Skip to main content

TECH VEDA

Linux kernel & Device drivers starts on 24th Oct 2026 enrollingCorporate on-site training - Submit proposal Pick your modulesSharpen your kernel skills: deep dives, drivers, Yocto, CVEs, careers — updated daily. Read the blog →Embedded Linux fast track starts 30th sept 2026 enrollingEmbedded Linux Mastery track starts 30th sept 2026 enrollingLinux systems engineering starts 30th sept 2026 enrolling
Kernel Security

Linux Kernel CVEs: What to Patch by Device (4 – 10 Oct 2026)

220 Linux kernel CVEs (4 - 10 Oct 2026) with the minimum safe version per branch - including CVE-2026-98323, CVE-2026-98365 and what to patch by device.

Linux Kernel CVEs: What to Patch by Device (4 – 10 Oct 2026)

The kernel CNA (the group that assigns Linux kernel CVE IDs) published 220 Linux kernel CVEs from 4 to 10 October 2026. 2 are rated CRITICAL (score 9.8), and both are in the software RDMA drivers: CVE-2026-98323 in siw and CVE-2026-98365 in rxe. 50 more are rated HIGH and 168 have no CNA score. Fixes are released for almost all records. CVE-2026-98375 is fixed only in 7.3-rc7, which is not released yet, and CVE-2026-98165 and CVE-2026-98376 list no stable-branch fix. No record states that a bug is being exploited. The action is to update to the fixed version for your branch. Minimum safe versions: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.55, and 7.2.9. CVE-2026-98365 lists no fix for 5.10, 5.15 and 6.1.

This week has 220 records. Last week had 1 record. This post describes 11 of them and names a few more. The two CRITICAL records are in software RDMA drivers, which most phones, cars and medical devices do not use. Most records are narrow driver and protocol fixes, so which ones matter depends on what your product uses. Use this post to find the Linux kernel CVEs that apply to your device class, then use the version table to plan one update.

The one action: update to the fixed version for your branch

Run uname -r and find your branch in the table. If your version is lower than the value in the second column, plan the update. Each value is the highest fixed version named by any of this week’s records for that branch, so one update covers every record that lists a fix for that branch. Each value equals the newest release on its branch in the kernel.org release list on 10 October 2026.

Stable branchUpdate to at leastNotes
5.105.10.271Longterm. 5.10.271 is the newest release. Many records name no 5.10 fix because the affected code is not in 5.10 or the fix was not applied to 5.10. CVE-2026-98365 lists no 5.10 fix.
5.155.15.222Longterm. 5.15.222 is the newest release. CVE-2026-98365 lists no 5.15 fix.
6.16.1.189Longterm. 6.1.189 is the newest release. CVE-2026-98365 lists no 6.1 fix.
6.66.6.158Longterm. 6.6.158 is the newest release.
6.126.12.112Longterm. 6.12.112 is the newest release.
6.186.18.55Longterm. 10 records published 7 to 9 Oct, for example CVE-2026-98374, need 6.18.55. Most other records need 6.18.54. 6.18.55 is the newest release.
7.27.2.9Current stable. The same records need 7.2.9. Most others need 7.2.8. 7.2.9 is the newest release.
mainline7.3-rc7 (not released yet)7.3-rc6 is the newest and does not have the fix for CVE-2026-98375. The records checked for this post are fixed in 7.3-rc5 or earlier.

Branches that are not listed were not affected, or the fix was released before this window. Check the record for your branch. A record can list no fix for an older branch where the bug may exist. The record does not say whether that branch is exposed, so check your tree and consider a newer longterm branch. CVE-2026-98375 (xen/netfront) is fixed only in 7.3-rc7, and CVE-2026-98165 and CVE-2026-98376 list no stable-branch fix. The kernel.org list of maintained releases no longer includes 7.1, so a 7.1 kernel should move to 7.2.

Mobile and automotive

Phones and vehicle units use Wi-Fi, Bluetooth and TCP. Fix the bugs that remote users or unprivileged local users can reach before other bugs.

CVE-2026-98339: Wi-Fi cfg80211 stale BSS entry removal

The kernel CNA scores this record 8.8 HIGH, with an adjacent-network vector, no privileges and no user interaction. A BSS entry is the kernel record of one Wi-Fi network. When the access point a device is connected to moves to a channel that already has a BSS entry, cfg80211 removes the old entry. The lookup also required the same BSS type, so an entry with the IBSS capability bit was not removed. The next step then triggered WARN_ON(!cmp). The record says an access point or device controlled by an attacker can trigger this. The record text describes a kernel warning, which is lower than the score suggests. Use the score as the CNA’s view and set your priority by reachability. The code is in net/wireless/scan.c and the related setting is CONFIG_CFG80211. It affects 5.4 and later. The fix is in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

CVE-2026-98290: Bluetooth RFCOMM lock inversion in listener cleanup

The score is 7.5 HIGH with an adjacent-network vector and high attack complexity. rfcomm_sock_cleanup_listen() takes the child socket lock before rfcomm_mutex. The RFCOMM worker takes them in the opposite order, so the kernel lock checker (lockdep) reports a possible deadlock. The impact is a possible deadlock, not memory corruption. RFCOMM carries serial-style classic Bluetooth profiles, so check whether your product enables it. The code is in net/bluetooth/rfcomm/sock.c. The related setting is CONFIG_BT_RFCOMM, which needs CONFIG_BT and CONFIG_BT_BREDR. It affects 5.15 and later. The fix is in 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. 5.10 is not affected. See the cve.org record.

CVE-2026-98374: TCP use-after-free of retransmit_skb_hint

The CNA has not scored this record. The record says a local unprivileged program that uses TCP Fast Open can make the kernel use freed memory in the TCP retransmit code. The record includes a KASAN trace (KASAN is a kernel memory error detector). The trigger also needs a specific network message to be delivered, so network conditions matter. This is memory corruption in the core TCP code. Check whether untrusted programs can run on your device. The code is in net/ipv4/tcp_output.c and is built with IPv4 networking. It affects 5.11 and later. The fix is in 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.55 and 7.2.9. The record shows 5.10 as not affected. The 6.18.55 and 7.2.9 values in the table come from this record and nine others. See the cve.org record.

Also check these records for phones and vehicle units. CVE-2026-98255 (not scored) fixes how TCP handles old ACKs. CVE-2026-98256 (7.8 HIGH), CVE-2026-98258 (7.8 HIGH), CVE-2026-98260 (7.8 HIGH) and CVE-2026-98281 (7.8 HIGH) fix exec, signal, POSIX timer and futex bugs that a local program can reach. CVE-2026-98373 (not scored) fixes a memory-management bug in mremap with huge pages. Read the records to see which branches have a fix.

Embedded and IoT

Embedded boards use many network chips and wireless parts. Check the driver in your board configuration before you set the priority.

CVE-2026-98239: Microchip LAN743x receive checksum use-after-free

The score is 8.1 HIGH with a network vector and high attack complexity. When a packet spans more than one receive buffer, the driver writes ip_summed through a pointer to a freed fragment. The record says multi-buffer receive can occur after a live MTU increase, so the risk depends on whether the MTU is changed while the system runs. The record also says it was not tested on real LAN743x hardware. The code is in drivers/net/ethernet/microchip/lan743x_main.c. The related setting is CONFIG_LAN743X, for the Microchip LAN743x and PCI11x1x PCI Express Ethernet devices. It affects 6.1 and later. The fix is in 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

CVE-2026-98348: Intel ipw2x00 libipw short association response

The score is 7.1 HIGH with an adjacent-network vector. The length of the information elements is computed with an unsigned subtraction. A frame shorter than the fixed fields gives a length near 64 KiB, and the parser reads past the receive buffer. Both the ipw2100 and ipw2200 receive paths reach this function. Related records: CVE-2026-98349 (same score, short beacon and probe responses) and CVE-2026-98193 (TKIP frames without a full MIC). The affected parts are old Intel PRO/Wireless 2100 and 2200BG PCI wireless cards, so this applies only to boards that still use them. The related setting is CONFIG_LIBIPW, which CONFIG_IPW2100 and CONFIG_IPW2200 select. It affects 2.6.15 and later. The fix is in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

Boards with SDIO or NXP Wi-Fi modules should also check CVE-2026-98189 (not scored, a wilc1000 receive buffer write), CVE-2026-98184 (not scored), CVE-2026-98185 (not scored) and CVE-2026-98186 (not scored) in the mwifiex driver. These are Wi-Fi frame parsing fixes. Read the records to see which branches have a fix.

Cloud and datacenter

The two CRITICAL records are here. This section also covers the SMB client, RDS and KVM on POWER hosts.

CVE-2026-98323: RDMA siw out-of-bounds write (CRITICAL 9.8)

The CNA scores this 9.8 CRITICAL with a network vector, no privileges and no user interaction. The siw driver can receive an extended header across more than one TCP callback. The next copy is limited by hdrlen - MIN_DDP_HDR instead of the number of missing bytes. The copy then writes past the header and overwrites the receive state, including fpdu_part_rcvd. A later callback uses a negative value as a copy offset, which gives an out-of-bounds write. The code runs only when the siw driver is in use. The code is in drivers/infiniband/sw/siw/siw_qp_rx.c. The related setting is CONFIG_RDMA_SIW, the software iWARP driver over TCP/IP. In practice the driver must be loaded and an siw device configured. The fix is in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

CVE-2026-98365: RDMA rxe integer overflow and out-of-bounds access (CRITICAL 9.8)

The score is 9.8 CRITICAL with a network vector. mr_check_range() checks iova + length, which can wrap to 0. The record says a remote peer can send RDMA requests that pass this range check by mistake. The code then uses a very large array index in rxe_mr_copy_xarray(). This gives an out-of-bounds read or write and a kernel oops (a kernel error report). The record says an unauthenticated remote peer can trigger it. In practice an rxe device must be configured and used by an RDMA service. The code is in drivers/infiniband/sw/rxe/rxe_mr.c. The related setting is CONFIG_RDMA_RXE, the software RoCE driver, which needs 64-bit, PCI and InfiniBand support. The record says the bug exists since 4.8. The fix is listed only for 6.6.158, 6.12.112, 6.18.54 and 7.2.8. The record lists no fix for 5.10, 5.15 and 6.1. See the cve.org record.

CVE-2026-98171: SMB client use-after-free in compound encrypted PDUs

The score is 8.8 HIGH with a network vector and user interaction required. In receive_encrypted_standard(), a stale next_buffer pointer can cause a use-after-free. A bounds check also used the length before decryption, so NextCommand could point into old data, and an integer overflow weakened the upper bound check. The server, or an attacker on the network path, must send crafted frames, so a client that mounts a share from an untrusted server or network is exposed. The code is in fs/smb/client/smb2ops.c. The related setting is CONFIG_CIFS, the SMB3 and CIFS client. It affects 4.19 and later. The fix is in 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. The record lists no 5.10 or 5.15 fix, and it does not say whether those branches are exposed. Several other SMB client records in this batch are HIGH, for example CVE-2026-98169, CVE-2026-98173, CVE-2026-98174 and CVE-2026-98175. See the cve.org record.

CVE-2026-98261: CIFS use-after-free in cifs_chan_skip_or_disable()

The score is 8.1 HIGH with a network vector and high attack complexity. When a secondary channel is no longer supported by the server, the code drops the channel reference and then keeps using the freed server pointers. This is the SMB multichannel path. The code is in fs/smb/client/smb2pdu.c and the related setting is CONFIG_CIFS. It affects 6.8 and later, and the record also lists a 6.6 backport. The fix is in 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

CVE-2026-98257: RDS over InfiniBand connection deadlock

The score is 7.5 HIGH with a network vector and an availability-only impact. When a peer negotiates an old protocol version, the handler calls rds_conn_destroy() while it holds a lock that the shutdown work needs. The two workers wait on each other, and the RDS connection workqueues stop and do not recover. This is an availability problem only. The code is in net/rds/ib_cm.c. The related setting is CONFIG_RDS_RDMA, which needs CONFIG_RDS and InfiniBand support. It affects 2.6.37 and later. The fix is in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

CVE-2026-98283: KVM PowerPC Book3S HV nested guest use-after-free

The score is 8.8 HIGH with a local vector and a changed scope. kvmhv_emulate_tlbie_all_lpid() drops mmu_lock without holding a reference on the nested guest. The record says the free path is fully controlled by the L1 guest. A concurrent request can free the object while the host still uses it. This is a guest-to-host risk on shared PowerNV hosts that run nested guests. The code is in arch/powerpc/kvm/book3s_hv_nested.c, in the powerpc architecture directory, so it is built only for POWER. The related setting is CONFIG_KVM_BOOK3S_64_HV, which depends on CONFIG_PPC_POWERNV. There is no x86 KVM record in this batch. It affects 4.20 and later. The fix is in 6.1.189, 6.6.158, 6.12.112, 6.18.54 and 7.2.8. See the cve.org record.

Also check CVE-2026-98357 (8.1 HIGH, network vector) in the iSER target code. The BPF records are CVE-2026-98376 (not scored; it lists no stable-branch fix), CVE-2026-98378, CVE-2026-98382, CVE-2026-98383 and CVE-2026-98384 (all not scored). Some BPF bugs need privilege to reach, so check whether unprivileged BPF is allowed on your hosts.

Medical devices

Connected clinical devices use Wi-Fi, Bluetooth, TCP/IP and network file shares. These records apply when the device uses the same code. For devices with Wi-Fi, such as patient monitors, check CVE-2026-98339. Check CVE-2026-98290 only if the device uses classic Bluetooth RFCOMM. Many wearables use Bluetooth Low Energy, which does not use RFCOMM. For devices on a clinical network, check CVE-2026-98374 for TCP. A device that only mounts an SMB share with the kernel client is in scope for CVE-2026-98171 and CVE-2026-98261, even if it never acts as a server. Devices built on Microchip LAN743x Ethernet should check CVE-2026-98239. Check whether your device uses RDMA, RDS or POWER KVM. Most medical devices do not.

Medical-device patching depends on validation and regulatory revalidation (US FDA postmarket cybersecurity guidance, EU MDR, IEC 62304). The action is to plan the stable update through the manufacturer’s change-control process. Do not delay it without a documented risk assessment, and use compensating controls such as network segmentation and disabling unused services in the meantime.

How to check if these Linux kernel CVEs apply to you

Ask three questions. First: which version do you run? Second: is the related setting enabled? Third: can an attacker reach the code?

Version: run uname -r and compare it with the table. The example output below is only an illustration. Your values will differ.

raghu@techveda.org:~$ uname -r
6.6.150

Configuration: check the CONFIG_* setting named in each CVE section. If the symbol is not set, the code is not built. A module must also be loaded before its code runs.

raghu@techveda.org:~$ zcat /proc/config.gz | grep -E 'CONFIG_(RDMA_SIW|RDMA_RXE|BT_RFCOMM|CFG80211|CIFS|LAN743X|RDS_RDMA)='
CONFIG_CFG80211=m
CONFIG_CIFS=m

Reachability decides which bugs to fix first. Fix remote or over-the-air bugs first. Fix local unprivileged bugs next. Fix guest-to-host bugs on shared hosts after that. Fix privileged or configuration-only bugs last. For the 168 records with no CNA score, use the same reachability order.

Key takeaways

  • The kernel CNA published 220 CVEs for 4 to 10 October 2026. 2 are CRITICAL, 50 are HIGH and 168 have no CNA score.
  • Both CRITICAL records are in the software RDMA drivers: CVE-2026-98323 (siw) and CVE-2026-98365 (rxe). They matter only if CONFIG_RDMA_SIW or CONFIG_RDMA_RXE is set and in use.
  • Minimum safe versions: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.55 and 7.2.9.
  • Wi-Fi, Bluetooth, TCP and SMB client fixes matter most for phones, vehicles, wearables and clinical devices.
  • Fixes are released for almost all records. CVE-2026-98375 needs 7.3-rc7, which is not released yet. No record states that a bug is being exploited.
Was this worth your time?

Frequently asked questions

How many Linux kernel CVEs were published from 4 to 10 October 2026?
The kernel CNA published 220 records in this window, according to NVD. 2 are CRITICAL, 50 are HIGH and 168 have no CNA score. The IDs run without gaps from CVE-2026-98165 to CVE-2026-98384.

Which are the CRITICAL Linux kernel CVEs this week?
CVE-2026-98323 in the siw software iWARP driver and CVE-2026-98365 in the rxe software RoCE driver. Both have a CNA score of 9.8. Both matter only on systems that use these RDMA drivers.

Do the records say these bugs are being exploited?
No record states that a bug is being exploited. Fixes are released for almost all records, so the action is to schedule the stable update.

I applied last week’s minimum safe versions. Is that enough?
No. Last week’s single record had lower fixed versions, for example 6.1.187 and 6.6.156 (see the previous edition). This week’s versions are higher on every branch, so update again.

Why does the table not show a fix for CVE-2026-98365 on 5.10, 5.15 and 6.1?
The record says the bug exists since 4.8, but it lists fixed versions only for 6.6, 6.12, 6.18 and 7.2. The record does not say whether the older branches are exposed. Check whether the rxe code exists in your tree and whether CONFIG_RDMA_RXE is set. If it is, move to a newer longterm branch or disable the driver.

Further reading

RB
Raghu Bharadwaj

Founder, TECH VEDA — 20+ years teaching the Linux kernel, device drivers and embedded systems.

Follow on LinkedIn

Get new posts by email

Kernel, embedded Linux and AI-era engineering — a few sharp reads a month. No spam.

We email occasionally and never share your address.