These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-53072 is a HIGH severity vulnerability in the Linux kernel's Bluetooth component. The vulnerability is caused by a locking issue in the hci_conn_request_evt() function when the HCI_PROTO_DEFER protocol is set. This can lead to a use-after-free (UAF) vulnerability if the connection is deleted concurrently. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The issue is reso [truncated]
CVE-2026-53070 is a HIGH severity vulnerability in the Linux kernel, affecting SCTP UDP transmission. The vulnerability arises from the improper handling of BH (bottom half) disabling in the udp_tunnel_xmit_skb() and udp_tunnel6_xmit_skb() functions. This can lead to incorrect recursion level detection, causing packets to be dropped in ip(6)_tunnel_xmit() or __dev_queue_xmit(). The issue was resolved by d [truncated]
CVE-2026-53068 is a HIGH severity vulnerability in the Linux kernel drm/komeda component. The vulnerability is caused by an integer overflow in the AFBC framebuffer size check, which can lead to out-of-bounds memory access. The vulnerability has a CVSS score of 7.1 and was published on 2026-06-24. The vulnerability was resolved by adding usage of check_add_overflow() to safely compute the minimum required [truncated]
A Linux kernel vulnerability was reported and resolved. The function drm_atomic_get_plane_state() can return an error pointer and was not checked for it. An error pointer check has been added. This vulnerability is categorized under CWE-476 and affects Linux kernel versions from 4.17 to 7.0.10. Users of these versions should apply patches to mitigate the vulnerability.
A MEDIUM severity vulnerability was found in the Linux kernel's ASoC sti component. The vulnerability is caused by regmap_field objects allocated at player init that are never freed, potentially leaking resources if the driver is removed. To address this issue, the code has been updated to use devm_regmap_field_alloc(), which automatically limits the lifetime of the allocations to the lifetime of the devi [truncated]
A null pointer dereference vulnerability was found in the Linux kernel's dm cache passthrough mode. When dm-cache starts to invalidate a cache entry and bio prison cell lock fails due to concurrent write to the same cached block, mg->cell remains NULL. The error path in invalidate_complete() attempts to unlock and free the cell unconditionally, causing a NULL pointer dereference. This vulnerability can be [truncated]
The Linux kernel has a vulnerability that causes a write hang in passthrough mode. The issue arises from the invalidate_remove() function, which has incomplete logic for handling write hit bios after cache invalidation. This results in write operations hanging. The fix involves adding a new invalidate_committed() continuation that submits remapped writes to the cache origin after metadata commit completes [truncated]
CVE-2026-53062 is a vulnerability in the Linux kernel's dm cache policy smq. The vulnerability occurs when the policy invalidate_mapping operation is called simultaneously from multiple workers in passthrough mode, leading to potential data races and use-after-free issues. To exploit this vulnerability, an attacker would need to create a cache device, populate the cache, reload the cache into passthrough [truncated]
A vulnerability was found in the Linux kernel's dm cache module. The vulnerability occurs when switching to passthrough mode, allowing dirty mappings to be loaded, which can result in data loss. This happens because the dirty mapping check for passthrough mode was performed during table creation, assuming that table reload occurs after suspension. However, LVM's table preload breaks this assumption, causi [truncated]
A memory leak vulnerability was found in the Linux kernel's dm cache metadata. When failing to acquire the root_lock in dm_cache_metadata_abort due to a read-only block_manager, a temporary block_manager created outside the root_lock is not properly released, causing a memory leak. This issue can be reproduced by reloading a new table while the metadata is read-only. The vulnerability can lead to memory e [truncated]
A Linux kernel vulnerability, CVE-2026-53056, was resolved by addressing a power-frequency mismatch issue in the drm/msm/dpu component. During DPU runtime suspend, a call to dev_pm_opp_set_rate(dev, 0) was dropping the MMCX rail to MIN_SVS while the core clock frequency remained at its original highest rate. Upon runtime resume, re-enabling the clock without adjusting the voltage led to a mismatch, potent [truncated]
CVE-2026-53053 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 8.8. The vulnerability is related to the iommu/amd module and has been resolved by fixing the clone_alias() function to use the original device's devid. The vulnerability was published on June 24, 2026, and last modified on June 28, 2026. The CVE record and NVD detail provide further information on this vulnerability.
A vulnerability was found in the Linux kernel's ASoC qcom qdsp6 topology. The vulnerability is caused by a lack of checking the widget type before accessing its private data. This could lead to incorrect memory access if the widget is virtual and not associated with a DSP graph, container, or module. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Users of the Linux kernel with ASoC qc [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the PCI: tegra194 component. The vulnerability occurs when PERST# is deasserted twice, causing a CBB timeout at DBI register offset 0x8bc. This happens because pci_epc_deinit_notify() and dw_pcie_ep_cleanup() are called before reset_control_deassert() powers on the controller core. The issue can be resolved by adjusting the cal [truncated]
A vulnerability in the Linux kernel has been resolved, specifically in the quota subsystem. The issue involves a race condition between dquot_scan_active() and quota deactivation in quota_release_workfn(). This race can lead to a situation where dquot_scan_active() works on a freed dquot under memory pressure. The problem is not only cosmetic but can cause the caller of dquot_scan_active() to work on a dq [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel's gfs2, which could lead to a NULL pointer dereference during unmount. This issue arises when flushing out outstanding glock work, and a check was missed in gfs2_log_release(). The vulnerability exists due to the gfs2_log_flush() and gfs2_log_release() functions not handling the deallocation of sdp->sd_jdesc properly, leading to potential syste [truncated]
A vulnerability was found in the Linux kernel's efi/capsule-loader, where an incorrect sizeof was used in phys array reallocation. This might cause an undersized allocation, potentially leading to a heap buffer overflow when storing physical addresses on 32-bit systems with PAE. The vulnerability affects Linux kernel versions 4.14.13 to 7.0.10, 4.15, and 6.12.91 or earlier. Linux kernel developers and mai [truncated]
CVE-2026-53045 is a critical vulnerability in the Linux kernel, with a CVSS score of 9.8. The vulnerability is related to the memory: tegra124-emc component and has been resolved by fixing the dll_change check. The code checking whether the specified memory timing enables DLL in the EMRS register was reversed. DLL is enabled if bit A0 is low. This vulnerability can be exploited remotely, and its exploitat [truncated]
CVE-2026-53044 is a high-severity vulnerability in the Linux kernel, specifically in the soc/tegra component. The vulnerability involves an incorrect ARRAY_SIZE usage in fabric lookup tables, which could cause out-of-bounds access during target timeout lookup. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.1, indicating a high severity. The vulnerability was published on [truncated]
CVE-2026-53043 is a critical vulnerability in the Linux kernel's DLM (Distributed Lock Manager) implementation. The vulnerability allows for out-of-bounds reads past the qr_regions buffer due to insufficient validation of the qr_numregions field in DLM_QUERY_REGION network messages. This can be exploited by crafting a message with qr_numregions exceeding O2NM_MAX_REGIONS (32 entries), leading to potential [truncated]
The Linux kernel has a vulnerability that has been resolved, related to fwctl class init ordering, which could lead to a NULL pointer dereference on device removal. This issue arises from CXL being linked before fwctl in drivers/Makefile, causing cxl_pci_driver_init() to run first. When cxl_pci_probe() calls fwctl_register() and then device_add(), fwctl_class is not yet registered, resulting in class_to_s [truncated]
CVE-2026-53040 is a use-after-free vulnerability in the Linux kernel's ocfs2 filesystem. The bug occurs when the OCFS2_IOC_INFO ioctl is issued with OCFS2_INFO_FL_NON_COHERENT, allowing a crafted filesystem to trigger an out-of-bounds bitmap walk. This vulnerability has been resolved by computing the bitmap capacity from the filesystem format and clamping the scan to the computed capacity.
A vulnerability in the Linux kernel's ocfs2 has been resolved. The OCFS2_IOC_GROUP_ADD ioctl can trigger a BUG_ON in ocfs2_set_new_buffer_uptodate() due to a lack of validation on user-controlled group block input before caching. This issue allows for potential system crashes or privilege escalation. The vulnerability exists because ocfs2_group_add() calls ocfs2_set_new_buffer_uptodate() on a user-control [truncated]
A Linux kernel vulnerability was found in the ima_fs component. The vulnerability occurs when the TPM algorithm is not supported, causing an out-of-bounds read in hash_algo_name. This happens because ima_tpm_chip->allocated_banks[i].crypto_id is initialized to HASH_ALGO__LAST for unsupported algorithms, which are then accessed by hash_algo_name[]. The issue was resolved by creating a file name with '_tpm_ [truncated]
A Linux kernel vulnerability was resolved in the HID component, specifically addressing a potential deadlock in hid_post_reset() when resetting a USB device with both HID and storage or UAS components. The fix applies GFP_NOIO to allocations in hid_pre_reset() and hid_post_reset() to prevent deadlocks. This vulnerability affects Linux kernel maintainers, Linux distribution vendors, and organizations using [truncated]
CVE-2026-53036 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to an off-by-one error in the check_imm signed range check for arm64 BPF JIT. This error allows for incorrect branch displacements, potentially leading to code execution. The vulnerability was published on June 24, 2026, and last modified on June 28, 2026. The CVE record and NVD deta [truncated]
A null pointer dereference vulnerability was found in the Linux kernel's af_unix and sockmap components. The vulnerability occurs when a socket's peer is not properly set up before its state is updated, allowing a BPF program to update the sockmap and cause a null pointer dereference. This issue arises from a race condition between the unix_stream_connect() function, which sets the socket's state to TCP_E [truncated]
A NULL dereference vulnerability was patched in the Linux kernel, specifically in the map_kptr_match_type function for scalar registers. The issue arose from refactoring in commit ab6c637ad027, which led to a NULL pointer being dereferenced when a scalar register stored in a kptr slot has no BTF. This vulnerability affects Linux kernel users and maintainers, who should ensure their systems are up-to-date [truncated]
A memory leak vulnerability was found in the Linux kernel's renesas_i3c_i3c_xfers() function. The xfer structure allocated by renesas_i3c_alloc_xfer() was never freed, leading to a memory leak. This issue has been resolved by using the __free(kfree) cleanup attribute to automatically free the memory when the variable goes out of scope. The vulnerability affects Linux kernel deployments and requires patchi [truncated]
A Linux kernel vulnerability, CVE-2026-53029, was resolved to address an uninit-value issue in ntfs_iomap_begin. The vulnerability was reported by syzbot and caused by a 0 value in clen, leading to *lcn being triggered before it was set. The fix involves moving the check for a 0 value in clen forward to before updating lcn. This vulnerability affects the Linux kernel's ntfs3 filesystem implementation and [truncated]