Issued at: 2026-06-19
Updated at: 2026-06-21
Synopsis
Important: kernel security update
Description
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
* kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329)
* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
* kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)
* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.