2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53260 — Linux: In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53260

In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop(). The captured reqsk_put() in __inet_csk_reqsk_queue_drop() is called only when it successfully removes reqsk from ehash. Moreover, reqsk_timer_handler() calls another reqsk_put() after that. This indicates that the reqsk was missing both refcnts for eh CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53256 — Linux: KASAN reported a slab-use-after-free in lock_sock_nested() from rfcomm_connect_ind(), with the freeing stack going through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53256

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock, but returns the selected listener after dropping that lock without taking a reference. rfcomm_connect_ind() then locks the listener, queues a child socket on it, and may notify it after unlocking it. The buggy scenario involves two paths, with each column showing the order CVSSv3.1 8.0 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53254 — Linux: A malicious remote device can send truncated MCC frames and trigger out-of-bounds reads in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53254

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers cast skb->data to protocol-specific structs without validating skb->len first. A malicious remote device can send truncated MCC frames and trigger out-of-bounds reads in these handlers. Fix this by using skb_pull_data() to validate and access the required data before dereferencing it. rfcomm_recv_rpn() requires special handling CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53248 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53248

In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace period. In the RX path, skb_dst_set_noref() sets a non-refcounted pointer from the skb to the metadata_dst. This function requires RCU read-side protection and the dst must remain valid until all RCU readers complete. Sinc CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53247 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53247

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_free_dev() calls metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace period. In the RX path, skb_dst_set_noref() sets a non-refcounted pointer from the skb to the metadata_dst. This function requires RCU read-side protection and the dst must remain valid until all RCU readers complete. CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53246 — Linux: If the length field is inflated, the parameter walk can run beyond the actual

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53246

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie is parsed and its parameters are later walked by sctp_process_init() using sctp_walk_params(). However, the chunk header length of this cached INIT chunk was not validated against the remaining buffer in the COOKIE_ECHO paylo CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53240 — Linux: In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53240

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload __input_process_payload() stores first_skb into xtfs->ra_newskb under drop_lock when starting partial reassembly, then unlocks and breaks out of the processing loop. The post-loop check reads xtfs->ra_newskb without the lock to decide whether first_skb is still owned: if (first_skb && first_iplen && !defer && first_skb != xtfs->ra_ CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53232 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53232

In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events. This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53230 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53230

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using the PF's log_max_current_uc/mc_list capabilities. When querying a VF vport with a larger configured max (via devlink), the firmware response can overflow this buffer: BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core] Read of size 4 CVSSv3.1 8.7 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53228 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53228

In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry and continues using it after iptunnel_handle_offloads(). For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone(). When the skb header is cloned, skb_header_unclone() can call pskb_expand_head(), which may move the skb head. The pskb_expand_head() contract requires po CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53225 — Linux: In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53225

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address par CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53224 — Linux: Later, sctp_process_init() accesses INIT parameters unconditionally, which may lead to out-of-bounds reads.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53224

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, but did not ensure that the INIT chunk is large enough to contain a complete INIT header. A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose length field is smaller than sizeof(struct sctp_init_chunk). CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53221 — Linux: In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53221

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a tunnel fails, the code falls back to searching for wildcard tunnels: - Tunnels matching the packet's local address, with any remote address wildcard remote). - Tunnels matching the packet's remote address, with any local address (wildcard local). However, vti6 stores all these different types o CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53217 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53217

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX queue packet offset, so hardware writes received data at dma_addr + MVPP2_SKB_HEADROOM. The current CPU sync starts at dma_addr and only covers rx_bytes + MVPP2_MH_SIZE bytes, which syncs the unused headroom and misses the same number of bytes at the packet tail. On non-coherent DMA systems this can leave the CPU reading stale cac CVSSv3.1 8.6 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53216 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53216

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with PAGE_SIZE as frame size. XDP helpers use frame_sz to validate tail growth and to derive the hard end of the data area. Advertising PAGE_SIZE for short buffers can let bpf_xdp_adjust_tail() grow a packet past the CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53215 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53215

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer. mvpp2_rx_refill() can fail after the current buffer has been handed to XDP or attached to an skb. In those cases mvpp2_run_xdp() may have recycled, redirected, or queued the page for XDP_TX, and an skb free also retir CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53200 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53200

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX XN has already been extracted from its bitfield position so using FIELD_PREP() on the mask that clears XN[0] is completely broken, having the effect of unconditionally granting execute permissions... Fix the obvious mistake by manipulating the right bit. CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53198 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53198

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A deferred byte-range lock (an SMB2_LOCK that blocks) registers an async work on conn->async_requests via setup_async_work(), with cancel_fn = smb2_remove_blocked_lock and cancel_argv[0] pointing at the struct file_lock. When the request is cancelled, the worker frees the file_lock with locks_free_lock() and takes the cancelled early-e CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53188 — Linux: In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53188

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_ucaps() Sashiko pointed out it is not safe to rely only on the devt because char/block alias so if the user finds a block device with the same dev_t it can masquerade as a ucap cdev fd. Test the f_ops to only accept authentic cdevs. CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53186 — Linux: In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53186

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data + resp_data_len, where resp_data_len is the full 32-bit value supplied by the SRP target and is never checked against the number of bytes actually received (wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so at most 96 bytes are copied, but the source offset is not bounded. A mal CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53178 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53178

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer underflow. CVSSv3.1 8.1 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53176 — Linux: The copy into the 8192-byte login->req_buf runs far out of bounds and faults, crashing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53176

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus ISER_HEADERS_LEN with no lower bound, and login_req_len is a signed int. A remote iSER initiator can post a login Send work request carrying fewer than ISER_HEADERS_LEN (76) bytes, so the subtraction underflows and login CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53175 — Linux: In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53175

In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet complete using inet_frag_queue_flush(). That helper frees all the skbs queued on the fragment queue but does not set INET_FRAG_COMPLETE, and leaves q->fragments_tail and q->last_run_head pointing at the freed skbs. The queue itse CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53171 — Linux: Arithmetic wraparound can therefore under-report region usage and bypass the bounds validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53171

In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix arithmetic issues in dma_length() dma_length() derives DMA region usage from command stream values and updates region_size[]: len = ((len + stride[0]) * size0 + stride[1]) * size1 region_size[region] = max(..., len + dma->offset) Several arithmetic issues can corrupt the derived region size: - signed stride values may underflow when added to len - intermediate multiplications ma CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53170 — Linux: In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53170

In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leaving dma->len at U64_MAX to signal missing setup. The only setter is NPU_SET_DMA0_LEN; if userspace omits this command and issues NPU_OP_DMA_START, dma->len remains U64_MAX. In dma_length(), a positive stride added to U64_MAX wraps to a small value. With size0 == 1, check_mul_ove CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score