[NEW] [high] Linux Kernel: Multiple Vulnerabilities Enable Unspecified Attack
A remote, anonymous attacker can exploit multiple vulnerabilities in Linux Kernel to conduct an unspecified attack, including potentially arbitrary code execution, disclosure of information, manipulation of data, or denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities in the Linux Kernel enable unspecified attacks including code execution, information disclosure, data manipulation, and denial of service.
- Who is affected
- Linux systems running vulnerable kernel versions.
- Urgency
- High; remote unauthenticated attack vector with multiple severe impact classes.
- Action
- Update the Linux Kernel to a patched version addressing the identified CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Linux Kernel
Get an email when a new Linux Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2799
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-684290.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684310.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684320.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684330.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684340.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684350.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684360.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684370.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-684380.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-68450: In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node o…nvd
- unknownCVE-2026-68449: In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix i…nvd
- unknownCVE-2026-68448: In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_…nvd
- highCVE-2026-68447: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU …nvd
- highCVE-2026-68446: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_s…nvd
- highCVE-2026-68445: In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO…nvd
- unknownCVE-2026-68444: In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NUL…nvd
- unknownCVE-2026-68443: In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforc…nvd
- highCVE-2026-68442: In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXT…nvd
- unknownCVE-2026-68441: In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_R…nvd
- highCVE-2026-68440: In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overf…nvd
- unknownCVE-2026-68439: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix po…nvd
Recent advisories for Linux Kernel
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-74579: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fi…nvd · 2026-08-17
- highCVE-2026-74578: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - f…nvd · 2026-08-16
- unknownCVE-2026-74577: In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_…nvd · 2026-08-15
- highCVE-2026-74576: In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded…nvd · 2026-08-15
- highCVE-2026-74575: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDoma…nvd · 2026-08-15
- highCVE-2026-74574: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev …nvd · 2026-08-15
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17