On September 24 and 25, 2026 the Linux kernel project published 606 CVEs in two days: 234 on the 24th, 372 on the 25th. It is the second multi-day wave in eight days, after the 878 entries of September 16–17.
NVD had scored 129 of them at analysis time. The other 477 are KernelScan provisional assessments.
The headline numbers are calmer than last week: 7 Critical instead of 37, and 216 entries rated 7.0 or higher instead of 376. Of those 216, only 36 are reachable over the network. Another 27 need radio or fabric range, and 153 are local.
What changed is who the attacker is. Last week’s remote bugs sat in servers: someone connects to your share or your storage target. This week, many sit in clients and hosts — the SMB client, the NVMe host, the Fibre Channel initiator. There, the attacker is the server or device on the other end. That thread runs through this post.
The batch at a glance
- 606 CVEs — 234 on 2026-09-24, 372 on 2026-09-25
- 7 Critical, 209 High, 332 Medium, 58 Low — 216 rated 7.0 or higher
- 129 scored by NVD, 477 KernelScan provisional
- High-rated by attack vector: 36 network, 27 adjacent, 153 local
- 20 of the 36 network Highs are file and storage protocols — 7 of them in the SMB client
- By source tree: 277 drivers, 110 fs, 89 net, 67 kernel, 25 arch
- Top bug class: 125 use-after-free, then 71 out-of-bounds reads and 47 NULL dereferences
- 95 entries date back to 2.6.12, the start of git history; 22 were introduced in 7.1
Read the numbers as a snapshot. Severity uses NVD’s score where one exists and ours otherwise. Where both exist and disagree, we say so per CVE. Fix versions are per-CVE records; a branch that isn’t listed is not proof that no backport exists.
The standouts
Three RDMA storage Criticals
Three of the seven Criticals are RDMA storage transports. They share one precondition: an RDMA fabric.
CVE-2026-97413 (Critical 9.8) is the cleanest. The RTRS server takes a length from the network and subtracts it without a bounds check. A malicious client sends a larger value, the result wraps to a huge size, and the kernel uses it as a memory length. No authentication, no race. NVD and our assessment agree exactly.
CVE-2026-100075 (Critical 9.8) is a use-after-free in the SCSI RDMA target’s error path. NVD calls it network-reachable. We read it as adjacent (7.7): the attacker must sit on the RDMA fabric, which is usually a dedicated storage network.
CVE-2026-93228 (Critical 9.1) rejects a malformed NFS-over-RDMA chunk. Its own description notes that an earlier patch already made the dangerous code path safe. Treat it as hardening, not as a standalone 9.1.
The gates are CONFIG_INFINIBAND_RTRS_SERVER, CONFIG_INFINIBAND_SRPT and CONFIG_SUNRPC_XPRT_RDMA. Watch the last one: it is on by default whenever InfiniBand is built. nfsd only listens on RDMA when configured to — but that is a runtime fact, and your VEX statement should say so.
The NFS server Critical
CVE-2026-93207 (Critical 9.8) is a use-after-free in the NFS server’s Kerberos (RPCSEC_GSS) credential decoder. A failed decode leaves stale data behind, and the next request uses it.
It is tempting to call this “Kerberos only”. It isn’t: CONFIG_NFSD_V4 pulls the decoder in, so every NFSv4 server has it. The real question is whether untrusted hosts can reach port 2049. Introduced in 6.3; fixed in 6.6.157, 6.12.109, 6.18.50, 7.2.4 and 7.3-rc1.
IPVS: Critical on paper, narrow in practice
CVE-2026-98078 (Critical 9.3, our score only) is a swapped argument pair in IPVS connection sync. It leaks 24 bytes of kernel heap per sync message and corrupts the connection’s sequence state.
But the leaked bytes go to the backup load balancer, not back to the attacker. And it only matters on IPVS clusters that run the sync daemon. Everyone else can set it aside.
Two SMB client Criticals
CVE-2026-97565 and CVE-2026-97563 (both Critical 9.1) are in the SMB client. The attacker is the file server you mount. They get the worked example below.
Where we score higher than NVD
Last week’s disagreements were NVD rating things higher than us. This week three go the other way:
- CVE-2026-98096 (High 7.4 by NVD, ours 9.8) — an out-of-bounds write in IPv6 Segment Routing. It only fires if
seg6_enabledis switched on, which is off by default. - CVE-2026-97953 (High 7.0 by NVD, ours 9.8) — TX ring corruption in
stmmac, the Ethernet controller in a large share of embedded SoCs. - CVE-2026-97570 (High 8.1 by NVD, ours 9.8) — an index overrun in Broadcom’s
bnxt_en. Introduced in 7.1, so no 6.x build has it.
The published score stays NVD’s. Our higher reading is a reason to look first.
The high-rated CVEs, grouped by where they bite
Twelve subsystems hold 116 of the 216 high-rated entries. BPF leads with 23, none Critical. The Criticals sit in SMB, InfiniBand, netfilter and SUNRPC.
The twelve subsystems with the most entries rated 7.0 or higher — 116 of 216. The other 100 are spread across 63 subsystems. “drivers/net (other)” is VXLAN, DSA switches, bonding, PPP, MCTP and 802.15.4.
Network-reachable: 36 Highs
Storage, NFS and AFS — 10 Highs, 4 Critical. Besides the Criticals above: three more storage-server bugs (svcrdma, nfsd, and the NVMe-oF RDMA target) and one AFS client race. Two more are on the NVMe host side, covered further down.
SMB — 10 Highs, 2 Critical. Seven in the client (see the example). Three in the ksmbd server, all needing a login. Two of those are permission bugs: CVE-2026-93282 (High 8.1) and CVE-2026-93786 (High 8.1) can grant a user access the administrator never gave. On a NAS, that can be worse than a crash.
Transport protocols — 7 Highs. Two in SCTP, three in RDS-over-TCP, two in MPTCP. Check MPTCP in particular — distributions increasingly build it in.
IP layer — 4 Highs. IPVS and Segment Routing (above), a bonding bug, and CVE-2026-97417 (High 7.5) in connection tracking. That one only crashes CPUs that can’t do unaligned memory reads. A rare case where the answer depends on the architecture, not the config.
NIC drivers — 5 Highs. Three in bnxt_en, two in stmmac. If you don’t ship the hardware, you don’t ship the driver.
Radio, fabric and cable: 27 Highs
- 10 wireless — five in Intel’s
iwlwifi, the rest in Qualcomm, Realtek and the shared Wi-Fi stack - 4 Bluetooth — all in L2CAP and RFCOMM parsing
- 6 Fibre Channel — the attacker is a device on your SAN
- 7 one-offs — Thunderbolt, 802.15.4, PPP over serial, a Logitech receiver and similar
A product with no radio, no SAN and no hot-plug ports can drop this whole group.
Local: 153 Highs
BPF — 23 Highs. Almost all in the verifier, the code that decides whether a BPF program is safe to run. CVE-2026-98039 (High 8.8) gives a program kernel read/write. On a container host this is the most important cluster in the batch. On a sealed appliance with unprivileged BPF disabled, it barely matters.
Core networking via netlink — 23 Highs. VXLAN, traffic control, netfilter, bridge, IPv6, Open vSwitch and more. Most need CAP_NET_ADMIN. The deciding question: are unprivileged user namespaces enabled? They hand that capability to any user.
GPU and accelerators — 13 Highs. Mostly AMD and the Arm Ethos-U NPU. No CONFIG_DRM, no accelerator, no problem.
Video decoders — 8 Highs. Seven are unchecked tile counts in hardware video decoders (Rockchip, MediaTek, Hantro). They are “local”, but the values come from the video file. On a set-top box or signage player that plays outside content, the attacker is whoever supplies the video.
Virtualization — 7 Highs. The one to watch is CVE-2026-93782 (High 7.8), a guest-to-host race in vhost-scsi. Two others are in vdpa_sim, a test simulator. If that is in your production build, removing it is the fix.
ACPI and on-disk filesystems. 8 ACPICA Highs (below) and 11 filesystem Highs, mostly crafted-image bugs. The filesystem ones only matter if your product mounts media it didn’t create.
The other direction: when the peer is the attacker
Triage usually assumes the kernel is the server and the attacker is the client. This batch has many entries where it’s reversed. The kernel reads a reply from a server, a disk, the firmware or a hypervisor — and trusts it too much.
These are easy to get wrong in both directions. Call them internet-facing and you overstate them. Call them local and you miss the product that talks to infrastructure it doesn’t control.
- The file server. A malicious SMB server sends a malformed reply, and the client reads past its buffer. See the example below.
- The storage device. CVE-2026-98056 (High 7.5): an NVMe controller can make the host loop across billions of namespace IDs. Over NVMe-oF, that controller is a remote machine.
- The firmware. Eight ACPICA Highs, all present since 2.6.12. NVD rates them up to 8.4; we rate them 4.4–6.9, because the input comes from firmware tables. On bare metal, whoever controls those has already won. In a confidential VM it flips: the hypervisor supplies the tables, and the hypervisor is not trusted.
- The hypervisor. CVE-2026-93827 (High 8.4) is a double free in the guest’s virtio-fs driver. In a normal VM, a robustness fix. In a TDX or SEV-SNP guest, an attack surface.
- The guest. CVE-2026-97957 (High 8.8) runs the other way: a VM with a passed-through
hinicnetwork function can overflow a buffer on the host.
Config alone can’t settle these — the code is there because the product needs it. The question becomes: which peers do you trust, and is that trust enforced or just assumed?
A useful example: 22 SMB client CVEs
The in-kernel SMB client carries 22 entries: 10 rated 7.0 or higher, 2 Critical. More products use it than you’d think — backup-to-NAS, media players, industrial panels that pull recipes from a Windows share.
Filter 1: is the client built at all?
With CONFIG_CIFS=n, all 22 are “not affected, code not present”. Many embedded products stop here.
Filter 2: is SMB1 built?
Both Criticals — CVE-2026-97565 and CVE-2026-97563 (both Critical 9.1) — are in the old SMB1 read path. They trust the length and offset fields in the server’s reply.
That code is only compiled with CONFIG_CIFS_ALLOW_INSECURE_LEGACY. The catch: it defaults to on. Turn it off and both Criticals leave the binary.
Leave it on and they are still only reached on mounts that ask for vers=1.0; modern clients negotiate SMB2.1 or newer by default. A third SMB1 bug, CVE-2026-93787 (High 8.1), sits in code that is always built, so for that one the mount option is the only gate.
The uncomfortable part: products still using vers=1.0 do it because the server on the other end is old. So the devices most likely to have these Criticals switched on are the ones talking to the least-maintained servers.
Then: who is the attacker?
- 6 come from the server. The three SMB1 bugs, plus three that hit any SMB version — led by CVE-2026-97555 (High 8.8), a heap overflow in ACL handling. If your product only mounts one fixed, admin-configured share, this is a trust question. If users can type in any share path, it’s an open door.
- 1 is a race on the client. CVE-2026-97562 (High 7.5 by NVD; ours 7.0, local) — the server doesn’t control the timing.
- 3 need a local user on the client, such as CVE-2026-93785 (High 7.5). They matter on multi-user systems, much less on an appliance.
Across all 22: 10 originate at the server, 12 on the client.
So one module gives three different answers: not built, only reachable over an SMB1 mount you may not use, or exposed to every server you connect to. A list sorted by CVSS puts the two SMB1 Criticals on top — and they may not even be in your build.
Appliance triage
- NAS and storage targets — the NFS Critical first, then RDMA if you export over it, then the two ksmbd permission bugs.
- Anything that mounts shares — the SMB client cluster, and the SMB1 config switch.
- Load balancers and gateways — IPVS if you run sync; Segment Routing only if enabled; SCTP and MPTCP only if you use them.
- Hypervisors — vhost-scsi, the hinic passthrough bug, and BPF. No KVM entries this time.
- Confidential-computing guests — the ACPICA bugs and the virtio-fs double free.
- Container platforms — BPF and the netlink networking bugs. Both hinge on what unprivileged users are allowed to do.
- Embedded, media and automotive —
stmmac, the video decoders, and the wireless and Bluetooth group. - Headless devices — 44 GPU/accelerator, 10 media and 17 sound entries drop out with a
.configcheck alone.
Medium and low still matter
390 entries score below 7.0. 182 of them are in drivers, led by networking (45) and GPU (23). The rest are spread across filesystems (75), networking (47) and core kernel (38).
At this level the ranking often flips. An xfs Medium on a storage box that formats every disk as xfs matters more than a GPU High on a device with no GPU.
Compliance output should say why
Severity and applicability are different questions. Every verdict should carry its reason:
- affected — an NFSv4 server reachable by untrusted clients, against CVE-2026-93207
- not affected, code not present — the SMB1 Criticals when
CONFIG_CIFS_ALLOW_INSECURE_LEGACYis off - not affected, code not reachable — the Segment Routing bug when
seg6_enabledis off. Name the condition, because someone can change it later. - in triage — genuinely open; for 477 of these 606, NVD hasn’t scored them yet
- remediation — a verified fix or an accepted mitigation, recorded separately
“Not affected because we trust the server” can be a valid statement. But the reader has to be able to see that it rests on trust, not on missing code.
How KernelScan helps
KernelScan checks kernel version, architecture and .config to decide whether the vulnerable code is in your build at all. That verdict stays separate from the CVE’s severity score, which is never overwritten.
The security factors you select add the threat model. That is what turns the SMB example into three clear verdicts instead of ten High findings. Open cases stay visible as in-triage instead of being quietly closed.
Which fixes to take
The recurring releases are 6.12.111, 6.18.53, 7.2.7 and 7.3-rc1 to rc3. Check each CVE individually.
Older LTS branches are thin so far. Of 387 entries whose flaw predates 6.6, only 37 list a 6.6 fix — versus 306 for 6.12. If you ship 6.1 or 6.6, a missing branch means “check your vendor’s tree”, not “you’re covered”.
Age cuts both ways. 92 entries were introduced in 6.13 or later and can’t be in a 6.12 build — CVE-2026-97570 (7.1) is one. Others, like the SMB1 Criticals and all eight ACPICA bugs, have been there since 2.6.12.
Numbers from the KernelScan CVE corpus at analysis time (snapshot 2026-09-26). Severity uses NVD scores where available (129 of 606) and KernelScan provisional assessments otherwise (477). Groupings follow recorded component paths. Fix versions are per-CVE records.