Linux Security Updates – 28 June 2026

Linux has released security updates to address several vulnerabilities in the Linux Kernel.

The addressed vulnerabilities allow the attacker to conduct denial-of-service attacks, gain elevated privileges, obtain sensitive information, manipulate data, bypass security restrictions, or execute arbitrary code on the affected systems.

Sample of the addressed vulnerabilities:

1. Linux Kernel’s Traffic Control Packet Editing (pedit) Subsystem Privileges Escalation Vulnerability (CVE-2026-46331):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

2. Linux Kernel’s drm/xe/dma-buf Subsystem Use-After-Free Vulnerability (CVE-2026-52951):

  • CVSS: 7
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Denial of Service

It should be noted that security researchers disclosed a proof-of-concept (PoC) exploit for the vulnerability “CVE-2026-46331” that exists in the wild.

Vulnerabilities

Redhat
Ubuntu

Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed and should check with its vendors for updates, if any.

Below is a sample of the distributors’ fixes:
Redhat
Ubuntu

References

Redhat
Ubuntu