CVE-2026-53260 — Linux: In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in
In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop(). The captured reqsk_put() in __inet_csk_reqsk_queue_drop() is called only when it successfully removes reqsk from ehash. Moreover, reqsk_timer_handler() calls another reqsk_put() after that. This indicates that the reqsk was missing both refcnts for eh CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile