Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 62ae9f2d by Salvatore Bonaccorso at 2026-07-25T16:46:25+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,50 @@ +CVE-2026-64522 [net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA] + - linux 7.0.12-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/abe003b33223ff33552f291644bf35d9c2f992fb (7.1-rc5) +CVE-2026-64521 [pinctrl: meson: amlogic-a4: fix deadlock issue] + - linux 7.0.12-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e72ce029810390eb987a036fb2c8a5da9a23b685 (7.1-rc5) +CVE-2026-64519 [NFSD: Fix infinite loop in layout state revocation] + - linux 7.0.12-1 + [trixie] - linux 6.12.94-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4f8ef58c10bfe5f86a643c7c8331b37e69e3dae1 (7.1-rc4) +CVE-2026-64518 [tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().] + - linux 7.0.12-1 + [trixie] - linux 6.12.94-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/03cb001ef87b3f8d859cf7f96329acf3d6235d29 (7.1-rc4) +CVE-2026-64517 [drm/xe/gsc: Fix double-free of managed BO in error path] + - linux 7.0.12-1 + [trixie] - linux 6.12.94-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d3ded53fab90996e7d94a39049e11962dd066725 (7.1-rc5) +CVE-2026-64516 [drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets] + - linux 7.0.12-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3e5a1d5bb2ff061e64c7992f8e5404dfd4c2d0f3 (7.1-rc5) +CVE-2026-64515 [wifi: mac80211: fix MLE defragmentation] + - linux 7.0.12-1 + [trixie] - linux 6.12.94-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a74e893f30db64cdce0fc7a96d3baa417bcd55f5 (7.1-rc5) +CVE-2026-64520 [firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies] + - linux 7.0.12-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3974ea1938406f9bfa7c1f48d4e43533f447bb08 (7.1-rc5) CVE-2026-64511 [ACPI: NFIT: core: Fix possible NULL pointer dereference] - linux 7.1.4-1 [trixie] - linux 6.12.96-1 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62ae9f2d88b5943ea20cc4e8e7e3f979603b7ed3 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62ae9f2d88b5943ea20cc4e8e7e3f979603b7ed3 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
