The following issues are fixed by the ReadyKernel patch:

v8.46 and newer:

 * CVE-2026-64561
   KVM: x86: shadow MMU: Fix stale-root check ordering that lets a guest
   create invalid shadow pages and trigger a host denial of service or
   host escape.

v8.44 and newer:

 * CVE-2026-52993
   Fix skb double-free in tipc_buf_append() when validation fails after skb reallocation.
 * CVE-2026-53006
   Fix saddr and daddr UAF in icmpv6_rcv().

v8.43 and newer:

 * CVE-2026-46242, CVE-2026-43074
   Fix Use-After-Free and Double-Free in eventpoll leading to potential
   privilege escalation.

v8.42 and newer:

 * CVE-2026-43499
   Fix Use-After-Free in rtmutex leading to potential privilege escalation.

v8.35 and newer:

 * CVE-2026-53359
   KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level

v8.34 and newer:

 * CVE-2026-53359
   KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
   KVM: x86: Fix shadow paging use-after-free due to unexpected role

v8.33 and newer:

 * CVE-2026-46300
   Fix Fragnesia vulnerability, that allows local privilege escalation.
   Patch contains already merged f84eca581739 ("net: skbuff: preserve
   shared-frag marker during coalescing") and currently reviewed v5 of
   "net: skbuff: propagate shared-frag marker through
   frag-transfer helpers" (https://lore.kernel.org/all/ageeJfJHwgzmKXbh@v4bel/)

v8.32 and newer:

 * CVE-2026-46333
   Fix ssh-keysign-pwn attack that allows reading root-owned files by unprivileged users.

v8.31 and newer:

 * CVE-2026-43284, CVE-2026-43500
   Fixes for Dirty Frag attack which allows to get root privileges from a non-root user.

v8.30 and newer:

 * CVE-2026-31431
   Fixes for CopyFail attack which allows to get root privileges from a non-root user.

v8.28 and newer:

 * VSTOR-126957
   Fix out of bound access in iov iteration in ploop.

 * PSBM-161840
   Fix percpu pages free list corruption due to race in tcache attach/detach.

v8.27 and newer:

 * VSTOR-120551
   Fix deadlock due to missing unlock in vstorage kio.

v8.26 and newer:

 * VSTOR-118628
   Fix data coruption on dm-qcow2 on missed sync for REQ_FUA.

v8.25 and newer:

 * VSTOR-116467
   Fix null pointer (rpc->clnt_cs) dereference crash in kio pcs.

v8.24 and newer:

 * VSTOR-114444
   Kernel panic could happen on a Node running Intel Ethernet Network Adapter E810-XXV for SFP and other cards running under "ice" network driver.

v8.22 and newer:

 * VSTOR-112356
   Fix null pointer dereference crash in kio pcs.

v8.21 and newer:

 * VSTOR-110285
   Fix dirty data detection mechanism in ploop cluster allocation.

v8.20 and newer:

 * VSTOR-110285
   Ploop images could become non-aligned to cluster size which prohibited ploop image mounting.

v8.19 and newer:

 * VSTOR-108868
   Fix excess disk space usage in ploop preallocation algorithm.

v8.17 and newer:

 * VSTOR-109853
   Kernel crashed with checksumless storage chunk servers (CSes).

v8.16 and newer:

 * VSTOR-109363
   Filesystem corruption on qcow2 formatted ploop images during parallel workloads.

v8.15 and newer:

 * VSTOR-108908
   Fix RDMA/cma crash on corrupted workqueue.
 * VSTOR-108725
   Fix crash in dm-ploop on out of bounds bat access in discard writeback.
 * VSTOR-107975
   Fix self deadlock in dm-ploop on bat lock in ploop resize.
