Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: e514d41a by Salvatore Bonaccorso at 2026-08-22T19:49:38+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,593 @@ +CVE-2026-74731 [sched_ext: Skip sub-disable teardown for never-linked sub-schedulers] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8c13364db9c9a43ed286f3a8d0fb9477b1adc43c (7.2-rc7) +CVE-2026-74727 [ovpn: skip rehash for peers already removed from by_id] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/33ec10567fe14456063daf549fdf1a4f53448e4c (7.2-rc7) +CVE-2026-74709 [xsk: clear metadata pointer when no timestamp is requested] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/9f60a67df8d3c862503bee62bada8e7089cba438 (7.2-rc7) +CVE-2026-74708 [xsk: validate launch-time metadata size] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/439ce2dddf3d22129b9113a7881637256a35e936 (7.2-rc7) +CVE-2026-74707 [xsk: validate metadata when processing requests] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/849b1664dbda1cf6c63e0fd4f9dec23782b8c851 (7.2-rc7) +CVE-2026-74706 [bnge: Fix NULL pointer dereference in aux device release] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1cb4298810e27e037d3ca07286ecbb97e89ba58d (7.2-rc7) +CVE-2026-74703 [vhost-scsi: Validate T10 PI scatterlist counts] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d876c493fc4b811941bfeb4c80beb2dfc4bf025e (7.2-rc7) +CVE-2026-74702 [vhost-scsi: reject feature changes after endpoint] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/42bc45df5905e2b7dccb72adaf7730f66cfbe03f (7.2-rc7) +CVE-2026-74699 [drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c5f500161709f27719701334190dff2325868ef0 (7.2-rc7) +CVE-2026-74698 [net/mlx5e: fix BQL reset on SQ re-activation] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e7386770be1bf810bcd6af39d1e4bfeab3408430 (7.2-rc7) +CVE-2026-74686 [rqspinlock: Reset tail when preserving queue on deadlock] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/7a3c0289c3c8eb4607dff448ae9ff9f902c813af (7.2-rc7) +CVE-2026-74681 [usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/7e22c9f79b200672f3e477421b6c9050d8cf70a5 (7.2-rc7) +CVE-2026-74674 [mm: fix incorrect flush address in direct page table reclaim] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/478a1c3abebfc717db0d1281a9cdd7befafee542 (7.2-rc7) +CVE-2026-74652 [serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/36672c8d7d14e9c43287528455d2c97b526ea6ad (7.2-rc7) +CVE-2026-74645 [mm/damon/lru_sort: error out for >10000 active_mem_bp] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/06befa61c427e74319781e6f35a364cfc32dbae8 (7.2-rc7) +CVE-2026-74643 [samples/damon/mtier: error out for zero quota goal target values] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a16fd3ad9d89b05475864da97327870464611736 (7.2-rc7) +CVE-2026-74642 [ALSA: usb: Fix UAF at delayed release of MIDI2 EPs] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f8a80cfb68613fb7e6452b66447dbc63f435d140 (7.2) +CVE-2026-74640 [ALSA: FCP: fix OOB write in fcp_meter_ctl_get()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/620f1e52a46f604635efd0fb78138afd6a513b5d (7.2-rc7) +CVE-2026-74639 [ALSA: us144mkii: re-anchor capture URBs on resubmission] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2615f0fb90df8cf5a96133ca4be74294ed288604 (7.2-rc7) +CVE-2026-74633 [tracing: Fix NULL pointer dereference in module event cache removal] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b69859204d4db3acd86c1c2dadcef0d77b451933 (7.2) +CVE-2026-74629 [net/dibs: Correct freeing of dmb_clientid_arr] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/9e6869be49064915edb6c8776b27c376cfdb0df5 (7.2) +CVE-2026-74627 [net: devmem: prevent net-iov / page mixing] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/53a43508ee332d8bffe40590c3d189c92a551f9f (7.2-rc7) +CVE-2026-74617 [dibs: initialise dibs->lock in dibs_dev_alloc()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c27e360545373b7aee9862a5beef3b9fb3df0c25 (7.2-rc7) +CVE-2026-74596 [fs,fsverity: remove check for fsverity being enabled in setattr_prepare()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d2f96bcb89d36d488a10e3bcf819b98536968286 (7.2-rc7) +CVE-2026-74591 [mm/filemap: __filemap_add_folio() restore index before retrying] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/86da3f7e1e609e1e8bfbab198af68467c5a015a5 (7.2-rc7) +CVE-2026-74733 [gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/9dc325327babe7f159e84cbe9380a45342da0585 (7.2-rc6) +CVE-2026-74732 [drm/amd/display: Check for tg ops in dce110_set_avmute] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/3141e3d61469bba2624a91c5e2407f110b33b29e (7.2-rc7) +CVE-2026-74730 [NFS: Pin the 'struct nfs_server' during a FREE_STATEID call] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/cf616096a0f3a2b60f7d68b6b39674a6867ded9c (7.2-rc7) +CVE-2026-74729 [soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/1acef6d85bfd98bd9dfe1f08bffa397a4dda8a6f (7.2-rc7) +CVE-2026-74728 [xfs: handle NULL b_addr in xfs_buf_free] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d852729c5f4f830fbe7413df032e29459b3daf83 (7.2-rc7) +CVE-2026-74726 [bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d (7.2-rc7) +CVE-2026-74725 [enic: fix tx_hang_reset use-after-free on device removal] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/ec680ea4ba1bca92a767fb7e7869758bfdd886e3 (7.2-rc7) +CVE-2026-74724 [ipvs: avoid out-of-bounds write in ip_vs_nat_icmp] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/646922a0379496154e8c8faca4f8e2fd9100cacc (7.2-rc7) +CVE-2026-74723 [btrfs: lzo: reject inline extents without valid headers] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/0fa78ef637deb5dbe341582f88553a4bce496de0 (7.2-rc7) +CVE-2026-74722 [btrfs: fix memory leak in btrfs_do_encoded_write()] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d2a4e4e626b2f4670b69b430c357f03f53eb6632 (7.2-rc7) +CVE-2026-74721 [accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8d51e0fd3e698919d2adeff71936377f0c0d4aa0 (7.2-rc7) +CVE-2026-74720 [bpf: Preserve pointer state for commuted arithmetic] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/a4c6f804b44c5c790269b25e0e61cf4e9f117c86 (7.2-rc7) +CVE-2026-74719 [net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/976245094925bab9bc39366b2e9ab44ffcde61d0 (7.2-rc7) +CVE-2026-74718 [devlink: fix net namespace reference leak in reload] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1c4dac9bf1d2ac31da63b794bdec697777cbd0fd (7.2-rc7) +CVE-2026-74717 [net/mlx5: fw_tracer, return NULL on create error] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5 (7.2-rc7) +CVE-2026-74716 [accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4a19f7ab5972ef608b31ae921419bc3e04b3f8ad (7.2-rc7) +CVE-2026-74715 [bpf: Fix netns reference imbalance in conntrack kfuncs] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fdeba03fea78407a8c52faa99177c9f7f29f90eb (7.2-rc7) +CVE-2026-74714 [bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e5fd3f514e27db1f05fbd72ba615d74941e23c51 (7.2-rc7) +CVE-2026-74713 [vhost_iotlb: bound map allocation in add_range] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94 (7.2-rc7) +CVE-2026-74712 [vdpa/mlx5: Fix buffer length in create_direct_keys()] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/727e1f569855df83579edbd73dcb4a0723543a12 (7.2-rc7) +CVE-2026-74711 [hwmon: (pmbus) Fix type confusion in notification logic] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/59bd68ab05a8f9c9a60b6ec44682084184803ff4 (7.2-rc7) +CVE-2026-74710 [xsk: require at least 16 bytes of TX metadata] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1bb30b181d9f0484e141f8411e15ed906d5c6780 (7.2-rc7) +CVE-2026-74705 [udp: fix potential use-after-free in tunnel segmentation] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d0f86fb36eb260abd10007b62c9dcc1028e03e61 (7.2-rc7) +CVE-2026-74704 [net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/2a33516f9ef59ad11844d4fc152f889449b5daf3 (7.2-rc7) +CVE-2026-74701 [net/openvswitch: check Ethernet header length in key_extract()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/cf6f8b29befb92173659bcef6a441d274947bfae (7.2-rc7) +CVE-2026-74700 [net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/a347304b2ca1a5377d5bd2d8a72e4b4f12afe648 (7.2-rc7) +CVE-2026-74697 [bnxt_en: Disable EOP for TPA on all chips to prevent data corruption] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/c3faf548a00f4c17100cc9204746975fa46a73b9 (7.2-rc7) +CVE-2026-74696 [tcp: fix TFO max_qlen accounting across reuseport migration] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a0ab2ba83e35159d81cec830a92e885ecf8139be (7.2-rc7) +CVE-2026-74695 [netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/8aecf0bbcc72605592134c917c222207d8f63ab0 (7.2-rc7) +CVE-2026-74694 [net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/afa58b7384913c8773d837acdb07b035690ec5d2 (7.2-rc7) +CVE-2026-74693 [net: prestera: validate firmware header length] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/8ae344eb540af3f457179b52bc6061416752485c (7.2-rc7) +CVE-2026-74692 [net/smc: fix TOCTOU race between smc_listen_out() and listener close] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/185a4caeecabc150106deda1da170b09f2ad803f (7.2-rc7) +CVE-2026-74691 [net: thunderbolt: Tear down DMA paths before stopping the rings] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4 (7.2-rc7) +CVE-2026-74690 [s390/ism: Fix UAF of sba and ieq during ism_dev_exit()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/b1896543ce59c4258625a35cf41e23a9a1f80ea2 (7.2-rc7) +CVE-2026-74689 [net/atm: fix slab-out-of-bounds read in vcc_setsockopt()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3 (7.2-rc7) +CVE-2026-74688 [sctp: clear control chunk transport if it is being removed] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/c9158ceaf27780ef64534ad72f44ffde3f8ccc49 (7.2-rc7) +CVE-2026-74687 [watchdog: at91sam9_wdt: prevent timer rearm during teardown] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783 (7.2-rc7) +CVE-2026-74685 [hwmon: (ltc4282) Clamp negative current limits] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e253dd5f9f6d875a317895bf43ec9534ed7523cb (7.2-rc7) +CVE-2026-74684 [net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/3874892dd27d5387aa9a06f58d9060f18f351d24 (7.2-rc7) +CVE-2026-74683 [Input: evdev - sanitize event type index when fetching event masks] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/3abd29c61d2ef37c4102cf755b18be53bb9dbea6 (7.2-rc7) +CVE-2026-74682 [ALSA: usb-audio: fix OOB write on Type II inbound URBs] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/69ee44e1a23be62318189dc4b37fa4ad94053269 (7.2-rc7) +CVE-2026-74680 [usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/c2f811314be351d86b6ab41e9297ae80d8da6f86 (7.2-rc7) +CVE-2026-74679 [usb: gadget: f_ncm: Use unsigned int for ndp_index] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/6b1c8a9403a26cb0fed7a648916c74dc236da591 (7.2-rc7) +CVE-2026-74678 [net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1f428e30947395d9b9aacee03e25a4e6cfcad7a4 (7.2-rc7) +CVE-2026-74677 [net: usb: ipheth: fix carrier_work UAF on disconnect] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/fde39b8a521780391fb4e5bda2c0aa4928947f12 (7.2-rc7) +CVE-2026-74676 [vt: add permission check for KDSKBMETA ioctl] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/a7ad0034453ba4c353f9b8f810ee2569de33d283 (7.2-rc7) +CVE-2026-74675 [vt: stabilize tty reference in kbd_keycode with tty_port_tty_get] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/e25d47a526939ad44b75f778b8a7500562b84fc1 (7.2-rc7) +CVE-2026-74673 [Input: evdev - fix information leak in evdev_pass_values()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/90f305f2c7a30257c683e13f4bf7c798eea992a0 (7.2-rc7) +CVE-2026-74672 [mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/26444eb71465c9934d9d418ef69c43f61185329b (7.2-rc7) +CVE-2026-74671 [ima: fix out-of-bounds read in xattr_verify()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/5ff232d31106f45ac87c3b64e1d35a0667777797 (7.2-rc7) +CVE-2026-74670 [ipvs: stop estimator after disabled calc phase] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/558f67f1340f803a346ecd14a69c49653111c5f4 (7.2-rc7) +CVE-2026-74669 [ipvs: clear IPv4 options after rebasing tunnel ICMP errors] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/e0ba936287dfe9783426aac27e5fd76fe35b38c9 (7.2) +CVE-2026-74668 [packet: use consistent hard_header_len in TX_RING send path] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/21b5953e7494c16a42e6cd8cf110e18d13ae4a6b (7.2-rc7) +CVE-2026-74667 [net/packet: reset the MAC header on the packet-socket transmit path] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/c2707480cfbf19c7619acc9c089d17f20869821f (7.2-rc7) +CVE-2026-74666 [packet: synchronize pressure clearing with ring reconfiguration] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/1a35da325cac4d5bcad76a2aa943408a6f1d9000 (7.2-rc7) +CVE-2026-74665 [net: fix skb length accounting after generic XDP frag adjustment] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/33f2b2eb33d666ecac68031e0f31424fb70528db (7.2) +CVE-2026-74664 [net: openvswitch: reallocate update replies for mismatched IDs] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/5d1c224dd914579524a183a514c12b95095d12ce (7.2-rc7) +CVE-2026-74663 [net/sched: reject overly deep qdisc hierarchies] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01 (7.2-rc7) +CVE-2026-74662 [inet: frags: publish queues before arming timer] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/653d7ddf6cba867777a3d14c4f83ace008c5ad13 (7.2-rc7) +CVE-2026-74661 [mac802154: fix netdev use-after-free in beacon worker] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5f26a690e8efa54315e4922368daf54e0b8f5515 (7.2-rc7) +CVE-2026-74660 [netfilter: ebt_nflog: pin the NFLOG backend] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/30825970339c107bacaf7f61af90fcdb1f597ca1 (7.2-rc7) +CVE-2026-74659 [net: bridge: mrp: fix uninitialised bytes on the wire] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/63488dba65ef91373ef616575b32eb0eb21459f4 (7.2-rc7) +CVE-2026-74658 [futex: Prevent robust futex exit race some more] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/6d4514ca9cdf61fec4ec634cf50386f6f7e69748 (7.2-rc7) +CVE-2026-74657 [ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/4ff9548d84945d2cbf9e4c207288063a200ea397 (7.2-rc7) +CVE-2026-74656 [ipv4: fix use-after-free in fib_nhc_update_mtu()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/bc5bde9ce3cc36502839dfe98e068f7303a50982 (7.2) +CVE-2026-74655 [serial: qcom-geni: fix TX DMA buffer flush] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e3c04834ae1ab5e9cfbe8ac54ec734aa4774249d (7.2-rc7) +CVE-2026-74654 [serial: 8250_dma: Clear stale RX state on shutdown] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41 (7.2-rc7) +CVE-2026-74653 [serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/1423415471274abda87024967d7fe2206ceee0ea (7.2-rc7) +CVE-2026-74651 [staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/1c3e23e78862493e8cf1adad02b10ffcb8b9921c (7.2-rc7) +CVE-2026-74650 [staging: rtl8723bs: fix OOB read in WMM_param_handler()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/ae21407350151bddfd4fea7aa39bd0643c0ca9d3 (7.2-rc7) +CVE-2026-74649 [staging: rtl8723bs: fix missing shared-key auth challenge length check] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/2c56ef658ac8c6bca36bc5574715e8f717207c6c (7.2-rc7) +CVE-2026-74648 [staging: rtl8723bs: validate monitor transmit frame lengths] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/6829665d050983907b560173e49dcc6c11cb2730 (7.2-rc7) +CVE-2026-74647 [misc: fastrpc: Remove buffer from list prior to unmap operation] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/6102ceb4eab845743ee57acd3863fbd06e93c927 (7.2-rc7) +CVE-2026-74646 [misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b85a0e91d7d6cd06a53c881a46f749cfcef416a2 (7.2-rc7) +CVE-2026-74644 [mm/damon/ops-common: putback folios on invalid migrate nid] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5deb65c34e682e7c5f5df417a70e223e8fcc5f5a (7.2-rc7) +CVE-2026-74641 [ALSA: usx2y: bound the hwdep mmap fault offset] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/2ca1eea3cd17930daffe9e429a7c89232036ec24 (7.2-rc7) +CVE-2026-74638 [drm/v3d: Serialize the scheduler timeout handlers] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/4da94744707b27a3ae1197bdd7127da4505dc5b1 (7.2-rc7) +CVE-2026-74637 [perf/core: Fix group leader use-after-free after sibling detach] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/42c5ca1f0a288a52878bd72a5595b08261057438 (7.2) +CVE-2026-74636 [tracing: Fix race between update_event_fields and, event_define_fields] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c3730b8373bb5059d735509b9e6a00d7eb337d7c (7.2) +CVE-2026-74635 [fbdev: bitblit: bound-check glyph index in bit_cursor()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/e033cbf3975a8465f879ebd5989dc35b04423a4d (7.2-rc7) +CVE-2026-74634 [ring-buffer: Prevent subbuf order change when resizing is disabled] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/bf98d7b0d5a99991e47e66cee4eb1d3fa514be97 (7.2-rc7) +CVE-2026-74632 [mm/huge_memory: fix huge_zero_pfn race] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb (7.2-rc7) +CVE-2026-74631 [net: smc: fix splice entry lifetime imbalance in smc_rx_splice] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/5d9686af2976741bbd79b150d1c9e60b81e7f12e (7.2-rc7) +CVE-2026-74630 [ipv6: prevent in6_dev_get() from resurrecting inet6_dev] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/0e243671bc7b8eaf00f83dd2f4367436dc0cff98 (7.2-rc7) +CVE-2026-74628 [net/x25: fix use-after-free of the socket by its timers] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/2195424c3da2ef1829a63b807e3a900a90e57d85 (7.2-rc7) +CVE-2026-74626 [NTB: ntb_netdev: Preserve RX queue depth on allocation failure] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d2121faf133ac3bf9531b53a7e21273649a08517 (7.2) +CVE-2026-74625 [netfilter: bridge: release template ct on non-IP path] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f (7.2) +CVE-2026-74624 [netfilter: nf_conntrack: defer invalid log until after unlock] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2d19b95c9723001f214f7a47d67b09f46238f200 (7.2) +CVE-2026-74623 [net: atlantic: free stranded TX buffers on ring deinit] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/452636ea5410a96e02ebaaf80b21e3620b98e0dd (7.2-rc7) +CVE-2026-74622 [net: atlantic: free RX pages of consumed but not refilled buffers] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/e8e7471ef686b6c002218fee9671cc61992ae01a (7.2-rc7) +CVE-2026-74621 [net/sched: act_ct: fix sk_buff leak when the header checks reject a packet] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8a7ed561671aa6a911a2de99e59ef670a4d0b1df (7.2) +CVE-2026-74620 [net/sched: act_gact, act_police: range check the fallback control action] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/883b56ae58fe657d8497806c7059646e9ba6dbd0 (7.2) +CVE-2026-74619 [ovl: don't warn when the mount is completed from another user namespace] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/63981fc786daaa626cb14d9be1406f674d79f98f (7.2) +CVE-2026-74618 [binfmt_misc: don't warn when the mount is completed from another user namespace] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/79fdf39f1a31f88cb3833b6f8091fbf6acdca2c6 (7.2) +CVE-2026-74616 [xdp: reject clones that overrun skb_shared_info tailroom] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e48e8edbef2eb824201495daa5234560f632b23c (7.2-rc7) +CVE-2026-74615 [vxlan: do not arm the ageing timer on a device that is down] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/b37971686ec59fb027fa4910ba16805e68fddb97 (7.2) +CVE-2026-74614 [vsock/virtio: read virtqueues under worker locks] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/ebac8f6b1ef0e9278afe204b8692a7479988dace (7.2-rc7) +CVE-2026-74613 [vsock/virtio: avoid refilling the RX queue after teardown] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/a31e0ad444698d8aa7534a0f89fda543730f97a5 (7.2-rc7) +CVE-2026-74612 [veth: fix skb length accounting after XDP frag adjustment] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/cb6379feaaff11c4e1e79c26c745ffa23182768a (7.2) +CVE-2026-74611 [tls: rx: restore msg_iter before TLS 1.3 optimistic retry] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1c8629651cb54f7b51db8fc0b1a9944e4a4b0f5e (7.2-rc7) +CVE-2026-74610 [tls: don't leave a full plaintext sk_msg ring unpushed] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/7bca91d63341274e857f4aeaad54d229405e93dc (7.2-rc7) +CVE-2026-74609 [tipc: read le->link under the node lock in tipc_node_link_down()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/cba9ccb47e9fa4cc77692fb896cc5ab57a667882 (7.2) +CVE-2026-74608 [smb: client: Fix use-after-free in cifs_try_adding_channels()] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4986410316b1ae0e63c6ce418e4eb196723626e7 (7.2-rc7) +CVE-2026-74607 [KVM: SVM: Serialize accesses to the owner and mirror list with separate lock] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1d78d33275ef2a16c6d080910b291d0a97a0e613 (7.2-rc7) +CVE-2026-74606 [eventfs: Fix use-after-free in eventfs_remove_rec()] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fd73b691702170d37d66f4b0278530cea8ed419a (7.2-rc7) +CVE-2026-74605 [eventfs: Use children field for rcu head and add memory barriers] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f0ece16ffca7384787b692431961ce202907acf5 (7.2-rc7) +CVE-2026-74604 [Revert "thermal/drivers/hwmon: Cleanup coding style a bit"] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/ff8da20b6f47c48d46e47f93f7a59e2d56ee9107 (7.2-rc7) +CVE-2026-74603 [ptp: ocp: Fix board ID over-read] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6b69f2ef10cdb018c0b127a7cab88e590bbddba4 (7.2-rc7) +CVE-2026-74602 [ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6d014e44b68ddd43f71288d2a4dbb1a259869149 (7.2-rc7) +CVE-2026-74601 [ring-buffer: Use current_context for safe per-CPU buffer swap] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/f27bdc43077e4fcb5557dfc315ee8d91e741f483 (7.2-rc7) +CVE-2026-74600 [mm/page_table_check: skip special zero mappings] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8db4bab826ccc9ec10fa41736a48031cd338d392 (7.2-rc7) +CVE-2026-74599 [mm/ptdump: always stabilise against page table freeing using init_mm] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/27c32e5538344b13c1505a08861e04620c125d47 (7.2-rc7) +CVE-2026-74598 [ipv6: fix Route Information option length validation] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824 (7.2-rc7) +CVE-2026-74597 [ip6_tunnel: clear skb2->cb[] in ip6ip6_err()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/f803c086399da277b5d0ff36a107d0f162751800 (7.2-rc7) +CVE-2026-74595 [fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()] + - linux 7.1.9-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/cf6c993c0feca7984797e634deba3c80342e199a (7.2-rc7) +CVE-2026-74594 [sched/psi: Shut down rtpoll_timer in psi_cgroup_free()] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/5457025fa8ca3c0d2732109513de839e3e797190 (7.2-rc7) +CVE-2026-74593 [sched_ext: Take cgroup_lock() first in scx_cgroup_lock()] + - linux 7.1.9-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5f8b69642d18e1f3e11996707842ac530444e959 (7.2-rc7) +CVE-2026-74592 [ima: Instantiate file_truncate and path_truncate hooks] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/b80bed5c871a80151351342c065579405ce77145 (7.2-rc7) +CVE-2026-74590 [fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions] + - linux 7.1.9-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3e8ec7c0387273329374f5c7bd61f5f38af71fe1 (7.2-rc7) +CVE-2026-74589 [bpf, sockmap: Fix sk_redir use-after-free in send verdict] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/a76624733730e541e4955fdecf506af2f6b20558 (7.2-rc7) +CVE-2026-74588 [sctp: keep chunk->transport in step with the list it is queued on] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/9f2cf069a9a72a2d6b97ca8b4c70e714aac99749 (7.2-rc7) +CVE-2026-74587 [sctp: fix use-after-free of cached ASCONF chunk] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/8c283e7b56adce00193837f3311b06662466fb21 (7.2) +CVE-2026-74586 [sctp: clear new_transport when removing a peer] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3 (7.2) +CVE-2026-74585 [thunderbolt: Bound the DROM dual link port number before indexing sw->ports] + - linux 7.1.9-1 + NOTE: https://git.kernel.org/linus/d6764992f17b23d91ff93ce905ab53c2aa7191f0 (7.2-rc7) CVE-2026-74584 [RDMA/bnxt_re: zero shared page before exposing to userspace] - linux 7.0.14-1 [trixie] - linux 6.12.95-1 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e514d41a58ebd974691e000fa12a735469455d9b -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e514d41a58ebd974691e000fa12a735469455d9b You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
