Upstream linux-hardened tag v7.0.12-hardened1 available #17
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Upstream tag: v7.0.12-hardened1
Local latest: v7.0.11-hardened2
CVEs reported fixed in
7.0.12since7.0.11(source: kernel.org CVE project).Severity = Red Hat's rating (best-effort; the kernel CNA publishes no CVSS), not the project's own. List as of 2026-06-13T20:00Z — the feed can lag, so re-check vulns.git before building.
CVE-2026-46316 — Important (CVSS 7.0) — KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
CVE-2026-46317 — Moderate (CVSS 7.0) — KVM: arm64: Reassign nested_mmus array behind mmu_lock
CVE-2026-46318 — Low (CVSS 5.5) — Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"
CVE-2026-46320 — Moderate (CVSS 5.5) — tap: free page on error paths in tap_get_user_xdp()
CVE-2026-46321 — Moderate (CVSS 5.5) — tun: free page on short-frame rejection in tun_xdp_one()
CVE-2026-46322 — Moderate (CVSS 5.5) — tun: free page on build_skb failure in tun_xdp_one()
Action: review the upstream signature, then push a matching
local tag (
git tag v7.0.12-hardened1 && git push origin v7.0.12-hardened1)which triggers build-kernel.yml.
See docs/users/cve-policy.md for the SLA.
Released