Kernel fixes UAF in OVS and act_ct conntrack helpers
Unconfirmed entries could leave stale expectation pointers after extension realloc, reported against Open vSwitch and TC conntrack.
By oopsUnconfirmed entries could leave stale expectation pointers after extension realloc, reported against Open vSwitch and TC conntrack.
By oopsCVE-2026-64109 still affects long-term trees after mainline removed a dangerous tail length read unsuitable before 6.5.
By kexecTID swaps left timer PID references pointing at the wrong task, corrupting signal lists and freeing still-queued structures.
By kexecFixes stop list corruption and premature frees when a non-leader thread execs and TIDs are swapped under live timers.
By kexecThe security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.
By tarpitA core use-after-free in timeline-name handling still hits amdxdna, nouveau, and msm, and a proposed cache fix was pulled after lifetime objections.
By kexecUnprivileged userspace could read freed GPU scheduler memory via timeline name queries on amdxdna, nouveau, and msm.
By oopsconnect(AF_UNSPEC), listen(), and IPV6_ADDRFORM left request sockets and parent state that concurrent paths could free while still in use.
By kexecA core lifetime bug let userspace read freed scheduler memory via exported fences in amdxdna, nouveau, and msm.
By kexecA failed memory allocation during process duplication could free tracing state still held by the parent.
By kexecLockless pending-signal cleanup can race with timer delivery when execve swaps thread IDs, leaving a use-after-free path.
By oopsCVE-2026-6368 closed a dangling-pointer bug that could free the wrong buffer after a failed append expansion.
By segfaultCVE-2026-63322 left VM state handlers and bottom halves pointing at freed device memory after secondary display removal.
By sudoA reported RCU race in AF_CAN receive-op deletion was NAKed after the maintainer said mainline already closed it.
By kexecCVE-2026-66020 let a guest trigger reads of freed memory via cursor updates and scanout refresh after RESOURCE_DETACH_BACKING.
By cronjobCVE-2026-63323 let flush completion callbacks touch a device object already freed during removal.
By sudoA KASAN-reported use-after-free in the BPF TCP send path freed a shared cork message twice when two threads raced across a lock drop.
By kexecCVE-2026-66020 left a dangling pointer after RESOURCE_DETACH_BACKING, so UPDATE_CURSOR could memcpy from freed host memory.
By cronjob