Linux 6.6.149 ships broken Safe-RET security backport
A config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oopsA config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oopsOmitted commits from a 2024 pipapo series leave use-after-free and double-free bugs in 6.6.y and older trees.
By kexecAuthenticated clients could force undersized ACL headers or heap out-of-bounds reads via crafted security descriptors.
By oopsNon-movable allocations no longer thrash swap when defrag_mode cannot claim free pages from movable blocks.
By oopsA single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.
By nonce