[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Mar 26 19:34:57 GMT 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
27b6bbbc by Salvatore Bonaccorso at 2024-03-26T20:34:23+01:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,59 @@
+CVE-2024-26650 [platform/x86: p2sb: Allow p2sb_bar() calls during PCI device probe]
+ - linux 6.6.15-1
+ [bookworm] - linux 6.1.76-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ [buster] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5913320eb0b3ec88158cfcb0fa5e996bf4ef681b (6.8-rc2)
+CVE-2024-26649 [drm/amdgpu: Fix the null pointer when load rlc firmware]
+ - linux 6.6.15-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ [buster] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bc03c02cc1991a066b23e69bbcc0f66e8f1f7453 (6.8-rc1)
+CVE-2024-26648 [drm/amd/display: Fix variable deferencing before NULL check in edp_setup_replay()]
+ - linux 6.6.15-1
+ NOTE: https://git.kernel.org/linus/7073934f5d73f8b53308963cee36f0d389ea857c (6.8-rc1)
+CVE-2024-26647 [drm/amd/display: Fix late derefrence 'dsc' check in 'link_set_dsc_pps_packet()']
+ - linux 6.6.15-1
+ NOTE: https://git.kernel.org/linus/3bb9b1f958c3d986ed90a3ff009f1e77e9553207 (6.8-rc1)
+CVE-2024-26646 [thermal: intel: hfi: Add syscore callbacks for system-wide PM]
+ - linux 6.6.15-1
+ [bookworm] - linux 6.1.76-1
+ NOTE: https://git.kernel.org/linus/97566d09fd02d2ab329774bb89a2cdf2267e86d9 (6.8-rc1)
+CVE-2024-26645 [tracing: Ensure visibility when inserting an element into tracing_map]
+ - linux 6.6.15-1
+ [bookworm] - linux 6.1.76-1
+ NOTE: https://git.kernel.org/linus/2b44760609e9eaafc9d234a6883d042fc21132a7 (6.8-rc2)
+CVE-2024-26644 [btrfs: don't abort filesystem when attempting to snapshot deleted subvolume]
+ - linux 6.6.15-1
+ [bookworm] - linux 6.1.76-1
+ NOTE: https://git.kernel.org/linus/7081929ab2572920e94d70be3d332e5c9f97095a (6.8-rc2)
+CVE-2023-52627 [iio: adc: ad7091r: Allow users to configure device events]
+ - linux 6.6.15-1
+ [bookworm] - linux 6.1.76-1
+ [buster] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/020e71c7ffc25dfe29ed9be6c2d39af7bd7f661f (6.8-rc1)
+CVE-2023-52626 [net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context]
+ - linux 6.6.15-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ [buster] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3876638b2c7ebb2c9d181de1191db0de8cac143a (6.8-rc2)
+CVE-2023-52625 [drm/amd/display: Refactor DMCUB enter/exit idle interface]
+ - linux 6.7.7-1
+ NOTE: https://git.kernel.org/linus/8e57c06bf4b0f51a4d6958e15e1a99c9520d00fa (6.8-rc1)
+CVE-2023-52624 [drm/amd/display: Wake DMCUB before executing GPINT commands]
+ - linux 6.7.7-1
+ NOTE: https://git.kernel.org/linus/e5ffd1263dd5b44929c676171802e7b6af483f21 (6.8-rc1)
+CVE-2023-52623 [SUNRPC: Fix a suspicious RCU usage warning]
+ - linux 6.7.7-1
+ NOTE: https://git.kernel.org/linus/31b62908693c90d4d07db597e685d9f25a120073 (6.8-rc1)
+CVE-2023-52622 [ext4: avoid online resizing failures due to oversized flex bg]
+ - linux 6.7.7-1
+ NOTE: https://git.kernel.org/linus/5d1935ac02ca5aee364a449a35e2977ea84509b0 (6.8-rc1)
+CVE-2023-52621 [bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers]
+ - linux 6.7.7-1
+ NOTE: https://git.kernel.org/linus/169410eba271afc9f0fb476d996795aa26770c6d (6.8-rc1)
CVE-2024-29735
- airflow <itp> (bug #819700)
CVE-2024-2889 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27b6bbbcf993dd5aea53fc23e9d6ea6bfa70c6f3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27b6bbbcf993dd5aea53fc23e9d6ea6bfa70c6f3
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240326/cab6f183/attachment.htm>
More information about the debian-security-tracker-commits
mailing list