[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 10 18:01:32 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ffb32b0e by Salvatore Bonaccorso at 2026-08-10T16:09:21+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,1572 @@
+CVE-2026-68424 [mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/75c0c09541b49daa08fddbc2c18c2232f4eab7d8 (7.2-rc4)
+CVE-2026-68423 [mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4b45d7836b9526b8776af5f29219615be9417230 (7.2-rc4)
+CVE-2026-68420 [xfrm: reject optional IPTFS templates in outbound policies]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ea528f18231ec0f33317be57f8866913b19aba6e (7.2-rc4)
+CVE-2026-68419 [RDMA/irdma: Prevent rereg_mr for non-mem regions]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a846aecb931b4d65d5eafa92a0623545af46d4f2 (7.2-rc4)
+CVE-2026-68416 [mtd: fix double free and WARN_ON in add_mtd_device() error paths]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9d4af746af8ce27eefc2338b2feaa1e01f28b6c3 (7.2-rc4)
+CVE-2026-68415 [xfrm: clear mode callbacks after failed mode setup]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2538bd3cd1ff5af655908469544ac7b7ae259386 (7.2-rc4)
+CVE-2026-68394 [Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2bf282f8f715f5d05d6f4c49ffb3bd241c5e667e (7.2-rc4)
+CVE-2026-68392 [Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/16cd66443957e4ad42155c6fec401012f600c6f8 (7.2-rc4)
+CVE-2026-68390 [Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c363202ec841df36421ec280eea3d5f94f556143 (7.2-rc4)
+CVE-2026-68389 [Bluetooth: hci_qca: Clear memdump state on invalid dump size]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bf587a10c33e5571a299742e45bc18960b9912e7 (7.2-rc4)
+CVE-2026-68387 [can: raw: add locking for raw flags bitfield]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1e5185c090589f4146d728ab36417d8a5419f127 (7.2-rc4)
+CVE-2026-68385 [s390/checksum: Fix csum_partial() without vector facility]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4bb06b60d982355e22647b3d12d6619419f8c1fa (7.2-rc4)
+CVE-2026-68384 [drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/56441f9e08ad68697295b8835266d2bc48ab59b5 (7.2-rc4)
+CVE-2026-68381 [ksmbd: pin conn during async oplock break notification]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9 (7.2-rc4)
+CVE-2026-68380 [accel/amdxdna: Fix use-after-free of mm_struct in job scheduler]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/faebb7ba1ac65fa5810b640df02ce04e509fdc11 (7.2-rc4)
+CVE-2026-68379 [tcp: fix TIME_WAIT socket reference leak on PSP policy failure]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2c1931a81122c3cdc4c89448fe0442c69e21c0d5 (7.2-rc4)
+CVE-2026-68378 [dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d2e914a4a0d0f753dbae830264850d044026167c (7.2-rc4)
+CVE-2026-68372 [usb: core: port: Deattach Type-C connector on component unbind]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e0b291fe117964037e0ba382eff4bb365d531c3a (7.2-rc5)
+CVE-2026-68358 [hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f151d0143ac4e086f92f52328ebdbdc50933d8ef (7.2-rc5)
+CVE-2026-68356 [watchdog: airoha: Prevent division by zero when clock frequency is zero]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bcfcd7619f277842430d197556463b401b839ee9 (7.2-rc5)
+CVE-2026-68348 [ASoC: tas2781: bound firmware description string parsing]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bc889dfcea9294a1eae7f8e2f3573a90764ae4d0 (7.2-rc5)
+CVE-2026-68347 [iommu/amd: Fix IRQ unsafe locking in gdom allocation]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0db3a430d9681fdb29890bef6934cd89cd1745d0 (7.2-rc5)
+CVE-2026-68346 [ALSA: hda: cs35l41: validate and free ACPI mute object]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3b597d24dc0455ae926f1053f97c2725038fc3cd (7.2-rc5)
+CVE-2026-68345 [arm_mpam: guard MBWU state before adding it to garbage]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/977f52909c624210178a1247fab0b02b110c1106 (7.2-rc5)
+CVE-2026-68342 [ovpn: avoid putting unrelated P2P peer on socket release]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b52c5103f64ee825996ca1ab8df7283cde8c5f86 (7.2-rc5)
+CVE-2026-68341 [ovpn: fix use after free in unlock_ovpn()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e1ad6fe5db719874efa45b2caf9934552e09fc43 (7.2-rc5)
+CVE-2026-68339 [Bluetooth: btusb: validate Realtek vendor event length]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/df541cd485ff80a5ddc579d99687bc7506df9851 (7.2-rc5)
+CVE-2026-68334 [rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/745fb794c3e933c023af9dbb5876a5e16ad2dc71 (7.2-rc5)
+CVE-2026-68332 [net: airoha: Fix potential use-after-free in airoha_ppe_deinit()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2484568a335cd7bda951c75b3a7d95ea36161ae7 (7.2-rc5)
+CVE-2026-68330 [net: airoha: Fix DMA direction for NPU mailbox buffer]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6f884eb87a79e0c482baef2ad96c96b81d024235 (7.2-rc5)
+CVE-2026-68321 [net: txgbe: fix FDIR filter leak on remove]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ecaa37826340520664a4e5522f803ff48fc3f564 (7.2-rc5)
+CVE-2026-68319 [pds_core: fix deadlock between reset thread and remove]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ab0eec0ff0a421737a37f510ceab5c6ea59cd05a (7.2-rc5)
+CVE-2026-68317 [pds_core: fix auxiliary device add/del races]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bfa33cd513c7ceb93c5a4c30e5662acd73c0a916 (7.2-rc5)
+CVE-2026-68316 [accel: ethosu: Fix element size accounting for cmd stream validation]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/18a551482a4a326790698b273e76d7575a51a57d (7.2-rc5)
+CVE-2026-68314 [net: mctp i3c: clean up notifier and buses if driver register fails]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/03d1057305ef17ac3f5936ac1580bc9a1a826e14 (7.2-rc5)
+CVE-2026-68311 [wifi: mt76: mt7925: guard link STA in decap offload]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/96ea44f2269f30364cffa054ee3a87e595bef0d4 (7.2-rc5)
+CVE-2026-68308 [wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e858cf6bf99880343348ff1e8c942aaff1d9d592 (7.2-rc5)
+CVE-2026-68307 [wifi: mt76: mt7925: fix crash in reset link replay]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bd8b2ec838184236c3fcbf738a926328836adf12 (7.2-rc5)
+CVE-2026-68306 [wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2fffc472bec490c8357defcee9c075ca74467352 (7.2-rc5)
+CVE-2026-68298 [drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d2c6800ad1802bed72a6de1416536737f114f1d6 (7.2-rc5)
+CVE-2026-68296 [net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/675ed582c1aa4d919dd535490de08c015005c653 (7.2-rc5)
+CVE-2026-68292 [ice: prevent tstamp ring allocation for non-PF VSI types]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/144539bbfd3cea1ab0fb6f5216d6004c1f4f029b (7.2-rc5)
+CVE-2026-68290 [rds: tcp: unregister sysctl before tearing down listen socket]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/167e54c703ccd4fa028feb568b0d1002020cff86 (7.2-rc5)
+CVE-2026-68285 [LoongArch: BPF: Fix memory leak in bpf_jit_free()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/47e20d4b3da97ef3881d1e55e43545c22424f3fc (7.2-rc5)
+CVE-2026-68283 [tracing: Fix use-after-free freeing trigger private data]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/79097812153b826fc156a2930ec8a90ed9edf4a2 (7.2-rc5)
+CVE-2026-68282 [drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/45895f4d4d5f222d07412f90664f88b059627859 (7.2-rc1)
+CVE-2026-68281 [drm/imagination: Count paired job fence as dependency in prepare_job()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9cd74f935306cd857f46686975c43383e1d95f94 (7.2-rc1)
+CVE-2026-68275 [drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/93475c34111916df71c63e510fc52db01351f809 (7.2-rc1)
+CVE-2026-68274 [drm/xe/guc: Fix buffer overflow in steered register list allocation]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0 (7.2-rc1)
+CVE-2026-68272 [drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/84c4c36acd5c4b2558b5069f869a165b2c655c84 (7.2-rc1)
+CVE-2026-68271 [drm/nouveau: fix reversed error cleanup order in ucopy functions]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ab99ead646b1b833ecd57fe577a2816f2e848167 (7.2-rc1)
+CVE-2026-68270 [drm/sysfb: Avoid possible truncation with calculating visible size]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b771974988ec7ce077a7246fa0fa588c246fe581 (7.2-rc1)
+CVE-2026-68268 [drm/xe: Return error on non-migratable faults requiring devmem]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/136fb61ba8571076dc5d49350a0e6d002d740b74 (7.2-rc2)
+CVE-2026-68265 [drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7bc597ce74bab4153b2009c92eccf889e9d74044 (7.2-rc4)
+CVE-2026-68263 [drm/imagination: Fix double call to drm_sched_entity_fini()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4af24c27a39ba147a613a09e10b9e0f7294524c0 (7.2-rc2)
+CVE-2026-68262 [drm/imagination: Fix user array stride in pvr_set_uobj_array()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a (7.2-rc2)
+CVE-2026-68261 [drm/imagination: fix error checking of pvr_vm_context_lookup()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cf385cf6e713eba0720651174dac0b2d2f5bb8f8 (7.2-rc3)
+CVE-2026-68260 [drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/17e2030f37600994440f875dc410615d5c66ee6d (7.2-rc5)
+CVE-2026-68256 [drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a6e14b976be48eebd8769cb5b883a6af7fc5ade1 (7.2-rc2)
+CVE-2026-68240 [drm/gpusvm: publish dpagemap early to avoid device mapping leak on error]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7f708f51e3955bda0d77a0b67ab9bea6c97fea99 (7.2-rc4)
+CVE-2026-68239 [drm/ttm: Account for NULL and handle pages in ttm_pool_backup]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5b7b3b6595ee77d01c7463757baed114786094dd (7.2-rc4)
+CVE-2026-68237 [drm/amdgpu/userq: fix indefinite fence wait during GPU reset]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5d75ec2e5f1736c2f10c7d6f4565bf1bf29f29a7 (7.2-rc4)
+CVE-2026-68232 [drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/847b371debf3c8c72384ab7b9a0c4123a74cc925 (7.2-rc5)
+CVE-2026-68230 [media: amlogic-c3: Add validations for ae and awb config]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9724164f71974a2a44a5e026614fbcc05bab6d91 (7.2-rc1)
+CVE-2026-68228 [media: chips-media: wave5: Move src_buf Removal to finish_encode]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b20157147089a9c16a38c7810e2fe6f2df8e3277 (7.2-rc1)
+CVE-2026-68225 [media: i2c: alvium: fix critical pointer access in alvium_ctrl_init]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4f6f28ff24709710c08557c127b3e4c3fb1b4159 (7.2-rc1)
+CVE-2026-68224 [media: mali-c55: Fix possible ERR_PTR in enable_streams]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/94c6402e423d36a2bd6f62055a65a0d439d84da7 (7.2-rc1)
+CVE-2026-68221 [media: nuvoton: npcm-video: fix memory leaks in probe and remove]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/50cc0e547da50b887e63dfa1ad203cd5b735d01e (7.2-rc1)
+CVE-2026-68220 [media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/567418eedd25b3d86d489807682030b4b98b73d9 (7.2-rc1)
+CVE-2026-68219 [media: nxp: imx8-isi: Fix potential out-of-bounds issues]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/57a7ec5c9f38ce6c4d6209c4b75c8e57e1fea6cf (7.2-rc1)
+CVE-2026-68208 [media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e8f319eae96a3d718e810d52432020a2b77f5f60 (7.2-rc1)
+CVE-2026-68201 [ALSA: timer: drain a slave's callback before its master detaches it]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bdefe1346a8e6b8dc8593406dc2617e985fcbcab (7.2-rc5)
+CVE-2026-68200 [ALSA: timer: don't re-enter an instance callback that is still running]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/70d28bfcd6224eed75986b3b987b997e59643fa4 (7.2-rc5)
+CVE-2026-68193 [wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/feeff151c83e7f0ffcdedcad5343852d23d1f6e1 (7.2-rc5)
+CVE-2026-68191 [wifi: ath12k: fix NULL pointer dereference in rhash table destroy]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/70231dcd782201579990ded73e0435d18bb524ca (7.2-rc5)
+CVE-2026-68179 [misc: nsm: only unlock nsm_dev on post-lock error paths]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ce1fed11d18e163baf7f875152a33bf80f625c1a (7.2-rc5)
+CVE-2026-68178 [misc: nsm: pin the module while the device is open]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3b231f1e9990f4c21220d0a69733ce2105891ff9 (7.2-rc5)
+CVE-2026-68177 [tracing: Delay module ref count for "enable_event" trigger]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e091351b38818ef620d27f44f4bfd625f13afbff (7.2-rc5)
+CVE-2026-68174 [tracing: Fix union collision of module and refcnt for dynamic events]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b4eb07bde606c2096b24252be589e735eff6d413 (7.2-rc5)
+CVE-2026-68173 [ublk: wait on ublk_dev_ready() instead of ub->completion]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/432a9b2780c0a01caf547bd1fc2fcf28aeb8d173 (7.2-rc5)
+CVE-2026-68172 [arm64: make huge_ptep_get handled unaligned addresses]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f73a8edc2ccc6ec72c37d5c578e7592d2e1f9922 (7.2-rc5)
+CVE-2026-68170 [mptcp: fix stale skb->sk reference on subflow close]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bd7aae448f6ee9d82599a4474664de1e6e91a535 (7.2-rc5)
+CVE-2026-68168 [afs: Fix afs_edit_dir_remove() to get, not find, block 0]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/62d9853aa4ce6e9797b6949804891be14b219752 (7.2-rc5)
+CVE-2026-68167 [btrfs: do not try compression for data reloc inodes]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ae4316f332e03e628712e9dfb89f2b7d3c70c21a (7.2-rc5)
+CVE-2026-68163 [mm/page_vma_mapped: fix device-private PMD handling]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f84ca9b1888d8fce7dfefe0e750fa971f8797486 (7.2-rc5)
+CVE-2026-68150 [fs/super: fix emergency thaw double-unlock of s_umount]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/503d67fbaec6fdeaba391cb497675071db9d16ea (7.2-rc5)
+CVE-2026-68149 [fs: preserve ACL_DONT_CACHE state in forget_cached_acl()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4b9a5458d02e214ef2b384124ca626e3e381d778 (7.2-rc5)
+CVE-2026-68139 [net/mlx5e: Use sender devcom for MPV master-up]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e32649b4bad90a6216d8e93cd7dd050af8ac9740 (7.2-rc5)
+CVE-2026-68134 [ptp: ptp_s390: Add missing facility check]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e78f1ac37afcb16cb6fef8a2c92591eab6558956 (7.2-rc5)
+CVE-2026-68133 [ice: fix PTP Call Trace during PTP release]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f6a7e00b81e35ef1325234925f2fe1e53b466f92 (7.2-rc5)
+CVE-2026-68128 [ice: reject out-of-range ptype in ice_parser_profile_init]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/59abb87159c53605c063f6e2ceb215b5eba43ee6 (7.2-rc5)
+CVE-2026-68126 [mac802154: hold an interface reference across the scan worker]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/234e5e898b713bc0b3a631b6f002897f43d046c8 (7.2-rc5)
+CVE-2026-68122 [ovpn: fix peer refcount leak in TCP error paths]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/63bbe18fc03062f483c627838a566a707b62da79 (7.2-rc5)
+CVE-2026-68120 [rtase: Workaround for TX hang caused by hardware packet parsing]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1c50efa1faf3a1a96e100b07ec7a2f3164d90bee (7.2-rc5)
+CVE-2026-68119 [tcp: initialize standalone TCP-AO response padding]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e1a9d3cc11829c5414a75eb39c704f461936eb24 (7.2-rc5)
+CVE-2026-68116 [vxlan: mdb: Fix source list corruption on a failed replace]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dcd9b465965422b9654f6026e8a2fa8984f74c3c (7.2-rc5)
+CVE-2026-68101 [drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/52f650963d8825e97a0ccdd2b616f8a01d9d3d38 (7.2-rc2)
+CVE-2026-68095 [fuse-uring: fix race between registration and connection abortion]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/952b5d36f6a298f57c52a59e72076c69386a8aaf (7.2-rc1)
+CVE-2026-68094 [sched_ext: Preserve rq tracking across local DSQ dispatch]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/18d62044cda7a2b40f59d910659c0b0d6accad37 (7.2-rc4)
+CVE-2026-68428 [KVM: x86/mmu: Fix use-after-free on vendor module reload]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/52f2f7c30126037975389aa04d24c506a5177c35 (7.2-rc5)
+CVE-2026-68427 [gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/266cddf7bd0f6c79b6c0633aef742a22bf70265b (7.2-rc4)
+CVE-2026-68426 [xfrm: fix stale skb->prev after async crypto steals a GSO segment]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/3f4c3919baf0944ad96580467c302bc6c7758b00 (7.2-rc4)
+CVE-2026-68425 [IB/mad: Drop unmatched RMPP responses before reassembly]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/d2e52d610b9b09694261632340b801a421e0b0c5 (7.2-rc4)
+CVE-2026-68422 [btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ce6050bafb4e33377dc17fcc357736bfc351180c (7.2-rc4)
+CVE-2026-68421 [sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b7d9c359e5cf867f7eb23df3bb1c6b9e58af24da (7.2-rc4)
+CVE-2026-68418 [RDMA/irdma: Prevent user-triggered null deref on QP create]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b9b0889071569d43623c260074e159cd8f26adb1 (7.2-rc4)
+CVE-2026-68417 [RDMA/siw: publish QP after initialization]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/bb27fcc67c429d97f785c92c35a6c5adebb05d7f (7.2-rc4)
+CVE-2026-68414 [wifi: cfg80211: cancel sched scan results work on unregister]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/edf0730be33696a1bd142792830d392129e495cc (7.2-rc4)
+CVE-2026-68413 [wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/0d388f62031dbabcba0f44bb91b59f10e88cac17 (7.2-rc4)
+CVE-2026-68412 [wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/c6659f66d4ee4841aafae5659d2ef5e4c5c63cb6 (7.2-rc4)
+CVE-2026-68411 [wifi: mac80211_hwsim: clamp virtio RX length before skb_put]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/10a2b430f8f06ae14b9590b6f6faa6b588ef0654 (7.2-rc4)
+CVE-2026-68410 [wifi: libertas: fix memory leak in helper_firmware_cb()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/63c2391deefb31e1b801b7f32bd502ca4808639b (7.2-rc4)
+CVE-2026-68409 [wifi: mac80211: defer link RX stats percpu free to RCU]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/aa2eb62525188269cdd402a583b9a8ed94657ff0 (7.2-rc4)
+CVE-2026-68408 [wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2b0eab425e1f658d8fe1df7590e3b9af5959505e (7.2-rc4)
+CVE-2026-68407 [wifi: nl80211: free RNR data on MBSSID mismatch]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c (7.2-rc4)
+CVE-2026-68406 [wifi: cfg80211: validate PMSR FTM preamble range]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/36230936468f0ba4930e94aef496fc229d4bb951 (7.2-rc4)
+CVE-2026-68405 [wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f3858d5b1432098c1936e03d6e03dd0e33facf60 (7.2-rc4)
+CVE-2026-68404 [wifi: cfg80211: use wiphy work for socket owner autodisconnect]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/0c2ed186bbe14304415476d6707b747dddcd8583 (7.2-rc4)
+CVE-2026-68403 [wifi: brcmfmac: initialize SDIO data work before cleanup]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/2a665946e0407a05a3f81bd56a08553c446498e0 (7.2-rc4)
+CVE-2026-68402 [wifi: cfg80211: bound element ID read when checking non-inheritance]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/cb8afea4655ff004fa7feee825d5c79783525383 (7.2-rc4)
+CVE-2026-68401 [firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3383ffb7ef937317361713ffcc21921a7848511a (7.2-rc4)
+CVE-2026-68400 [firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b4d961351aa84fdf0148783fb1f3a1391b8a0adb (7.2-rc4)
+CVE-2026-68399 [bpf: Fix UAF in sock clone early bailouts]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f (7.2-rc4)
+CVE-2026-68398 [ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ec4215683e47424c9c4762fd3c60f552a3119142 (7.2-rc4)
+CVE-2026-68397 [net/iucv: take a reference on the socket found in afiucv_hs_rcv()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4fa349156043dc119721d067329714179f501749 (7.2-rc4)
+CVE-2026-68396 [scsi: core: wake eh reliably when using scsi_schedule_eh]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/dccf3b1798b70f94e958b3d00b83010399e6fb05 (7.2-rc4)
+CVE-2026-68395 [ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0 (7.2-rc4)
+CVE-2026-68393 [Bluetooth: hci_sync: extend conn_hash lookup critical sections]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d5efd6e4b8b0634af6843178fe1a7dd2b2178a3d (7.2-rc4)
+CVE-2026-68391 [Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/da55f570191d5d72f10c607a7043b947eb05ea46 (7.2-rc4)
+CVE-2026-68388 [smb/client: handle overlapping allocated ranges in fallocate]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/b09ae45d85dc816987a71db9eebc54b0ae288e94 (7.2-rc4)
+CVE-2026-68386 [bpf, sockmap: Reject unhashed UDP sockets on sockmap update]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/66efd3368ae10d05e08fbe6425b50fdec7186ac7 (7.2-rc4)
+CVE-2026-68383 [drm/xe/guc: Keep scheduler timeline name alive]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/299bc6d50b1bed7d1f408391736712f01a0855e2 (7.2-rc4)
+CVE-2026-68382 [drm/xe/guc: Hold device ref until queue teardown completes]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9b7e60184f4b22e893d4ae95234d5f26261a430c (7.2-rc4)
+CVE-2026-68377 [net/sched: act_tunnel_key: Defer dst_release to RCU callback]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f1f5c8a3955f8fda3f84ed883ac8daa1847e724c (7.2-rc4)
+CVE-2026-68376 [sctp: fix auth_hmacs array size in struct sctp_cookie]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e0b5252a59383b77d1b8dbeda00b7184dd95f4d3 (7.2-rc4)
+CVE-2026-68375 [bnxt_en: Handle partially initialized auxiliary devices]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1cb8553c02e93e5a150cebd42f9ee3db0ece4707 (7.2-rc4)
+CVE-2026-68374 [usb: core: sysfs: add lock to bos_descriptors_read()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4e0197fbb0eec588795d5431716a244d9ac8fa93 (7.2-rc5)
+CVE-2026-68373 [wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/61a799ffd1e5a4fd3702d547828b7ff3d161468e (7.2-rc5)
+CVE-2026-68371 [usb: musb: omap2430: Do not put borrowed of_node in probe]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c947360ae63eee1c9eacc030dd6f5a53f717addf (7.2-rc5)
+CVE-2026-68370 [usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/d5e5cd3654d2b5359a12ea6586120f05b28634ee (7.2-rc5)
+CVE-2026-68369 [usb: gadget: printer: fix infinite loop in printer_read()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/c2e819be6a5c7f34344926b4bd7e3dfca58cf48a (7.2-rc5)
+CVE-2026-68368 [usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/1febec7e47cdcd01f43fb0211094e3010474666e (7.2-rc5)
+CVE-2026-68367 [usb: gadget: f_tcm: synchronize delayed set_alt with teardown]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/79e2d75725c85607f8a9d87ae9cace62a19f767d (7.2-rc5)
+CVE-2026-68366 [usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/b70dc75e85ba968b7b76eebfe5d63000080b875b (7.2-rc5)
+CVE-2026-68365 [USB: serial: io_edgeport: cap received transmit credits]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/faaddd811c5099f11a5f52e68a6b31a5898cda4f (7.2-rc5)
+CVE-2026-68364 [drm/amd/display: Fix ISM dc_lock deadlock during suspend]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/3714fe242592e3699ac5e2c19d68b275a210be7d (7.2-rc1)
+CVE-2026-68363 [wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/dad9f96945d77ecd4708f730c06ef54dcd8cc057 (7.2-rc5)
+CVE-2026-68362 [wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e8d85672dd7e2523f774caafba8f858384e18df7 (7.2-rc5)
+CVE-2026-68361 [hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9ab8656548cd737b98d0b19c4253aff8d68e97f4 (7.2-rc5)
+CVE-2026-68360 [hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/94c87871b051d7ad758828a805215a2ec194512a (7.2-rc5)
+CVE-2026-68359 [hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e (7.2-rc5)
+CVE-2026-68357 [watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661 (7.2-rc5)
+CVE-2026-68355 [wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7f11e70629650ff6ea140984e5ce188b775b2683 (7.2-rc5)
+CVE-2026-68354 [firewire: net: Fix fragmented datagram reassembly]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/d52a13adbb8ccbab99cd3bad36804e87d8b5c052 (7.2-rc5)
+CVE-2026-68353 [wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495 (7.2-rc5)
+CVE-2026-68352 [wifi: ath6kl: fix OOB read from firmware IE lengths in connect event]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/6b47b29730de3232b919d8362749f6814c5f2a33 (7.2-rc5)
+CVE-2026-68351 [wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4cde55b2feff9504d1f993ab80e84e7ccb62791c (7.2-rc5)
+CVE-2026-68350 [wifi: carl9170: fix OOB read from off-by-two in TX status handler]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a3f42f1049ad80c65560d2b078ad426c3134f78d (7.2-rc5)
+CVE-2026-68349 [wifi: carl9170: fix buffer overflow in rx_stream failover path]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a1a21995c2e1cc2ca6b2226cfe4f5f018370182a (7.2-rc5)
+CVE-2026-68344 [usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/71132cedd1ecbc4032d76e9928c18a10f7e39b80 (7.2-rc5)
+CVE-2026-68343 [smb: client: validate DFS referral PathConsumed]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f6f5ee2aa33b350c671721b965251c42cebb962e (7.2-rc5)
+CVE-2026-68340 [hwmon: occ: validate poll response sensor blocks]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/70e76e700fc6c46afb4e17aec099a1ea089b4a22 (7.2-rc5)
+CVE-2026-68338 [net/packet: avoid fanout hook re-registration after unregister]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/50aff80475abd3533eef4320477037e6fcc6b56e (7.2-rc5)
+CVE-2026-68337 [bpf: Reject redirect helpers without a bpf_net_context]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/3f4920d165b29052255527d8ae7619e7ec132ece (7.2-rc5)
+CVE-2026-68336 [bonding: fix devconf_all NULL dereference when IPv6 is disabled]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1c975de3343cdef506f2eecc833cc1f14b0401c4 (7.2-rc5)
+CVE-2026-68335 [rds: drop incoming messages that cross network namespace boundaries]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/5521ae71e32a8069ed4ca6e792179dc57bc43ab2 (7.2-rc5)
+CVE-2026-68333 [dpaa2-switch: put MAC endpoint device on disconnect]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4c1eabbef7a1707635652e956e39db1269c3af2b (7.2-rc5)
+CVE-2026-68331 [dpaa2-eth: put MAC endpoint device on disconnect]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/b4b201cc93ff70150853aba03e14d314d1980ca0 (7.2-rc5)
+CVE-2026-68329 [iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/1e75a8255f11c81fb07e81e5029cfd75804350a0 (7.2-rc5)
+CVE-2026-68328 [nfp: Check resource mutex allocation]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc (7.2-rc5)
+CVE-2026-68327 [wan: wanxl: Only reset hardware after BAR mapping]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/91957b89da995607cb654b1f9a3c126ddbaee10f (7.2-rc5)
+CVE-2026-68326 [wifi: mwifiex: bound uAP association event IEs to the event buffer]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f0858bfc7d3cab411a447b88e3ef970e575032c9 (7.2-rc5)
+CVE-2026-68325 [iommu/amd: Bound the early ACPI HID map]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/fb80117fddb5b477218dc99bb53911b72c3847f8 (7.2-rc5)
+CVE-2026-68324 [iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/754f8efe45f87e3a9c6871b645b2f9d46d1b407b (7.2-rc5)
+CVE-2026-68323 [tipc: serialize udp bearer replicast list updates]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/350e592ff4e30e48ffb55e142d11a73e63f4869c (7.2-rc5)
+CVE-2026-68322 [rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/9c805e592a29be9e4e61ff1bd567da04aa8fd6f9 (7.2-rc5)
+CVE-2026-68320 [sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9 (7.2-rc5)
+CVE-2026-68318 [pds_core: fix use-after-free on workqueue during remove]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0ad134881508c36b65c1a8864f8bec53adbd3327 (7.2-rc5)
+CVE-2026-68315 [sctp: validate stream count in sctp_process_strreset_inreq()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/18ae07691d43183d270de8be9dc8e027906015d9 (7.2-rc5)
+CVE-2026-68313 [tipc: fix infinite loop in __tipc_nl_compat_dumpit]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/22f8aa35964e8f2ab026578f45befc9605fd1b28 (7.2-rc5)
+CVE-2026-68312 [cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c2f2e83e3bbc5483730fd4ee903182761f1ae50f (7.2-rc5)
+CVE-2026-68310 [wifi: mt76: mt7915: guard HE capability lookups]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8e9db062654a388d0fa587acbeeae68dd33eba41 (7.2-rc5)
+CVE-2026-68309 [wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2c1fb2335f5e3afb34f91bc07ecb63517c328090 (7.2-rc5)
+CVE-2026-68305 [drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers]
+ - linux 7.1.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4c92afb4c143526d340545ca581e88e6952ea511 (7.2-rc5)
+CVE-2026-68304 [wifi: brcmfmac: fix 802.1X-SHA256 call trace warning]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7cb34f6c4fe8a68af621d870abe63bfca2275dd6 (7.2-rc5)
+CVE-2026-68303 [drm/vc4: hvs/v3d: Fix null dereference in unbind]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/7dc3680b7ffe01add3e9299fde8471d2dd53a8ae (7.2-rc5)
+CVE-2026-68302 [amt: re-read skb header pointers after every pull]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3656a79f94c471827a08f2cacce5f94ad5e52c24 (7.2-rc5)
+CVE-2026-68301 [net: hsr: fix memory leak on slave unregistration by removing synced VLANs]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dcf15eaf5641812f1cfc5e96537380132a7da89d (7.2-rc5)
+CVE-2026-68300 [sctp: auth: verify auth requirement when auth_chunk is NULL]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/8e04823c120b376ef7dab14b60ebf6823aa16c14 (7.2-rc5)
+CVE-2026-68299 [vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/34a71f5361fc3adb5b7138da78750b0d535a8252 (7.2-rc5)
+CVE-2026-68297 [tipc: fix u16 MTU truncation in media and bearer MTU validation]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8 (7.2-rc5)
+CVE-2026-68295 [LoongArch: BPF: Zero-extend signed ALU32 div/mod results]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dacd348b8a993373576fe2ee2d8b114740ba57a6 (7.2-rc5)
+CVE-2026-68294 [net: qrtr: restrict socket creation to the initial network namespace]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/3b536db8fb32da9e9c62f2bb45e2e319331f0426 (7.2-rc5)
+CVE-2026-68293 [net/mlx5: Fix MCIA register buffer overflow on 32 dword reads]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/11c057d23465c7a5817a7284c896d19d54c0b616 (7.2-rc5)
+CVE-2026-68291 [idpf: fix max_vport related crash on allocation error during init]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/237f1f7653b8729169af11fae79f01b90d00b87e (7.2-rc5)
+CVE-2026-68289 [tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/47f42ff521b4eeb46e82f9a46a4783a99f7570d7 (7.2-rc5)
+CVE-2026-68288 [net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/5e9c8baee0329fbefe7c67aea945e2a07f15e98b (7.2-rc5)
+CVE-2026-68287 [drop_monitor: fix size calculations for 64-bit attributes]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/7089f7ab99c89f443c92d8fcc585e63f2727f0b3 (7.2-rc5)
+CVE-2026-68286 [drop_monitor: perform u64_stats updates under IRQ-disabled section]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/fd098a23bf8fda7eae48db9b06e7c34fc4d228fa (7.2-rc5)
+CVE-2026-68284 [bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/2d66a033864e27ab8d5e44cb36f31d9d2413bee4 (7.2-rc5)
+CVE-2026-68280 [drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/2d8b08844c0ecc6f2002fa68711e779aa18c8585 (7.2-rc1)
+CVE-2026-68279 [drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/1a8f537f5a1eeac941f262fe73078d6b08ba83c0 (7.2-rc1)
+CVE-2026-68278 [drm/dp/mst: fix buffer overflows in sideband chunk accumulation]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/55bd5e685bda455b9b50c835f8c8442d52a344a3 (7.2-rc1)
+CVE-2026-68277 [drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/6b89ba3dba2f583626fb693e47e951ffb8bf591f (7.2-rc1)
+CVE-2026-68276 [drm/amdgpu/gfx: fix cleaner shader IB buffer overflow]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3 (7.2-rc1)
+CVE-2026-68273 [drm/amdgpu: Fix context pstate override handling]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c1dc4ccb82c9e56325d8e7514ca4c90bd1efb351 (7.2-rc1)
+CVE-2026-68269 [drm/i915/gem: Add missing nospec on parallel submit slot]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/914a76a9f08366434bf595700f62026b7a19a9cc (7.2-rc1)
+CVE-2026-68267 [drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e70086a3a06d276b4a5d9a2c51c9330c6cf72780 (7.2-rc2)
+CVE-2026-68266 [drm/xe: Hold a dma-buf reference for imported BOs]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/62775525a27c3b0d56382e08ba81ee2d322058b6 (7.2-rc4)
+CVE-2026-68264 [drm/xe/pt: Reset current_op in xe_pt_update_ops_init()]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6384271ac1ac0099198d15df79212a19ebdb929d (7.2-rc4)
+CVE-2026-68259 [drm/amdkfd: Check bounds in allocate_event_notification_slot]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/bb52249fbbe948875155ccd45cd8d74bf4ae747b (7.2-rc3)
+CVE-2026-68258 [drm/amdkfd: Check bounds on CRIU restore queue type and mqd size]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/47ea05f246bebc81c7796f56265cffd812cf0601 (7.2-rc3)
+CVE-2026-68257 [drm/amdkfd: fix 32-bit overflow in CWSR total size calculation]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/2b0386d4293920e690c0e017708f999b93cc729b (7.2-rc4)
+CVE-2026-68255 [drm/virtio: bound EDID block reads to the response buffer]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd (7.2-rc2)
+CVE-2026-68254 [drm/i915/vrr: require valid min/max vfreq for VRR]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f8a9262c7a6fc2de9802e14b0228114f0333869e (7.2-rc2)
+CVE-2026-68253 [drm/i915/hdcp: check streams[] bounds before overflow]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bbb15a6b042d02e5508a02b4847e02d2579ee7bc (7.2-rc2)
+CVE-2026-68252 [drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e80e28f398f5d9f6e361ffb56382d2e74fc87556 (7.2-rc2)
+CVE-2026-68251 [drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ec42c96c322e5cc48099ab5e67b5cbe236cb1949 (7.2-rc2)
+CVE-2026-68250 [drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/b9dd618a635d39fbb211454b6e8837b2a7f10fb0 (7.2-rc2)
+CVE-2026-68249 [drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/9e98ed3113943257ad6e5c1e6beddbdb482a70ad (7.2-rc2)
+CVE-2026-68248 [drm/i915: Return NULL on error in active_instance]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1e33f0de5fdcd09e51fdec1e5822448970b6420f (7.2-rc2)
+CVE-2026-68247 [drm/i915/bios: range check LFP Data Block panel_type2]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2084503f2d087bf956198e7f6eb25b03a7049cb2 (7.2-rc2)
+CVE-2026-68246 [drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/0eebcab1ea2a77f086a04108f386f82ee3496022 (7.2-rc2)
+CVE-2026-68245 [drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/04cc4aa3617b0ed67e859f91f09de5d896a46f3a (7.2-rc3)
+CVE-2026-68244 [drm/i915/gem: Do not leak siblings[] on proto context error]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/eed3de2acf6aa5154d49098b026710b646db67ee (7.2-rc3)
+CVE-2026-68243 [drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2b56757a9a7456825eb668fde92299e01c5e2721 (7.2-rc3)
+CVE-2026-68242 [drm/i915/gt: Fix NULL deref on sched_engine alloc failure]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/82ec992c404c3dc774c5e9f3d4aa858e97187675 (7.2-rc3)
+CVE-2026-68241 [drm/i915/mst: limit DP MST ESI service loop]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/005771c18c5b2c98cb4e7517661aea460990fd3f (7.2-rc3)
+CVE-2026-68238 [drm/amdgpu: Release VFCT ACPI table reference]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/65bff26617607c1331283232016c0e89088c5b78 (7.2-rc4)
+CVE-2026-68236 [drm/amd/display: set new_stream to NULL after release]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/9fa26b9eed6195bf840f39ac183b9a6237548755 (7.2-rc4)
+CVE-2026-68235 [drm/amd/display: dce100: skip non-DP stream encoders for DP MST]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5 (7.2-rc4)
+CVE-2026-68234 [drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a2f895f3c852063258d62e9f74b081de07ca95df (7.2-rc4)
+CVE-2026-68233 [drm/vc4: Shut down BO cache timer before teardown]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/6273dd3ffb54ec581855b82ae77331b66028249c (7.2-rc5)
+CVE-2026-68231 [media: airspy: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/04344d0b4929caa94c0df72f767752aa0935ef5d (7.2-rc1)
+CVE-2026-68229 [media: cedrus: skip invalid H.264 reference list entries]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/10358ea986c3c85516d1c8206486464f79d36e76 (7.2-rc1)
+CVE-2026-68227 [media: cx231xx: fix devres lifetime]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7d6358ab02866e5b7ed8d3a00805297617bbb0ec (7.2-rc1)
+CVE-2026-68226 [media: cx23885: add ioremap return check and cleanup]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a0701e387b46e2481c05b47f1235b954bfc2af3e (7.2-rc1)
+CVE-2026-68223 [media: meson: vdec: Fix memory leak in error path of vdec_open]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/940f161f734b25f175a95d2684c2021f6323693a (7.2-rc1)
+CVE-2026-68222 [media: msi2500: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7201c17786a498497bca57752883b90914d405ac (7.2-rc1)
+CVE-2026-68218 [media: pci: dm1105: Free allocated workqueue]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/1a65db225b25bb8c8febf16974c060e0cc242eb9 (7.2-rc1)
+CVE-2026-68217 [media: pwc: Drain fill_buf on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/906e410dcffbbd99fb4081abab817a830033aa28 (7.2-rc1)
+CVE-2026-68216 [media: pwc: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/975b2ee20e569d47821e4f6c9761b4664d48a6a4 (7.2-rc1)
+CVE-2026-68215 [media: radio-si476x: Unregister v4l2_device on probe failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/436a693af04ffb889aaf87cb69ec1f2b21d3569c (7.2-rc1)
+CVE-2026-68214 [media: rtl2832: fix use-after-free in rtl2832_remove()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/680daf40a82d483949f87f0d8f98639dc47e610c (7.2-rc1)
+CVE-2026-68213 [media: rtl2832_sdr: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/33ca0aab6f4bd90921fc1395478f38f72c4d19af (7.2-rc1)
+CVE-2026-68212 [media: saa7134: Fix a possible memory leak in saa7134_video_init1]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f86ed548386e3050e5f8f25b450d09dc009d9a88 (7.2-rc1)
+CVE-2026-68211 [media: stm32-dcmipp: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ffc8eec06378a340d708c889184ab3e14b57d540 (7.2-rc1)
+CVE-2026-68210 [media: stm32: dcmi: unregister notifier on probe failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/084973ebd67b28f0945c5d45408f86c58b540110 (7.2-rc1)
+CVE-2026-68209 [media: sun4i-csi: Return queued buffers on start_streaming() failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/bbba3e260a62810a717b4442a3bb96d0ec0f6309 (7.2-rc1)
+CVE-2026-68207 [media: ti: vpe: unwind v4l2 device registration on probe error]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6 (7.2-rc1)
+CVE-2026-68206 [media: v4l2-ctrls: validate HEVC active reference counts]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/afbe4bc252d90a6f8fad869b06d5430f615f22f9 (7.2-rc1)
+CVE-2026-68205 [media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/06cb687a5132fcffe624c0070576ab852ac6b568 (7.2-rc1)
+CVE-2026-68204 [media: vivid: check for vb2_is_busy() when toggling caps]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/c2d1a2130c93f6d758af58590b86b2254c7a1dec (7.2-rc1)
+CVE-2026-68203 [media: vivid: fix cleanup bugs in vivid_init()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a07c179a92e949172ca52f6d4a13202ea88cd4b7 (7.2-rc1)
+CVE-2026-68202 [ALSA: seq: close a re-opened queue timer in the destructor]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9 (7.2-rc5)
+CVE-2026-68199 [wifi: ath6kl: fix OOB access from firmware ADDBA window size]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/44126b6994eeb28f2103b638e698f40a1244f327 (7.2-rc5)
+CVE-2026-68198 [wifi: ath6kl: fix use-after-free in aggr_reset_state()]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/ba7debb4dd6427386862220e8335a53a4bfc235d (7.2-rc5)
+CVE-2026-68197 [wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/c3d68e294cbb6a4090bb219d3dcaca85a011809b (7.2-rc5)
+CVE-2026-68196 [wifi: wilc1000: validate assoc response length before subtracting header]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de (7.2-rc5)
+CVE-2026-68195 [wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/39afc46c0243d10b7795e6e6cf4ae91f41732120 (7.2-rc5)
+CVE-2026-68194 [wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/da4082e91acabc1498611ed8ccc53f0610baefc6 (7.2-rc5)
+CVE-2026-68192 [wifi: brcmfmac: make release_scratchbuffers idempotent]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/538c51e9d124cf656f2dd0c0394a8545efc7102d (7.2-rc5)
+CVE-2026-68190 [staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/0e95ff792ae0aa6fbad9455943e9e1e4062670e9 (7.2-rc5)
+CVE-2026-68189 [Bluetooth: hci_sync: Protect UUID list traversal]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e9027ffbf5a0f3c12ca8900822e884eae9f0821b (7.2-rc5)
+CVE-2026-68188 [Bluetooth: RFCOMM: Fix session UAF in set_termios]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/c783399efc22d035443f1dfbf2a09bf9562aaa5e (7.2-rc5)
+CVE-2026-68187 [exec: fix unsigned loop counter wrap in transfer_args_to_stack()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/16cc4f5c1c4b9e45eca7f7deefa5410a292db599 (7.2-rc5)
+CVE-2026-68186 [binfmt_misc: set have_execfd only once the interpreter is opened]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/bbf5f639918dc011aaf60aab8480218758ee68c5 (7.2-rc5)
+CVE-2026-68185 [LoongArch: Move jump_label_init() before parse_early_param()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ea68d444a658783234a06f05414e41cf93a18fb2 (7.2-rc5)
+CVE-2026-68184 [cdrom: fix stack out-of-bounds read in CDROMVOLCTRL]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/b27e195d4db8dea263050bdbeb11881b2999c9c6 (7.2-rc5)
+CVE-2026-68183 [firmware: stratix10-svc: fix memory leaks and list corruption bugs]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/9119ceb76e987c2ec2b549ea100e3268ce3a1c7c (7.2-rc5)
+CVE-2026-68182 [comedi: comedi_parport: deal with premature interrupt]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/17221216ae8ce6a24e8a4e787382e3ebc81b88a8 (7.2-rc5)
+CVE-2026-68181 [mei: bus: access mei_device under device_lock on cleanup]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f112ea910e554d58b4b39a4492b7d302f0f4204f (7.2-rc5)
+CVE-2026-68180 [intel_th: fix MSC output device reference leak]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/761b785a0cfbce43761227bc42a7f984f31f8921 (7.2-rc5)
+CVE-2026-68176 [tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/144f29e85702234b23d2a62abf723e6a17eb5427 (7.2-rc5)
+CVE-2026-68175 [tracing: Fix resource leak on mmiotrace trace_pipe close]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/c1d87e724ae55e781b7cc7ccafb34d9e668582b2 (7.2-rc5)
+CVE-2026-68171 [arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e057b94772328221405b067c3a85fe479b915dc8 (7.2-rc5)
+CVE-2026-68169 [mptcp: pm: userspace: fix use-after-free in get_local_id]
+ - linux 7.1.6-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9 (7.2-rc5)
+CVE-2026-68166 [userfaultfd: prevent registration of special VMAs]
+ - linux 7.1.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3c58f641e813c3c71039f8fd4d4e2a3aab713288 (7.2-rc5)
+CVE-2026-68165 [mm/damon/core: validate ranges in damon_set_regions()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1292c0ecb1caefb8ca064a3639d5673991e8810c (7.2-rc5)
+CVE-2026-68164 [mm/damon/core: disallow overlapping input ranges for damon_set_regions()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/954157679ec34661c2e87e7eb796104a797c32db (7.2-rc5)
+CVE-2026-68162 [sctp: avoid auth_enable sysctl UAF during netns teardown]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/f8d5e7846025f4ab15a461235f8ebae9094a361a (7.2-rc5)
+CVE-2026-68161 [sctp: close UDP tunnel sockets during netns teardown]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c (7.2-rc5)
+CVE-2026-68160 [ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02 (7.2-rc5)
+CVE-2026-68159 [libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/9f00f9cf2be293efe899db67dc5272e3a9c62717 (7.2-rc5)
+CVE-2026-68158 [libceph: Fix multiplication overflow in decode_new_up_state_weight()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/98917a499ec7064c14fc56d180a4fd636fc2784c (7.2-rc5)
+CVE-2026-68157 [libceph: guard missing CRUSH type name lookup]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/bbeae12fda3384a90fbebc8a19ba9d33f85b5361 (7.2-rc5)
+CVE-2026-68156 [libceph: refresh auth->authorizer_buf{,_len} after authorizer update]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/937d61f86d377a3aa578adae7a3dfcecdddf9d89 (7.2-rc5)
+CVE-2026-68155 [libceph: Reject monmaps advertising zero monitors]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/40480eee361ed9676b3f844d532ac28b47251634 (7.2-rc5)
+CVE-2026-68154 [libceph: reject zero bucket types in crush_decode]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/05f90284223381005d6bcddab3fda4a97f9c3401 (7.2-rc5)
+CVE-2026-68153 [libceph: remove debugfs files before client teardown]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e4c804726c4afce3ba648b982d564f6af2cfa328 (7.2-rc5)
+CVE-2026-68152 [amt: fix use-after-free in AMT delayed works]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ea20c44935d6142daecfa9b39d635033a7553e1b (7.2-rc5)
+CVE-2026-68151 [binfmt_elf_fdpic: only honour the first PT_INTERP]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/3349ef6a366a61d631f6a263d12cea240957719d (7.2-rc5)
+CVE-2026-68148 [fscrypt: Add missing superblock check in find_or_insert_direct_key()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b5fa40226e71c17847b9ff2816c6ca4133d0d994 (7.2-rc5)
+CVE-2026-68147 [fscrypt: Avoid dynamic allocation in fscrypt_get_devices()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6fe4e4b8259e1330945b5f3c9476e08473b8e0e8 (7.2-rc5)
+CVE-2026-68146 [ftrace: Add global mutex to serialize trace_parser access]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/7720b63bcef3f54c7fe288774b720a227d54a306 (7.2-rc5)
+CVE-2026-68145 [iomap: fix out-of-bounds bitmap_set() with zero-length range]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9c7d8f7c8994c790fca501dc45ce66e7356cbe05 (7.2-rc5)
+CVE-2026-68144 [phonet: pep: fix use-after-free in pep_get_sb()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/0f71f852a96af9685858ce59fda34ecbf85c283d (7.2-rc5)
+CVE-2026-68143 [net: slip: serialize receive against buffer reallocation]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d (7.2-rc5)
+CVE-2026-68142 [geneve: require CAP_NET_ADMIN in the device netns for changelink]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01 (7.2-rc5)
+CVE-2026-68141 [net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/47a5116e56a6b6fe1e909f244e39cd0fc26ceee4 (7.2-rc5)
+CVE-2026-68140 [net/iucv: fix use-after-free of a severed iucv_path]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a (7.2-rc5)
+CVE-2026-68138 [net/sched: serialize qdisc_rtab_list against concurrent get/put]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047 (7.2-rc5)
+CVE-2026-68137 [net/x25: fix use-after-free in x25_kill_by_neigh()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/5499e0602d2faafd42c580d25f615903c3fbe11b (7.2-rc5)
+CVE-2026-68136 [net: gro: fix double aggregation of flush-marked skbs]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e751256486d0ded20f5a9f9863467f1dce65142f (7.2-rc5)
+CVE-2026-68135 [net: hip04: fix RX buffer leak on build_skb failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/14fa65d10f5696b063a7d8d26e8291ea84a2c6ed (7.2-rc5)
+CVE-2026-68132 [super: fix emergency thaw deadlock on frozen block devices]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/749d7aa0377aae32af8c0a4ad43371e7bf830ab5 (7.2-rc5)
+CVE-2026-68131 [rbd: Reset positive result codes to zero in object map update path]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4 (7.2-rc5)
+CVE-2026-68130 [ksmbd: defer destroy_previous_session() until after NTLM authentication]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c74801ee524f477c174a1899782b6c3b6918d407 (7.2-rc5)
+CVE-2026-68129 [gve: fix Rx queue stall on alloc failure]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b65352a1bac64442ad95e64f385b40ccb9f1b0db (7.2-rc5)
+CVE-2026-68127 [ila: reload IPv6 header after pskb_may_pull in checksum adjust]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/92d3817649df2b0b6a008a686c8275c88d7ef594 (7.2-rc5)
+CVE-2026-68125 [mac802154: llsec: reject frames shorter than the authentication tag]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b (7.2-rc5)
+CVE-2026-68124 [mctp: serial: handle zero-length frames to prevent rx buffer overflow]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/793b9b729f1e8de57be8c8daf1a9838be96cabed (7.2-rc5)
+CVE-2026-68123 [openvswitch: fix GSO userspace truncation underflow]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/4032f8ed10fcb84d41c508dfb04be96589f78dfe (7.2-rc5)
+CVE-2026-68121 [pppoe: reload header pointer after dev_hard_header()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/e9c238f6fe42fb1b4dba3a578277de32cb487937 (7.2-rc5)
+CVE-2026-68118 [tcp: challenge ACK for non-exact RST in SYN-RECEIVED]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/a28c4fcbf774e23b4779cae468e3497a5ad1f4a1 (7.2-rc5)
+CVE-2026-68117 [tipc: clear sock->sk on the failed-insert path in tipc_sk_create()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/ba0533fc163f905fe817cfabdf8ed4058da44800 (7.2-rc5)
+CVE-2026-68115 [drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/d06c4173a7c38c7a39e98859f839ce714c7af2c9 (7.2-rc2)
+CVE-2026-68114 [drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/6560e6bd76127844e39f09fa591c2791dc7932e8 (7.2-rc2)
+CVE-2026-68113 [drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/cd3b3efa1ced05528d9128755338baa62a6b562d (7.2-rc2)
+CVE-2026-68112 [drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/00f4050f7c367d7bdce347ca279ce467c434cf15 (7.2-rc2)
+CVE-2026-68111 [drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/6302be10b521f5106ce01eb5a724b9e7945a5061 (7.2-rc2)
+CVE-2026-68110 [drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/40cdbe9fa424cc6264a7aed93a04bd7d69109d9e (7.2-rc2)
+CVE-2026-68109 [drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/767648c18d7872bbf54481ba846e055f7e1c0213 (7.2-rc2)
+CVE-2026-68108 [drm/amdgpu/vce: fix integer overflow in image size]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/186bfdc4e26d019b2e7570cb121964a1d89b2e5b (7.2-rc2)
+CVE-2026-68107 [drm/amdgpu/vcn4: avoid rereading IB param length]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/3b4082fabc67c9780b06eb959e59dd92fa79c0f0 (7.2-rc2)
+CVE-2026-68106 [drm/amdgpu: fix division by zero with invalid uvd dimensions]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/0c01c811be47e6b146552dd59bfedbea8f09b8f4 (7.2-rc2)
+CVE-2026-68105 [drm/amdgpu: Fix kernel panic during driver load failure]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/a279bd143b3c184358b658e43a057e31ee8c4de5 (7.2-rc2)
+CVE-2026-68104 [drm/amdgpu: invoke pm_genpd_remove() before freeing genpd]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/28c9b3c5dc35cc790d11e26ca3fc6e068be63998 (7.2-rc2)
+CVE-2026-68103 [drm/amdgpu: reject mapping a reserved doorbell to a new queue]
+ - linux 7.1.6-1
+ NOTE: https://git.kernel.org/linus/a609b6278bf3cde17eeee6620091465521e4b02c (7.2-rc2)
+CVE-2026-68102 [drm/amdgpu: fix aperture mapping leak]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ea772a440d56b285f4d491affac50ecd41f6b402 (7.2-rc2)
+CVE-2026-68100 [ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/47f0b34f6bc98ed85bfdc293e8f3e432ec24958d (7.2-rc2)
+CVE-2026-68099 [ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bbf0a8e931204ecdab494a88d43b0a24a04285c5 (7.2-rc5)
+CVE-2026-68098 [ksmbd: bound DACL dedup walk to copied ACEs]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/58d97fcd0bf1aee694e244cc28635b9df95b543b (7.2-rc5)
+CVE-2026-68097 [ksmbd: validate ACE size against SID sub-authorities]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/5152c6d49e3fd4e9f2e857c57527aead752f1f87 (7.2-rc5)
+CVE-2026-68096 [audit: fix recursive locking deadlock in audit_dupe_exe()]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/81905b5acbe77284734438df3fbec1158e6429a3 (7.2-rc1)
+CVE-2026-68093 [KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug]
+ - linux 7.1.6-1
+ [trixie] - linux 6.12.101-1
+ NOTE: https://git.kernel.org/linus/25f744ffa0c8e799e06250ce2e618367b166b0d4 (7.2-rc4)
CVE-2026-68092 [time/jiffies: Register jiffies clocksource before usage]
- linux 7.1.4-1
[trixie] - linux 6.12.100-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ffb32b0ec2bbce6fc6d943d7720a875366923eb6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ffb32b0ec2bbce6fc6d943d7720a875366923eb6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/d2acc8bc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list