CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
Published Jun 25, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
10 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=6.12<7.0.13
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
Linux Linux kernel=7.1-rc5
Linux Linux kernel=7.1-rc6
debian/linux<=6.12.94-1
5.10.223-15.10.262-16.1.176-16.1.180-16.12.101-17.1.8-27.1.9-1
debian/linux-6.12
6.12.101-1~deb12u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.101-1Fixed in 7.1.8-2Fixed in 7.1.9-1 - Upgrade
Upgrade
debian/linux-6.12to a version that resolves this vulnerability.Fixed in 6.12.101-1~deb12u1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Patch tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req()
Event History
Jun 25, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 13, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Aug 19, 2026
Data Sourced
via Ubuntu·08:45 PM
RemedyDescriptionSeverityAffected Software
Aug 22, 2026
Data Sourced
via Debian·08:49 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53260?
The severity of CVE-2026-53260 is rated at risk level 37.
2
How do I fix CVE-2026-53260?
To fix CVE-2026-53260, update the Linux kernel to the latest patched version that addresses this vulnerability.
3
What systems are affected by CVE-2026-53260?
CVE-2026-53260 affects the Linux kernel, specifically the components related to TCP connection handling.
4
What type of vulnerability is CVE-2026-53260?
CVE-2026-53260 is classified as a Use After Free vulnerability.
5
When was CVE-2026-53260 published?
CVE-2026-53260 was published on June 25, 2026.