PatchSiren

Linux CVE debriefs · Page 85

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52990

A Linux kernel vulnerability, CVE-2026-52990, was found in the fsnotify subsystem. The issue arises from a race condition between adding and removing fsnotify marks, leading to an inode reference leak. This leak can cause a hung task during umount operations. The vulnerability has been resolved by deferring the transition of the HAS_IREF flag from fsnotify_recalc_mask() to fsnotify_put_mark(). This change [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-52989

CVE-2026-52989 is a critical vulnerability in the Linux kernel, specifically affecting the nvmet-tcp component. The vulnerability has a CVSS score of 9.8, indicating a high severity level. The issue arises from the nvmet_tcp_build_pdu_iovec() function not properly propagating errors to its callers, which can lead to the misuse of uninitialized variables. This could allow an attacker to execute arbitrary c [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52987

A vulnerability in the Linux kernel has been resolved, involving a double drm_exec_fini() call in the userq validate path. The issue was found using a prototype static analysis tool and confirmed by code review. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The CVE record was published on 2026-06-24T17:17:09.517Z and last modified on 2026-06-28T08:16:28.030Z.

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52985

The Linux kernel was vulnerable to an uninit-value issue in the netdevsim component. This was caused by the use of skb_put instead of skb_put_zero, leading to uninitialized IP headers in dummy sk_buff. The issue was addressed by replacing skb_put with skb_put_zero to guarantee zero initialization of the whole IP header. This vulnerability could potentially allow an attacker to leak uninitialized data. Lin [truncated]

CRITICAL Linux CVE published 2026-06-24

CVE-2026-52982

CVE-2026-52982 is a use-after-free vulnerability in the Linux kernel's rtl8150_start_xmit() function. The vulnerability occurs when the URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev->tx_skb) on another CPU in softirq context before usb_submit_urb() returns in the submitter. This leads to a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52980

A yield-triggered crash can occur when a newly forked sched_entity enters the fair class with an unexpectedly set se->rel_deadline. The issue arises from __sched_fork() not clearing rel_deadline, leading to an abnormally large deadline and potential NULL dereference. This vulnerability affects Linux kernel deployments and requires prompt attention from maintainers and users.

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52979

A vulnerability was found in the Linux kernel's net: psp, which could allow an attacker to exploit the system. The issue arises from the psp_assoc_device_get_locked() function, which obtains a psp_dev reference and then acquires a lock. However, before the lock is taken, the psp_dev_unregister() function can run to completion, potentially causing issues. This vulnerability has been resolved by adding a ch [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52977

A Linux kernel vulnerability, CVE-2026-52977, was resolved to address a potential lockup condition in the requeue-PI mechanism during signal or timeout wakeup. This issue arises from a race condition between two tasks, A and B, where task A is waiting for requeue-PI and task B is performing requeue-PI. The vulnerability could lead to a system live lock, particularly problematic on UP systems where task A [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52976

CVE-2026-52976 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability exists in the drm/xe component and involves two error handling issues in the xe_exec_queue_create_ioctl() function. An attacker with local access could potentially exploit this vulnerability to gain elevated privileges. The vulnerability was resolved by fixing error cleanup in the xe_exec_queue [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52974

A vulnerability in the Linux kernel has been resolved, involving a memory leak in the TLS (Transport Layer Security) subsystem. Specifically, when the `tls_set_device_offload_rx()` function fails during the setup of offload RX, it leads to a memory leak of the anchor skb (socket buffer) allocated by `alloc_skb(0)` in `tls_strp_init()`. This issue was introduced by a commit that changed how the strparser i [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52973

CVE-2026-52973 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the futex subsystem and has been resolved by loosening the check for private default hash allocation. The vulnerability allows for a slab-use-after-free attack, potentially leading to privilege escalation. The Linux kernel maintainers have addressed this issue by modifying the nee [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52971

CVE-2026-52971 is a high-severity use-after-free vulnerability in the Linux kernel, specifically affecting the ena network driver. The vulnerability arises from a race condition between the get_timestamp and ena_com_phc_destroy functions, which can lead to a use-after-free error. This error occurs when the ena_com_phc_destroy function frees the DMA memory while the get_timestamp function is still using it [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52970

A Linux kernel vulnerability, CVE-2026-52970, was resolved by a commit addressing a missing expect put in object evaluation for netfilter. This fix prevents potential issues with netfilter object evaluation. Linux kernel users and administrators should assess and apply the patch to prevent exploitation. The vulnerability involves a fix for a missing expect put in object evaluation for netfilter, specifica [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52969

CVE-2026-52969 is a high-severity vulnerability in the Linux kernel's KVM subsystem. A u64 wrap issue allows for out-of-bounds memory access, enabling local, unprivileged attackers to potentially escalate privileges or crash the system. The vulnerability arises from inadequate validation of the 'offset' variable in the kvm_reset_dirty_gfn() function. An attacker can exploit this by crafting specific entri [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52968

A vulnerability was found in the Linux kernel's KVM: s390: pci subsystem. The flaw in GAIT table indexing due to double-scaling pointer arithmetic can cause out-of-bounds accesses when aisb >= 32. This issue affects Linux kernel users, particularly those with KVM: s390: pci deployments. The vulnerability was resolved by removing the erroneous sizeof multiplication. To mitigate the risk, users should revie [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52967

CVE-2026-52967 is a high-severity vulnerability in the Linux kernel, with a CVSS score of 8.1. The vulnerability is related to the smb/client component and could potentially lead to an infinite loop and out-of-bounds read on 32-bit architectures. The issue arises from incorrect handling of ErrorDataLength and ErrorContextData in the symlink_data() function. Successful exploitation of this vulnerability co [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52966

A vulnerability was found in the Linux kernel. The drm: Replace old pointer to new idr commit introduced a logical error by failing to replace the newly generated IDR pointer to old id's pointer at the correct location within the 'change handle' logic. This issue can lead to problems with the 'change handle' logic and potentially allow for denial of service or other malicious activities. Users of the Linu [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52965

The Linux kernel was vulnerable to an infinite LRU walk on swapout failure in the drm/ttm module. This issue has been resolved by deferring del_bulk_move to the success path only. The vulnerability affected the Linux kernel's drm/ttm module, allowing for potential denial of service or privilege escalation. Linux kernel users and administrators should be aware of this vulnerability and take recommended act [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52964

A vulnerability was found in the Linux kernel's USB MIDI 2.0 endpoint parser. The parser does not properly validate the length of the endpoint descriptor, which can lead to a buffer overflow. This vulnerability has been resolved by adding bounds checking to the parser. The vulnerability affects the Linux kernel and has been assigned a CVE. Users of the Linux kernel should be aware of this vulnerability an [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52963

A vulnerability was found in the Linux kernel's ALSA usb-audio module. The snd_usbmidi_get_ms_info() function did not properly validate the size of the MIDIStreaming endpoint descriptor, potentially leading to a buffer overflow. This vulnerability has been resolved with a patch that bounds MIDI endpoint descriptor scans. The vulnerability affects Linux kernel developers and maintainers, Linux distribution [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52961

A Linux kernel vulnerability was resolved, addressing a BUG_ON in __ceph_build_xattrs_blob() caused by a race condition introduced when moving required_blob_size computation. The issue could lead to a kernel crash. This CVE has a CVSS score of 5.5 and is considered MEDIUM severity. The vulnerability affects Linux kernel developers and administrators responsible for maintaining and securing Linux systems. [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52960

A vulnerability was found in the Linux kernel, specifically in the ceph module. The issue involves the improper handling of folios not suitable for writeback, leading to a reference count leak. The batch holds references to the folios, so it is necessary to put the folios that are removed. This vulnerability has been resolved in the Linux kernel. The Common Vulnerability Scoring System (CVSS) score for th [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52959

CVE-2026-52959 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The issue is in the virt: sev-guest component, where a buffer size is controlled by the host, potentially leading to page allocator corruption. The vulnerability was introduced and resolved in the Linux kernel. The CVE was published on 2026-06-24T17:17:06.157Z and last modified on 2026-06-28T08:16:26.690Z.

HIGH Linux CVE published 2026-06-24

CVE-2026-52957

CVE-2026-52957 is a high-severity vulnerability in the Linux kernel's libceph component. The vulnerability occurs in the decode_choose_args() function, where a null-pointer dereference can happen when decoding CRUSH maps. This can be triggered by a potentially corrupted message containing a crush_choose_arg_map with an invalid bucket index. The issue is caused by insufficient checks on the bucket index, w [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52956

CVE-2026-52956 is a high-severity vulnerability in the Linux kernel's libceph component. The vulnerability is caused by a potential out-of-bounds memory access in the __ceph_x_decrypt() function. This function interprets a part of the buffer as a ceph_x_encrypt_header and accesses its magic field without ensuring the buffer is large enough to hold this struct. The vulnerability can be triggered by a messa [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52951

CVE-2026-52951 is a high-severity Use-After-Free vulnerability in the Linux kernel's drm/xe/dma-buf component. The vulnerability arises from improper handling of empty buffer objects and Use-After-Free (UAF) races when triggering the invalidate_mappings hook. Attackers could potentially exploit this vulnerability to cause system crashes or execute arbitrary code. The issue was resolved by moving the attac [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52950

CVE-2026-52950 is a high-severity vulnerability in the Linux kernel, specifically affecting the drm/xe/dma-buf component. This use-after-free vulnerability has been resolved by combining the allocation and initialization of a buffer as one unit, making retries safe. The vulnerability was reported by Sashiko and has been addressed in the kernel's stable branch. The Common Vulnerability Scoring System (CVSS [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52949

A vulnerability was found in the Linux kernel, specifically in the drm/ttm module. The issue is related to an infinite LRU walk on backup failure in the ttm_bo_shrink() path. A fix has been applied, similar to the one used in ttm_bo_swapout(). The del_bulk_move operation is now moved from before the backup to after success only, using ttm_resource_del_bulk_move_unevictable(). This change prevents the infi [truncated]

MEDIUM Linux CVE published 2026-06-24

CVE-2026-52948

CVE-2026-52948 is a vulnerability in the Linux kernel's I2C_TIMEOUT ioctl, which can cause a local Denial of Service (DoS). The ioctl accepts a user-provided timeout in multiples of 10 ms, but fails to properly check for integer overflow. A malicious user can pass a large value that overflows when multiplied by 10, resulting in a truncated 32-bit unsigned value. This value is then assigned to the SMBus co [truncated]

HIGH Linux CVE published 2026-06-24

CVE-2026-52947

CVE-2026-52947 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to a refcount saturation and potential Use-After-Free (UAF) in the qrtr_port_remove function. This could allow a local attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability was introduced due to a race condition in the qrtr_port_remove functio [truncated]