Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 9b34479d by Salvatore Bonaccorso at 2026-08-12T07:36:41+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,103 @@ +CVE-2026-68443 [hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/ff0c5c53d08274e200b48a4d53aa078265e873cb (7.2-rc5) +CVE-2026-68442 [btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/5eff4d5b17fa1950e80bfd1ba43dc0699e61a644 (7.2-rc5) +CVE-2026-68440 [net: txgbe: fix heap overflow when reading module EEPROM] + - linux 7.1.6-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6a905a71fd43ce8b45f05044b11491337f232c9d (7.2-rc5) +CVE-2026-68439 [wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8d1b6738c1ab48c086b17e7994034aca94258931 (7.2-rc5) +CVE-2026-68438 [smp: Make CSD lock acquisition atomic for debug mode] + - linux 7.1.6-1 + [trixie] - linux <not-affected> (Vulnerable code not present) + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/35551efb155e3b83445a6c3f66cb498d5efc182c (7.2-rc5) +CVE-2026-68437 [drm/imagination: Fit paired fragment job in the correct CCCB] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/4baf9e70cb756d78dd56419f8baee2978a72d0c3 (7.2-rc1) +CVE-2026-68429 [drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bookworm] - linux <not-affected> (Vulnerable code not present) + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/613059875958e7b217b250ed14c3b189f9488421 (7.2-rc2) +CVE-2026-68450 [btrfs: free mapping node on duplicate reloc root insert] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6a8269b6459ed870a8156c106a0f597383907872 (7.2-rc5) +CVE-2026-68449 [ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/c2130f6553f4a5cbdc259de069600117a995f197 (7.2-rc4) +CVE-2026-68448 [ovl: check access to copy_file_range source with src mounter creds] + - linux 7.1.6-1 + NOTE: https://git.kernel.org/linus/a1e0eb8f55cfe09bb31a202a388babc411292656 (7.2-rc5) +CVE-2026-68447 [drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size] + - linux 7.1.6-1 + NOTE: https://git.kernel.org/linus/426ffae6ecc7ec77d32bf8be065c21a1b881b084 (7.2-rc2) +CVE-2026-68446 [drm/vmwgfx: Validate vmw_surface_metadata::array_size] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991 (7.2-rc5) +CVE-2026-68445 [drm/vc4: Prevent shader BO mappings from becoming writable] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/0c9e6367639548307d3f578f6943ce72c9d39087 (7.2-rc5) +CVE-2026-68444 [firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8 (7.2-rc4) +CVE-2026-68441 [net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains] + - linux 7.1.6-1 + NOTE: https://git.kernel.org/linus/ec48b3be2c8595dd290be883dbd4fb8b2f9f5d5e (7.2-rc5) +CVE-2026-68436 [drm/amd/display: use kvzalloc to allocate struct dc] + - linux 7.1.6-1 + NOTE: https://git.kernel.org/linus/75050390151a14802be433c3856ddcb483cecd24 (7.2-rc2) +CVE-2026-68435 [LoongArch: Fix address space mismatch in kexec command line lookup] + - linux 7.1.6-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/485ed44db5694d8d2e5027f63ad608e705286f30 (7.2-rc5) +CVE-2026-68434 [serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/7fb13fd7e9a59a37cd911efff83abe19e3ee029d (7.2-rc5) +CVE-2026-68433 [libceph: bound get_version reply decode to front len] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 (7.2-rc5) +CVE-2026-68432 [vxlan: require CAP_NET_ADMIN in the device netns for changelink] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e (7.2-rc5) +CVE-2026-68431 [ksmbd: validate minimum PDU size for transform requests] + - linux 7.1.6-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/cfc0b8e5080aec87700774e8568765eaa4b7b92b (7.2-rc5) +CVE-2026-68430 [drm/amdgpu/gfx8: drop unecessary BUG_ON()] + - linux 7.1.6-1 + [trixie] - linux 6.12.101-1 + NOTE: https://git.kernel.org/linus/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5 (7.2-rc2) CVE-2026-19556 - chromium <unfixed> [bullseye] - chromium <end-of-life> (see #1061268) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9b34479d354352105b32ff35333485e4e8f8eab7 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9b34479d354352105b32ff35333485e4e8f8eab7 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
