Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 913490a1 by Salvatore Bonaccorso at 2026-07-20T20:01:05+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,39 @@ +CVE-2026-64207 [net/sched: dualpi2: fix GSO backlog accounting] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/05ed733b65ab977dd931e7f7ac0f62fdb81205c2 (7.2-rc1) +CVE-2026-64206 [Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3) +CVE-2026-64205 [i2c: i801: fix hardware state machine corruption in error path] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/10dd1a736d557e310a77117832874729a0175d57 (7.2-rc1) +CVE-2026-64192 [bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4 (7.2-rc2) +CVE-2026-64191 [i2c: stub: Reject I2C block transfers with invalid length] + - linux 7.0.14-1 + [trixie] - linux 6.12.95-1 + [bookworm] - linux 6.1.177-1 + NOTE: https://git.kernel.org/linus/6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e (7.1-rc3) +CVE-2026-64190 [net: team: fix NULL pointer dereference in team_xmit during mode change] + - linux 7.1.3-1 + NOTE: https://git.kernel.org/linus/25fe708bbc59289d3d1ea4b126fbc1b460a072a5 (7.1-rc6) +CVE-2026-64189 [netfilter: ipset: fix race between dump and ip_set_list resize] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/7cd9103283b26b917360ec99d7d2f2d761bcf1ab (7.2-rc2) +CVE-2026-64188 [net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()] + - linux 7.0.14-1 + [trixie] - linux 6.12.95-1 + [bookworm] - linux 6.1.177-1 + NOTE: https://git.kernel.org/linus/d00c953a8f69921f484b629801766da68f27f658 (7.1-rc5) +CVE-2026-64187 [xfs: fail recovery on a committed log item with no regions] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4) CVE-2026-13577 - libdancer2-perl <unfixed> NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/ View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/913490a1fcc5a6ec3fddacc5f46923c3e9915602 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/913490a1fcc5a6ec3fddacc5f46923c3e9915602 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
