[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 10 18:01:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
de094360 by Salvatore Bonaccorso at 2026-08-10T16:03:28+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,51 @@
+CVE-2026-68092 [time/jiffies: Register jiffies clocksource before usage]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.100-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f24df84cbe05e4471c04ac4b921fc0340bbc7752 (7.2-rc1)
+CVE-2026-68091 [HID: wacom: stop hardware after post-start probe failures]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/ec2612b8ad9e642596db011dd8b6568ef1edeaa1 (7.2-rc1)
+CVE-2026-68090 [debugobjects: Plug race against a concurrent OOM disable]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/b81dde13cc163450dcb402dcc915ef13ba241e01 (7.2-rc1)
+CVE-2026-68089 [iio: core: fix uninitialized data in debugfs]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ab92ed206d41fd171ebd37bc46360d9f2140d043 (7.2-rc1)
+CVE-2026-68088 [usb: gadget: function: rndis: add length check to response query]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	[bullseye] - linux 5.10.262-1
+	NOTE: https://git.kernel.org/linus/95f90eea070837f7c72207d5520f805bdefc3bc5 (7.2-rc3)
+CVE-2026-68087 [HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()]
+	- linux 7.1.4-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/55f1ad573e34abf9a0443c34bc5a63d74edba7d7 (7.2-rc1)
+CVE-2026-68086 [mm/khugepaged: write all dirty file folios when collapsing]
+	- linux 7.1.4-1
+	NOTE: https://git.kernel.org/linus/
+CVE-2026-68085 [Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	NOTE: https://git.kernel.org/linus/1b0d946d6f08bd39211385bc703a440911b41e46 (7.2-rc3)
+CVE-2026-68084 [staging: vme_user: fix location monitor leak in tsi148 bridge]
+	- linux 7.1.4-1
+	[trixie] - linux 6.12.96-1
+	[bookworm] - linux 6.1.180-1
+	NOTE: https://git.kernel.org/linus/151edde741f8bc7f2931c5f44ab376d32b0c8beb (7.2-rc3)
 CVE-2026-68083 [ksmbd: fix path resolution in ksmbd_vfs_kern_path_create]
 	- linux 7.1.5-1
 	[trixie] - linux 6.12.100-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de094360d841c5598fc7b5b3d44123505fa2214f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de094360d841c5598fc7b5b3d44123505fa2214f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/b86b2265/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list