PatchSiren

Linux CVE debriefs · Page 84

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53028

A vulnerability was found in the Linux kernel's USB Type-C subsystem. The issue arises from a failure to properly handle error pointers, which could lead to a dereference of a possible ERR_PTR(). This vulnerability has been resolved with the addition of an early return and a fix for a spelling mistake in the error message. The vulnerability is located in the cd321x_update_work() function. The variable tps [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53025

CVE-2026-53025 is a high-severity use-after-free vulnerability in the Linux kernel's greybus: raw module. The bug occurs when a raw bundle is disconnected but its chardev remains open, leading to a use-after-free panic when the cdev is released. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. This issue was resolved by converting the struct device from a pointer to being embedde [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53023

The Linux kernel was vulnerable to an out-of-bounds read issue in the ntfs3 filesystem driver. The vulnerability was caused by a missing null terminator in the volume label after conversion from UTF-16 to UTF-8. This could allow local attackers to read beyond the end of the label buffer. The vulnerability was resolved by terminating the cached label explicitly after a successful conversion and clamping th [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53021

A vulnerability was found in the Linux kernel's scsi: target: core, which does not properly handle integer overflow in UNMAP bounds check. This could potentially allow attackers to bypass bounds checking. The CVE record was published on 2026-06-24T17:17:13.410Z. Users of Linux kernel should review and apply patches from official sources. The vulnerability affects Linux kernel users who should review compe [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53019

The Linux kernel vulnerability CVE-2026-53019 has been resolved. The vulnerability was caused by an inverted condition in the ccu_mix_trigger_fc() function, which could cause kernel panics during cpufreq scaling. This issue affected Linux kernel users and administrators, who should be aware of this vulnerability and take necessary actions to protect their systems. The vulnerability has been publicly discl [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53018

A Linux kernel vulnerability was resolved to avoid reading already updated pages during garbage collection in the f2fs file system. This issue occurs when a page is moved from one block address to another and then marked as uptodate, potentially leading to a VM_BUG_ON_FOLIO trigger. The fix prevents unnecessary I/O for already updated pages. This vulnerability impacts Linux kernel users and administrators [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53017

A vulnerability in the Linux kernel's f2fs filesystem can lead to data loss when fsync is performed on a newly created file concurrently with a checkpoint operation. This occurs because the f2fs_flush_nat_entries() function sets the IS_CHECKPOINTED and HAS_LAST_FSYNC flags for the nat_entry, but this does not guarantee that the checkpoint has completed successfully. The f2fs_need_inode_block_update() func [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53016

A PatchSiren debrief based on the Linux kernel CVE-2026-53016 source corpus. The Linux kernel vulnerability CVE-2026-53016 has been resolved, affecting the crypto: ccp - copy IV using skcipher ivsize. The issue arises from AF_ALG rfc3686-ctr-aes-ccp requests passing an 8-byte IV to the driver, while ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer, overrunning the provided buff [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53014

A vulnerability in the Linux kernel's net/sched: act_mirred has been resolved. The issue involves incorrect handling of the mac_header_xmit flag in tcf_blockcast_redir(), leading to potential skb header corruption and panic. This could impact network administrators and security teams responsible for Linux-based systems, particularly those using affected kernel versions. The vulnerability has been publicly [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53013

The Linux kernel vulnerability, CVE-2026-53013, relates to the macvlan component. A problem exists in the macvlan_get_size() function where it fails to account for the IFLA_MACVLAN_BC_CUTOFF attribute. This oversight can lead to an -EMSGSIZE error during network interface information dumping due to insufficient space in the netlink skb. The issue arises from the conditional inclusion of IFLA_MACVLAN_BC_CU [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53012

A vulnerability in the Linux kernel has been resolved. The issue involves the handling of IPv6 routes referencing IPv4 nexthops. When an IPv6 nexthop is replaced with an IPv4 nexthop, the has_v4 flag of all groups containing this nexthop is not updated, leading to a potential NULL pointer dereference. The fix involves calling nh_group_v4_update whenever the family changes, ensuring that the has_v4 flag is [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53011

CVE-2026-53011 is a HIGH severity vulnerability in the Linux kernel's net/sched taprio. The vulnerability was resolved in the Linux kernel and has a CVSS score of 7.8. The vulnerability occurs in the advance_sched() function when should_change_schedules() returns true, causing a use-after-free error. This error happens when switch_schedules() queues the old oper schedule for RCU freeing via call_rcu(), bu [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-53010

A use-after-free vulnerability was found in the Linux kernel's ksmbd implementation during durable reconnect in the smb2_open function. The vulnerability occurs when a file descriptor reference is dropped early, leading to potential use-after-free when accessing file properties. This issue can result in system crashes or potential code execution. Patches have been provided to resolve the issue. Linux kern [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53008

A race condition vulnerability was found in the Linux kernel's ice driver. The vulnerability occurs between the ice_free_tx_tstamp_ring() and ice_tx_map() functions, potentially leading to a NULL pointer dereference. This can happen when the ice_free_tx_tstamp_ring() function clears the ICE_TX_FLAGS_TXTIME flag after NULLing the tstamp_ring, allowing a concurrent ice_tx_map call on another CPU to derefere [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53007

A potential NULL pointer dereference issue was found in the Linux kernel's ice_set_ringparam function. The issue arises when the ICE_TX_RING_FLAGS_TXTIME bit is set and the subsequent ice_setup_tx_ring call fails, leading to a NULL pointer dereference in the unwinding sequence. This issue was identified through manual code review, and compile testing was performed. However, E830 devices were not available [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-53006

A use-after-free vulnerability was found in the Linux kernel's ipv6 implementation. The issue arises from the improper caching of source and destination addresses before a potential skb head change. This could lead to accessing freed memory, allowing for potential code execution or denial of service. The vulnerability is considered high severity and requires immediate attention from Linux kernel maintaine [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53005

A vulnerability in the Linux kernel has been resolved, related to the AF_UNIX and SOCKMAP components. The issue arises from SOCKMAP's ability to hide inflight file descriptors from AF_UNIX's garbage collector (GC), potentially leading to use-after-free and incorrect file descriptor counts. The Linux kernel patch addresses this by dropping all SCM attributes before passing skb to the SOCKMAP layer.

HIGH Linux CVE published 2026-06-24

CVE-2026-53004

A Linux kernel vulnerability was found in the SCTP implementation. The issue occurs in the sctp_getsockopt_peer_auth_chunks function, where an out-of-bounds write to userspace can happen. This happens because the function checks if the provided buffer is large enough for the peer's AUTH chunk list but does not account for the size of the struct sctp_authchunks header. An unprivileged userspace caller can [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53003

CVE-2026-53003 is a high-severity vulnerability in the Linux kernel that affects the PPPoE (Point-to-Point Protocol over Ethernet) implementation. The vulnerability is caused by the kernel's failure to properly handle Protocol Field Compression (PFC) frames, which can lead to a 4-byte misalignment of the network header and potentially trigger unaligned access exceptions on some architectures. To mitigate [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-53002

A critical vulnerability was resolved in the Linux kernel, addressing a stack-out-of-bounds write issue in the netfilter subsystem. The vulnerability, tracked as CVE-2026-53002, was caused by the use of sprintf, which has been replaced with scnprintf to prevent buffer overflow. This vulnerability affects various Linux kernel versions, including 2.6.20 to 7.0.10, and several Red Hat Enterprise Linux versions.

MEDIUM Linux CVE published 2026-06-24

CVE-2026-53001

A vulnerability in the Linux kernel has been resolved. The netfilter: xtables: restrict several matches to inet family is a partial revert of a previous commit to allow ipv4 and ipv6 only. This change affects the Linux kernel's netfilter functionality, specifically the xt_mac, xt_owner, and xt_physdev extensions, which are not used by ebtables in userspace. Additionally, xt_realm is only for ipv4, as dst- [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-53000

A vulnerability in the Linux kernel's netfilter NAT component has been addressed. The nf_nat_register_fn() function has been updated to handle partial exposure of hooks from error paths, which could be an issue for nfnetlink_hook. This change is related to the ability to dump active netfilter hooks from userspace, which was added in version 5.14. The update ensures that the nat hooks are properly deferred [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-52999

CVE-2026-52999 is a critical vulnerability in the Linux kernel's netfilter component. The vulnerability is caused by an out-of-bounds read on option matching in the nfnetlink_osf module. This flaw allows attackers to potentially read sensitive data from the kernel. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.1, indicating a critical severity level. The vulnerability wa [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52998

CVE-2026-52998 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.5. The vulnerability is related to a potential NULL dereference in the ttl check of the netfilter: nfnetlink_osf module. The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the device pointer was valid. This vulnerability has been resolved by removing the d [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52997

A vulnerability was found in the Linux kernel's sch_dualpi2. This vulnerability could lead to a NULL skb dereference during limit or memlimit enforcement. The issue arises when traffic classification results in packets being queued in the L-queue while the C-queue is empty. The vulnerability is related to the sch_dualpi2 qdisc, which did not correctly handle dequeuing packets when reducing backlog or memo [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52996

A Linux kernel vulnerability was resolved, involving a durable fd leak on ClientGUID mismatch in durable v2 open. The ksmbd_lookup_fd_cguid() function returns a ksmbd_file with its refcount incremented. However, in cases of ClientGUID mismatch, the reference obtained was not released, leading to resource leaks. The issue has been addressed by releasing the reference in the mismatch path and clearing dh_in [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52995

A local unprivileged user can exploit a vulnerability in the Linux kernel's RDS (Reliable Datagram Service) subsystem. The issue arises from the failure to zero a per-item info buffer before handing it to visitors, potentially leaking sensitive stack contents, including kernel text and data pointers, to user space. This can occur when a user opens an AF_RDS socket, sets SO_RDS_TRANSPORT=IB, binds to a loc [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-52993

CVE-2026-52993 is a critical vulnerability in the Linux kernel, specifically in the tipc_buf_append function. The vulnerability arises from the tipc_msg_validate function, which can reallocate the skb it is validating, potentially freeing the original skb. In the tipc_buf_append function, if the skb was reallocated and validation subsequently failed, the error handling path would free the original skb poi [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52992

A vulnerability in the Linux kernel has been resolved by adding validation for nzones in adfs_validate_bblk(). This change rejects ADFS disc records with a zero zone count during boot block validation, preventing an out-of-bounds write when nzones is 0. The vulnerability could lead to an out-of-bounds write when adfs_read_map() returns ZERO_SIZE_PTR, and adfs_map_layout() writes to dm[-1]. Linux kernel us [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52991

CVE-2026-52991 is a high-severity use-after-free vulnerability in the Linux kernel. The vulnerability exists in the pressure write and cgroup file release paths of the sched/psi subsystem. An attacker with local access and low privileges can exploit this vulnerability to achieve code execution or denial of service. The vulnerability was introduced due to a race condition between pressure write and cgroup [truncated]