// kernel tracker

Linux 6.12.92

LTS // updated 2026-07-14
running
6.12.92
open CVEs
144
next fix
6.12.93
11 CVEs
fix versions
3
6.12.93, 6.12.94, 6.12.95
CVEs — Linux 6.12.92
CVE Fixed In Score Description Links
CVE-2026-53247 6.12.94 9.8 Critical net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown ↗ CVE ⌥ commit
CVE-2026-53228 6.12.94 9.8 Critical ipv6: sit: reload inner IPv6 header after GSO offloads ↗ CVE ⌥ commit
CVE-2026-53225 6.12.94 9.1 Critical sctp: fix uninit-value in __sctp_rcv_asconf_lookup() ↗ CVE ⌥ commit
CVE-2026-53221 6.12.94 9.8 Critical ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() ↗ CVE ⌥ commit
CVE-2026-53216 6.12.94 9.8 Critical net: mvpp2: limit XDP frame size to the RX buffer ↗ CVE ⌥ commit
CVE-2026-53215 6.12.94 9.8 Critical net: mvpp2: refill RX buffers before XDP or skb use ↗ CVE ⌥ commit
CVE-2026-53186 6.12.94 9.1 Critical RDMA/srp: bound SRP_RSP sense copy by the received length ↗ CVE ⌥ commit
CVE-2026-53176 6.12.94 9.8 Critical IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN ↗ CVE ⌥ commit
CVE-2026-53175 6.12.94 9.8 Critical inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush ↗ CVE ⌥ commit
CVE-2026-53131 6.12.94 9.4 Critical netfilter: require Ethernet MAC header before using eth_hdr() ↗ CVE ⌥ commit
CVE-2026-52924 6.12.94 9.8 Critical sctp: purge outqueue on stale COOKIE-ECHO handling ↗ CVE ⌥ commit
CVE-2026-46316 6.12.93 9.3 Critical KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry ↗ CVE ⌥ commit
CVE-2026-53275 6.12.94 8.8 High ipv6: mcast: Fix use-after-free when processing MLD queries ↗ CVE ⌥ commit
CVE-2026-53273 6.12.94 7.8 High tee: optee: prevent use-after-free when the client exits before the supplicant ↗ CVE ⌥ commit
CVE-2026-53270 6.12.94 7.8 High ipvs: clear the svc scheduler ptr early on edit ↗ CVE ⌥ commit
CVE-2026-53268 6.12.94 8.2 High netfilter: conntrack_irc: fix possible out-of-bounds read ↗ CVE ⌥ commit
CVE-2026-53267 6.12.94 7.8 High netfilter: nft_ct: bail out on template ct in get eval ↗ CVE ⌥ commit
CVE-2026-53266 6.12.94 8.8 High netfilter: bridge: make ebt_snat ARP rewrite writable ↗ CVE ⌥ commit
CVE-2026-53265 6.12.94 7.8 High dm cache policy smq: check allocation under invalidate lock ↗ CVE ⌥ commit
CVE-2026-53264 6.12.94 7.8 High net/sched: act_api: use RCU with deferred freeing for action lifecycle ↗ CVE ⌥ commit
CVE-2026-53262 6.12.94 7.8 High l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() ↗ CVE ⌥ commit
CVE-2026-53256 6.12.94 8.0 High Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() ↗ CVE ⌥ commit
CVE-2026-53254 6.12.94 8.1 High Bluetooth: RFCOMM: validate skb length in MCC handlers ↗ CVE ⌥ commit
CVE-2026-53253 6.12.94 7.1 High Bluetooth: bnep: reject short frames before parsing ↗ CVE ⌥ commit
CVE-2026-53242 6.12.94 7.8 High ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams ↗ CVE ⌥ commit
CVE-2026-53239 6.12.94 7.8 High xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() ↗ CVE ⌥ commit
CVE-2026-53235 6.12.94 7.5 High net: add pskb_may_pull() to skb_gro_receive_list() ↗ CVE ⌥ commit
CVE-2026-53230 6.12.94 8.7 High net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list ↗ CVE ⌥ commit
CVE-2026-53229 6.12.94 7.5 High net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure ↗ CVE ⌥ commit
CVE-2026-53223 6.12.94 7.1 High net: guard timestamp cmsgs to real error queue skbs ↗ CVE ⌥ commit
CVE-2026-53217 6.12.94 8.6 High net: mvpp2: sync RX data at the hardware packet offset ↗ CVE ⌥ commit
CVE-2026-53212 6.12.94 7.8 High netfilter: nft_tunnel: fix use-after-free on object destroy ↗ CVE ⌥ commit
CVE-2026-53209 6.12.94 7.8 High Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend ↗ CVE ⌥ commit
CVE-2026-53205 6.12.94 7.1 High accel/ivpu: Add bounds checks for firmware log indices ↗ CVE ⌥ commit
CVE-2026-53203 6.12.94 7.1 High accel/ivpu: Add buffer overflow check in MS get_info_ioctl ↗ CVE ⌥ commit
CVE-2026-53202 6.12.94 7.8 High accel/ivpu: Fix signed integer truncation in IPC receive ↗ CVE ⌥ commit
CVE-2026-53199 6.12.94 7.5 High hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf ↗ CVE ⌥ commit
CVE-2026-53198 6.12.94 8.8 High ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL ↗ CVE ⌥ commit
CVE-2026-53194 6.12.94 7.8 High USB: serial: kl5kusb105: fix bulk-out buffer overflow ↗ CVE ⌥ commit
CVE-2026-53193 6.12.94 7.8 High ALSA: timer: Forcibly close timer instances at closing ↗ CVE ⌥ commit
CVE-2026-53192 6.12.94 7.8 High ALSA: timer: Fix UAF at snd_timer_user_params() ↗ CVE ⌥ commit
CVE-2026-53191 6.12.94 7.8 High io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries ↗ CVE ⌥ commit
CVE-2026-53189 6.12.94 7.8 High mm/huge_memory: update file PMD counter before folio_put() ↗ CVE ⌥ commit
CVE-2026-53185 6.12.94 7.8 High zram: fix use-after-free in zram_bvec_write_partial() ↗ CVE ⌥ commit
CVE-2026-53184 6.12.94 7.5 High udp: clear skb->dev before running a sockmap verdict ↗ CVE ⌥ commit
CVE-2026-53183 6.12.94 7.5 High mptcp: allow subflow rcv wnd to shrink ↗ CVE ⌥ commit
CVE-2026-53182 6.12.94 7.8 High wifi: nl80211: reject oversized EMA RNR lists ↗ CVE ⌥ commit
CVE-2026-53180 6.12.94 7.5 High timers/migration: Fix livelock in tmigr_handle_remote_up() ↗ CVE ⌥ commit
CVE-2026-53161 6.12.94 7.8 High misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context ↗ CVE ⌥ commit
CVE-2026-53160 6.12.94 7.8 High misc: fastrpc: fix use-after-free race in fastrpc_map_create ↗ CVE ⌥ commit
CVE-2026-53147 6.12.94 8.1 High thunderbolt: Validate XDomain request packet size before type cast ↗ CVE ⌥ commit
CVE-2026-53146 6.12.94 7.1 High thunderbolt: Limit XDomain response copy to actual frame size ↗ CVE ⌥ commit
CVE-2026-53133 6.12.94 7.8 High RDMA/umem: Fix truncation for block sizes >= 4G ↗ CVE ⌥ commit
CVE-2026-53132 6.12.94 7.1 High vsock/virtio: fix potential unbounded skb queue ↗ CVE ⌥ commit
CVE-2026-52947 6.12.94 7.8 High net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove ↗ CVE ⌥ commit
CVE-2026-52946 6.12.94 7.5 High fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling ↗ CVE ⌥ commit
CVE-2026-52942 6.12.94 7.1 High netfilter: nf_log: validate MAC header was set before dumping it ↗ CVE ⌥ commit
CVE-2026-52935 6.12.94 7.8 High xfrm: espintcp: do not reuse an in-progress partial send ↗ CVE ⌥ commit
CVE-2026-52929 6.12.94 7.5 High sctp: stream: fully roll back denied add-stream state ↗ CVE ⌥ commit
CVE-2026-52917 6.12.94 7.1 High sctp: diag: reject stale associations in dump_one path ↗ CVE ⌥ commit
CVE-2026-52910 6.12.94 7.8 High bpf: Free reuseport cBPF prog after RCU grace period. ↗ CVE ⌥ commit
CVE-2026-52908 6.12.94 7.8 High RDMA: During rereg_mr ensure that REREG_ACCESS is compatible ↗ CVE ⌥ commit
CVE-2026-52943 6.12.93 7.8 High net: skbuff: fix missing zerocopy reference in pskb_carve helpers ↗ CVE ⌥ commit
CVE-2026-52934 6.12.93 8.8 High batman-adv: tvlv: reject oversized TVLV packets ↗ CVE ⌥ commit
CVE-2026-52927 6.12.93 7.8 High netfilter: ebtables: fix OOB read in compat_mtw_from_user ↗ CVE ⌥ commit
CVE-2026-52923 6.12.93 7.8 High ipc: limit next_id allocation to the valid ID range ↗ CVE ⌥ commit
CVE-2026-46322 6.12.93 7.1 High tun: free page on build_skb failure in tun_xdp_one() ↗ CVE ⌥ commit
CVE-2026-46321 6.12.93 7.1 High tun: free page on short-frame rejection in tun_xdp_one() ↗ CVE ⌥ commit
CVE-2026-53362 6.12.95 ipv6: account for fraggap on the paged allocation path ↗ CVE ⌥ commit
CVE-2026-53361 6.12.95 af_unix: Set gc_in_progress to true in unix_gc(). ↗ CVE ⌥ commit
CVE-2026-53359 6.12.95 KVM: x86: Fix shadow paging use-after-free due to unexpected role ↗ CVE ⌥ commit
CVE-2026-53356 6.12.94 drm/i915/gem: Fix phys BO pread/pwrite with offset ↗ CVE ⌥ commit
CVE-2026-53355 6.12.94 net: rds: clear i_sends on setup unwind ↗ CVE ⌥ commit
CVE-2026-53354 6.12.94 arm64: errata: Mitigate TLBI errata on various Arm CPUs ↗ CVE ⌥ commit
CVE-2026-53353 6.12.94 hsr: Remove WARN_ONCE() in hsr_addr_is_self(). ↗ CVE ⌥ commit
CVE-2026-53352 6.12.94 signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() ↗ CVE ⌥ commit
CVE-2026-53350 6.12.94 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls ↗ CVE ⌥ commit
CVE-2026-53349 6.12.94 netfilter: nf_conntrack: destroy stale expectfn expectations on unregister ↗ CVE ⌥ commit
CVE-2026-53347 6.12.94 drm/virtio: Fix driver removal with disabled KMS ↗ CVE ⌥ commit
CVE-2026-53346 6.12.94 rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES ↗ CVE ⌥ commit
CVE-2026-53345 6.12.94 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying ↗ CVE ⌥ commit
CVE-2026-53343 6.12.94 ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow ↗ CVE ⌥ commit
CVE-2026-53339 6.12.94 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() ↗ CVE ⌥ commit
CVE-2026-53337 6.12.94 net: bonding: fix NULL pointer dereference in bond_do_ioctl() ↗ CVE ⌥ commit
CVE-2026-53336 6.12.94 nvmem: layouts: onie-tlv: fix hang on unknown types ↗ CVE ⌥ commit
CVE-2026-53332 6.12.94 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd ↗ CVE ⌥ commit
CVE-2026-53331 6.12.94 slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock ↗ CVE ⌥ commit
CVE-2026-53329 6.12.94 drm/amd/display: Use krealloc_array() in dal_vector_reserve() ↗ CVE ⌥ commit
CVE-2026-53328 6.12.94 sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() ↗ CVE ⌥ commit
CVE-2026-53274 6.12.94 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS ↗ CVE ⌥ commit
CVE-2026-53272 6.12.94 erofs: fix use-after-free on sbi->sync_decompress ↗ CVE ⌥ commit
CVE-2026-53271 6.12.94 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers ↗ CVE ⌥ commit
CVE-2026-53269 6.12.94 netfilter: synproxy: add mutex to guard hook reference counting ↗ CVE ⌥ commit
CVE-2026-53263 6.12.94 6lowpan: fix off-by-one in multicast context address compression ↗ CVE ⌥ commit
CVE-2026-53261 6.12.94 devlink: Release nested relation on devlink free ↗ CVE ⌥ commit
CVE-2026-53255 6.12.94 Bluetooth: MGMT: validate advertising TLV before type checks ↗ CVE ⌥ commit
CVE-2026-53252 6.12.94 Bluetooth: fix memory leak in error path of hci_alloc_dev() ↗ CVE ⌥ commit
CVE-2026-53251 6.12.94 Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync ↗ CVE ⌥ commit
CVE-2026-53249 6.12.94 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options ↗ CVE ⌥ commit
CVE-2026-53245 6.12.94 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr ↗ CVE ⌥ commit
CVE-2026-53241 6.12.94 ALSA: seq: dummy: fix UMP event stack overread ↗ CVE ⌥ commit
CVE-2026-53238 6.12.94 netlabel: validate unlabeled address and mask attribute lengths ↗ CVE ⌥ commit
CVE-2026-53237 6.12.94 gpio: mvebu: fix NULL pointer dereference in suspend/resume ↗ CVE ⌥ commit
CVE-2026-53236 6.12.94 tcp: restrict SO_ATTACH_FILTER to priv users ↗ CVE ⌥ commit
CVE-2026-53234 6.12.94 net: ibm: emac: Fix use-after-free during device removal ↗ CVE ⌥ commit
CVE-2026-53233 6.12.94 netdev: fix double-free in netdev_nl_bind_rx_doit() ↗ CVE ⌥ commit
CVE-2026-53227 6.12.94 net: openvswitch: fix possible kfree_skb of ERR_PTR ↗ CVE ⌥ commit
CVE-2026-53220 6.12.94 netfilter: revalidate bridge ports ↗ CVE ⌥ commit
CVE-2026-53219 6.12.94 netfilter: x_tables: avoid leaking percpu counter pointers ↗ CVE ⌥ commit
CVE-2026-53218 6.12.94 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag ↗ CVE ⌥ commit
CVE-2026-53214 6.12.94 ipv6: Fix a potential NPD in cleanup_prefix_route() ↗ CVE ⌥ commit
CVE-2026-53213 6.12.94 drm/vc4: fix krealloc() memory leak ↗ CVE ⌥ commit
CVE-2026-53210 6.12.94 tee: shm: fix shm leak in register_shm_helper() ↗ CVE ⌥ commit
CVE-2026-53208 6.12.94 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig ↗ CVE ⌥ commit
CVE-2026-53207 6.12.94 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison ↗ CVE ⌥ commit
CVE-2026-53196 6.12.94 USB: serial: io_ti: fix heap overflow in get_manuf_info() ↗ CVE ⌥ commit
CVE-2026-53195 6.12.94 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() ↗ CVE ⌥ commit
CVE-2026-53190 6.12.94 drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() ↗ CVE ⌥ commit
CVE-2026-53181 6.12.94 vsock/vmci: fix sk_ack_backlog leak on failed handshake ↗ CVE ⌥ commit
CVE-2026-53177 6.12.94 bnxt_en: Fix NULL pointer dereference ↗ CVE ⌥ commit
CVE-2026-53168 6.12.94 fuse: reject fuse_notify() pagecache ops on directories ↗ CVE ⌥ commit
CVE-2026-53159 6.12.94 misc: fastrpc: fix DMA address corruption due to find_vma misuse ↗ CVE ⌥ commit
CVE-2026-53158 6.12.94 misc: fastrpc: Fix NULL pointer dereference in rpmsg callback ↗ CVE ⌥ commit
CVE-2026-53156 6.12.94 nvmem: core: fix use-after-free bugs in error paths ↗ CVE ⌥ commit
CVE-2026-53154 6.12.94 mm/hugetlb: restore reservation on error in hugetlb folio copy paths ↗ CVE ⌥ commit
CVE-2026-53152 6.12.94 mmc: dw_mmc-rockchip: Add missing private data for very old controllers ↗ CVE ⌥ commit
CVE-2026-53150 6.12.94 thunderbolt: Reject zero-length property entries in validator ↗ CVE ⌥ commit
CVE-2026-53149 6.12.94 thunderbolt: Bound root directory content to block size ↗ CVE ⌥ commit
CVE-2026-53148 6.12.94 thunderbolt: Clamp XDomain response data copy to allocation size ↗ CVE ⌥ commit
CVE-2026-53144 6.12.94 drm/amdkfd: fix NULL dereference in get_queue_ids() ↗ CVE ⌥ commit
CVE-2026-53143 6.12.94 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 ↗ CVE ⌥ commit
CVE-2026-53140 6.12.94 drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups ↗ CVE ⌥ commit
CVE-2026-53138 6.12.94 drm/amd/display: Bound VBIOS record-chain walk loops ↗ CVE ⌥ commit
CVE-2026-53137 6.12.94 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size ↗ CVE ⌥ commit
CVE-2026-53136 6.12.94 drm/amd/display: Clamp VBIOS HDMI retimer register count to array size ↗ CVE ⌥ commit
CVE-2026-53135 6.12.94 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs ↗ CVE ⌥ commit
CVE-2026-53134 6.12.94 netfilter: nft_fib: fix stale stack leak via the OIFNAME register ↗ CVE ⌥ commit
CVE-2026-52948 6.12.94 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl ↗ CVE ⌥ commit
CVE-2026-52939 6.12.94 net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion ↗ CVE ⌥ commit
CVE-2026-52930 6.12.94 ipc/shm: serialize orphan cleanup with shm_nattch updates ↗ CVE ⌥ commit
CVE-2026-53360 6.12.93 KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use ↗ CVE ⌥ commit
CVE-2026-53358 6.12.93 Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() ↗ CVE ⌥ commit
CVE-2026-53080 6.12.93 net/sched: cls_fw: fix NULL dereference of "old" filters before change() ↗ CVE ⌥ commit
CVE-2026-52913 6.12.93 batman-adv: v: stop OGMv2 on disabled interface ↗ CVE ⌥ commit

LLVM musl libc libressl Independent