[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 08:55:00 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c965fa47 by Salvatore Bonaccorso at 2026-08-06T09:54:52+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,97 @@
+CVE-2026-64604 [KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/7ef78d71ca713d8c00f7c34ddcf276c808143f77 (7.2-rc1)
+CVE-2026-64603 [platform/x86: intel-hid: Protect ACPI notify handler against recursion]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c085d82613d5618814b84406c8b2d64f1bc305e7 (7.2-rc1)
+CVE-2026-64602 [iio: adc: spear: Initialize completion before requesting IRQ]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0 (7.2-rc3)
+CVE-2026-64601 [ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5cff1529a2f9b3461a7f5a6e36a86682fc290534 (7.2-rc2)
+CVE-2026-64599 [crypto: amlogic - avoid double cleanup in meson_crypto_probe()]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/6d827ade51a24e18d81afb9f32756d339520a14c (7.2-rc1)
+CVE-2026-64598 [smb/client: Fix error code in smb2_aead_req_alloc()]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/61f28012e5650c619223decdb7970e0d3162e949 (7.2-rc1)
+CVE-2026-64597 [smb: client: fix double-free in SMB2_close() replay]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f96e1cdcb63ed3321142ff2fcdf784e32cda8fee (7.2-rc1)
+CVE-2026-64596 [libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6de2aeffabaafaeda819e60ec8d04f199711e11a (7.2-rc1)
+CVE-2026-64595 [HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/73fde0cbff7d9d618591774a12c23434232752c1 (7.2-rc1)
+CVE-2026-64594 [usb: gadget: f_fs: initialize reset_work at allocation time]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.100-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/3137b243c93982fe3460335e12f9247739766e10 (7.2-rc3)
+CVE-2026-64593 [btrfs: do not trim a device which is not writeable]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/1b1937eb08f51319bf71575484cde2b8c517aedc (7.2-rc1)
+CVE-2026-64592 [riscv: mm: Unconditionally sfence.vma for spurious fault]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1b2c6b56a9fa0dcbef461039937de22b1cbecc7d (7.2-rc1)
+CVE-2026-64591 [iommu/vt-d: Avoid WARNING in sva unbind path]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/534b5f98ab7319d8004bbc7dab6481462243e883 (7.2-rc1)
+CVE-2026-64589 [i2c: core: fix NULL-deref on adapter registration failure]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2295d2bb101faa663fbc45fadbb3fec45f107441 (7.2-rc1)
+CVE-2026-64588 [fuse-uring: fix data races on ring->ready]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/46725a0056c884cf58a6897f222892807327d82d (7.2-rc1)
+CVE-2026-64590 [dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	NOTE: https://git.kernel.org/linus/504e2b4ab97a51d56d966cd36d0997ad30b65b2d (7.2-rc1)
 CVE-2026-64587 [net: ethernet: arc: emac: quiesce interrupts before requesting IRQ]
 	- linux 6.19.10-1
 	[trixie] - linux 6.12.85-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c965fa4736d49e778d4b4dd4a656debec913fb39

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c965fa4736d49e778d4b4dd4a656debec913fb39
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/55826557/attachment.htm>


More information about the debian-security-tracker-commits mailing list