[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 16:44:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
75a8f044 by Salvatore Bonaccorso at 2026-08-05T17:43:42+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,67 @@
+CVE-2026-64575 [bpf: tcp: fix double sock release on batch realloc]
+	- linux 7.1.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/980a813452754f8001704744e92f7aa697c53dd3 (7.2-rc5)
+CVE-2026-64566 [xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()]
+	- linux 7.1.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/430ea57d6daf765e88f90046afbfd1e071cb7200 (7.2-rc4)
+CVE-2026-64581 [xfrm: fix sk_dst_cache double-free in xfrm_user_policy()]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/c283e9ada7fcb7dd4b10592623086b2e6d2f9925 (7.2-rc4)
+CVE-2026-64580 [xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/136992de9bb91871084ae52d172610541c76e4d2 (7.2-rc4)
+CVE-2026-64579 [xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4 (7.2-rc4)
+CVE-2026-64578 [ksmbd: validate compound request size before reading StructureSize2]
+	- linux 7.1.6-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/15b38176fd1530372905c602fde51fe89ec8c877 (7.2-rc4)
+CVE-2026-64577 [gtp: check skb_pull_data() return in gtp1u_send_echo_resp()]
+	- linux 7.1.6-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cd170f051dba9ac146fabcd1b91726487c0cb9fa (7.2-rc5)
+CVE-2026-64576 [nexthop: initialize extack in nh_res_bucket_migrate()]
+	- linux 7.1.6-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6347c5314cee49f364aaf2e40ff15415a57a116e (7.2-rc5)
+CVE-2026-64574 [wifi: mac80211: tear down new links on vif update error path]
+	- linux 7.1.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/952c02b33f56207a160421bcd61e7ac53c9c59ae (7.2-rc5)
+CVE-2026-64573 [Bluetooth: qca: fix NVM tag length underflow in TLV parser]
+	- linux 7.1.6-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c90164ca0f7036942ba088eb7ea8d3f6c2352020 (7.2-rc4)
+CVE-2026-64572 [ipv4: fib: free fib_alias with kfree_rcu() on insert error path]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/f2f152e94a67bc746afaf05a1b2702c195553112 (7.2-rc4)
+CVE-2026-64571 [wifi: p54: validate RX frame length in p54_rx_eeprom_readback()]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea (7.2-rc4)
+CVE-2026-64570 [wifi: mac80211: fix fils_discovery double free on alloc failure]
+	- linux 7.1.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/286e52a799fa158bdbd77da1426c4d93f9a6e7ad (7.2-rc4)
+CVE-2026-64569 [mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/56d96fededd61192cd7cc8d2b0f36adfd59036c3 (7.2-rc4)
+CVE-2026-64568 [wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure]
+	- linux 7.1.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1d067abcd37062426c59ec73dbc4e87a63f33fea (7.2-rc4)
+CVE-2026-64567 [btrfs: reject free space cache with more entries than pages]
+	- linux 7.1.6-1
+	NOTE: https://git.kernel.org/linus/a2d8d5647ed854e38f941741aea45b9eb15a6350 (7.2-rc4)
 CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for WordPress  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to Reflected Cros ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75a8f04477fc22dc06c3396a3ea0d7334cbf0149

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75a8f04477fc22dc06c3396a3ea0d7334cbf0149
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/0bc8c2cb/attachment.htm>


More information about the debian-security-tracker-commits mailing list