These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-52946 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.5. The vulnerability involves a SOFTIRQ-unsafe lock order in fasync signaling, which can cause a deadlock when a process group receives a signal. The issue arises from the rwlock writer fairness mechanism, where a process holding a read lock in do_wait() can be interrupted by a softirq, leading to a deadlock. The f [truncated]
CVE-2026-52945 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 7.5. The vulnerability was introduced by a commit that enabled threaded NAPI by default, which caused a rare but critical issue with WireGuard encryption. The issue occurs when the decryption side stops working completely for a specific WireGuard peer under heavy networking load, while other peers remain unaffected. [truncated]
A vulnerability in the Linux kernel's ksmbd module allows clients to bypass file system control (FSCTL) permissions, potentially enabling unauthorized modification of file attributes on shared filesystems. This issue arises from the lack of proper permission checks for the FSCTL_SET_SPARSE operation, affecting Linux kernel versions 5.15 through 7.0.12. Linux administrators and users with shared filesystem [truncated]
CVE-2026-52942 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.1. The vulnerability is related to the netfilter component, specifically in the nf_log_syslog.c file. The issue arises from the dump_mac_header function, which does not properly validate the MAC header before dumping it, leading to an out-of-bounds read. This vulnerability can be exploited via the netdev logger, sp [truncated]
The Linux kernel was found to have a vulnerability that could lead to a NULL pointer dereference in the smc_msg_event tracepoint. This issue arises when the tracepoint is enabled and an SMC-D socket is used, causing the first sendmsg()/recvmsg() call to crash. The vulnerability has been resolved by logging an empty device name for SMC-D instead of dereferencing NULL. The CVE record was published on 2026-0 [truncated]
A vulnerability was found in the Linux kernel's tun_put_user() function, which did not zero the whole vnet header, leading to a potential information leak of 14 bytes of kernel stack on every read of a non-tunnel packet. The vulnerability has been resolved by zeroing the whole vnet header in tun_put_user(). Linux kernel users and administrators should be aware of this vulnerability and take steps to mitig [truncated]
A vulnerability in the Linux kernel's RDS/IB (Remote Direct Memory Access over InfiniBand) implementation could allow an unprivileged user to trigger a NULL pointer dereference. The issue arises from the handling of masked atomic completions in the rds_ib_send_cqe_handler() function. When a masked atomic opcode is used, the function does not properly handle it, leading to a NULL pointer dereference. This [truncated]
A vulnerability was found in the Linux kernel, specifically related to a NULL pointer dereference in bpf_sk_storage_clone and diag paths. The issue arises when bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NULL before removing the selem from the storage hlist. A concurrent RCU reader in bpf_sk_storage_clone() can observe the selem still on the list with smap already NULL, causing a NULL pointer der [truncated]
A Linux kernel vulnerability, CVE-2026-52937, was found in the tap_ioctl() function when handling SIOCGIFHWADDR requests. The function copies 16 bytes of an uninitialized on-stack struct sockaddr_storage to userspace, leaking 8 bytes of kernel stack contents. This could potentially defeat KASLR by exposing kernel .text and direct-map pointers. The vulnerability was resolved by initializing the struct sock [truncated]
The Linux kernel was vulnerable to a crypto: jitterentropy issue, which could cause performance issues due to a long-held spinlock. The problem was resolved by replacing the spinlock with a mutex. This change allows contended readers to sleep instead of spinning on a shared lock held across expensive entropy generation. Users of the Linux kernel should review their configurations to ensure they are not ex [truncated]
CVE-2026-52933 is a HIGH-severity vulnerability in the Linux kernel's io_uring/poll feature. A signed comparison issue in io_poll_get_ownership() could allow an attacker to trigger the slowpath. This vulnerability has been resolved by casting the atomic_read() result to unsigned int before the comparison. The Common Vulnerability Scoring System (CVSS) scored this vulnerability 7.8, indicating a HIGH sever [truncated]
A vulnerability in the Linux kernel has been resolved, which relates to the xfrm: ipcomp component. The issue involves freeing destination pages on acomp errors. The problem was addressed by moving the out_free_req label up by a couple of lines to ensure that the allocated dst SG list gets freed on error as well as success. This change aims to prevent potential memory leaks and ensure the proper handling [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-24T08:16:23.157Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects the Linux kernel, specifically the IPC subsystem, and relates to a use-after-free flaw. The vulnerability arises from the lack of proper synchronization between shm_destroy [truncated]
CVE-2026-52929 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.5. The vulnerability was resolved by fully rolling back denied add-stream state in the SCTP stream. When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt, leaving removed stream metadata behind. This can cause a null-pointer dereference in the scheduler get path when a later re- [truncated]
CVE-2026-52927 is a HIGH severity vulnerability in the Linux kernel's netfilter ebtables. The vulnerability is caused by an out-of-bounds read in the compat_mtw_from_user function, which converts ebtables extensions from 32-bit user structures to kernel native structures. The function lacks proper validation of the user-supplied match_size/target_size, leading to an out-of-bounds read as reported by KASAN [truncated]
The Linux kernel was vulnerable to a batman-adv issue where the current gateway was not cleared during mesh teardown, potentially leaving stale gateway state. This issue has been resolved. The vulnerability affected the batman-adv component of the Linux kernel, which is used for managing mesh networks. The issue could lead to problems if the mesh is recreated later. Users of Linux kernel batman-adv functi [truncated]
A potential null pointer dereference vulnerability has been identified in the Linux kernel when removing a port from a VRF. The vulnerability arises from a lack of RCU synchronization, which can cause an RCU reader to see a new master device without l3mdev operations, leading to a null pointer dereference. This vulnerability affects Linux kernel users and administrators, who should be aware of the potenti [truncated]
A use-after-free vulnerability exists in the Linux kernel's SCTP implementation. When handling a Stale Cookie ERROR, the association is rolled back from COOKIE_ECHOED to COOKIE_WAIT, but the outbound stream scheduler state is not properly invalidated. This can lead to crashes and potential code execution. The vulnerability affects Linux kernel developers, Linux distribution maintainers, and users of Linux [truncated]
CVE-2026-52923 is a HIGH-severity vulnerability in the Linux kernel, with a CVSS score of 7.8. The bug, located in the ipc_idr_alloc() function in the checkpoint/restore path, allows an attacker to allocate an SysV IPC id beyond the valid range, leading to potential memory corruption and crashes. The vulnerability was introduced due to an open-ended upper bound in idr_alloc(). The fix bounds the requested [truncated]
CVE-2026-52922 is a high-severity vulnerability in the Linux kernel's batman-adv module. The vulnerability occurs in the batadv_dat_forward_data() function, which calls pskb_copy_for_clone() to duplicate an skb for each DHT candidate. However, it does not check the return value before passing it to batadv_send_skb_prepare_unicast_4addr(). This can lead to a NULL pointer dereference when the allocation fai [truncated]
A vulnerability has been resolved in the Linux kernel related to netfilter: ipset. The hash set variants hash:ip,mark, hash:ip,port, hash:ip,port,ip, and hash:ip,port,net iterate IPv4 ranges with a 32-bit iterator. The iterator must stop once the last address in the requested range has been processed to prevent traversal from continuing past the original boundary. This vulnerability can lead to unintended [truncated]
CVE-2026-52920 is a HIGH severity vulnerability in the Linux kernel, with a CVSS score of 8.3. The vulnerability has been resolved and affects the netfilter: xt_policy module. The issue is related to strict mode inbound policy matching. The vulnerability was published on 2026-06-24T08:16:21.950Z and modified on 2026-06-28T08:16:23.683Z. The CVE record and NVD detail are available for further information.
CVE-2026-52919 is a HIGH severity vulnerability in the Linux kernel's batman-adv module. The vulnerability is caused by a tp_meter counter underflow during shutdown, which can lead to a use-after-free when the interface is removed while the zombie thread is still active. The issue arises from the batadv_tp_sender_shutdown() function unconditionally decrementing the 'sending' atomic counter, allowing it to [truncated]
CVE-2026-52918 is a HIGH severity vulnerability in the Linux kernel's Bluetooth component. The vulnerability allows for unsynchronized access to the accept queue, which can lead to a use-after-free condition. This can be exploited by an attacker to potentially execute arbitrary code or cause a denial of service. The vulnerability has been resolved by adding a dedicated lock for queue updates and polling. [truncated]
CVE-2026-52917 is a HIGH-severity vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation. The vulnerability occurs in the diag (diagnostic) component, specifically in the dump_one path, where stale associations can be incorrectly reported. This happens when the exact sock_diag lookup holds a transport reference, blocks on lock_sock(sk), and then resumes after the as [truncated]
A vulnerability in the Linux kernel's batman-adv module allows for stack exhaustion through crafted BATADV_UNICAST_FRAG packets. The issue arises from the recursive processing of defragmented payloads without proper bounds checking, enabling malicious senders to cause a denial of service. This vulnerability affects Linux kernel users who utilize batman-adv and requires patches to mitigate potential denial [truncated]
CVE-2026-52909 is a Linux kernel vulnerability affecting the ip6_vti (IPv6 Virtual Tunnel Interface) implementation. The issue arises because the netns_immutable flag is not set on the per-netns fallback tunnel device (ip6_vti0). This flag is crucial as it prevents the device from being moved to another network namespace, which could lead to unintended exposure or manipulation. The vulnerability was repor [truncated]
CVE-2026-52908 is a Linux kernel vulnerability affecting the RDMA subsystem. The issue arises during the reregistration of Memory Regions (MRs) and involves ensuring compatibility with REREG_ACCESS. If the IB_MR_REREG_ACCESS changes from Read-Only (RO) to Read-Write (RW), the umem (user memory) must be re-evaluated to ensure it is properly pinned as RW. This requires adding a function, ib_umem_check_rereg [truncated]
A vulnerability was found in the Linux kernel, specifically in the net/sched component. The issue is related to the pedit partial COW leading to page cache corruption. The tcf_pedit_act() function computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint. However, the hint does not account for the runtime header offset added by typed keys, which can leave part of th [truncated]
CVE-2026-43494 is a Linux kernel networking bug in the RDS zero-copy send path. If page pinning fails during rds_message_zcopy_from_user(), the code releases the pinned pages and clears one notifier field, but leaves op_nents set. A later cleanup path in rds_message_purge() can then iterate over that stale count and free the pages again, creating a double-free condition in kernel cleanup logic.