Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
Summary
Hide ▲
Show ▼
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on affected builds. Fixed releases include 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, and 7.0.13, with the mainline fix entering 7.1-rc7. Administrators are being told to install a distribution kernel carrying the fix rather than rely on the upstream version number alone.
Related Happenings
Linux stable kernel maintainers security patch release for CVE-2026-64564
Security Patch Release
H score28
First: 07.08.2026 14:10
Last: 07.08.2026 14:10
Sources 1
About this happening:
Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched bu...
Linux stable kernel maintainers security patch release for CVE-2026-64564
Security Patch ReleaseAbout this happening: Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched bu...
Rails maintainers security patch release for CVE-2026-66066
Security Patch Release
H score40
First: 01.08.2026 17:20
Last: 01.08.2026 17:20
Sources 1
About this happening:
Rails published an advisory and version guidance for CVE-2026-66066, a critical Active Storage flaw affecting specific release lines and requiring upgrades. The patch...
Rails maintainers security patch release for CVE-2026-66066
Security Patch ReleaseAbout this happening: Rails published an advisory and version guidance for CVE-2026-66066, a critical Active Storage flaw affecting specific release lines and requiring upgrades. The patch...
Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726
Security Patch Release
H score45
First: 29.07.2026 18:39
Last: 29.07.2026 18:39
Sources 1
About this happening:
Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours...
Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726
Security Patch ReleaseAbout this happening: Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
H score34
First: 22.07.2026 13:50
Last: 22.07.2026 13:50
Sources 1
About this happening:
Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch ReleaseAbout this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Timeline
-
28.07.2026 11:04 2 articles · 10d ago
Linux kernel upstream fix lands for CVE-2026-53264
Mitigation Patch UpdateLinux kernel maintainers land the upstream fix for CVE-2026-53264, a use-after-free race in the network traffic-control subsystem that can be abused for local privilege escalation on affected builds, and begin backporting it to stable branches.
Show sources
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit — thehackernews.com — 28.07.2026 11:04
- AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched — www.infosecurity-magazine.com — 28.07.2026 17:45
-
28.07.2026 11:04 2 articles · 10d ago
Debian, Ubuntu, and SUSE show uneven kernel fix coverage for CVE-2026-53264
Mitigation Patch UpdateAs of July 28, 2026, Debian lists fixed kernels for supported stable releases, Ubuntu still marks multiple maintained kernel packages vulnerable, and SUSE lists CVE-2026-53264 as pending across multiple products; administrators are advised to install a distribution kernel carrying the fix rather than rely on the upstream version number alone.
Show sources
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit — thehackernews.com — 28.07.2026 11:04
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit — thehackernews.com — 28.07.2026 11:04