PatchSiren

Linux CVE debriefs · Page 79

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53351

A MEDIUM severity vulnerability was found in the Linux kernel, with a CVSS score of 5.5. The vulnerability has been resolved with a patch. The patch fixes a warning while dumping core. Linux kernel users and administrators should be aware of this vulnerability and take necessary actions to protect their systems. The vulnerability affects Linux kernel deployments and may have operational impacts if not addressed.

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53350

A NULL pointer dereference vulnerability was found in the Linux kernel's ASoC wm_adsp component. The vulnerability occurs when removing firmware controls without checking if the private data pointer is NULL. This can happen in two cases: 1) when the control is a SYSTEM control and no ALSA control is created, or 2) when the codec driver registers a control_add() callback that hides the control. The vulnera [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53349

A Linux kernel vulnerability, CVE-2026-53349, was resolved by destroying stale expectfn expectations on unregister. The vulnerability affected the netfilter component, specifically the nf_conntrack module. NAT helpers like nf_nat_h323 stored a raw pointer to module text in exp->expectfn. When the expected connection arrived, init_conntrack() invoked exp->expectfn(), now a stale pointer into the unloaded m [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53348

A NULL pointer dereference vulnerability was found in the Linux kernel's ASoC SDCA implementation. The vulnerability occurs when sdca_dev_unregister_functions() iterates over SDCA function descriptors and calls sdca_dev_unregister() on each func_dev without checking for NULL. This can lead to a kernel oops when a function registration has failed partway through or the device cleanup races with probe defer [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53347

The Linux kernel was vulnerable to a medium-severity issue (CVSS 5.5) that could lead to a denial-of-service (DoS) attack when the virtio-gpu driver was built with disabled KMS. This issue, resolved in various kernel updates, resulted in a crash on driver removal or unbinding due to access of uninitialized data. The vulnerability affects Linux kernel versions 6.4 through 7.1 rc7. System administrators and [truncated]

HIGH Linux CVE published 2026-07-01

CVE-2026-53346

A HIGH severity vulnerability was found in the Linux kernel, specifically in the rust: arm64 module. The vulnerability is caused by a rustc bug that prevents the uwtable annotation from being emitted for compiler-generated functions. This leads to boot failures when CONFIG_UNWIND_PATCH_PAC_INTO_SCS is enabled. The issue is resolved by setting the uwtable llvm module flag for CONFIG_UNWIND_TABLES. The fix [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53345

The Linux kernel was updated to address a vulnerability in KVM that triggered a warning when memory was dirtied without a vCPU when the VM was dying. This change allows for fixing a memory leak for x86 SEV-ES guests without hitting a false positive warning. The vulnerability was resolved by modifying KVM's behavior to only complain about not having a running/loaded vCPU when marking a page dirty if the VM [truncated]

Review Linux CVE published 2026-07-01

CVE-2026-53330

The Linux kernel has a vulnerability in the drm/amd/display component. An out-of-bounds read occurs in dp_get_eq_aux_rd_interval() due to an incorrect array size. This issue can lead to potential security risks if exploited. Users of the Linux kernel with drm/amd/display component should review and apply patches or mitigations. The vulnerability arises from the aux_rd_interval array being declared with MA [truncated]

Review Linux CVE published 2026-07-01

CVE-2026-53327

CVE-2026-53327 is a vulnerability in the Linux kernel that affects the debugobjects functionality. The vulnerability is caused by a failure to check the pi_blocked_on condition before calling fill_pool(), which can lead to a priority inheritance chain corruption. This vulnerability was resolved by expanding the conditional to take current::pi_blocked_on into account. The vulnerability was published on 202 [truncated]

Review Linux CVE published 2026-06-26

CVE-2026-53321

CVE-2026-53321 is a Linux kernel vulnerability resolved by capping busy_poll_to to 10 msec in io_uring/napi. The vulnerability could lead to kernel complaints on a task being stuck due to lack of conditional rescheduling. The fix ensures that the napi polling time does not exceed 10 msec, preventing potential preemption complaints. This change was made to address the issue without introducing significant [truncated]

Review Linux CVE published 2026-06-26

CVE-2026-53318

CVE-2026-53318 is a vulnerability in the Linux kernel's mt76 driver, specifically in the mt7925_tx_check_aggr() function. The vulnerability has been resolved by moving the NULL check for 'sta' before dereferencing it to prevent a possible crash. The CVE record was published on 2026-06-26T20:17:25.137Z and last modified on 2026-06-30T14:44:27.313Z. The vulnerability's CVSS score and severity are currently [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53317

CVE-2026-53317 is a vulnerability in the Linux kernel's wifi mt76 mt7921. The issue arises when a station is configured with an AID (Association ID) over 20, causing a firmware crash. This situation was encountered during testing using an AP interface on 7922 hardware with a modified hostapd. The modified hostapd allocated AIDs starting at 65, leading to the firmware crash. The fix prevents these AIDs fro [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53315

CVE-2026-53315 is a NULL pointer dereference vulnerability in the Linux kernel's drm/amd/ras component. The vulnerability exists in the ras_core_get_utc_second_timestamp() function, which retrieves the current UTC timestamp. The function checks ras_core in a conditional statement before calling a platform-specific RAS system callback. However, when the condition fails, the function prints an error message [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53314

CVE-2026-53314 is a vulnerability in the Linux kernel related to the padata CPU offline callback. The issue arises from the callback being in the wrong section, leading to a warning about a DEAD callback error. This vulnerability was reported by syzbot and tracked to the padata_cpu_dead function. The problem is resolved by moving the CPU offline callback to the ONLINE section, where failure is allowed. Th [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53310

A vulnerability in the Linux kernel's soc/tegra component has been resolved. The issue, identified as CVE-2026-53310, relates to the handling of cross-fabric target timeout lookups. When a fabric receives an error interrupt, the error may have occurred on a different fabric. However, the target timeout lookup was using the wrong base address, leading to a kernel page fault. The fix involves adding a funct [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53299

CVE-2026-53299 is a vulnerability in the Linux kernel that has been resolved. The vulnerability is related to the airoha_qdma_init_tx_queue routine, where a NULL pointer dereference occurs when queue entry list allocation fails. The issue arises due to early ndesc initialization in airoha_qdma_init_tx_queue(). The fix involves moving ndesc initialization to the end of airoha_qdma_init_tx routine. This vul [truncated]

HIGH Linux CVE published 2026-06-26

CVE-2026-53296

CVE-2026-53296 is a Linux kernel vulnerability affecting the mailbox-test component. The vulnerability involves a probe error that prevents freeing previously obtained channels, potentially leading to a memory leak and use-after-free (UAF) scenarios. The Linux kernel maintainers have resolved this issue by ensuring that channels are freed on probe error. This fix prevents potential memory leaks and UAF sc [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53295

CVE-2026-53295 is a Linux kernel vulnerability that has been resolved. The issue involves adding a sanity check for the channel array in the mailbox controller to prevent an OOPS (out-of-order) error. The vulnerability might not be immediately visible because mailbox controllers might instantiate very early. The Linux kernel maintainers have addressed this issue by adding a check to ensure that a channel [truncated]

HIGH Linux CVE published 2026-06-26

CVE-2026-53294

A vulnerability in the Linux kernel has been resolved, specifically in the mailbox-test component. The RX channel can be aliased to the TX channel if it has a different MMIO, requiring special handling when freeing channels to prevent double-free occurrences. This issue has been addressed in the kernel. The CVE was published on 2026-06-26T20:17:22.310Z and modified on 2026-06-30T14:44:27.313Z. The vulnera [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53293

CVE-2026-53293 is a vulnerability in the Linux kernel related to the AMDGPU_INFO_READ_MMR_REG functionality. Multiple issues were identified in the code, including incorrect ordering of the reset semaphore and mm_lock, memory allocation while holding the reset semaphore, and improper use of down_read_trylock(). These issues could lead to potential deadlocks and other problems. The vulnerability was resolv [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53292

CVE-2026-53292 is a vulnerability in the Linux kernel that could lead to a kernel panic. The vulnerability is caused by a BUG_ON() statement in the pn_socket_autobind() function, which is triggered when the pn_socket_bind() function returns -EINVAL and the socket has not been bound. This can happen when the socket's state is not TCP_CLOSE. The vulnerability can be exploited by a user-triggerable path, lea [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53291

CVE-2026-53291 is a vulnerability in the Linux kernel's ALSA hda/conexant module. The vulnerability is caused by a missing error check for jack detection in the cx_probe() function. The function snd_hda_jack_detect_enable_callback() returns a pointer that must be checked using IS_ERR(). If the registration fails, the driver continues to probe, but the jack detection callback will not be registered. This c [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53285

CVE-2026-53285 is a vulnerability in the Linux kernel that has been resolved. The vulnerability is related to the drm/amd/display module and involves wrapping DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED. This vulnerability was introduced due to a conflict between FPU-enabled regions and memory allocation, leading to a kernel crash. The issue arises from dcn32_validate_bandwidth() wrap [truncated]

MEDIUM Linux CVE published 2026-06-26

CVE-2026-53282

CVE-2026-53282 is a vulnerability in the Linux kernel related to the x86/kexec functionality. The issue arises from the purgatory code shipped by kexec-tools attempting to access a return address above the stack top in non-kjump kexec scenarios. This access may fail due to changes introduced by a previous commit, leading to potential faults. The vulnerability has been addressed by ensuring the return addr [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53275

CVE-2026-53275 is a use-after-free vulnerability in the Linux kernel's IPv6 multicast handling. The vulnerability occurs when processing MLD queries, where a pointer to the multicast group address is retrieved and later dereferenced without being reloaded, leading to a use-after-free condition. This issue was resolved by copying the multicast group address when the packet is initially parsed. The Common V [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53270

CVE-2026-53270 is a HIGH-severity vulnerability in the Linux kernel's IPVS scheduler. The vulnerability occurs when the IPVS scheduler pointer is not cleared early enough during the editing of a service, allowing packets to use the old scheduler after it has been freed. This can lead to a use-after-free vulnerability. The vulnerability has been resolved by clearing the scheduler pointer early in the ip_vs [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53269

CVE-2026-53269 is a Linux kernel vulnerability in the netfilter synproxy component. The vulnerability arises from a race condition that occurs when multiple users attempt to add iptables targets or nftables expressions concurrently. This can lead to a situation where the reference count of hook structures is not properly synchronized, potentially causing a use-after-free or other memory corruption issues. [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53268

CVE-2026-53268 is a HIGH severity vulnerability in the Linux kernel's netfilter conntrack_irc module. The vulnerability is caused by a possible out-of-bounds read when parsing fails after matching the command string. This vulnerability has been resolved in the Linux kernel. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.2, indicating a HIGH severity level. The CVSS vector [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53267

CVE-2026-53267 is a HIGH severity vulnerability in the Linux kernel's netfilter component. The vulnerability is caused by a bug in the nft_ct module, which allows an attacker to overflow the kernel stack by triggering a 16-byte memcpy operation on a template conntrack object. This can be exploited by an attacker with local access to the system, potentially leading to privilege escalation. The bug was intr [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53265

CVE-2026-53265 is a HIGH severity vulnerability in the Linux kernel, specifically in the dm cache policy smq. The vulnerability was resolved by moving the allocation check under the mq->lock to prevent a check-then-act race. This change ensures that the predicate and destructive operations are serialized by the same lock, preventing potential corruption of the SMQ queues or hash table. The vulnerability h [truncated]