Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 76f6abc9 by Salvatore Bonaccorso at 2026-07-25T16:45:00+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,1223 @@ +CVE-2026-64511 [ACPI: NFIT: core: Fix possible NULL pointer dereference] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/027e128abb82788189d6d45b68e3e8e7329b67be (7.2-rc1) +CVE-2026-64506 [wifi: rtw89: correct drop logic for malformed AMPDU frames] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/63ccdfac8677387dfdbd9d4336089e9823280704 (7.2-rc1) +CVE-2026-64502 [iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/91bc6767a4f55dc470d8a56b55b9f2ea09094efe (7.2-rc1) +CVE-2026-64501 [iio: adc: ad_sigma_delta: fix CS held asserted and state leaks] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c72da0688575e5ef39c36bb44fed53aa18f8ae65 (7.2-rc1) +CVE-2026-64499 [iio: adc: ti-ads1119: fix PM reference leak in buffer preenable] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/adf4bc07f814da8329278d32600147f5a150938c (7.2-rc3) +CVE-2026-64498 [iio: buffer: hw-consumer: free scan_mask on buffer release] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6325d6e2204327965b849c0a16efb6ac9202e5a8 (7.2-rc1) +CVE-2026-64492 [iio: temperature: tmp006: use devm_iio_trigger_register] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3c5eed894efd93d68d7f6a359a81ddef0e928774 (7.2-rc1) +CVE-2026-64491 [ALSA: usx2y: us144mkii: fix work UAF on disconnect] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/147996e7e7c9e8339c0e04f6fa7ccb3e4d448ff7 (7.2-rc2) +CVE-2026-64490 [ALSA: virtio: Validate control metadata from the device] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c77a6cbb36ff8cbc1f084d94f8dcda5250935271 (7.2-rc1) +CVE-2026-64485 [ALSA: compress: Fix task creation error unwind] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4a60127debb9e370d6c0e22a307326b624a141f3 (7.2-rc1) +CVE-2026-64479 [ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4 (7.2-rc1) +CVE-2026-64477 [x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fc16126cc11d9f507130bf84ab137ee0938c900e (7.2-rc2) +CVE-2026-64474 [vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a26b499b757cfc8bbff1088bb1b844639e250893 (7.2-rc1) +CVE-2026-64473 [vfio: Remove device debugfs before releasing devres] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/dc7fe87de492ea7f33a72b78d26650b75bf37f4f (7.2-rc2) +CVE-2026-64467 [rust_binder: use a u64 stride when cleaning up the offsets array] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/803c8a9502e9b97cd6ae937618ef4a8fd6274343 (7.2-rc3) +CVE-2026-64466 [rust_binder: clear freeze listener on node removal] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/bc4a9828897871ff3e5a1f8a1d346decbf4ee95e (7.2-rc3) +CVE-2026-64464 [xhci: sideband: fix ring sg table pages leak] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/49f6e3c3ef19f04f6657ed8dce550e36c763abb8 (7.2-rc3) +CVE-2026-64460 [PCI/IOV: Skip VF Resizable BAR restore on read error] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f34f1712229d71ce4286440fef12526fd4590b37 (7.2-rc1) +CVE-2026-64459 [tcp: restore RCU grace period in tcp_ao_destroy_sock] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30 (7.2-rc2) +CVE-2026-64457 [virtio_pci: fix vq info pointer lookup via wrong index] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f7d380fb525c13bdd114369a1979c80c346e6abc (7.2-rc1) +CVE-2026-64453 [usb: misc: usbio: fix disconnect UAF in client teardown] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/0bfeec21984fedd32987f4e4c0cde34b445af404 (7.2-rc3) +CVE-2026-64451 [tracing: Fix NULL pointer dereference in func_set_flag()] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c3e94604675e3db186111b8942650d86577df9b0 (7.2-rc3) +CVE-2026-64447 [staging: media: ipu7: fix double-free and use-after-free in error paths] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d3a9a8cf2d7fd61a2f63df61f6cbc0a9bb007cc0 (7.2-rc1) +CVE-2026-64439 [crypto: krb5 - filter out async aead implementations at alloc] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6c9dddeb582fde005360f4fe02c760d45ca05fb5 (7.2-rc1) +CVE-2026-64433 [Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fa85d985f614bc3feb343000f14a1072e99b0df1 (7.2-rc3) +CVE-2026-64431 [ntfs: avoid calling post_write_mst_fixup() for invalid index_block] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5b6eedd7cc2936f9238e852b553a1b326105bde8 (7.2-rc3) +CVE-2026-64427 [HID: logitech-dj: Fix maxfield check in DJ short report validation] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/590cc4d782487632a52f37c2171bee1eeea29627 (7.2-rc3) +CVE-2026-64426 [io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2564ca2e31bd8ee8348362941af2ee4671e487ca (7.2-rc1) +CVE-2026-64418 [mm: shrinker: fix shrinker_info teardown race with expansion] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/65476d31d8056e859c48580f82295ce159196ffe (7.2-rc3) +CVE-2026-64415 [mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/66366d291f666ddeda5f8c84f253e308de3e6b55 (7.2-rc1) +CVE-2026-64414 [netfilter: handle unreadable frags] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/da5b58478a9c1b85608c9e40a3b8432d071b409e (7.2-rc3) +CVE-2026-64410 [netfilter: flowtable: IPIP tunnel hardware offload is not yet support] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6c5dcab95f4cd42a1648739ec9300fbb4b1a021f (7.2-rc3) +CVE-2026-64407 [Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/badff6c3bed8923a1257a853f137d447976eec30 (7.2-rc3) +CVE-2026-64404 [Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d5541eb148da72d5e0a1bca8ecd171f9fc8b366f (7.2-rc3) +CVE-2026-64402 [coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/98495b5a4d77dd22e106f462b76e1093a55b29a7 (7.2-rc1) +CVE-2026-64387 [smb: client: fix query directory replay double-free] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/9647492b5e41954be59d5157eddbcd4cdc1656f7 (7.2-rc1) +CVE-2026-64386 [smb: client: fix query_info() replay double-free] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2a88561d66eb855813cf004a0abe648bbb17de5e (7.2-rc1) +CVE-2026-64385 [smb: client: fix double-free in SMB2_ioctl() replay] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9 (7.2-rc1) +CVE-2026-64384 [smb: client: fix change notify replay double-free] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/145f820dcbb2cced374f2532f8a61a44dce4a615 (7.2-rc1) +CVE-2026-64383 [smb: client: fix double-free in SMB2_flush() replay] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a (7.2-rc1) +CVE-2026-64382 [smb: client: fix double-free in SMB2_open() replay] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b55e182f2324bc6a604c21a47aa6c448f719a532 (7.2-rc1) +CVE-2026-64368 [mm/slab: do not limit zeroing to orig_size when only red zoning is enabled] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/648927ceb84021a25a0fbd5673740956f318d534 (7.2-rc1) +CVE-2026-64367 [HID: hid-goodix-spi: validate report size to prevent stack buffer overflow] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/db0a0768d09273aadadeb76730cd658d720333a4 (7.2-rc1) +CVE-2026-64366 [HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6b3014ec0e9a390ca563030b2d7689921f0daef5 (7.2-rc1) +CVE-2026-64358 [media: mtk-jpeg: cancel workqueue on release for supported platforms only] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b1845a227fda37b2fe5327df3ca0015d7e290235 (7.2-rc1) +CVE-2026-64357 [xfs: fix exchmaps reservation limit check] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/0a5213bbff62b51c7d4999ac8c7e11ea57d00d45 (7.2-rc1) +CVE-2026-64356 [xfs: fix memory leak in xfs_dqinode_metadir_create()] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/45de375b25060edf46e20abb36521ba530336ceb (7.2-rc2) +CVE-2026-64354 [bpf: Validate BTF repeated field counts before expansion] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b9452b594fd3aecbfd4aa0a6a1f741330a37dab7 (7.2-rc1) +CVE-2026-64353 [bpf: Keep dynamic inner array lookups nullable] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/53040a81ae57cdca8af8ac36fe4e661730cf7c6b (7.2-rc1) +CVE-2026-64349 [usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e0f844d9d74200d311c6438a0f04270834ba5365 (7.2-rc3) +CVE-2026-64339 [usb: misc: usbio: bound bulk IN response length to the received transfer] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8c6314489550fa81d41723a0ff33f655b5b6c7b6 (7.2-rc3) +CVE-2026-64328 [usb: gadget: f_fs: Fix DMA fence leak] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/baa6b6068a3f2bf2ed525a1cb37975905dadc658 (7.2-rc3) +CVE-2026-64327 [usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/82cfd4739011bdc7e87b5d585703427e89ddfaa5 (7.2-rc3) +CVE-2026-64326 [block: skip sync_blockdev() on surprise removal in bdev_mark_dead()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/49f06cff50a4ccf3b7a1a662ceb892b3b21a527a (7.2-rc1) +CVE-2026-64321 [nvme: target: rdma: fix ndev refcount leak on queue connect] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/badc53620fe813b3a9f727ef9526f98567c2c898 (7.2-rc1) +CVE-2026-64314 [crypto: chacha20poly1305 - validate poly1305 template argument] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/265b861bece38318b8e0fc8fac0643d4ef906d31 (7.2-rc1) +CVE-2026-64311 [crypto: loongson - Remove broken and unused loongson-rng] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/af3d1bb9a09daf928fc3f173689fb7904d6a6d4f (7.2-rc1) +CVE-2026-64310 [crypto: ccp - Do not initialize SNP for SEV ioctls] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fb1758e74b8061aacfbce7bbb7a7cc650537e167 (7.2-rc1) +CVE-2026-64309 [crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5a1364da2f04217a36e2fdfa2db4ee025b383a20 (7.2-rc1) +CVE-2026-64308 [crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f91e9dbb5845d1e5abf1028e6df57dcf61583e1b (7.2-rc1) +CVE-2026-64302 [x86/mm: Fix freeing of PMD-sized vmemmap pages] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/39406c05f8f150f1685839acd38ffdd69ff92031 (7.2-rc1) +CVE-2026-64300 [perf/aux: Fix page UAF in map_range()] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5948aaf64f81f217a25dcc2bf6c0779bca19566c (7.2-rc3) +CVE-2026-64295 [mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/ffd017237cfe99e6e5602ab14179b0e6878a0840 (7.2-rc3) +CVE-2026-64293 [iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/be93d186ae88a92e7aa77e122d4e661fa57b1e39 (7.2-rc1) +CVE-2026-64292 [iommufd: Move vevent memory allocation outside spinlock] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/47443565d10c51366c9382dbc8597cd6c460b8a2 (7.2-rc1) +CVE-2026-64291 [iommufd: Set veventq_depth upper bound] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6ebf2eb46fbd5b40393ff8fbb847ba96925beaff (7.2-rc1) +CVE-2026-64289 [iommufd: Set upper bounds on cache invalidation entry_num and entry_len] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4d70986002f2f3eaaed89124fb2522bded38b016 (7.2-rc1) +CVE-2026-64288 [KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4be6cbeb93d26994bd1827ddbce391e3c4395c8f (7.2-rc1) +CVE-2026-64285 [KVM: SEV: Pin source page for write when adding CPUID data for SNP guest] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f13e900599089b10113ceb36013423f0837c6792 (7.2-rc1) +CVE-2026-64284 [KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/0ffedf43910e44b76c2c1db4e9fbf12b268190c1 (7.2-rc1) +CVE-2026-64282 [KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/9f76b039a72d7e06374aa96862f0232ed53f7787 (7.2-rc1) +CVE-2026-64281 [svcrdma: wake sq waiters when the transport closes] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e5248a7426030db1e126363f72afdb3b71339a5c (7.2-rc1) +CVE-2026-64278 [i2c: imx-lpi2c: mark I2C adapter when hardware is powered down] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/218cfe364b55b2768221629bd4a69ad190b7fbbc (7.2-rc1) +CVE-2026-64267 [fuse: avoid 32-bit prune notification count wrap] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/54243797cedf55447b4c5d560e8cd709900061ae (7.2-rc1) +CVE-2026-64265 [fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f8fce75fedf73ac72aa09163deb8f4291fdcaad2 (7.2-rc1) +CVE-2026-64264 [fuse-uring: fix EFAULT clobber in fuse_uring_commit] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3a0a8bc51a13951c5141262bf770eeea3e0b6228 (7.2-rc1) +CVE-2026-64263 [fuse-uring: fix moving cancelled entry to ent_in_userspace list] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/198f45eeb9f78b2a2d6d8be95e4e43468eb2c6bc (7.2-rc1) +CVE-2026-64262 [fuse-uring: end fuse_req on io-uring cancel task work] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/bea4fe98204b6ce7eb8e29f7bf867dd7619b3ddd (7.2-rc1) +CVE-2026-64261 [fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d351da75066955144515cb2f9aa959f24a04287a (7.2-rc1) +CVE-2026-64260 [fuse-uring: Avoid queue->stopped races and set/read that value under lock] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b70a3aca16934c196f92abb17b01c1647b9bb63c (7.2-rc1) +CVE-2026-64259 [fuse-uring: make a fuse_req on SQE commit only findable after memcpy] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1efd3d474fc0ba74dfd984249bca78807d739812 (7.2-rc1) +CVE-2026-64258 [fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1c57a69be962d459c5e705f5cb4355b841b3461c (7.2-rc1) +CVE-2026-64256 [xfs: don't wrap around quota ids in dqiterate] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/d766e4e5e85d829629c3ba503802fe1303d7b591 (7.2-rc4) +CVE-2026-64514 [userfaultfd: gate must_wait writability check on pte_present()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/8e80af52db652fbc41320eee45a4f73bc029faf2 (7.2-rc1) +CVE-2026-64513 [KVM: x86: Unconditionally recompute CR8 intercept on PPR update] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/bb365a506b1e6fb050c0fceaad354fe395385ef0 (7.2-rc1) +CVE-2026-64512 [ACPI: CPPC: Suppress UBSAN warning caused by field misuse] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1 (7.2-rc1) +CVE-2026-64510 [ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/38bf27511ef41bffebd157ec3eba41fc89ba59cd (7.2-rc1) +CVE-2026-64509 [rust: block: fix GenDisk cleanup paths] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2957771379fa335103a4b539db57bb2271e12142 (7.2-rc1) +CVE-2026-64508 [bpf: Support for hardening against JIT spraying] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/96cce16e26dd02a8678f1e87f88a4b5cdb63b995 (7.2-rc2) +CVE-2026-64507 [x86/bugs: Enable IBPB flush on BPF JIT allocation] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d (7.2-rc2) +CVE-2026-64505 [usb: gadget: function: rndis: add length check for header] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/21b5bf155435008e0fb0736795289788e63d426f (7.2-rc3) +CVE-2026-64504 [iio: accel: bmc150: clamp the device-reported FIFO frame count] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb (7.2-rc3) +CVE-2026-64503 [iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/44a5fd874bb6873bdaec59f722c1d57832fbc9df (7.2-rc3) +CVE-2026-64500 [iio: adc: lpc32xx: Initialize completion before requesting IRQ] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/e561b35633f450ee607e87a6401d97f156a0cd54 (7.2-rc3) +CVE-2026-64497 [iio: chemical: scd30: Cleanup initializations and fix sign-extension bug] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/60d877910a43c305b5165131b258a17b1d772d57 (7.2-rc1) +CVE-2026-64496 [iio: event: Fix event FIFO reset race] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/af791d295737ea6b6ff2c8d8488462a49c14af01 (7.2-rc3) +CVE-2026-64495 [iio: gyro: bmg160: bail out when bandwidth/filter is not in table] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/8320c77e67382d5d55d77043a5f60a867d408a2b (7.2-rc1) +CVE-2026-64494 [iio: light: gp2ap002: fix runtime PM leak on read error] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/38b72267b7e22768a1f26d9935de4e1752a1dc85 (7.2-rc3) +CVE-2026-64493 [iio: pressure: mpl115: fix runtime PM leak on read error] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fbe67ff37a6fd855a6c097f84f3738bd13d0a898 (7.2-rc3) +CVE-2026-64489 [ALSA: ymfpci: check snd_ctl_new1() return value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e64d170346d00b580c0043de3e5ccb3e331c47d4 (7.2-rc1) +CVE-2026-64488 [ALSA: aoa: check snd_ctl_new1() return value] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/8df560fefe6fed6a20b7e06720eeaeccec349ac0 (7.2-rc1) +CVE-2026-64487 [ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd (7.2-rc1) +CVE-2026-64486 [ALSA: cmipci: check snd_ctl_new1() return value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c205bd1b28fb7e5f1061a4e78813fad7d315cb3e (7.2-rc1) +CVE-2026-64484 [ALSA: es1938: check snd_ctl_new1() return value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/1edd1f02dddd20aeb6066ded41017615766ea42f (7.2-rc1) +CVE-2026-64483 [ALSA: firewire: isight: bound the sample count to the packet payload] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/29b9667982e4df2ed7744f86b1144f8bb58eb698 (7.2-rc1) +CVE-2026-64482 [ALSA: gus: check snd_ctl_new1() return value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c7fa99d30c7a166a5e5db5a585ce7501ff68326b (7.2-rc1) +CVE-2026-64481 [ALSA: hda/cs35l41: Fix firmware load work teardown] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b65020d5398f499c09498c9786dba6d67ae57664 (7.2-rc1) +CVE-2026-64480 [ALSA: ice1712: check snd_ctl_new1() return value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2b929b91b0f3bc6de8a844370049cd99ee8e31ff (7.2-rc1) +CVE-2026-64478 [ALSA: usb-audio: avoid kobject path lookup in DualSense match] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7693c0cc415f3a16a7a3355f245474a5e661be4e (7.2-rc1) +CVE-2026-64476 [vfio/pci: Latch disable_idle_d3 per device] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4575e9aac5336d1365138c0284773bf8da4b1fa3 (7.2-rc2) +CVE-2026-64475 [vfio/pci: Release the VGA arbiter client on register_device() failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/daedde7f024ecf88bc8e832ed40cf2c795f0796a (7.2-rc2) +CVE-2026-64472 [vfio/mlx5: Fix racy bitfields and tighten struct layout] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/f2365a63b02ddea32e7db78b742c2503ec7b81f1 (7.2-rc2) +CVE-2026-64471 [Bluetooth: btusb: fix use-after-free on registration failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/eedc6867ebad73edbfaf9a0a65fbef7115cc4753 (7.2-rc1) +CVE-2026-64470 [Bluetooth: btusb: fix use-after-free on marvell probe failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/c5b600a3c05b1a7a110d558df935a8fc8a471c79 (7.2-rc1) +CVE-2026-64469 [binder: fix UAF in binder_thread_release()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/114a116aaa5f0295376cdf12da743c5bce3b20ce (7.2-rc3) +CVE-2026-64468 [binder: fix UAF in binder_free_transaction()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/f223d27a546c1e1f48d38fd67760e78f068fe8c4 (7.2-rc3) +CVE-2026-64465 [usb: xhci: Fix sleep in atomic context in xhci_free_streams()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/42c37c4b75d38b51d84f31a8e29427f5e06a7c2a (7.2-rc3) +CVE-2026-64463 [usb: typec: tcpci_rt1711h: unregister TCPCI port with devres] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/e8da46d99d3710106e7c44db14566bf9b57386b5 (7.2-rc3) +CVE-2026-64462 [PCI: altera: Fix resource leaks on probe failure] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/7a94138caeb27f3c49c1dbd93bf422098925bb28 (7.2-rc1) +CVE-2026-64461 [PCI: mediatek: Fix IRQ domain leak when port fails to enable] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/f865a57896bd92d7662eb2818d8f48872e2cbbc7 (7.2-rc1) +CVE-2026-64458 [mm/damon/ops-common: handle extreme intervals in damon_hot_score()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/35d4a3cf70a855b50e53189ac2f8463e20a02046 (7.2-rc3) +CVE-2026-64456 [hwrng: virtio: clamp device-reported used.len at copy_data()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/e3046eeada299f917a8ad883af4434bfb86556b1 (7.2-rc1) +CVE-2026-64455 [USB: chaoskey: Fix slab-use-after-free in chaoskey_release()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/abf76d3239dee97b66e7241ad04811f1ce562e28 (7.2-rc3) +CVE-2026-64454 [usb: dwc3: run gadget disconnect from sleepable suspend context] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/010382937fb69892b3469ac4d30af072262f59e8 (7.2-rc3) +CVE-2026-64452 [6lowpan: fix NHC entry use-after-free on error path] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/1720db928e5a58ca7d75ac1d514c3b73fd7061a7 (7.2-rc1) +CVE-2026-64450 [tipc: fix out-of-bounds read in broadcast Gap ACK blocks] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/2b66974a1b6134a4bbc3bfed181f7418f688eb54 (7.2-rc2) +CVE-2026-64449 [staging: vme_user: bound slave read/write to the kern_buf size] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/9f32f38265014fac7f5dc9490fb01a638ce6e121 (7.2-rc3) +CVE-2026-64448 [smb: client: restrict implied bcc[0] exemption to responses without data area] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f (7.2-rc3) +CVE-2026-64446 [staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5a752a616e756844388a1a45404db9fc29fec655 (7.2-rc3) +CVE-2026-64445 [staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/a1fc19d61f661d47204f095b593de507884849f7 (7.2-rc3) +CVE-2026-64444 [staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/f9654207e92283e0acac5d64fe5f8835383b5a23 (7.2-rc3) +CVE-2026-64443 [staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/ed51de4a86e173c3b0ef78e039c2e49e08b11f16 (7.2-rc3) +CVE-2026-64442 [staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/ef61d628dfad38fead1fd2e08979ae9126d011d5 (7.2-rc3) +CVE-2026-64441 [staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344 (7.2-rc3) +CVE-2026-64440 [staging: rtl8723bs: fix OOB write in HT_caps_handler()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/f8001e1a516ba3b495728c65b61f799cbfad6bd0 (7.2-rc3) +CVE-2026-64438 [crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/277281c10c63791067d24d421f7c43a15faa9096 (7.2-rc1) +CVE-2026-64437 [ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/10f293a07f9e10e988b0ae44e2e99c631f5a68e0 (7.2-rc1) +CVE-2026-64436 [net: af_key: initialize alg_key_len for IPComp states] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/d129c3177d7b1138fd5066fcc63a698b3ba415b0 (7.2-rc1) +CVE-2026-64435 [audit: Fix data races of skb_queue_len() readers on audit_queue] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7 (7.2-rc3) +CVE-2026-64434 [Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/b66774b48dd98f07254951f74ea6f513efe7ff8b (7.2-rc1) +CVE-2026-64432 [fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/57382ec6ac63b63dce2789e835fded28b698ae79 (7.2-rc1) +CVE-2026-64430 [NTB: epf: Avoid calling pci_irq_vector() from hardirq context] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f (7.2-rc1) +CVE-2026-64429 [gpio: eic-sprd: use raw_spinlock_t in the irq startup path] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/90f0109019e6817eb40a486671b7722d1544ae29 (7.2-rc1) +CVE-2026-64428 [gpio: sch: use raw_spinlock_t in the irq startup path] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/286533cb14a3c8a8bd39ff64ea2fc8e1aa0f638b (7.2-rc1) +CVE-2026-64425 [io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/29bef9934b2521f787bb15dd1985d4c0d12ae02a (7.2-rc1) +CVE-2026-64424 [netpoll: fix a use-after-free on shutdown path] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/45f1458a85017a023f138b22ac5c76abd477db42 (7.2-rc2) +CVE-2026-64423 [ipv4: igmp: remove multicast group from hash table on device destruction] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7993211bde166471dffac074dc965489f86531f8 (7.2-rc3) +CVE-2026-64422 [net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/efb8763d7bbb40cff4cc55a6b62c3095a038149c (7.2-rc1) +CVE-2026-64421 [media: nxp: imx8-isi: Fix use-after-free on remove] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b670bf89824ede5d07d20bb9bfbafb754846081d (7.2-rc1) +CVE-2026-64420 [mfd: cros_ec: Delay dev_set_drvdata() until probe success] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/8b2c1d41bc36c100b38ce5ee6def246c527eaf8a (7.2-rc1) +CVE-2026-64419 [mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/b902890c62d200b3509cb5e09cf1e0a66553c128 (7.2-rc1) +CVE-2026-64417 [mm: shrinker: fix NULL pointer dereference in debugfs] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e30453c61e185e914fde83c650e268067b140218 (7.2-rc3) +CVE-2026-64416 [mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/63b02a9409cb5180398491b093e48bcb5315f5fb (7.2-rc1) +CVE-2026-64413 [netfilter: ebtables: zero chainstack array] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/cbfe53599eebffd188938ab6774cc41794f6f9d5 (7.2-rc3) +CVE-2026-64412 [netfilter: ebtables: module names must be null-terminated] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/084d23f818321390509e9738a0b08bbf46df6425 (7.2-rc3) +CVE-2026-64411 [netfilter: ebtables: terminate table name before find_table_lock()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d (7.2-rc3) +CVE-2026-64409 [Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a257407e2bbbb099ed427719a50563f67fa366d8 (7.2-rc1) +CVE-2026-64408 [Bluetooth: bnep: pin L2CAP connection during netdev registration] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/bb067a99a0356196c0b89a95721985485ebce5a5 (7.2-rc3) +CVE-2026-64406 [Bluetooth: fix UAF in bt_accept_dequeue()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/4bd0b274054f2679f28b70222b607bb0afc3ab9a (7.2-rc3) +CVE-2026-64405 [Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()] + - linux 7.1.4-1 + [bookworm] - linux 6.1.119-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/12917f591cea1af36087dba5b9ec888652f0b42a (7.2-rc3) +CVE-2026-64403 [Bluetooth: L2CAP: validate option length before reading conf opt value] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/687617555cedfb74c9e3cb85d759b908dcb17856 (7.2-rc3) +CVE-2026-64401 [smb: client: resolve SWN tcon from live registrations] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/ec457f9afe5ae9538bdcd58fd4cb442b9787e183 (7.2-rc1) +CVE-2026-64400 [ksmbd: prevent path traversal bypass by restricting caseless retry] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/54bab9ba5a9f156ffa9324fcbe5a356fd0242f95 (7.2-rc1) +CVE-2026-64399 [ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/388e4139db27a9e3612c9d356b826f5b1ff6a9e3 (7.2-rc1) +CVE-2026-64398 [ksmbd: add a permission check for FSCTL_SET_ZERO_DATA] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/3320ba068198adc144c89d6661b805acce01735b (7.2-rc1) +CVE-2026-64397 [ksmbd: serialize QUERY_DIRECTORY requests per file] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/be6d26bf27499977c746abc163659915082348d8 (7.2-rc1) +CVE-2026-64396 [ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e (7.2-rc1) +CVE-2026-64395 [ksmbd: require source read access for duplicate extents] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/cedff600f1642aa982178503552f0d007bc829c8 (7.2-rc1) +CVE-2026-64394 [ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/44df157a1183a7f746caa970c169255da5ac61f8 (7.2-rc1) +CVE-2026-64393 [ksmbd: run set info with opener credentials] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b383bcad3d2fe634b26efbce53e22bbb5753a520 (7.2-rc1) +CVE-2026-64392 [ksmbd: use opener credentials for delete-on-close] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/52e2f21911158ec961cd5aae19c56460db382af0 (7.2-rc1) +CVE-2026-64391 [ksmbd: use opener credentials for ADS I/O] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/baa5e094886fffa7e6272edcb5e08be5ce28262c (7.2-rc1) +CVE-2026-64390 [ksmbd: track the connection owning a byte-range lock] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb (7.2-rc1) +CVE-2026-64389 [ksmbd: validate NTLMv2 response before updating session key] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/954d196bebb2b50151cb96454c72dc113b2af1ac (7.2-rc1) +CVE-2026-64388 [smb/client: fix chown/chgrp with SMB3 POSIX Extensions] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/760ef2c579c2609cf17fb1cd5392f64d42d43d33 (7.2-rc1) +CVE-2026-64381 [smb: client: Fix next buffer leak in receive_encrypted_standard()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b (7.2-rc1) +CVE-2026-64380 [smb: client: harden POSIX SID length parsing] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422 (7.2-rc2) +CVE-2026-64379 [smb: client: mask server-provided mode to 07777 in modefromsid] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/e3d9c7160d483fc8f9e225aafad8ecbbc43f3151 (7.2-rc3) +CVE-2026-64378 [writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d (7.2-rc1) +CVE-2026-64377 [cpufreq: qcom-cpufreq-hw: Fix possible double free] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/bcb8889c4981fdde42d4fd2c29a77d510fe21da2 (7.2-rc1) +CVE-2026-64376 [firmware_loader: fix device reference leak in firmware_upload_register()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/896df22ee57648b0c505bd76ddbc6b2341834696 (7.2-rc1) +CVE-2026-64375 [proc: protect ptrace_may_access() with exec_update_lock (FD links)] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/6255da28d4bb5349fe18e84cb043ccd394eba75d (7.2-rc1) +CVE-2026-64374 [sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/dd29c017aed628076e915fe4cdfb5392fd4c5cab (7.2-rc1) +CVE-2026-64373 [cpufreq: Fix hotplug-suspend race during reboot] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/a9029dd55696c651ee46912afa2a166fa456bb3e (7.2-rc1) +CVE-2026-64372 [cpufreq: pcc: fix use-after-free and double free in _OSC evaluation] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/266d3dd8b757b48a576e90f018b51f7b7563cc32 (7.2-rc1) +CVE-2026-64371 [proc: protect ptrace_may_access() with exec_update_lock (part 1)] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/6650527444dadc63d84aa939d14ecba4fadb2f69 (7.2-rc1) +CVE-2026-64370 [posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/87bd2ad568e15b90d5f7d4bcd70342d05dad649c (7.2-rc1) +CVE-2026-64369 [s390: Revert support for DCACHE_WORD_ACCESS] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/37540b8c287fc817bdbd0c62bb75ad6eab0e5d03 (7.2-rc1) +CVE-2026-64365 [HID: letsketch: fix UAF on inrange_timer at driver unbind] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/46c8beeccd8ab2c863827254a85ea877654a3534 (7.2-rc3) +CVE-2026-64364 [HID: multitouch: fix out-of-bounds bit access on mt_io_flags] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/8813b0612275cc61fe9e6603d0ee019247ade6be (7.2-rc3) +CVE-2026-64363 [HID: appleir: fix UAF on pending key_up_timer in remove()] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/75fe87e19d8aff81eb2c64d15d244ab8da4de945 (7.2-rc3) +CVE-2026-64362 [HID: lg-g15: cancel pending work on remove to fix a use-after-free] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7705b4140d188ce22656f6e541ae7ef834c7e11a (7.2-rc3) +CVE-2026-64361 [hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/966cb76fb2857a4242cab6ea2ea17acf818a3da7 (7.2-rc1) +CVE-2026-64360 [hfs/hfsplus: zero-initialize buffer in hfs_bnode_read] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf (7.2-rc1) +CVE-2026-64359 [nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9 (7.2-rc1) +CVE-2026-64355 [bpf: Reject fragmented frames in devmap] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/aa496720618f1a6054f1c870bf10b4f6c99bf656 (7.2-rc1) +CVE-2026-64352 [bpf: Allow LPM map access from sleepable BPF programs] + - linux 7.1.4-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/2f884d371fafea137afea504d49ee4a7c8d7985b (7.2-rc1) +CVE-2026-64351 [net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/47b6bcef6e679593d2e86e04ee72c46a4e2f7139 (7.2-rc1) +CVE-2026-64350 [usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64 (7.2-rc3) +CVE-2026-64348 [usb: free iso schedules on failed submit] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b9399d25fbb34a05bbe76eeedd730f62ff2670e9 (7.2-rc3) +CVE-2026-64347 [usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/f8f680609c2b3ab795ffcd6f21585b6dfc46d395 (7.2-rc3) +CVE-2026-64346 [usb: gadget: udc: Fix use-after-free in gadget_match_driver] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea (7.2-rc3) +CVE-2026-64345 [usb: gadget: f_printer: take kref only for successful open] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/30adce93d5c4a5a1ec29d9249e3fdfcc391d406b (7.2-rc3) +CVE-2026-64344 [USB: idmouse: fix use-after-free on disconnect race] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/ff002c153f9722caece3983cc23dc4d9d4652cb4 (7.2-rc3) +CVE-2026-64343 [USB: ldusb: fix use-after-free on disconnect race] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/19bdfc7b3c179331eafa423d87e1336f43bbfeb8 (7.2-rc3) +CVE-2026-64342 [USB: iowarrior: fix use-after-free on disconnect] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/bc0e4f16c44e50daa0b1ea729934baa3b4815dee (7.2-rc3) +CVE-2026-64341 [USB: iowarrior: fix use-after-free on disconnect race] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/c602254ba4c10f60a73cd99d147874f86a3f485c (7.2-rc3) +CVE-2026-64340 [USB: legousbtower: fix use-after-free on disconnect race] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/62fc8eb1b1481051f7bab4aa93d79809053dd09f (7.2-rc3) +CVE-2026-64338 [USB: misc: uss720: unregister parport on probe failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3 (7.2-rc3) +CVE-2026-64337 [usb: mtu3: unmap request DMA on queue failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/0bddda5a11665c210339de76d27ebbd1a2e0b43c (7.2-rc3) +CVE-2026-64336 [USB: serial: keyspan_pda: fix information leak] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6bfc8d01ac4068eced509f8fc74d0cd205e4dcec (7.2-rc3) +CVE-2026-64335 [USB: serial: digi_acceleport: fix broken rx after throttle] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/83a3dfc018943b05b6daf3a6f891833e1aabfa1f (7.2-rc3) +CVE-2026-64334 [USB: serial: digi_acceleport: fix hard lockup on disconnect] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5c1ea24b53bf3bfb859f0a05573997487975da23 (7.2-rc3) +CVE-2026-64333 [USB: serial: digi_acceleport: fix write buffer corruption] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65 (7.2-rc3) +CVE-2026-64332 [USB: ulpi: fix memory leak on registration failure] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/8af6812795869a66e9b26044f455b13deecdb69c (7.2-rc3) +CVE-2026-64331 [usbip: vudc: fix NULL deref in vep_dequeue()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a (7.2-rc3) +CVE-2026-64330 [usb: typec: tcpm: Validate SVID index in svdm_consume_modes()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7b681dd5fbf60b24a13c14661e5b7735759fb491 (7.2-rc3) +CVE-2026-64329 [usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/1f0bdc2884b67de337215079bba166df0cdf4ac5 (7.2-rc3) +CVE-2026-64325 [wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon] + - linux 7.1.4-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/351dd7d2c80d23e56dcce6faa4e62bea5b0877c7 (7.2-rc1) +CVE-2026-64324 [udf: validate free block extents against the partition length] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5f0419457f89dce1a3f1c8e62a3adf2f39ab8168 (7.2-rc1) +CVE-2026-64323 [udf: validate VAT header length against the VAT inode size] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/d8202786b3d75125c84ebc4de6d946f92fde0ee8 (7.2-rc1) +CVE-2026-64322 [udf: validate sparing table length as an entry count, not a byte count] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/3ec997bd5508e9b25210b5bbec89031629cdb093 (7.2-rc1) +CVE-2026-64320 [nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/53cd102a7a56079b11b897835bd9b94c14e6322c (7.2-rc1) +CVE-2026-64319 [nvmet-auth: validate reply message payload bounds against transfer length] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3a413ece2504c70aa34a20be4dafec04e8c741f9 (7.2-rc1) +CVE-2026-64318 [partitions: aix: bound the pp_count scan to the ppe array] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 (7.2-rc1) +CVE-2026-64317 [isofs: bound Rock Ridge symlink components to the SL record] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5fa1d6a5ec2356d2107dead614437c66fa7138b1 (7.2-rc1) +CVE-2026-64316 [crypto: caam - use print_hex_dump_devel to guard key hex dumps] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/3f57657b6ea23f933371f2c2846322f441773cee (7.2-rc1) +CVE-2026-64315 [crypto: caam - use print_hex_dump_devel to guard key hex dumps] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/8005dc808bcce7d6cc2ae015a3cde1683bee602d (7.2-rc1) +CVE-2026-64313 [crypto: ecc - Fix carry overflow in vli multiplication] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 (7.2-rc1) +CVE-2026-64312 [crypto: pcrypt - restore callback for non-parallel fallback] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/ed459fe319376e876de433d12b6c6772e612ca36 (7.2-rc1) +CVE-2026-64307 [crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/08f0e65e784c4b20e6e620dd4f68d8636073a3d2 (7.2-rc1) +CVE-2026-64306 [crypto: drbg - Fix returning success on failure in CTR_DRBG] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b (7.2-rc1) +CVE-2026-64305 [crypto: qat - protect service table iterations with service_lock] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e (7.2-rc1) +CVE-2026-64304 [crypto: qat - validate RSA CRT component lengths] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b3ac78756588059729b9195fcc9f4b37d54057a5 (7.2-rc1) +CVE-2026-64303 [spi: fsl-lpspi: terminate the RX channel on TX prepare failure path] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/01980b5da56e573d62798d0ff6c86bcaa2b22cbe (7.2-rc1) +CVE-2026-64301 [regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/fa11039d6cdff84584a3ef8cc1f5e1b56e045da2 (7.2-rc1) +CVE-2026-64299 [tracing: Prevent out-of-bounds read in glob matching] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/0a6070839b1ef276d5b05bedfb787743e140fb17 (7.2-rc3) +CVE-2026-64298 [NFSv4: include MAY_WRITE in open permission mask for O_TRUNC] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5140f099ecd8a2f2808b7f7b720ee1bad8468974 (7.2-rc3) +CVE-2026-64297 [module: decompress: check return value of module_extend_max_pages()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/786d2d84416a9a1c1a47b71a68d679d886284be2 (7.2-rc1) +CVE-2026-64296 [exfat: bound uniname advance in exfat_find_dir_entry()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/3a1230e7b043c62737b05a3e9275ca83a43ad20a (7.2-rc1) +CVE-2026-64294 [mm: do file ownership checks with the proper mount idmap] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e187bc02f8fa4226d62814592cf064ee4557c470 (7.2-rc3) +CVE-2026-64290 [iommufd: Break the loop on failure in iommufd_fault_fops_read()] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/172fc8b19825a0f5884c38f2289188284e2d45ee (7.2-rc1) +CVE-2026-64287 [KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8cc8bbbfab14c22c5551d0dd19b208a44b141c76 (7.2-rc1) +CVE-2026-64286 [KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/e8042f6e1d7befb2fb6b10a75918642bcd0acf9a (7.2-rc1) +CVE-2026-64283 [KVM: guest_memfd: Treat memslot binding offset+size as unsigned values] + - linux 7.1.4-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6 (7.2-rc1) +CVE-2026-64280 [fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()] + - linux 7.1.4-1 + NOTE: https://git.kernel.org/linus/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27 (7.2-rc1) +CVE-2026-64279 [i2c: core: fix adapter deregistration race] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f (7.2-rc1) +CVE-2026-64277 [Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/57c10915f2c16c90e0d46ad00876bf39ece40fc2 (7.2-rc1) +CVE-2026-64276 [Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/d577e46785d45484b2ab7e7309c49b18764bf56c (7.2-rc1) +CVE-2026-64275 [Input: elan_i2c - prevent division by zero and arithmetic underflow] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/df2b818fa009c10ff6ba875a1663ff001cda9558 (7.2-rc1) +CVE-2026-64274 [Input: goodix - clamp the device-reported contact count] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/5ed62a96e06be4e94b8296b7932afee550a70e04 (7.2-rc1) +CVE-2026-64273 [Input: iforce - bound the device-reported force-feedback effect index] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2 (7.2-rc1) +CVE-2026-64272 [Input: mms114 - fix touch indexing for MMS134S and MMS136] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d (7.2-rc1) +CVE-2026-64271 [Input: touchwin - reset the packet index on every complete packet] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/478cdd736f2ce3114f90e775d7358136d3977b94 (7.2-rc1) +CVE-2026-64270 [Input: mms114 - reject an oversized device packet size] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/66725039f7090afe14c31bd259e2059a68f04023 (7.2-rc1) +CVE-2026-64269 [RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/963af8d97a8c6a117134a8d0db1415e0489200b1 (7.2-rc1) +CVE-2026-64268 [RDMA/siw: bound Read Response placement to the RREAD length] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/7d29f7e9dbd844cae4d3e559cf78324b9642fd6b (7.2-rc1) +CVE-2026-64266 [fuse: re-lock request before returning from fuse_ref_folio()] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/b5befa80fdbe287a98480effed9564712924add5 (7.2-rc1) +CVE-2026-64257 [smb: client: reject overlapping data areas in SMB2 responses] + - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4) CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...) TODO: check CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76f6abc9dad91654f846602a79f930d53c7e6bb3 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76f6abc9dad91654f846602a79f930d53c7e6bb3 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
