These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-53263 is an off-by-one error in the Linux kernel's 6lowpan implementation, specifically in the lowpan_iphc_mcast_ctx_addr_compress function. The vulnerability causes data corruption and potential kernel stack memory leaks. The issue was introduced due to incorrect offset calculations in memcpy operations, affecting the compressed multicast address and leading to unintended data transmission over the network.
CVE-2026-53261 is a vulnerability in the Linux kernel that involves the release of nested relations in devlink. The vulnerability occurs when a devlink instance is created with a nested relation before registration, but then fails probe before devl_register() is reached. In such cases, the devlink->rel is leaked because devl_unregister() is not called. This vulnerability can be mitigated by releasing any [truncated]
CVE-2026-53259 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the handling of anycast addresses in the IPv6 stack. A use-after-free bug can occur when a device is torn down while an anycast address is being added to the global hash. This can lead to a situation where a freed memory location is accessed, causing a crash or potentially allowin [truncated]
CVE-2026-53256 is a use-after-free vulnerability in the Linux kernel's Bluetooth RFCOMM implementation. The bug arises from a race condition between the rfcomm_connect_ind() function and the listener socket close operation. An attacker could potentially exploit this vulnerability to execute arbitrary code or cause a denial-of-service (DoS) attack. The vulnerability has been resolved by taking a reference [truncated]
CVE-2026-53255 is a vulnerability in the Linux kernel's Bluetooth MGMT advertising TLV validation. A malformed field in the MGMT_OP_ADD_ADVERTISING request can cause the parser to read one byte past the advertising data, potentially leading to a KASAN-reported out-of-bounds read. The issue is resolved by moving the existing element-length check before any type-octet inspection. This change ensures that ea [truncated]
CVE-2026-53254 is a high-severity vulnerability in the Linux kernel's Bluetooth RFCOMM protocol. The vulnerability allows a malicious remote device to send truncated MCC frames and trigger out-of-bounds reads in the handlers. This can lead to a denial of service or potentially allow for code execution. The vulnerability has been patched in the Linux kernel. Users are advised to update their kernel to the [truncated]
CVE-2026-53253 is a HIGH severity vulnerability in the Linux kernel Bluetooth BNEP component. The vulnerability allows a BNEP peer to send a short BNEP SDU, which can cause a slab-out-of-bounds read. The issue has been resolved by rejecting short frames before parsing. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.1. The CVE was published on 2026-06-25T09:16:43.253Z and [truncated]
CVE-2026-53252 is a memory leak vulnerability in the Linux kernel's Bluetooth HCI UART configuration. The vulnerability occurs when device initialization fails before hci_register_dev() completes, resulting in a leak of percpu memory. This vulnerability has been resolved by explicitly calling cleanup_srcu_struct() in the fallback branch of bt_host_release() before freeing the device. Linux kernel users sh [truncated]
CVE-2026-53251 is a Linux kernel Bluetooth vulnerability related to handling of ISO connections. The issue arises from a missing release of a reference to a hci_dev object, which could potentially lead to a use-after-free vulnerability. This CVE was introduced in the Linux kernel's Bluetooth ISO implementation. The Linux kernel maintainers have addressed this issue with a series of patches. Users should e [truncated]
A TOCTOU vulnerability in the Linux kernel's xsk_skb_metadata() function allows for out-of-bounds memory access during checksum computation in the transmit path. This issue arises from the function's practice of reading csum_start and csum_offset from shared memory for bounds validation, then reading them again for skb assignment, creating a window for a malicious userspace application to overwrite these [truncated]
CVE-2026-53247 is a critical vulnerability in the Linux kernel's mtk_eth_soc component. The vulnerability is caused by a use-after-free error in the metadata dst teardown process. This occurs when the mtk_free_dev() function calls metadata_dst_free(), which frees the metadata_dst with kfree() immediately, bypassing the RCU grace period. As a result, a use-after-free can occur if any skb still holds a nore [truncated]
CVE-2026-53245 is a Linux kernel vulnerability affecting the net/802/mrp module. The vulnerability involves a parsing issue in the mrp_pdu_parse_vecattr function, which can lead to incorrect processing of vector attribute events. This can cause the MRP applicant state to be corrupted, potentially leading to unexpected behavior or crashes. The issue arises from incorrect handling of the valen variable, whi [truncated]
A vulnerability was discovered in the Linux kernel's Virtual File System (VFS). The vulnerability, tracked as CVE-2026-53244, has a CVSS score of 7.5 and is classified as HIGH severity. The vulnerability is related to the handling of dentry references in the nfsd4_create_file() function. Specifically, the function fails to unlock the parent dentry when an error occurs during the atomic_create() operation. [truncated]
CVE-2026-53243 is a vulnerability in the Linux kernel that involves the improper initialization of a stack variable in the `rseq_exit_user_update()` function. This issue was reported by syzbot and is related to the use of an uninitialized stack variable, potentially leading to information leaks. The vulnerability has been resolved by moving the assignment of `ids.node_id` outside the structure initializat [truncated]
The Linux kernel has a vulnerability in the ALSA PCM subsystem that could lead to a kernel panic due to wait queue list corruption. This issue arises from the improper use of init_waitqueue_entry and add_wait_queue with conditional remove_wait_queue in snd_pcm_drain(). The vulnerability has been resolved by replacing these functions with init_wait_entry, prepare_to_wait, and finish_wait. The CVSS score fo [truncated]
CVE-2026-53240 is a high-severity use-after-free vulnerability in the Linux kernel, specifically affecting the xfrm: iptfs component. The vulnerability arises from a race condition in the __input_process_payload function, where a concurrent CPU can complete reassembly and free the skb, leading to a use-after-free in skbuff_head_cache. This vulnerability has been resolved through a patch that replaces the [truncated]
CVE-2026-53235 is a vulnerability in the Linux kernel's net module, specifically in the skb_gro_receive_list() function. The vulnerability arises from a missing call to pskb_may_pull() before calling skb_pull(). This can lead to a BUG_ON() failure when the skb arrives via napi_gro_frags(). The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The issue was resolved by adding a call [truncated]
CVE-2026-53233 is a vulnerability in the Linux kernel that affects the netdev component. The vulnerability is caused by a double-free issue in the netdev_nl_bind_rx_doit() function. This vulnerability can be exploited by a user with local access to the system, and it has been resolved by the Linux kernel developers. The vulnerability has been publicly disclosed and is awaiting analysis. There is no inform [truncated]
A vulnerability in the Linux kernel has been resolved, involving the failure to clean the sfp upstream if phy probing fails. This issue, reported by Sashiko, results in a dangling 'upstream' field in the sfp-bus, which may be used later during SFP events. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It was published on June 25, 2026, and modified on June 28, 2026. The CVE [truncated]
A vulnerability was found in the Linux kernel, specifically in the PHY-driven SFP cages setup when using genphy. The issue arises because the genphy code does not support PHY-driver SFP cages. Furthermore, running sfp_bus_add_upstream() for genphy leads to a deadlock due to PHY probing running under RTNL for genphy but not for non-genphy drivers. This problem was reproduced and confirmed to cause a deadlo [truncated]
CVE-2026-53228 is a critical vulnerability in the Linux kernel's IPv6 implementation. The vulnerability arises from the improper handling of the inner IPv6 header after GSO offloads in the `ipip6_tunnel_xmit` function. This can lead to the use of a stale pointer, potentially allowing an attacker to read from a freed skb head. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9 [truncated]
CVE-2026-53227 is a vulnerability in the Linux kernel that affects the openvswitch component. The vulnerability is related to the handling of error pointers in the allocation of the 'reply' skb. If the allocation of 'reply' happens after locking the ovs_mutex and it fails, 'reply' is left with an ERR_PTR, and execution jumps to the correspondent cleanup stage which will try to free an invalid pointer. Thi [truncated]
CVE-2026-53225 is a critical vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. The vulnerability exists in the __sctp_rcv_asconf_lookup() function in net/sctp/input.c. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header. This causes the receive path to read up to [truncated]
CVE-2026-53224 is a critical vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. The vulnerability arises from improper validation of embedded INIT chunk and address list lengths in cookies. An attacker can exploit this vulnerability by sending a malformed COOKIE_ECHO packet, potentially leading to out-of-bounds reads. The vulnerability has a CVSS score of 9.1 a [truncated]
A HIGH severity vulnerability, CVE-2026-53223, has been resolved in the Linux kernel. The vulnerability is related to the handling of timestamp control messages (cmsgs) in the Linux kernel's networking subsystem. Specifically, it affects the way the kernel handles error queue skbs (socket buffer packets) and timestamping. The vulnerability could allow an attacker to potentially disclose sensitive informat [truncated]
CVE-2026-53221 is a critical vulnerability in the Linux kernel's ip6_vti module. The vulnerability is caused by a bug in the vti6_tnl_lookup() function, which fails to properly match tunnels, leading to potential hash collisions. This vulnerability has a CVSS score of 9.8 and is considered critical. The vulnerability was published on June 25, 2026, and modified on June 28, 2026. The Linux kernel maintaine [truncated]
CVE-2026-53220 is a vulnerability in the Linux kernel's netfilter component. The vulnerability arises from the ebt_redirect_tg() function, which dereferences the return value of br_port_get_rcu() without checking for NULL, leading to a kernel panic when the bridge port has been removed. The issue is exacerbated by the fact that userspace can not only remove the port from the bridge but also place the devi [truncated]
CVE-2026-53218 is a vulnerability in the Linux kernel's netfilter nft_exthdr component. The vulnerability arises from improper register tracking when the F_PRESENT flag is set. In the nft_exthdr_init() function, user-controlled data (priv->len) is passed to nft_parse_register_store(), which marks a range of bytes in the register bitmap as initialized. However, when the NFT_EXTHDR_F_PRESENT flag is set, on [truncated]
CVE-2026-53217 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 8.6. The vulnerability is related to the mvpp2 net driver, which does not properly synchronize received data at the hardware packet offset. This can cause the CPU to read stale cache contents for the end of the received frame on non-coherent DMA systems. The vulnerability was resolved by using dma_sync_single_range_f [truncated]
A critical vulnerability, CVE-2026-53215, has been identified in the Linux kernel. The vulnerability is related to the refill of RX buffers before XDP or skb use in the mvpp2 driver. If exploited, it could allow an attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability has a CVSS score of 9.8 and is considered critical. The Linux kernel maintainers have resolved the [truncated]