Linux Kernel: 25 Vulnerabilities Disclosed Together on September 4, 2026
Key findings • 25 Linux kernel vulnerabilities disclosed together on September 4, 2026. • Vulnerabilities affect diverse subsystems including SELinux, graphics, and networking. • Fixes ad…

Key findings
- 25 Linux kernel vulnerabilities disclosed together on September 4, 2026.
- Vulnerabilities affect diverse subsystems including SELinux, graphics, and networking.
- Fixes address issues in security policy, data validation, and error handling.
- The batch includes fixes for
drm/amdgpuUVD handling andnetfsoperations. - Users are urged to update their Linux kernel to patch these issues.
On September 4, 2026, a batch of 25 vulnerabilities was disclosed in the Linux kernel. These vulnerabilities span various subsystems, including SELinux, audio codecs, graphics drivers, networking, and virtualization. The disclosures highlight potential issues in security policy handling, error path management, data validation, and resource management within the kernel.
Several vulnerabilities relate to the SELinux subsystem. CVE-2026-80913 addresses an issue where the kernel did not require every boolean value to be defined in the policy image, potentially leading to undefined behavior. Similarly, CVE-2026-80912 fixes a flaw where an unclaimed class value could be passed to security_get_classes(), leaving a NULL pointer.
The Advanced Linux Sound Architecture (ASoC) and its related components are affected by multiple issues. CVE-2026-80911 resolves an error path in sof_widget_setup_unlocked() that could lead to a double decrement of the use count. CVE-2026-80910 corrects enum kcontrol accesses in the lpass-wsa-macro driver, preventing incorrect value interpretation. CVE-2026-80900 enhances the robustness of message size checks in the SDCA driver.
The graphics drivers, specifically drm/amdgpu and drm/xe, also have several disclosed vulnerabilities. CVE-2026-80909, CVE-2026-80908, and CVE-2026-80907 all pertain to the Unified Video Decoder (UVD) in drm/amdgpu, addressing issues with invalid H.265 references and dimensions, as well as incorrect minimum DPB size calculations for H.264. CVE-2026-80903 in drm/xe/oa fixes a sync entry leak on OA config emit failure.
Networking components are affected by several fixes. CVE-2026-80906 and CVE-2026-80905 address incorrect transport headers when sending VLAN-tagged frames in the packet and tap subsystems, respectively. CVE-2026-80904 in net/tls ensures that tls_sw_splice_read() fails after a failed asynchronous decryption. CVE-2026-80900 in netfs addresses issues with clearing PG_private_2 on copy-to-cache append failures and releasing readahead folios on iterator preparation failure. CVE-2026-80898 also in netfs fixes clearing PG_private_2 on copy-to-cache append failure. CVE-2026-80897 in netfs addresses releasing readahead folios on iterator preparation failure. CVE-2026-80900 in ASoC: SDCA makes UMP message size check more robust.
Virtualization and memory management are also touched upon. CVE-2026-80918 and CVE-2026-80919 address race conditions and ordering issues in the mshv (Microsoft Hyper-V) module related to IRQfds and virtual processor array publishing. CVE-2026-80902 in dmaengine: sun6i-dma fixes the reclaim of descriptors while terminating DMA. CVE-2026-80901 addresses checksum validation in ipvs for ICMPv6 packets. CVE-2026-80894 in iommufd corrects the hardware page table passed to iommufd_auto_response_faults on replacement. CVE-2026-80893 fixes swap entry corruption when clearing the uffd-wp bit at fork() in mm/hugetlb. CVE-2026-80892 addresses the LZMA stream pool size in erofs. CVE-2026-80891 in KVM: s390 validates AIBV and AISB before pinning guest pages. CVE-2026-80890 in sctp rejects stale cookies with mismatched verification tags. CVE-2026-80889 in can: isotp fixes timer drain order, wakeup handling, and tx_gen ordering.
The vulnerabilities CVE-2026-80899 and CVE-2026-80892, both related to erofs, indicate a move away from the fscache backend and a more robust handling of LZMA stream pool sizing, respectively.
The timely disclosure of these 25 vulnerabilities on a single day underscores the ongoing efforts to identify and address security weaknesses within the Linux kernel. Users are advised to update their systems to incorporate these fixes to mitigate potential risks.
The batch of vulnerabilities was disclosed on September 4, 2026. The vulnerabilities span multiple subsystems within the Linux kernel. Key areas addressed include SELinux, audio, graphics, networking, and virtualization. Fixes involve data validation, error handling, and resource management. Users are advised to update their Linux kernel to the latest versions to incorporate these security patches. CVE-2026-80913, CVE-2026-80912, CVE-2026-80911, CVE-2026-80910, CVE-2026-80909, CVE-2026-80908, CVE-2026-80907, CVE-2026-80906, CVE-2026-80905, CVE-2026-80904, CVE-2026-80903, CVE-2026-80902, CVE-2026-80901, CVE-2026-80900, CVE-2026-80899, CVE-2026-80898, CVE-2026-80897, CVE-2026-80896, CVE-2026-80895, CVE-2026-80894, CVE-2026-80893, CVE-2026-80892, CVE-2026-80891, CVE-2026-80890, CVE-2026-80889