PatchSiren

Linux CVE debriefs · Page 81

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53213

CVE-2026-53213 is a vulnerability in the Linux kernel's drm/vc4 component. The issue involves a memory leak caused by improper handling of the krealloc() function. Specifically, the original pointer passed to krealloc() is overwritten with its return value without checking if the latter is NULL, leading to a memory leak. To fix this, a temporary variable should be used to check the return value of kreallo [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53212

CVE-2026-53212 is a high-severity vulnerability in the Linux kernel, caused by a use-after-free issue in the netfilter subsystem. The vulnerability occurs when the metadata_dst_free() function is called, which directly kfree()s the metadata_dst, ignoring the dst_entry refcount. This can lead to a dangling pointer being left in packets that took a reference via dst_hold() in nft_tunnel_obj_eval() and are s [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53211

CVE-2026-53211 is a vulnerability in the Linux kernel's netfilter nft_meta_bridge component. The issue arises from the NFT_META_BRI_IIFHWADDR register, which is initialized with a length of 6 bytes (ETH_ALEN) but is rounded up to two 32-bit registers (8 bytes) by the register-init tracking. When nft_meta_bridge_get_eval() performs a memcpy from br_dev->dev_addr to the destination register, it only writes [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53209

CVE-2026-53209 is a HIGH-severity vulnerability in the Linux kernel's Bluetooth component. The vulnerability exists in the hci_sync module, where an oversized Broadcast Announcement prepend can cause a buffer overflow. This can lead to a denial-of-service (DoS) or potentially allow an attacker to execute arbitrary code. The vulnerability has a CVSS score of 7.8 and was published on June 25, 2026.

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53208

CVE-2026-53208 is a vulnerability in the Linux kernel's Bluetooth L2CAP protocol. The vulnerability allows a Bluetooth BR/EDR peer within radio range to force 168 ECHO_RSP frames from one 681-byte fixed-channel signaling packet containing packed ECHO_REQ commands. This issue was resolved by defining Linux's BR/EDR signaling MTU as the spec minimum of 48 bytes and rejecting any larger signaling packet with [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53203

CVE-2026-53203 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.1. The vulnerability is caused by a buffer overflow in the accel/ivpu component, specifically in the MS get_info_ioctl function. The vulnerability has been resolved by adding a buffer overflow check. The Common Vulnerability Scoring System (CVSS) score is 7.1, indicating a HIGH severity vulnerability. The vulnerabi [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53202

CVE-2026-53202 is a HIGH severity vulnerability in the Linux kernel, specifically in the accel/ivpu component. It involves a signed integer truncation issue in IPC receive that could lead to a potential buffer overflow. The vulnerability is caused by the casting of firmware-supplied data_size to a signed int before being used in min_t(). Large unsigned values (>= 0x80000000) become negative, causing unsig [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53198

CVE-2026-53198 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 8.8. The vulnerability is caused by a use-after-free error in the ksmbd module, which can be exploited by an authenticated SMB client to execute arbitrary code. The vulnerability was introduced by a faulty handling of deferred file locks, which can be cancelled and freed prematurely, leading to a use-after-free error [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53195

A heap overflow vulnerability was discovered in the Linux kernel's USB: serial: io_ti module. The build_i2c_fw_hdr() function allocates a fixed-size buffer and copies data into it without validating the length, potentially leading to a heap overflow. This vulnerability has been resolved by rejecting images where the firmware header length exceeds the available destination space.

HIGH Linux CVE published 2026-06-25

CVE-2026-53189

A HIGH severity vulnerability, CVE-2026-53189, with a CVSS score of 7.8, has been resolved in the Linux kernel. The issue involves updating the file PMD counter before folio_put() in __split_huge_pmd_locked(). If folio_put() drops the last reference, mm_counter_file() can later read freed folio state via folio_test_swapbacked(). The counter update has been moved before folio_put() to address this vulnerab [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53188

CVE-2026-53188 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 8.8. The vulnerability is related to the RDMA/core component, specifically in the ib_get_ucaps() function. The issue arises from the fact that the current implementation relies solely on the device number (devt) to validate the file operations (fops) passed to the function. However, this approach is not secure becaus [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53187

A vulnerability in the Linux kernel's RDMA/core DMAH alloc has been resolved. The cpu_id attribute supplied by user space is passed directly to cpumask_test_cpu() without verification, leading to a potential out-of-bounds read. This vulnerability has been assigned a CVSS score of 7.1 and a HIGH severity rating. The vulnerability was reported by Smatch and has been fixed by rejecting any cpu_id that is not [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53185

A use-after-free vulnerability was discovered in the Linux kernel's zram component. The issue arises from the zram_bvec_write_partial function, which passes its parent bio down, allowing the read to be dispatched asynchronously. This leads to the caller running memcpy_from_bvec, zram_write_page, and __free_page on the buffer, leaving the async read to write into a freed page. The vulnerability has been re [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53182

CVE-2026-53182 is a HIGH-severity vulnerability in the Linux kernel, specifically in the nl80211 component. It allows for an out-of-bounds write due to improper validation of EMA RNR lists. The vulnerability has been resolved by rejecting oversized EMA RNR lists. This fix aligns the parser with the data structure it fills and matches the existing bound check used by nl80211_parse_mbssid_elems(). The Commo [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53180

A HIGH severity vulnerability, CVE-2026-53180, was resolved in the Linux kernel. The vulnerability was caused by a livelock in tmigr_handle_remote_up(), which could lead to a denial-of-service attack. The issue arose from the incorrect assumption that the local softirq path had already handled the CPU's timers. This assumption was wrong because jiffies could advance after handling the CPU's global timers [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53178

A high-severity vulnerability has been resolved in the Linux kernel, specifically in the staging: rtl8723bs: rtw_mlme component. The vulnerability, tracked as CVE-2026-53178, involves adding bounds checks to prevent unsigned integer underflow when subtracting fixed IE offsets from ie_length. This issue is particularly relevant to Linux kernel maintainers and users who need to ensure the security of their systems.

CRITICAL Linux CVE published 2026-06-25

CVE-2026-53175

CVE-2026-53175 is a critical vulnerability in the Linux kernel that allows for use-after-free attacks. The vulnerability is caused by the fqdir_pre_exit() function not properly resetting the rb_fragments, fragments_tail, and last_run_head pointers after flushing a fragment queue. This can lead to a use-after-free attack, allowing an attacker to execute arbitrary code. The vulnerability affects the Linux k [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53171

CVE-2026-53171 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 8.8. The vulnerability is related to the accel/ethosu component and is caused by arithmetic issues in the dma_length() function. This function is used to derive DMA region usage from command stream values and update region_size[]. The vulnerability can be exploited due to several arithmetic issues that can corrupt th [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53170

CVE-2026-53170 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 8.8. The vulnerability is caused by the improper handling of DMA commands with uninitialized length in the accel/ethosu driver. An attacker with local access and low privileges can exploit this vulnerability to execute DMA with stale physical addresses, potentially leading to privilege escalation and denial of servic [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53169

CVE-2026-53169 is a vulnerability in the Linux kernel that allows unprivileged users to cause a denial-of-service (DoS) attack. The vulnerability is caused by the improper handling of NPU_OP_RESIZE commands from userspace, which can lead to unbounded kernel log spam and potentially cause a kernel panic if panic_on_warn is set. The vulnerability has been resolved by replacing the WARN_ON(1) placeholder wit [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53167

CVE-2026-53167 is a Linux kernel vulnerability related to FUSE_NOTIFY_RETRIEVE. The vulnerability has been resolved by limiting FUSE_NOTIFY_RETRIEVE to uptodate folios. This change prevents !uptodate folios, which can contain uninitialized data, from being treated as if they were present. The security impact of this vulnerability is limited to systems that do not enable automatic zero-initialization of al [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53165

A vulnerability in the Linux kernel has been resolved, which could lead to a null pointer dereference during error reporting. The vulnerability occurs when a buffered read fails, and the error is reported with fserror_report_io(). This function is called after ifs->read_bytes_pending has been decremented by the bytes attempted to be read. For a folio split across multiple read completions, the folio is on [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53164

A vulnerability in the Linux kernel's iommu/dma has been resolved. The issue arises when iommu_dma_iova_link_swiotlb() processes an unaligned mapping in three parts: head, middle, and trailer. If the middle part is empty due to no aligned pages, it calls iommu_map() with a 0 size, which is considered illegal by the iommupt implementation. This leads to an error unwind that starts from the wrong spot, corr [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53163

A vulnerability was discovered in the Linux kernel's locking/rtmutex component. The issue arises from a null-pointer dereference in the remove_waiter() function, which occurs when a waiter is not enqueued. This vulnerability was triggered via FUTEX_CMP_REQUEUE_PI. The problem stems from task_blocks_on_rt_mutex() not arming the waiter upon deadlock detection, resulting in a nil waiter->task. Recent changes [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53162

A vulnerability was discovered in the Linux kernel, specifically in the memcg (memory cgroup) subsystem. The vulnerability arises from the use of get_random_u32_below() in the nmi context, which can lead to corruption of the ChaCha batch state. This can cause issues with memcg charge draining, potentially leading to unexpected behavior or crashes. The vulnerability has been resolved by replacing the rando [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53161

CVE-2026-53161 is a high-severity use-after-free vulnerability in the Linux kernel. The vulnerability exists in the fastrpc module, which is used for communication between the Linux kernel and the Digital Signal Processor (DSP). The vulnerability occurs when the user closes the file descriptor, freeing the fastrpc_user structure, while an in-flight DSP invocation completes and schedules context cleanup vi [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53154

CVE-2026-53154 is a vulnerability in the Linux kernel that affects the hugetlb folio copy paths. The vulnerability arises from a missing restore_reserve_on_error() call before folio_put() on error paths in hugetlb_mfill_atomic_pte() and copy_hugetlb_page_range(). This omission leads to a reservation leak in the VMA's reserve map, potentially causing a SIGBUS error at a previously reserved address under hu [truncated]

HIGH Linux CVE published 2026-06-25

CVE-2026-53153

CVE-2026-53153 is a vulnerability in the Linux kernel's memory management subsystem. The vulnerability arises from the memcg_reparent_list_lrus function, which clears the dying memcg's xarray entry before reparenting its per-node lists into the parent. This creates a window where a concurrent list_lru_del operation can see the xarray entry as NULL, leading to a use-after-free condition. An attacker with l [truncated]

MEDIUM Linux CVE published 2026-06-25

CVE-2026-53152

CVE-2026-53152 is a vulnerability in the Linux kernel, specifically in the dw_mmc-rockchip module. The vulnerability arises from the lack of private data for very old controllers (rk2928, rk3066, rk3188), which do not support UHS speeds and never handled phase data. A commit (ff6f0286c896) made private data mandatory, causing NULL-pointer dereferences in old SoCs. To address this, the old types should be [truncated]

CRITICAL Linux CVE published 2026-06-25

CVE-2026-53151

CVE-2026-53151 is a critical vulnerability in the Linux kernel's rxrpc ACK parser. The vulnerability allows for potential modification of the received skbuff in rxrpc_input_soft_acks() and incorrect access of the buffer in a fragmented UDP packet. This could lead to a denial of service or potential code execution. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicati [truncated]