CVE Weekly Report — Week of Jun 1 – June 7, 2026
2026-W23
5
Total CVEs
0
Critical
0
High
0
Actively exploited
🔴 Critical CVEs (2)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-46266 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incom… | Jun 3 |
| CVE-2026-46244 | Linux | 9.1 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync … | Jun 3 |
🟠 High CVEs (14)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-46264 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of dev… | Jun 3 |
| CVE-2026-46273 | Linux | 8.6 | — | In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So… | Jun 3 |
| CVE-2026-46270 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_… | Jun 3 |
| CVE-2026-46251 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption … | Jun 3 |
| CVE-2026-46259 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading rea… | Jun 3 |
| CVE-2026-46271 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link … | Jun 3 |
| CVE-2026-46267 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein… | Jun 3 |
| CVE-2026-46263 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder i… | Jun 3 |
| CVE-2026-46260 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node()… | Jun 3 |
| CVE-2026-46253 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_s… | Jun 3 |
| CVE-2026-46246 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for e… | Jun 3 |
| CVE-2026-46265 | Linux | 7.5 | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i… | Jun 3 |
| CVE-2026-46250 | Linux | 7.3 | — | In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as globa… | Jun 3 |
| CVE-2026-46243 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti… | Jun 1 |
🟡 Medium CVEs (17)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-46249 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Fix PF driver crash with kexec kernel… | Jun 3 |
| CVE-2026-46248 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->li… | Jun 3 |
| CVE-2026-46247 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map … | Jun 3 |
| CVE-2026-46245 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD i… | Jun 3 |
| CVE-2026-46269 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference… | Jun 3 |
| CVE-2026-46256 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: NFS/localio: prevent direct reclaim recursion into … | Jun 3 |
| CVE-2026-46255 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: don't explicitly disable clock… | Jun 3 |
| CVE-2026-46254 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to handle unaligned dfa ta… | Jun 3 |
| CVE-2025-71313 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_wor… | Jun 3 |
| CVE-2026-46252 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in regulator_resolve_s… | Jun 3 |
| CVE-2026-46268 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning conditi… | Jun 3 |
| CVE-2026-46258 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: Avoid NULL dereference in linehandle_cr… | Jun 3 |
| CVE-2026-46257 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when r… | Jun 3 |
| CVE-2026-46262 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr… | Jun 3 |
| CVE-2026-46261 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: spi: wpcm-fiu: Fix potential NULL pointer dereferen… | Jun 3 |
| CVE-2025-71314 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches(… | Jun 3 |
| CVE-2026-46272 | Linux | 4.7 | — | In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf… | Jun 3 |
🔵 Low CVEs (5)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-8404 | Django | 3.1 | — | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3 |
| CVE-2026-35193 | Django | 3.1 | — | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3 |
| CVE-2026-48587 | Django | 3.1 | — | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan… | Jun 3 |
| CVE-2026-6873 | Django | 3.1 | — | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in… | Jun 3 |
| CVE-2026-7666 | Django | 3.1 | — | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` … | Jun 3 |
