These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-53146 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.1. The vulnerability is related to the Thunderbolt subsystem and can lead to data exposure. The issue arises from the tb_xdomain_copy() function, which copies data from a received packet buffer without properly checking the actual frame size. This can cause the function to read past the valid frame data in the DMA [truncated]
A high-severity vulnerability, CVE-2026-53145, was found in the Linux kernel. The vulnerability is related to the drm/gem component and has a CVSS score of 7.8. It was published on June 25, 2026, and modified on June 28, 2026. The vulnerability is caused by a race condition between the gem_close and gem_change_handle ioctls. To address this issue, several code changes were made, including renaming a local [truncated]
CVE-2026-53143 is a HIGH severity vulnerability in the Linux kernel, specifically in the drm/amdkfd component. A buffer overflow occurs in SDMA queue checkpoint/restore on GFX11, allowing for potential memory corruption and information disclosure. The vulnerability has a CVSS score of 7. The issue arises from a copy-paste regression unique to v11, where the CP-compute variants of checkpoint_mqd/restore_mq [truncated]
CVE-2026-53140 is a Linux kernel vulnerability affecting the drm/v3d component. The vulnerability arises from a failure to release vaddr mappings when an indirect CSD has zeroed workgroups. This issue was resolved by modifying the v3d_rewrite_csd_job_wg_counts_from_indirect() function to jump to the cleanup path instead of returning directly. The CVE was published on 2026-06-25 and modified on 2026-06-30. [truncated]
CVE-2026-53139 is a vulnerability in the Linux kernel's drm/v3d component. The vulnerability arises from a compute shader dispatch that encodes its workgroup counts in the CFG0..CFG2 registers. If a dispatch has a zero count in any of the three dimensions, it is considered invalid. The hardware processes 0 as 65536, while the user-space driver exposes a maximum of 65535. Furthermore, a submission with a z [truncated]
CVE-2026-53134 is a vulnerability in the Linux kernel's netfilter: nft_fib component. The vulnerability arises from a stale stack leak via the OIFNAME register. When the destination register is declared with a length of IFNAMSIZ (four 32-bit registers) for NFT_FIB_RESULT_OIFNAME, but on the lookup-fail, RTN_LOCAL, and oif-mismatch paths, nft_fib{4,6}_eval() only writes one register via '*dest = 0'. This l [truncated]
CVE-2026-53132 is a HIGH severity vulnerability in the Linux kernel's vsock/virtio. The vulnerability is caused by a potential unbounded skb queue in virtio_transport_inc_rx_pkt() and virtio_transport_recv_enqueue(). If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs->rx_bytes stays at 0. The fix estimates the skb metadata size by (Number o [truncated]
A critical vulnerability, CVE-2026-53131, was found in the Linux kernel. The vulnerability exists in the netfilter component, specifically in the `ip6t_eui64`, `xt_mac`, `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog`. These components access `eth_hdr(skb)` without verifying that the skb is associated with an Ethernet device and that the MAC header is set. This vulnerabilit [truncated]
CVE-2026-53130 is a HIGH-severity vulnerability in the Linux kernel's OMFS filesystem. The vulnerability arises from the lack of a lower-bound check on the s_sys_blocksize value, which can lead to an unsigned underflow and potentially overwrite kernel memory. The vulnerability has a CVSS score of 7.8 and was published on June 24, 2026. The issue was resolved by adding a lower-bound check in the omfs_fill_ [truncated]
A memory leak vulnerability was found in the Linux kernel's wifi: ath11k beacon template setup. The functions ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates but fail to free it when parameter setup returns an error. This can cause memory leaks if the setup fails. The affected product is the Linux kernel. The vulnerability class is a memory leak. [truncated]
A medium-severity vulnerability, CVE-2026-53103, was found in the Linux kernel. This issue could lead to a potential deadlock in the mt7925_roc_abort_sync function. The vulnerability arises from a deadlock between roc_abort_sync() and roc_work(). The roc_work() function holds the dev->mt76.mutex, while roc_abort_sync() waits for roc_work() to finish using cancel_work_sync(). If the caller already owns the [truncated]
A memory leak vulnerability was found in the Linux kernel, specifically in the mt76 module. The mt76_connac_mcu_alloc_sta_req() function allocates an skb, which is expected to be freed by mt76_mcu_skb_send_msg(). However, if an intermediate function fails before sending, the allocated skb is leaked. This can lead to a memory leak, which can be exploited by an attacker to cause a denial of service. Linux k [truncated]
A deadlock vulnerability was found in the Linux kernel's WiFi mt76 module. The mt76_remain_on_channel() and mt76_roc_complete() functions call mt76_set_channel() while holding dev->mutex, leading to a deadlock. This issue has been resolved by using __mt76_set_channel() instead of mt76_set_channel() and adding cancel_delayed_work_sync() for mac_work. The affected product is the Linux kernel, specifically v [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, with a CVSS score of 5.5. The vulnerability was resolved by switching CONFIG_CFI_CLANG to CONFIG_CFI. This change was made due to a rename in commit 23ef9d439769, making the code compiler-agnostic. The vulnerability affects users of the Linux kernel, particularly those using version 7.0. The issue was caused by the incorrect use of CONFIG_CFI_ [truncated]
A use-after-free vulnerability exists in the Linux kernel's mt7915_mac_dump_work() function. When the mt7915 pci chip is detaching, the mt7915_crash_data is released, but the work item dump_work may still be running or pending, leading to use-after-free bugs. This vulnerability could allow an attacker to cause a system crash or potentially elevate privileges. The vulnerability exists due to a race conditi [truncated]
The Linux kernel was found to have a use-after-free vulnerability in the mt7996_mac_dump_work() function. This issue arises when the mt7996 pci chip is detaching, and the mt7996_crash_data is released, but the work item dump_work may still be running or pending, leading to use-after-free bugs. The vulnerability can be fixed by ensuring dump_work is properly canceled before the crash_data is deallocated. T [truncated]
A Linux kernel vulnerability, CVE-2026-53095, was resolved by fixing the abuse of kprobe_write_ctx via freplace. This issue allowed uprobe programs to modify struct pt_regs, potentially leading to unintended behavior when kprobe attaches to kernel functions. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Linux kernel users and administrators should be aware of this vulnerability and e [truncated]
A vulnerability in the Linux kernel has been addressed, related to the handling of packet headers in the qdisc_pkt_len_segs_init function. This issue could potentially allow malicious packets to be detected and dropped earlier. The vulnerability affects Linux kernel developers and maintainers, network administrators, and security teams responsible for Linux-based systems. The Common Vulnerability Scoring [truncated]
CVE-2026-53090 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the bpf (Berkeley Packet Filter) subsystem, specifically in the handling of ld_{abs,ind} instructions in subprograms. The issue arises from the code generator in bpf_gen_ld_abs() having an abnormal exit path, which the verifier must simulate to ensure proper validation. This vulne [truncated]
A use-after-free vulnerability was found in the Linux kernel's BPF subsystem when filling offloaded map or program information. The issue arises from a race condition between obtaining the network namespace and its potential destruction. An attacker with local access could exploit this to cause a denial of service or potentially execute arbitrary code.
CVE-2026-53088 is a critical vulnerability in the Linux kernel's bcmgenet network driver. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. It was published on June 24, 2026, and last modified on June 28, 2026. The vulnerability is caused by an off-by-one error in the bcmgenet_put_txcb function, which can lead to incorrect cleanup of txcb. This vulnerability affects the Linux kernel [truncated]
CVE-2026-53087 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.5. The vulnerability is related to the bcmgenet network driver, where a tx queue reclaim issue leads to leaking free_bds. When reclaiming the tx queue, the write pointer is fast-forwarded to drop any data in flight, but these dropped frames are not added back to the pool of free bds. Additionally, the netdev is not [truncated]
CVE-2026-53085 is a high-severity vulnerability in the Linux kernel, allowing for a use-after-free attack. The vulnerability exists in the open-coded task_vma iterator, which reads task->mm locklessly and acquires mmap_read_trylock() but never calls mmget(). If the task exits concurrently, the mm_struct can be freed as it is not SLAB_TYPESAFE_BY_RCU, resulting in a use-after-free. Safely reading task->mm [truncated]
CVE-2026-53081 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to BPF (Berkeley Packet Filter) and specifically deals with the enforcement of regsafe base id consistency for BPF_ADD_CONST scalars. The issue arises when the verifier compares two scalar registers carrying BPF_ADD_CONST, allowing for the construction of verifier states that can lea [truncated]
A vulnerability in the Linux kernel's BPF sock_ops program can lead to out-of-bounds reads and kernel pointer leaks. The issue arises when accessing ctx fields with the same destination and source registers, causing the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros to fail to zero the destination register in certain paths. This can result in stale ctx pointers being retained, potentially leading to st [truncated]
CVE-2026-53077 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability restricts the use of RDS/IB to the initial network namespace, preventing its use in other network namespaces. The existing RDS/IB code will not work properly in non-initial network namespaces. This vulnerability was published on June 24, 2026, and last modified on June 28, 2026. The CVE record [truncated]
CVE-2026-53076 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 7.1. The vulnerability occurs when copying elements from a BPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the same value_size that is not rounded up to 8 bytes. This can happen when a CGROUP_STORAGE map is created with a value_size not aligned to 8 bytes, and a pcpu map is created with the same value_size. [truncated]
CVE-2026-53075 is a HIGH severity vulnerability in the Linux kernel's ppp (Point-to-Point Protocol) component. The vulnerability arises from the incorrect authorization of unattached administrative ioctls in the ppp device. Specifically, the /dev/ppp open operation is authorized against the user namespace of the file's credentials, while unattached administrative ioctls operate on the network namespace of [truncated]
A vulnerability was found in the Linux kernel. The bpf_prog_test_run_skb() function did not properly validate the length of IPv4 and IPv6 inputs, potentially leading to crashes or privilege escalation. The issue has been resolved by rejecting short IPv4/IPv6 inputs. This vulnerability affects Linux kernel versions 5.9 to 7.0.10 and has been assigned a CVSS score of 5.5. Users of affected kernel versions s [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, affecting Bluetooth. The vulnerability has been resolved with a patch. To address this issue, apply the provided patches or updates from the Linux kernel maintainers. This vulnerability could allow for a null pointer dereference if hci_register_dev() fails. The HCI_UART_PROTO_INIT flag is not cleared before calling hu->proto->close(hu) and set [truncated]