VYPR
Published Sep 17, 2026· Updated Sep 18, 2026· 1 source

Android SDK: 25 Linux Kernel Vulnerabilities Disclosed Together on September 17, 2026

Key findings • 25 Linux kernel vulnerabilities disclosed together on September 17, 2026. • Issues span multiple subsystems including networking, graphics, storage, and HID. • Vulnerabilit…

Key findings

  • 25 Linux kernel vulnerabilities disclosed together on September 17, 2026.
  • Issues span multiple subsystems including networking, graphics, storage, and HID.
  • Vulnerabilities include race conditions, use-after-free bugs, and improper locking.
  • Fixes are available in updated Linux kernel releases.
  • No active exploitation or specific threat actors were mentioned.
  • Android SDK users should ensure their systems are updated to patched kernel versions.

On September 17, 2026, a significant batch of 25 vulnerabilities was disclosed in the Linux kernel, impacting various subsystems including networking, graphics, storage, and input devices. These disclosures highlight a range of issues such as race conditions, use-after-free bugs, improper locking, and validation errors. The vulnerabilities were disclosed together, indicating a coordinated disclosure event.

Several vulnerabilities were identified within the graphics (DRM) subsystem. CVE-2026-93195 and CVE-2026-93194 address resource leaks and potential use-after-free issues in the dw-dp driver, while CVE-2026-93193 fixes an OF node reference leak in the analogix_dp driver. Additionally, CVE-2026-93192 resolves a condition where a job is not properly cleared on failure in the v3d driver, and CVE-2026-93180 addresses a NULL pointer dereference on partial unmap of an evicted buffer in the panthor driver. CVE-2026-93179 corrects a VoltageObjectInfo zero-stride loop and out-of-bounds read in the amd/powerplay component.

The networking stack also saw multiple disclosures. CVE-2026-93203 addresses CRC corruption in the batman-adv module. CVE-2026-93199 and CVE-2026-93200 fix issues within the i3c master driver, preventing it from treating its own device as a duplicate target and resolving a use-after-free related to sysfs attribute callbacks. CVE-2026-93173 discusses a potential issue with bpf_prog_free in sleepable_lsm_hooks, and CVE-2026-93174 addresses incorrect padding copies in copy_map_value_long for per-CPU map values.

Storage and memory management components were also affected. CVE-2026-93201 resolves validation issues in the dm-pcache component related to persistent memory cache decoding. CVE-2026-93197 improves LRU size accounting on reparenting in memory cgroups, and CVE-2026-93174 addresses per-CPU map value padding in the bpf subsystem. CVE-2026-93185 ensures jack work is drained on remove in the rt700-sdw driver, and CVE-2026-93184 reworks runtime PM handling in the fsl_audmix probe. CVE-2026-93172 handles potential allocation failures in free_area_init_core_hotplug.

Other affected areas include HID devices and sound subsystems. CVE-2026-93189 and CVE-2026-93188 fix use-after-free bugs and out-of-bounds reads related to HID device input handling and profile indexing, respectively. CVE-2026-93191 corrects incorrect task context checks in smack_msg_queue_msgrcv. The ASoC subsystem has several fixes: CVE-2026-93187 returns errors for invalid format counts in ipc4-topology, CVE-2026-93185 ensures jack work is drained on remove, and CVE-2026-93184 reworks runtime PM handling in the fsl_audmix probe. CVE-2026-93171 addresses a potential double-unlock in the lp5860 LED driver. Finally, CVE-2026-93182 fixes an overflow in update_tg_cfs_runnable, and CVE-2026-93181 corrects ref/unref ordering in uncore_event_cpu_online.

The disclosures indicate that fixes are available in updated Linux kernel releases. No active exploitation or specific threat actors were mentioned in the disclosure. Users of the Android SDK, which incorporates the Linux kernel, should ensure their systems are updated to patched kernel versions to mitigate these vulnerabilities.

The broad range of affected subsystems underscores the importance of timely kernel updates for maintaining system security and stability. Users should consult their specific Android version's security bulletin for details on which kernel versions contain these fixes.

Vypr Intelligence reported on this batch of vulnerabilities, noting the wide variety of subsystems impacted and the types of flaws discovered, including race conditions and use-after-free bugs.

The fixes for these vulnerabilities are available in updated Linux kernel releases.

This batch of 25 vulnerabilities affects multiple core components of the Linux kernel, including graphics, networking, storage, and HID subsystems. The vulnerabilities include race conditions, use-after-free bugs, improper locking, and validation errors. Fixes for these issues are available in updated Linux kernel releases. No active exploitation or specific threat actors were mentioned in the disclosure. The Android SDK relies on the Linux kernel, making these vulnerabilities relevant to Android devices. The disclosures highlight the ongoing need for diligent security patching in the Linux kernel. CVE-2026-93171, CVE-2026-93172, CVE-2026-93173, CVE-2026-93174, CVE-2026-93179, CVE-2026-93180, CVE-2026-93181, CVE-2026-93182, CVE-2026-93184, CVE-2026-93185, CVE-2026-93187, CVE-2026-93188, CVE-2026-93189, CVE-2026-93190, CVE-2026-93191, CVE-2026-93192, CVE-2026-93193, CVE-2026-93194, CVE-2026-93195, CVE-2026-93196, CVE-2026-93197, CVE-2026-93199, CVE-2026-93200, CVE-2026-93201, CVE-2026-93203

Synthesized by Vypr AI
Android SDK: 25 Linux Kernel Vulnerabilities Disclosed Together on September 17, 2026 · VYPR