2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53088 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53088

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb. We want to return the tx_cb that gets rewinded, so we must rewind the pointer first then return the tx_cb that it points to. That way the txcb can be correctly cleaned up. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53086 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53086

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions with queues that are still chugging along. Instead lets only restart the timed out queue. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53075 — Linux: In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53075

In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_ns, while unattached administrative ioctls operate on current->nsproxy->net_ns. As a result, a local unprivileged user can create a new user namespace with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace, and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCAT CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53072 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53072

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assumes it is held, and if conn is deleted concurrently -> UAF. Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen, and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53071 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53071

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() b CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53057 — Linux: In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53057

In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after updating DDT/PDT entries Add riscv_iommu_iodir_iotinval() to perform required TLB and context cache invalidations after updating DDT or PDT entries, as mandated by the RISC-V IOMMU specification (Section 6.3.1 and 6.3.2). CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53055 — Linux: If the software subsequently accesses this req, a use-after-free error will occur.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53055

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free the request memory (req) before the transmission function finishes. If the software subsequently accesses this req, a use-after-free error will occur. The qp_ctx memory exists throughout the packet sending process, so replace t CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-53053 — Linux: This meant that the source devid used to look up and copy the DTE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53053

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the original device's devid Currently clone_alias() assumes first argument (pdev) is always the original device pointer. This function is called by pci_for_each_dma_alias() which based on topology decides to send original or alias device details in first argument. This meant that the source devid used to look up and copy the DTE may be incorrect, leading to wrong or stal CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53049 — Linux: In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53049

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53046 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53046

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code from async hardware crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns -EINPROGRESS, ksmbd treats it as an error and immediately frees the request while the hardware DMA operation is still in flight. CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53045 — Linux: In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53045

In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The code checking whether the specified memory timing enables DLL in the EMRS register was reversed. DLL is enabled if bit A0 is low. Fix the check. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53043 — Linux: The o2net layer only validates message byte length; it does not constrain field values

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53043

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()". In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION network message is used to drive loops over the qr_regions buffer without sufficient validation. This series fixes two issues: - Patch 1 adds a bounds check to reject messages where qr_numregions exceeds O2NM_MAX_ CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53010 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53010

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor early during the durable reconnect process. If an error occurs subsequently (eg, ksmbd_iov_pin_rsp fails) or a scavenger accesses the file, it leads to a use-after-free when accessing fp properties (eg fp->create_time). Move the single put to CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53006 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53006

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call. CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-53002 — Linux: BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53002

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0 mangle_content_len+0x1ac/0x280 nf_nat_sdp_ CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52999 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52999

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each fingerprint checked. During TCP option parsing, nf_osf_match_one() advances the shared ctx->optp pointer. If a fingerprint perfectly matches, the function returns early without restoring ctx->optp to its initial state. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52993 — Linux: In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52993

In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been f CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52989 — Linux: In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52989

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue) and returns early. However, because the function returns void, the callers are entirely unaware that a fatal error has occurred and that the cmd->recv_msg.msg_iter was left uninitialized. Callers such CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52986 — Linux: Connection tracking helpers are designed to allow traffic to pass, not to block it.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52986

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request() with a new sip_parse_port() helper that validates each digit against the buffer limit, eliminating the use of simple_strtoul() which assumes NUL-terminated strings. The previous code dereferenced pointers without bounds checks after sip_parse_addr() and re CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52982 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52982

In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len for tx statistics after usb_submit_urb() has been called: BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760 drivers/net/usb/rtl8150.c:712 Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 The URB completion han CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-52968 — Linux Linux_kernel: This causes out-of-bounds accesses when aisb >= 32 (with ZPCI_NR_DEVICES=512) Fix by removing the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52968

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() index the GAIT by manually multiplying the index with sizeof(struct zpci_gaite). Since aift->gait is already a struct zpci_gaite pointer, this double-scales the offset, accessing element aisb*16 instead of aisb. This causes out-of-bounds accesses wh CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

CWECWE 125TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-52967 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52967

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8 CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52958 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52958

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value ex CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 17:17Z
CRIT

CVE-2026-52955 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52955

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 17:17Z
HIGH

CVE-2026-52952 — Linux: In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52952

In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In __iommu_group_set_domain_internal(), concurrent domain attachments are rejected when any device in the group is recovering. This is necessary to fence concurrent attachments to a multi-device group where devices might share the same RID due to PCI DMA alias quirks, but triggers the WARN_ON in __iommu_group_set_domain_nofail(). Other IO CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score