Upstream linux-hardened tag v7.0.11-hardened1 available #13

Closed
opened 2026-06-06 06:00:31 +00:00 by unredacted_bot · 1 comment

Upstream tag: v7.0.11-hardened1
Local latest: v7.0.10-hardened1

CVEs reported fixed in 7.0.11 since 7.0.10 (source: kernel.org CVE project; unscored — verify severity manually):

  • CVE-2026-46243 — smb: client: reject userspace cifs.spnego descriptions
  • CVE-2026-46244 — netfilter: nft_inner: Fix IPv6 inner_thoff desync

Action: review the upstream signature, then push a matching
local tag (git tag v7.0.11-hardened1 && git push origin v7.0.11-hardened1)
which triggers build-kernel.yml.

See docs/users/cve-policy.md for the SLA.

Upstream tag: v7.0.11-hardened1 Local latest: v7.0.10-hardened1 **CVEs reported fixed in `7.0.11` since `7.0.10`** (source: kernel.org CVE project; _unscored_ — verify severity manually): - CVE-2026-46243 — smb: client: reject userspace cifs.spnego descriptions - CVE-2026-46244 — netfilter: nft_inner: Fix IPv6 inner_thoff desync Action: review the upstream signature, then push a matching local tag (`git tag v7.0.11-hardened1 && git push origin v7.0.11-hardened1`) which triggers build-kernel.yml. See docs/users/cve-policy.md for the SLA.
Owner

Released

Released
zach closed this issue 2026-06-06 07:48:15 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
unredacted/linux-hardened-unredacted#13
No description provided.