd8cc057]
stable/6.12: [10b0ce629123a3737b4eda50188f73bb7be7b68b]
stable/6.18: [48a69cedde7388294e4ea6fd804156cd62bc04fc]
stable/6.6: [7f184ca38a90889f3f6665ff96748b95da39dbee]
stable/7.1: [7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a]
CVE-2026-68364: drm/amd/display: Fix ISM dc_lock deadlock during suspend
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68364
Introduced commit is not determined.Fixed in v7.2-rc1.
Fixed status
mainline: [3714fe242592e3699ac5e2c19d68b275a210be7d]
stable/7.1: [95776812e6b8f908563e8994d5d947b68baf68a6]
CVE-2026-68365: USB: serial: io_edgeport: cap received transmit credits
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68365
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [faaddd811c5099f11a5f52e68a6b31a5898cda4f]
stable/6.12: [64b687f9694777754285d489abbefa3784bc78da]
stable/6.18: [cbe00048b69d67c8a78293cb7681b4c9963b26c7]
stable/6.6: [ee57992c053a6d395e98ced2d4c9cc3b42d8c27a]
stable/7.1: [1e47d8228b8767c8ac722aedb388f70adeeda43d]
CVE-2026-68366: usb: gadget: uvc: clamp SEND_RESPONSE length to the
response buffer
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68366
Introduced by commit a5eaaa1 ("usb: gadget: uvc: use capped length
value") in v3.10-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b70dc75e85ba968b7b76eebfe5d63000080b875b]
stable/6.12: [662f6c6c6ff8a6c508e1646c09cae74e28f3cca6]
stable/6.18: [1f03658f3e9b2f8fd1d1003ba389a0390b49a350]
stable/6.6: [4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796]
stable/7.1: [c8510fbbea09ef0170b56b14dc2b5890dc75be07]
CVE-2026-68367: usb: gadget: f_tcm: synchronize delayed set_alt with teardown
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68367
Introduced by commit c52661d ("usb-gadget: Initial merge of target
module for UASP + BOT") in v3.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [79e2d75725c85607f8a9d87ae9cace62a19f767d]
stable/6.12: [a6eb5a0ae7cd313cfd7df78decd8f43b64c68703]
stable/6.18: [f282242906c12fd476b86757afba51f211d4f959]
stable/6.6: [3118bb872c7dff653294f193d5328a476619e04d]
stable/7.1: [4c6c6a5588b9a2f8437fb794e852d05fa60ebe53]
CVE-2026-68368: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68368
Introduced by commit 427694c ("usb: gadget: ncm: Handle decoding of
multiple NTB's in unwrap call") in v6.6-rc6.
Introduced by commit 2b74b0a ("USB: gadget: f_ncm: add bounds checks
to ncm_unwrap_ntb()") in v5.9-rc3.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st cip/5.10 cip/5.10-rt cip/6.1
cip/6.1-rt stable/5.10 stable/5.15 stable/6.1
Fixed status
mainline: [1febec7e47cdcd01f43fb0211094e3010474666e]
stable/6.12: [fff1059d139ef798bab917990524faaf25854ca8]
stable/6.18: [40c706a0224bde194667e3378c689b542fec4b44]
stable/6.6: [e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f]
stable/7.1: [41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c]
CVE-2026-68369: usb: gadget: printer: fix infinite loop in printer_read()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68369
Introduced by commit b185f01 ("usb: gadget: printer: factor out
f_printer") in v4.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c2e819be6a5c7f34344926b4bd7e3dfca58cf48a]
stable/6.12: [e03597ad9494b500344076589aeaa6c6d2d381d3]
stable/6.18: [4cde0b38cc0cb8b7dc17295801015148de37d1d2]
stable/6.6: [994afccfdcceb73be33f69a8a8ea71e260c9eca5]
stable/7.1: [e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e]
CVE-2026-68370: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68370
Introduced by commit 1da177e ("Linux-2.6.12-rc2") in v2.6.12.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d5e5cd3654d2b5359a12ea6586120f05b28634ee]
stable/6.12: [67b589d09a96882d56842dced5698ed8dd06ce45]
stable/6.18: [e239ea91b48180ed48a86ac25643832a02c88456]
stable/6.6: [e2b2740f1242bc70b5b46da2cdbbaa419f490e59]
stable/7.1: [e24b33618231034bf01dfaff4fd3409d4b4d5b2e]
CVE-2026-68371: usb: musb: omap2430: Do not put borrowed of_node in probe
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68371
Introduced by commit ffbe2fe ("usb: musb: omap2430: Fix probe
regression for missing resources") in v6.2-rc1.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1
Fixed status
mainline: [c947360ae63eee1c9eacc030dd6f5a53f717addf]
stable/6.12: [58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193]
stable/6.18: [0950ac52426b0ab32d3b8cf4afe1711668b19cb8]
stable/6.6: [eed56f105a7f70cbcfceb4df6deb6870fc58214d]
stable/7.1: [6c525c851e5912b9753622d796f2bc55c4913b04]
CVE-2026-68372: usb: core: port: Deattach Type-C connector on component unbind
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68372
Introduced by commit 1111078 ("usb: Inform the USB Type-C class about
enumerated devices") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e0b291fe117964037e0ba382eff4bb365d531c3a]
stable/6.12: [78d361e60caf1999d51bda0e1b1004f5d39fcfbc]
stable/6.18: [7714fb896ed308cf13d32d317040adc4f200b8e4]
stable/7.1: [e00109b5adf71635919248e9ab6300a662e6a3e8]
CVE-2026-68373: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68373
Introduced by commit 1264b95 ("at76c50x-usb: add driver") in v2.6.30-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [61a799ffd1e5a4fd3702d547828b7ff3d161468e]
stable/6.12: [bcde7249d45f52f994a9872bedf45994472ade77]
stable/6.18: [fb1b50ab699211e777dca5ccfb648788b6a6e519]
stable/6.6: [e165a1d295e7e814e13b0f92c86e5d48309509ce]
stable/7.1: [f742d9c98b5c504fc9e6744eef13a721c2aea486]
CVE-2026-68374: usb: core: sysfs: add lock to bos_descriptors_read()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68374
Introduced commit is not determined.Fixed in v7.2-rc5.
Fixed status
mainline: [4e0197fbb0eec588795d5431716a244d9ac8fa93]
stable/6.12: [c07caee449c968842a350bfefa049889923b8240]
stable/6.18: [217774e143d7b5a88739193284b6421be3978601]
stable/7.1: [ab82adf5e63b2d89ead7933ab753b9cedbe028e9]
CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68375
Introduced by commit 194fad5 ("bnxt_en: Refactor
bnxt_rdma_aux_device_init/uninit functions") in v6.10-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1cb8553c02e93e5a150cebd42f9ee3db0ece4707]
stable/7.1: [4e1caa5fdd0dea36938fe39cceb1522e9d86c937]
CVE-2026-68376: sctp: fix auth_hmacs array size in struct sctp_cookie
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68376
Introduced by commit 1f48564 ("[SCTP]: Implement SCTP-AUTH internals")
in v2.6.24-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [e0b5252a59383b77d1b8dbeda00b7184dd95f4d3]
stable/6.12: [d0a59ba58578e2b330fff80a44fe519f3ba7d8c7]
stable/6.18: [a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db]
stable/6.6: [0b4414e43e0861d67276031cc21401d7e87de3da]
stable/7.1: [3aa40c3bccac2312ea7cf97f329190637f972b5d]
CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68377
Introduced by commit 9174c3d ("net/sched: act_tunnel_key: fix memory
leak in case of action replace") in v5.0-rc3.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/4.19 cip/4.19-rt cip/4.19-st
Fixed status
mainline: [f1f5c8a3955f8fda3f84ed883ac8daa1847e724c]
stable/6.12: [2200a00ff247f70f5dcdb4e6f14b0d48ddac5467]
stable/6.18: [fed1b1ddab41a0e7a462ac690a0c8af6ff793624]
stable/6.6: [531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e]
stable/7.1: [2791a501da508b704a617b4dba29db54a65bc9f7]
CVE-2026-68378: dpll: fix NULL pointer dereference in
dpll_msg_add_pin_ref_sync()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68378
Introduced by commit 58256a2 ("dpll: add reference sync get/set") in v6.17-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [d2e914a4a0d0f753dbae830264850d044026167c]
stable/6.12: [66fbe0499ef517ab161b96c49886a891851f6481]
stable/6.18: [51c2fcc4cd2e4c52bd1970558f6e5356fdc51154]
stable/7.1: [4b3e6b9fdaeb40c6a2f7c41db3888b6ee628bdd2]
CVE-2026-68379: tcp: fix TIME_WAIT socket reference leak on PSP policy failure
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68379
Introduced by commit 659a289 ("tcp: add datapath logic for PSP with
inline key exchange") in v6.18-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2c1931a81122c3cdc4c89448fe0442c69e21c0d5]
stable/6.18: [e666af5dcc905ba694745963174d232deb478c55]
stable/7.1: [374742a961becbbfc7fbfd1382d978a05e492741]
CVE-2026-68380: accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68380
Introduced by commit aac2430 ("accel/amdxdna: Add command execution")
in v6.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [faebb7ba1ac65fa5810b640df02ce04e509fdc11]
stable/6.18: [6875ee2bef48f5d9f045d81a8a4d68893f768a8a]
stable/7.1: [e8fadbffc19a233d1eedebfb8df0f522d1388280]
CVE-2026-68381: ksmbd: pin conn during async oplock break notification
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68381
Introduced by commit 3aa660c ("ksmbd: prevent connection release
during oplock break notification") in v6.14-rc7.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12 stable/6.6
Fixed status
mainline: [aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9]
stable/6.12: [793e1c7041b93af96ff87e678329bc16aee7ba88]
stable/6.18: [6ecb252efa0b413ac3d9979fb4eec247f8fc1258]
stable/6.6: [0f72fc9659d7f585460d43c158055df5afdcffb6]
stable/7.1: [14062c74e5b25c27edcff7a2fe0dc701c930b372]
CVE-2026-68382: drm/xe/guc: Hold device ref until queue teardown completes
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68382
Introduced by commit 2d2be27 ("drm/xe: fix UAF around queue
destruction") in v6.12-rc2.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9b7e60184f4b22e893d4ae95234d5f26261a430c]
stable/7.1: [03d6f83979b0d75a0b0893dfe1735ec93facf515]
CVE-2026-68383: drm/xe/guc: Keep scheduler timeline name alive
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68383
Introduced by commit 6bd90e7 ("drm/xe: Make dma-fences compliant with
the safe access rules") in v6.17-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [299bc6d50b1bed7d1f408391736712f01a0855e2]
stable/7.1: [77fd62412431e8c80ef2ad61466bc76fe425f80a]
CVE-2026-68384: drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68384
Introduced by commit 864690c ("drm/xe/vf: Attach and detach CCS copy
commands with BO") in v6.18-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [56441f9e08ad68697295b8835266d2bc48ab59b5]
stable/6.18: [35ba43b541117bfb595e4b807ba447cf4335cc7d]
stable/7.1: [f2ebfd5cc87f1393a30c8b8b0a6c20cb22cffa97]
CVE-2026-68385: s390/checksum: Fix csum_partial() without vector facility
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68385
Introduced by commit dcd3e1d ("s390/checksum: provide
csum_partial_copy_nocheck()") in v6.9-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4bb06b60d982355e22647b3d12d6619419f8c1fa]
stable/6.12: [5fc0a2a6eeb99cac991242bb48796c7749ce3261]
stable/6.18: [1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722]
stable/7.1: [898bb2814f38399108bdd2113f38d97383a7036a]
CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68386
Introduced by commit 0c48eef ("sock_map: Lift socket state restriction
for datagram sockets") in v5.15-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [66efd3368ae10d05e08fbe6425b50fdec7186ac7]
stable/6.12: [17b7ef6b86112a4e61cee1e9009a4b318e3225c5]
stable/6.18: [250474c69bc3fc48a5fc21d7c349f279caad947a]
stable/6.6: [7ffe529e7127411806c8692fb1490f552c629dc2]
stable/7.1: [8692655da369961128658cf8539334b6a960ecb0]
CVE-2026-68387: can: raw: add locking for raw flags bitfield
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68387
Introduced by commit 890e519 ("can: raw: use bitfields to store flags
in struct raw_sock") in v6.18-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [1e5185c090589f4146d728ab36417d8a5419f127]
stable/6.18: [00ba4bf8798242253fefc1fa6a78db1d445fd024]
stable/7.1: [57791aab1129c9405f84bb0882de58967d8b44cd]
CVE-2026-68388: smb/client: handle overlapping allocated ranges in fallocate
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68388
Introduced by commit 966a3cb ("cifs: improve fallocate emulation") in v5.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/5.10 cip/5.10-rt stable/5.10
Fixed status
mainline: [b09ae45d85dc816987a71db9eebc54b0ae288e94]
stable/6.12: [377fe3e583e46369ee1004d5cfe12271d6589a68]
stable/6.18: [7e08ab7a061b17ac1989a225c6afb53f44a86808]
stable/6.6: [437637f5ff3f573b2edf8571de91fb00a21eb4e6]
stable/7.1: [a4a09e5142835633fffbde68bd0a039ba4d4bf97]
CVE-2026-68389: Bluetooth: hci_qca: Clear memdump state on invalid dump size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68389
Introduced by commit 06d3fdf ("Bluetooth: hci_qca: Add qcom
devcoredump support") in v6.6-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bf587a10c33e5571a299742e45bc18960b9912e7]
stable/6.12: [069258d5111eed9ac9586bee42d03d38e2975715]
stable/6.18: [cefb44c367b2b52e50f97bc8526d39df9bcf5e60]
stable/6.6: [5a3945e8dea6c9a8ec9e981169ac9487e1d6ad6a]
stable/7.1: [2363a757694752426fc47f3eadde15cf5f791fa5]
CVE-2026-68390: Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68390
Introduced by commit c530569 ("Bluetooth: hci_core: Introduce
HCI_CONN_FLAG_PAST") in v6.19-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c363202ec841df36421ec280eea3d5f94f556143]
stable/7.1: [8d892bec1dd134761cabec6ba23fe315d0f20f98]
CVE-2026-68391: Bluetooth: mgmt: hold reference for hci_conn in
mgmt_pending_cmds
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68391
Introduced by commit 7b445e2 ("Bluetooth: MGMT: Fix holding hci_conn
reference while command is queued") in v6.0-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [da55f570191d5d72f10c607a7043b947eb05ea46]
stable/6.12: [f915e74b6f18293d1d69a2a3305ef321ff7c0172]
stable/6.18: [d5b3b484b62bb0f4542e7622789d28871626cdf0]
stable/6.6: [b56f2ecafc08f372bf0529f9c4f3f429cb1702dc]
stable/7.1: [ecdcb55ea1c01dda074406f38058785a69526734]
CVE-2026-68392: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68392
Introduced by commit 227a0cd ("Bluetooth: MGMT: Fix not generating
command complete for MGMT_OP_DISCONNECT") in v6.11-rc7.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [16cd66443957e4ad42155c6fec401012f600c6f8]
stable/6.12: [579faba5ede6df6b7f36777c431dc8dcf9d272e7]
stable/6.18: [ca58ad287bfc5b9d31a72ecb8650289df2b57250]
stable/6.6: [8bc83f9ef6789571f399ff631a2a14a12b6d8585]
stable/7.1: [b11511006f9e17000de3f4cadee451364f658ca3]
CVE-2026-68393: Bluetooth: hci_sync: extend conn_hash lookup critical sections
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68393
Introduced by commit 6d0417e ("Bluetooth: hci_conn: Fix not setting
conn_timeout for Broadcast Receiver") in v6.15-rc5.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.12 stable/6.12
Fixed status
mainline: [d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d]
stable/6.18: [83b7e67698d0b93f685875ce82c8d335436834f7]
stable/7.1: [38326774df6198df0cc2744cc73bf77cb741c538]
CVE-2026-68394: Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68394
Introduced by commit 0ece498 ("Bluetooth: MGMT: Make
MGMT_OP_LOAD_CONN_PARAM update existing connection") in v6.11-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e]
stable/6.12: [65ce6fe1b92112ba9064ded932c03180da3dd230]
stable/6.18: [57059ff14d81df4a970b2ea8d8f54431bb91a025]
stable/7.1: [b82802b5ab26a7c69fc2e7a0f2baa3c13a6c21aa]
CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after
IRQ handler is registered
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68395
Introduced by commit 6293600 ("[libata] Add 460EX on-chip SATA driver,
sata_dwc_460ex") in v2.6.36-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0]
stable/6.12: [23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda]
stable/6.18: [daa80b422ed920a3c0c45153020b0ad7af7fb5a5]
stable/6.6: [fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4]
stable/7.1: [5d0797d6940b8dc894f950c52f7af0b42cb55ed0]
CVE-2026-68396: scsi: core: wake eh reliably when using scsi_schedule_eh
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68396
Introduced by commit 6eb045e ("scsi: core: avoid host-wide host_busy
counter for scsi_mq") in v5.5-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [dccf3b1798b70f94e958b3d00b83010399e6fb05]
stable/6.12: [866efe8ae8b8b4d095501001b026e1022734be28]
stable/6.18: [c7a15091237205770bd9bd4d14eb1f3029d97a34]
stable/7.1: [24d7abda6a2a19e113334accc10029f6a4b57257]
CVE-2026-68397: net/iucv: take a reference on the socket found in
afiucv_hs_rcv()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68397
Introduced by commit 3881ac4 ("af_iucv: add HiperSockets transport")
in v3.2-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4fa349156043dc119721d067329714179f501749]
stable/6.12: [1801cb20a5025a787d6853e19c38db138344b4b4]
stable/6.18: [c75a950e77356e526672cba4584080c6c8b793b6]
stable/6.6: [4dc0e63abf8bc7ba8892e617c1fb8b204361e022]
stable/7.1: [5595ea59cdf29182cf6a270cacc1426c57b603de]
CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix
pppol2tp RX UAF
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68398
Introduced by commit ee40fb2 ("l2tp: protect sock pointer of struct
pppol2tp_session with RCU") in v4.15-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/4.4 cip/4.4-rt cip/4.4-st
Fixed status
mainline: [ec4215683e47424c9c4762fd3c60f552a3119142]
stable/6.12: [3ab32218d7182705dae5c86f13925f458072da2c]
stable/6.18: [c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa]
stable/6.6: [4bb84e964ff0fe0a171c965362de72f9820dbce9]
stable/7.1: [06213c85d8c0994f786c093b8b2a517987943ca6]
CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68399
Introduced by commit 6ac99e8 ("bpf: Introduce bpf sk local storage")
in v5.2-rc1.
Introduced by commit f12dd75 ("bpf: net: Set sk_bpf_storage back to
NULL for cloned sk") in v5.2-rc6.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f]
stable/7.1: [14b49b5ab29979552c219a09e569b424fbbf4a6e]
CVE-2026-68400: firmware: arm_ffa: Fix Endpoint Memory Access
Descriptor offset calculation
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68400
Introduced by commit 1135805 ("firmware: arm_ffa: Update memory
descriptor to support v1.1 format") in v6.7-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b4d961351aa84fdf0148783fb1f3a1391b8a0adb]
stable/6.18: [b39b08e6bee812514b449dc874076890e6b871a0]
stable/7.1: [8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66]
CVE-2026-68401: firmware: arm_ffa: Fix out-of-bound writes in
ffa_setup_and_transmit()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68401
Introduced by commit 111a833 ("firmware: arm_ffa: Set reserved/MBZ
fields to zero in the memory descriptors") in v6.4-rc4.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/5.15 stable/6.1
Fixed status
mainline: [3383ffb7ef937317361713ffcc21921a7848511a]
stable/6.18: [cf5708c9d78c98214c62b1e5d049cd527a543b8e]
stable/7.1: [27abdaf0c5c89b06694e4c3d8318e8d6a60c1d1b]
CVE-2026-68402: wifi: cfg80211: bound element ID read when checking
non-inheritance
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68402
Introduced by commit f7dacfb ("cfg80211: support non-inheritance
element") in v5.2-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [cb8afea4655ff004fa7feee825d5c79783525383]
stable/6.12: [84bd907361c56fbd5523eceb2682cb39da059bd5]
stable/6.18: [11ac7a5e75f5132f1778e0c60981d30dc29fb869]
stable/6.6: [20c308d9a57722801961f816395bf825f7bde6bc]
stable/7.1: [ddf2773bcc8e49a43c561f22ec1e7924215d7947]
CVE-2026-68403: wifi: brcmfmac: initialize SDIO data work before cleanup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68403
Introduced by commit 9982464 ("brcmfmac: make sdio suspend wait for
threads to freeze") in v4.1-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2a665946e0407a05a3f81bd56a08553c446498e0]
stable/6.12: [6bd21ec8549a5854dd64204a66289952917a924c]
stable/6.18: [5c342437ea44bb829680ca9e4f683dd5b325b219]
stable/6.6: [f50a2b9e57a751e70ae9a272875d80d39eaccd6a]
stable/7.1: [c73c3fc1c7ca5a927639f0884624cb244ba791e4]
CVE-2026-68404: wifi: cfg80211: use wiphy work for socket owner autodisconnect
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68404
Introduced by commit bd2522b ("cfg80211: NL80211_ATTR_SOCKET_OWNER
support for CMD_CONNECT") in v4.11-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0c2ed186bbe14304415476d6707b747dddcd8583]
stable/7.1: [6d6123fef5a4af175cc6b6b12a03dd0f3c240b79]
CVE-2026-68405: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68405
Introduced by commit 397a7a2 ("mac80211: free ps->bc_buf skbs on vlan
device stop") in v3.9-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [f3858d5b1432098c1936e03d6e03dd0e33facf60]
stable/6.12: [962f755a47d7ec3bbf6c709697d7f4c5f798441d]
stable/6.18: [a424985c3ef2a87ce6057a853e18d0c441a86be8]
stable/6.6: [be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef]
stable/7.1: [4b8abf43bf34791c99d99dc3be13f897adefc461]
CVE-2026-68406: wifi: cfg80211: validate PMSR FTM preamble range
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68406
Introduced by commit 9bb7e0f ("cfg80211: add peer measurement with FTM
initiator API") in v5.0-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [36230936468f0ba4930e94aef496fc229d4bb951]
stable/6.12: [922d71fbaf99c1d5318151a0cb0a42ad448d07d9]
stable/6.18: [cfbda103aeae61071a122a6fc2bfe98cffbd7165]
stable/6.6: [44ea65d779e2d23b2264fea6af2d0c666a3ec9fb]
stable/7.1: [58320cb47df2accc7a20bb72c0150280732fa58f]
CVE-2026-68407: wifi: nl80211: free RNR data on MBSSID mismatch
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68407
Introduced by commit dbbb27e ("cfg80211: support RNR for EMA AP") in v6.4-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/6.1
Fixed status
mainline: [07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c]
stable/6.12: [312c8b9d7836ef58e552619a8c19be08b04032bb]
stable/6.18: [fb052a6e2fa866384d8edc237746583ec94c15af]
stable/6.6: [fa9592ef7de11f8c7042315d9bc20e91a97f679e]
stable/7.1: [6f919f29e9b75793104709987131b8d910d7800a]
CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to
fix deadlock
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68408
Introduced by commit 6dccbc9 ("wifi: cfg80211: cancel pmsr_free_wk in
cfg80211_pmsr_wdev_down") in v7.0-rc5.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt cip/6.12 stable/6.1 stable/6.12 stable/6.18 stable/6.6
Fixed status
mainline: [2b0eab425e1f658d8fe1df7590e3b9af5959505e]
stable/6.12: [21512b5f7a74fd18c996c22e6854efe57d570816]
stable/6.18: [133684982dd0c24359fcc641d19d89cc17d6e5ef]
stable/7.1: [0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e]
CVE-2026-68409: wifi: mac80211: defer link RX stats percpu free to RCU
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68409
Introduced by commit c71420d ("wifi: mac80211: RCU-ify link STA
pointers") in v6.0-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [aa2eb62525188269cdd402a583b9a8ed94657ff0]
stable/6.18: [2aa1789880fa5e41049b0f6a74a4fc2fa1997610]
stable/7.1: [a03fceae0c65b31ce31840dac5e26684ceecb65b]
CVE-2026-68410: wifi: libertas: fix memory leak in helper_firmware_cb()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68410
Introduced by commit 1dfba30 ("libertas: move firmware lifetime
handling to firmware.c") in v3.13-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [63c2391deefb31e1b801b7f32bd502ca4808639b]
stable/6.12: [eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c]
stable/6.18: [6cda91bbb8dc3d22ef0323008a12dcf73a5129da]
stable/6.6: [d497b7566e74920acfe283dd6b2cbf1682890796]
stable/7.1: [644640cde2fb216e6567de5eee780a38dbc95928]
CVE-2026-68411: wifi: mac80211_hwsim: clamp virtio RX length before skb_put
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68411
Introduced by commit 5d44fe7 ("mac80211_hwsim: add frame transmission
support over virtio") in v5.7-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [10a2b430f8f06ae14b9590b6f6faa6b588ef0654]
stable/6.12: [fade308845c89f784da8a6780c1e77258488f1b6]
stable/6.18: [6dc76371a9a360c29de00df5b11563102d9d675a]
stable/6.6: [82c5a30a66e2a7337d99476c67d6fc1a99c4250e]
stable/7.1: [99dc05c75acc3c8cde8d89c5371f4b569de5ac62]
CVE-2026-68412: wifi: cfg80211: Fix an error handling path in
cfg80211_wext_siwscan()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68412
Introduced by commit 2a51931 ("cfg80211/nl80211: scanning (and
mac80211 update to use it)") in v2.6.30-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c6659f66d4ee4841aafae5659d2ef5e4c5c63cb6]
stable/6.18: [e67dc2b8d5ac4bb804000b6732768a9ae678912f]
stable/7.1: [99d2e850c643e2c70fa165b722a1ad28347a8b3a]
CVE-2026-68413: wifi: ipw2100: fix potential memory leak in
ipw2100_pci_init_one()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68413
Introduced by commit 2c86c27 ("Add ipw2100 wireless driver.") in v2.6.20.16.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0d388f62031dbabcba0f44bb91b59f10e88cac17]
stable/6.12: [836a19c654dcb1b01878a70090af016fbd0fd7e5]
stable/6.18: [f442e581a88937671a22ceb3806c186265ef6254]
stable/6.6: [f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe]
stable/7.1: [7cbda50eebcd9aa00b0de382f776287cf7a36cf8]
CVE-2026-68414: wifi: cfg80211: cancel sched scan results work on unregister
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68414
Introduced by commit 807f8a8 ("cfg80211/nl80211: add support for
scheduled scans") in v3.0-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [edf0730be33696a1bd142792830d392129e495cc]
stable/6.12: [308ffdf575560d7e7b8b21f1e3ca6276630f73bf]
stable/6.18: [9293574ac208d18c11073538851fb69355beb3b5]
stable/6.6: [3368457b4871ae8f0f88d19c9a3e6270e850ede6]
stable/7.1: [b119c70b24776c8ab2a2c0515397b3b0ad4e66cd]
CVE-2026-68415: xfrm: clear mode callbacks after failed mode setup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68415
Introduced by commit 4b3faf6 ("xfrm: iptfs: add new iptfs xfrm mode
impl") in v6.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [2538bd3cd1ff5af655908469544ac7b7ae259386]
stable/6.18: [9845a35986a658816f7752f7ebd7c455a4c7dfdf]
stable/7.1: [c37a079230128a5237f45fb4e181bc069a5c2955]
CVE-2026-68416: mtd: fix double free and WARN_ON in add_mtd_device() error paths
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68416
Introduced by commit 19bfa9e ("mtd: use refcount to prevent
corruption") in v6.6-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [9d4af746af8ce27eefc2338b2feaa1e01f28b6c3]
stable/6.12: [e1e96aca1bdf391e2f49531c270ffc134e5b49a5]
stable/6.18: [f98ae09c727dcf34f745c875661c64b642e4abfa]
stable/6.6: [ffe21a3545b439e7b11578a701c22a847c149561]
stable/7.1: [820f983d641937a787e841ee4b93501f69f5683e]
CVE-2026-68417: RDMA/siw: publish QP after initialization
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68417
Introduced by commit f29dd55 ("rdma/siw: queue pair methods") in v5.3-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [bb27fcc67c429d97f785c92c35a6c5adebb05d7f]
stable/6.12: [74912ad168f87d6b2b670a87987bb302d6e64aa1]
stable/6.18: [fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d]
stable/6.6: [36e91a58397ca8c978e38a0bf389f0c6113fa8ca]
stable/7.1: [52f9fcb191143448df55fd215ff09c5207fed43e]
CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68418
Introduced by commit b48c24c ("RDMA/irdma: Implement device supported
verb APIs") in v5.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b9b0889071569d43623c260074e159cd8f26adb1]
stable/6.18: [ec675b4cdfd378d8c9dd8c93126c024f2469bd79]
stable/7.1: [728211c815f6eef28dd3df2a5b6297483185aa20]
CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68419
Introduced by commit 5ac388d ("RDMA/irdma: Add support to re-register
a memory region") in v6.7-rc1.
Fixed in v7.2-rc4.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [a846aecb931b4d65d5eafa92a0623545af46d4f2]
stable/6.12: [b5029e91c63406e4f4c8d58161048b41b6f0bd8c]
stable/6.18: [ca1c29f05274b737dc964e28b97803750d7cf7ec]
stable/6.6: [fb46d134e1b8690bed2da9005b36d32d2efd34ac]
stable/7.1: [dbaa37e060918c45517786e37ecab0f300b48fa9]
CVE-2026-68420: xfrm: reject optional IPTFS templates in outbound policies
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68420
Introduced by commit d1716d5 ("xfrm: add generic iptfs defines and
functionality") in v6.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ea528f18231ec0f33317be57f8866913b19aba6e]
stable/6.18: [d7fc6f351c478586980a521d63b0214d9c055e78]
stable/7.1: [9333f4b6f44858fc98eb12bf26b8d2959eb975d5]
CVE-2026-68421: sched_ext: Don't warn on core-sched forced idle in
put_prev_task_scx()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68421
Introduced by commit 7c65ae8 ("sched_ext: Don't call
put_prev_task_scx() before picking the next task") in v6.12-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [b7d9c359e5cf867f7eb23df3bb1c6b9e58af24da]
stable/6.18: [2907e9d0f05b506dfd58aec589a23042a56ef36b]
stable/7.1: [e2f188cdbf8312289532c36eb4e9eb1c9544d43a]
CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected
in merge_reloc_roots()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68422
Introduced by commit 24213fa ("btrfs: do proper error handling in
merge_reloc_roots") in v5.13-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ce6050bafb4e33377dc17fcc357736bfc351180c]
stable/6.12: [72f673d1c1deb819554d3e7e154f6d84301eb735]
stable/6.18: [60a23d4ea169e27403f3bb023bb98036797c0206]
stable/6.6: [b3d39b03799600c76c33486e2d29b73a771023db]
stable/7.1: [7591d1727067d6063247901ad25c4bdc4e5695c4]
CVE-2026-68423: mtd: virt_concat: fix use-after-free in
mtd_virt_concat_destroy()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68423
Introduced by commit 43db636 ("mtd: Add driver for concatenating
devices") in v7.1-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4b45d7836b9526b8776af5f29219615be9417230]
stable/7.1: [d36520e5da8bf87265b334def0daaadf3603cc62]
CVE-2026-68424: mtd: virt_concat: fix use-after-free in
mtd_virt_concat_destroy_joins()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68424
Introduced by commit 43db636 ("mtd: Add driver for concatenating
devices") in v7.1-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [75c0c09541b49daa08fddbc2c18c2232f4eab7d8]
stable/7.1: [4d91d783f93430c0efa834daff6640c07d87ebbc]
CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68425
Introduced by commit fa619a7 ("[PATCH] IB: Add RMPP implementation")
in v2.6.13.4.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d2e52d610b9b09694261632340b801a421e0b0c5]
stable/6.12: [6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72]
stable/6.18: [98d2d468b4faa1fdc68c0c6c238389906ee3490c]
stable/6.6: [dfa535c94406c03d3f0c869ef3ba5528e395737c]
stable/7.1: [ad9c9ad3204f63a46f0f7de29687a8e512f05e29]
CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a
GSO segment
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68426
Introduced by commit f53c723 ("net: Add asynchronous callbacks for
xfrm on layer 2.") in v4.16-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3f4c3919baf0944ad96580467c302bc6c7758b00]
stable/6.18: [33e1b0d25ca0d2818c635ff80e6aa0d295e08a98]
stable/7.1: [bbca7cc3b2b4b10afbfee99b81d9ee78f5423046]
CVE-2026-68427: gpu: host1x: Fix use-after-free in
host1x_bo_clear_cached_mappings
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68427
Introduced commit is not determined.Fixed in v7.2-rc4.
Affected code was added by 3cbf5e3 ("gpu: host1x: Allow entries in BO
caches to be freed") in v7.2-rc1.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.12 stable/6.1 stable/6.12 stable/6.18 stable/6.6 stable/7.1
Fixed status
mainline: [266cddf7bd0f6c79b6c0633aef742a22bf70265b]
stable/6.12: [5b7e5f84d3d4cea10c3764d2da274810a7934228]
stable/6.18: [5f4de3c717d34a24d555af581947742980778c02]
stable/6.6: [abeff53233b984571b87582bb588b4b38ef4ea50]
stable/7.1: [b773faa32b0a98c3eb2b50d96de631681e5d1157]
CVE-2026-68428: KVM: x86/mmu: Fix use-after-free on vendor module reload
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68428
Introduced by commit cb498ea ("KVM: Portability: Combine kvm_init and
kvm_init_x86") in v2.6.25-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [52f2f7c30126037975389aa04d24c506a5177c35]
stable/6.12: [32b9f89ed9e6d7a45075d64089c254a7f6e13695]
stable/6.18: [ec9daa8fd1b6f45545c9839dca55bd867fad9e13]
stable/6.6: [6f4be73880302d5642c83a0813fdfe1f5fd4b6e3]
stable/7.1: [43cfb20d62ffe49626d62beecfc32eb6f262191c]
CVE-2026-68429: drm/dp_mst: Handle torn-down topology gracefully in
drm_dp_mst_topology_queue_probe()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68429
Introduced by commit dbaeef3 ("drm/dp_mst: Add a helper to queue a
topology probe") in v6.12-rc1.
Fixed in v7.2-rc2.
Bug introduced commit was backported to following branches.
stable/6.6
Fixed status
mainline: [613059875958e7b217b250ed14c3b189f9488421]
stable/6.12: [4ed6d08c4a59ee6a8cb806347f6d9873de5d229e]
stable/6.18: [8c6d84a54823cd839e6ce22af559925f1320c310]
stable/6.6: [b1d05cc61dfa6c4bd5e67855bec6a03e955f512d]
stable/7.1: [afdff9103818656627920c21822e48a6dae2906f]
CVE-2026-68430: drm/amdgpu/gfx8: drop unecessary BUG_ON()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68430
Introduced commit is not determined.Fixed in v7.2-rc2.
Affected code was added by 4e638ae ("drm/amdgpu/gfx8: add support
kernel interface queue(KIQ)") in v4.11-rc1.
Fixed status
mainline: [84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5]
stable/6.12: [2404600dca5c0979485c6f2d9c62bd356a98870a]
stable/6.18: [f70bd5235d9efc2ee2f70293eea51888c5f2a54d]
stable/6.6: [ab05af6c345bc8460052c60de657ce6d4a2386f7]
stable/7.1: [db85aa861b8214fa0d1d8405c01488f604a455a0]
CVE-2026-68431: ksmbd: validate minimum PDU size for transform requests
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68431
Introduced by commit 368ba06 ("ksmbd: check the validation of pdu_size
in ksmbd_conn_handler_loop") in v6.4-rc6.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/6.1 cip/6.1-rt stable/5.15 stable/6.1
Fixed status
mainline: [cfc0b8e5080aec87700774e8568765eaa4b7b92b]
stable/7.1: [b62c510f59803f82f9b4c76ead2a56833b2984c7]
CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68432
Introduced by commit 8bcdc4f ("vxlan: add changelink support") in v4.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e]
stable/6.12: [32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f]
stable/6.18: [730c7e5fea7f06e0cdf21c547222ec93234fd1d6]
stable/6.6: [b3793d7dccb192ffff29894d11824db6251acdd5]
stable/7.1: [e8ad0d311e225939a9a6c745d6cc384c7364ec87]
CVE-2026-68433: libceph: bound get_version reply decode to front len
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68433
Introduced by commit 513a824 ("libceph: mon_get_version request
infrastructure") in v3.16-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0]
stable/6.12: [d60de8253c85a02d0e6194b0735e7a562981a04c]
stable/6.18: [4e7ebfaa0d14cf50e44041bfde38070d6dbc019f]
stable/6.6: [340e0386aa39da181015bee38f309018c335ce16]
stable/7.1: [0d934c934ec746d53fc7e4f53239792647bbae63]
CVE-2026-68434: serial: 8250_mid: Fix NULL function pointer
dereference on DNV/ICX-D/SNR platforms
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68434
Introduced by commit b1b4efe ("serial: 8250_mid: Disable DMA for
selected platforms") in v7.2-rc3.
Fixed in v7.2-rc5.
Bug introduced commit was backported to following branches.
cip/5.10 cip/6.1 cip/6.12 stable/5.10 stable/5.15 stable/6.1
stable/6.12 stable/6.18 stable/6.6 stable/7.1
Fixed status
mainline: [7fb13fd7e9a59a37cd911efff83abe19e3ee029d]
stable/6.12: [600dcd548fb2b00a69f447684f52ba45d5a3540e]
stable/6.18: [b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56]
stable/6.6: [1096397c31f6bffa95e77bdd18fbca085be83e10]
stable/7.1: [8cbad52ccfa6a7f089cfab34979bc6cc3bff25be]
CVE-2026-68435: LoongArch: Fix address space mismatch in kexec command
line lookup
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68435
Introduced by commit 4a03b2a ("LoongArch: Add kexec support") in v6.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [485ed44db5694d8d2e5027f63ad608e705286f30]
stable/6.18: [a94d6726ec8680a2b0c453fc782a543f68a1ea06]
stable/7.1: [7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7]
CVE-2026-68436: drm/amd/display: use kvzalloc to allocate struct dc
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68436
Introduced commit is not determined.Fixed in v7.2-rc2.
Fixed status
mainline: [75050390151a14802be433c3856ddcb483cecd24]
stable/7.1: [dbad70d40cad9c5e7586953275287fe7531fb811]
CVE-2026-68437: drm/imagination: Fit paired fragment job in the correct CCCB
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68437
Introduced by commit eaf01ee ("drm/imagination: Implement job
submission and scheduling") in v6.8-rc1.
Fixed in v7.2-rc1.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [4baf9e70cb756d78dd56419f8baee2978a72d0c3]
stable/6.12: [15a9863929206911a08b6f62de9c5da6931dbc9e]
stable/6.18: [e2c29d51c0f65459ae5bbf7ccc302df4c359c473]
stable/7.1: [4ddf82c18ee4b3d14ec7fa002c4039b46c961abc]
CVE-2026-68438: smp: Make CSD lock acquisition atomic for debug mode
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68438
Introduced by commit b0473dc ("smp: Improve smp_call_function_single()
CSD-lock diagnostics") in v7.1-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [35551efb155e3b83445a6c3f66cb498d5efc182c]
stable/7.1: [282d220bae5fbfc90cf0e3d5b5e42c00ad79f989]
CVE-2026-68439: wifi: mt76: mt7925: fix possible NULL-pointer deref in
mt7925_mcu_bss_he_tlv()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68439
Introduced by commit c948b5d ("wifi: mt76: mt7925: add Mediatek Wi-Fi7
driver for mt7925 chips") in v6.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8d1b6738c1ab48c086b17e7994034aca94258931]
stable/6.12: [42288cca984fb72ad3ebe43d4e7fdce9dcabfdb5]
stable/6.18: [313343ab8cab7417973e7bdd43d3c3e93044b447]
stable/7.1: [856f1588a2590e70b119e76c15315615a36aebc8]
CVE-2026-68440: net: txgbe: fix heap overflow when reading module EEPROM
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68440
Introduced by commit 9b97b6b ("net: txgbe: support getting module
EEPROM by page") in v6.19-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6a905a71fd43ce8b45f05044b11491337f232c9d]
stable/7.1: [febcced6958158e7e90a55a8567b3f5c3639c0b9]
CVE-2026-68441: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68441
Introduced by commit 27b29f6 ("bpf: add bpf_redirect() helper") in v4.4-rc1.
Introduced by commit 401cb7d ("net: Reference bpf_redirect_info via
task_struct on PREEMPT_RT.") in v6.11-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ec48b3be2c8595dd290be883dbd4fb8b2f9f5d5e]
stable/7.1: [c8fd74445e86f88096d2f6cf0f9e4d54d8ed1781]
CVE-2026-68442: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68442
Introduced by commit f86f7a7 ("btrfs: use the flags of an extent map
to identify the compression type") in v6.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [5eff4d5b17fa1950e80bfd1ba43dc0699e61a644]
stable/6.12: [2a9246a424f45f33a1b8367052611ebe874868ad]
stable/6.18: [9304713b70e7e1450e3a76e758836fe5391bfa95]
stable/7.1: [0e465c63f103a5ce6849614d6bda048d70eebec8]
CVE-2026-68443: hwmon: (gigabyte_waterforce) Stop device IO before
calling hid_hw_stop
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68443
Introduced by commit 42ac68e ("hwmon: Add driver for Gigabyte AORUS
Waterforce AIO coolers") in v6.8-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [ff0c5c53d08274e200b48a4d53aa078265e873cb]
stable/6.12: [a855f678ba37ef82c4dd22926ad740ecfb8dbedf]
stable/6.18: [f36e12cc8cfe996d627b8a82bd9df9e43270f6e2]
stable/7.1: [0842e9faab04f784d01125085195031252ff9695]
CVE-2026-68444: firmware: arm_ffa: Fix NULL dereference in
ffa_partition_info_get()
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68444
Introduced by commit d0c0bce ("firmware: arm_ffa: Setup in-kernel
users of FFA partitions") in v5.14-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8]
stable/6.12: [7201e56e52d18abf4cd0a2fee45daf9dc08b5b97]
stable/6.18: [996c5c19d5b5ac5b98a7b5a406b548305841c301]
stable/6.6: [86f5ea90f73bb7154593bb96f3411e197f3d4fbe]
stable/7.1: [12a42c610e4432e7708cc48d607e5903fffe0aad]
CVE-2026-68445: drm/vc4: Prevent shader BO mappings from becoming writable
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68445
Introduced by commit 463873d ("drm/vc4: Add an API for creating GPU
shaders in GEM BOs.") in v4.5-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [0c9e6367639548307d3f578f6943ce72c9d39087]
stable/6.12: [019e6ad247f7fd038d2e009789f6d9bfcccb1ae7]
stable/6.18: [6deaa317201851c644c431b57682e54d06b35838]
stable/6.6: [9f0ee411fc2d76333d6087c5862ffa907cf7a175]
stable/7.1: [fe168ef1d232d734d9998fd74822e2e20930dfff]
CVE-2026-68446: drm/vmwgfx: Validate vmw_surface_metadata::array_size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68446
Introduced by commit 504901d ("drm/vmwgfx: Refactor surface_define to
use vmw_surface_metadata") in v5.7-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a4f55260f7f7d4dc4d0ee55063dfb0c457b77991]
stable/6.12: [71779fe8bf403a9b3e28dc59229fa556db32d35d]
stable/6.18: [b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8]
stable/6.6: [5ff94e1279176b539d451e3e754fdcbd1a8d520a]
stable/7.1: [6910ccaf41678f7761ba2e57d72b77d056320b4d]
CVE-2026-68447: drm/amdkfd: clamp v9 CRIU control stack checkpoint
copy to BO size
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68447
Introduced commit is not determined.Fixed in v7.2-rc2.
The kfd_mqd_manager_v9.c was added by b91d43d ("drm/amdkfd: Add GFXv9
MQD manager") in v4.18-rc1.
Fixed status
mainline: [426ffae6ecc7ec77d32bf8be065c21a1b881b084]
stable/7.1: [a0d87beb2660a5098b2b0ecdc1e96810a9074ea9]
CVE-2026-68448: ovl: check access to copy_file_range source with src
mounter creds
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68448
Introduced by commit 5dae222 ("vfs: allow copy_file_range to copy
across devices") in v5.3-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [a1e0eb8f55cfe09bb31a202a388babc411292656]
stable/6.18: [9ec22c8113d8cf72ed7197bb61037dcad09e50d8]
stable/7.1: [1f4a107439d2e43db176e34919933e617cb7f2c5]
CVE-2026-68449: ata: sata_dwc_460ex: fix infinite loop in NCQ tag
completion bit-scanning
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68449
Introduced by commit 6293600 ("[libata] Add 460EX on-chip SATA driver,
sata_dwc_460ex") in v2.6.36-rc1.
Fixed in v7.2-rc4.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [c2130f6553f4a5cbdc259de069600117a995f197]
stable/6.12: [8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80]
stable/6.18: [1842d45f461a78988254631893329bdf4596e954]
stable/6.6: [4c6e64cae2b2dab32ad9099faa339f6a72c0ce16]
stable/7.1: [29b916d3556bd12a95be7c56ca391b8cd572f8be]
CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert
Announce: https://www.cve.org/CVERecord?id=CVE-2026-68450
Introduced by commit 57a304c ("btrfs: do not panic in
__add_reloc_root") in v5.13-rc1.
Fixed in v7.2-rc5.
Bug introduced commit is not backported to older stable kernels.
Fixed status
mainline: [6a8269b6459ed870a8156c106a0f597383907872]
stable/6.12: [14a8be9428435ee17f17fae7991215c246b7fd43]
stable/6.18: [797dc567146c7e3c4f8d9680e4fbc76e0a6d9151]
stable/6.6: [92bedc0455552b42ada1a1f42b0e3a8593cdfccc]
stable/7.1: [ae0629ff9ccb836416ada129f4edc7efea6eaaad]
* Updated CVEs
CVE-2025-38525: rxrpc: Fix irq-disabled in local_bh_enable()
stable/6.12, stable/6.6 were fixed.
Fixed status
stable/6.12: [8ac0b3baa7d8f732bd9e5cbf1d8b57e4802c6b36]
stable/6.6: [d94b82d452ca27a200cd67660dc48476386651d8]
CVE-2026-23385: netfilter: nf_tables: clone set on flush only
stable/6.6 was fixed.
Fixed status
stable/6.6: [e38f054f0af98224003e600545726fbd96379cfb]
CVE-2026-43197: netconsole: avoid OOB reads, msg is not nul-terminated
stable/6.12 was fixed.
Fixed status
stable/6.12: [8fe132c4873f9eb1b86ddbf31216e9d961a0b8b9]
CVE-2026-63978: net/handshake: Drain pending requests at net namespace exit
stable/6.18 was fixed.
Fixed status
stable/6.18: [2bf24a7e190aae0ea47c78099938ae056c622e44]
CVE-2026-63979: net/handshake: hand off the pinned file reference to accept_doit
stable/6.18 was fixed.
Fixed status
stable/6.18: [68eba6519cbd6359fb554a9720f3a3b6b2eba23f]
CVE-2026-64427: HID: logitech-dj: Fix maxfield check in DJ short
report validation
stable/6.12, stable/6.18, stable/6.6 were fixed.
Fixed status
stable/6.12: [80c1e18473f63fd7c6a2bc9ad6f3d0a6cc4fb500]
stable/6.18: [2b70bebc709489d29a31ac2935aeffb8d5228395]
stable/6.6: [95b3f23d632490b5eb285b9fcf7284f2ac8f9872]
CVE-2026-64523: net/handshake: Take a long-lived file reference at submit
stable/6.18 was fixed.
Fixed status
stable/6.18: [b913801ad9b9a51437d84d030ec6843e08976bd6]
CVE-2026-64563: rhashtable: clear stale iter->p on table restart
stable/6.12, stable/6.6 were fixed.
Fixed status
stable/6.12: [042fda5c088015f18838e5c692659a7be60aeb26]
stable/6.6: [c39643ad99fea749be50615550e8f0e6d6e60694]
Regards,
--
Masami Ichikawa
Cybertrust Japan Co., Ltd.
Email :[email protected]
:[email protected]