[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 15 20:14:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3c68a488 by security tracker role at 2026-08-15T19:13:53+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,553 +1,609 @@
-CVE-2026-73194
+CVE-2026-73635 (Allocation of resources without limits or throttling vulnerability in ...)
+ TODO: check
+CVE-2026-73634 (Uncontrolled resource consumption vulnerability in Apache Struts. An a ...)
+ TODO: check
+CVE-2026-73632 (Exposure of data element to wrong session vulnerability in the JSON pl ...)
+ TODO: check
+CVE-2026-73631 (Exposure of data element to wrong session vulnerability in the JSON pl ...)
+ TODO: check
+CVE-2026-19906 (A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This ...)
+ TODO: check
+CVE-2026-19905 (A weakness has been identified in Jinher OA 1.0. Impacted is an unknow ...)
+ TODO: check
+CVE-2026-19904 (A vulnerability was found in SourceCodester Online Book Store System 1 ...)
+ TODO: check
+CVE-2026-19903 (A vulnerability has been found in SourceCodester Online Clothing Store ...)
+ TODO: check
+CVE-2026-19901 (A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. ...)
+ TODO: check
+CVE-2026-19900 (A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The i ...)
+ TODO: check
+CVE-2026-19899 (A vulnerability was determined in SourceCodester Class and Exam Timeta ...)
+ TODO: check
+CVE-2026-19898 (A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted i ...)
+ TODO: check
+CVE-2026-19897 (A vulnerability has been found in mangroup dtale up to 3.22.0. This is ...)
+ TODO: check
+CVE-2026-19896 (A flaw has been found in mangroup dtale up to 3.22.0. This vulnerabili ...)
+ TODO: check
+CVE-2026-19895 (A vulnerability was detected in opensourcepos Open Source Point of Sal ...)
+ TODO: check
+CVE-2026-19894 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
+ TODO: check
+CVE-2026-19893 (A vulnerability was identified in D-Link DIR-842 2.01.B04. This impact ...)
+ TODO: check
+CVE-2026-19891 (A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This af ...)
+ TODO: check
+CVE-2026-19598 (The Pods \u2013 Custom Content Types and Fields plugin for WordPress i ...)
+ TODO: check
+CVE-2026-19474 (@fastify/multipart is a multipart form-data parser for Fastify. In ver ...)
+ TODO: check
+CVE-2026-18855 (The Link Library plugin for WordPress is vulnerable to arbitrary file ...)
+ TODO: check
+CVE-2026-18549 (@fastify/multipart is a multipart form-data parser for Fastify. In ver ...)
+ TODO: check
+CVE-2026-18500 (@fastify/jwt is a JSON Web Token plugin for Fastify. In versions befor ...)
+ TODO: check
+CVE-2026-18438 (The Templately \u2013 Elementor & Gutenberg Template Library: 6500+ Fr ...)
+ TODO: check
+CVE-2026-18165 (@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7 ...)
+ TODO: check
+CVE-2026-16142 (The TrueBooker plugin for WordPress is vulnerable to Account Takeover ...)
+ TODO: check
+CVE-2026-15142 (The Real Estate Manager Pro plugin for WordPress is vulnerable to Priv ...)
+ TODO: check
+CVE-2026-12248 (The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL In ...)
+ TODO: check
+CVE-2026-73194 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write vi ...)
- libdbi-perl 1.652-1 (bug #1144471)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 (1.652)
-CVE-2026-73193
+CVE-2026-73193 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write on ...)
- libdbi-perl 1.652-1 (bug #1144470)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 (1.652)
-CVE-2026-15689
+CVE-2026-15689 (Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allo ...)
NOT-FOR-US: Dancer2::Plugin::Auth::Extensible Perl module
-CVE-2026-74573 [iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE]
+CVE-2026-74573 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c3b8ee84a965058b41275069d4696f37a8b14bf6 (7.2-rc6)
-CVE-2026-74570 [ntfs: harden runlist realloc size calculations]
+CVE-2026-74570 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8bed376124ab4505b70083a2b91f2c7ef6d51e24 (7.2-rc6)
-CVE-2026-74554 [wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()]
+CVE-2026-74554 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/47abd2ca281531deee38a3b3770d885e270e9fc9 (7.2-rc6)
-CVE-2026-74539 [Bluetooth: ISO: lock sk in iso_sock_getname]
+CVE-2026-74539 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/89cf154d7c18e6e94a3da83051f3cf2bac317ae2 (7.2-rc6)
-CVE-2026-74528 [Bluetooth: hci_sync: hold conn in hci_past_sync() callback]
+CVE-2026-74528 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/abf9753edf3f88282c44a605f3945d8d4f8dd86c (7.2-rc6)
-CVE-2026-74526 [scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit]
+CVE-2026-74526 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ccff8c92571500fcfed21281e33daaf645bf692f (7.2-rc6)
-CVE-2026-74491 [of/address: Fix NULL bus dereference in of_pci_range_parser_one()]
+CVE-2026-74491 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/bba13ad17b1a11b3f1ed9b3a5d556191d7755a59 (7.2-rc6)
-CVE-2026-74489 [wifi: mac80211: fix tid_tx use-after-free on BA session stop]
+CVE-2026-74489 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2f067f5a450ea07efd249142a11d940a068fe29c (7.2-rc6)
-CVE-2026-74486 [binfmt_misc: use exe_file_deny_write_access() for the interpreter clone]
+CVE-2026-74486 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/fa5990ca8fd917003e526036bcc50413edb9722c (7.2-rc6)
-CVE-2026-74477 [uprobes: Fix NULL pointer dereference in hprobe_expire()]
+CVE-2026-74477 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cc679d7a6303e84d769f2afcde1fc51c51f127cd (7.2-rc6)
-CVE-2026-74462 [i2c: imx: mark I2C adapter when hardware is powered down]
+CVE-2026-74462 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/00d86dd5c2034e0e139e4806137b3b43e07ddd83 (7.2-rc6)
-CVE-2026-74577 [net: mpls: initialize rtm_tos in mpls_getroute()]
+CVE-2026-74577 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/295dd295e2137e10e9a5b1891d97e0f08de76f03 (7.2-rc6)
-CVE-2026-74576 [mm/slab: prevent unbounded recursion in free path with new kmalloc type]
+CVE-2026-74576 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d9e6a7623938968e3752b67e37eaff097e559a54 (7.2-rc5)
-CVE-2026-74575 [thunderbolt: Prevent XDomain delayed work use-after-free on disconnect]
+CVE-2026-74575 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/2c5d2d3c3f70cde2565d7b279b544893a2035842 (7.2-rc1)
-CVE-2026-74574 [dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()]
+CVE-2026-74574 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ee1d7274102285d78a53161fc705a8d8cd40b066 (7.2-rc6)
-CVE-2026-74572 [btrfs: zoned: fix deadlock between metadata writeback and transaction commit]
+CVE-2026-74572 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1ebe51c29fa9755d5b2fea28727c051117907cf8 (7.2-rc6)
-CVE-2026-74571 [btrfs: skip global block reserve accounting for rescue mounts]
+CVE-2026-74571 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/51a0e8399858621442807a26057bcd1cd3ced046 (7.2-rc6)
-CVE-2026-74569 [netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()]
+CVE-2026-74569 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5 (7.2-rc6)
-CVE-2026-74568 [KVM: arm64: vgic: Fix race between LPI release and re-registration]
+CVE-2026-74568 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cbfe2b24a1ea9de35032dbdd100fdc700f5be92d (7.2-rc6)
-CVE-2026-74567 [keys: fix out-of-bounds read in keyring_get_key_chunk()]
+CVE-2026-74567 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/63918731f9ae25b5deb022f118e941e6dddfcef4 (7.2-rc6)
-CVE-2026-74566 [keys: make keyring key-chunk byte order agree with keyring_diff_objects()]
+CVE-2026-74566 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/58565eef0f8d861aae92abfb7658458d661cee17 (7.2-rc6)
-CVE-2026-74565 [netfilter: nf_tables: make nft_object rhltable per table]
+CVE-2026-74565 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/f4f699790590bd0896c48a71e9232a65198f92f0 (7.2-rc6)
-CVE-2026-74564 [netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH]
+CVE-2026-74564 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/305b63e1402267459fdabb183af4527f6799eebf (7.2-rc6)
-CVE-2026-74563 [rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()]
+CVE-2026-74563 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/78f75d632f74b8de0f081a128588f7c37d0d1164 (7.2-rc6)
-CVE-2026-74562 [nexthop: take nh->lock for f6i_list walks in replace check and notify]
+CVE-2026-74562 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/072cd1f21819dedd2252e704d255de3b0cfc61a7 (7.2-rc6)
-CVE-2026-74561 [nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush]
+CVE-2026-74561 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/4787a6d2629b4e8c0b6bacab1f75c1660eca44d9 (7.2-rc6)
-CVE-2026-74560 [xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx]
+CVE-2026-74560 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a3c8382ebce4780c6b3ace2c09bc342313ac0186 (7.2-rc6)
-CVE-2026-74559 [xsk: drain continuation descs after overflow in xsk_build_skb()]
+CVE-2026-74559 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/bd44a6dcd4248883de90f5dad53ae80066e27096 (7.2-rc6)
-CVE-2026-74558 [xsk: reclaim invalid Tx descriptors in ZC batch path]
+CVE-2026-74558 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/72f2b4516faf55d4dfac2414649d3cffa5fd2c5e (7.2-rc6)
-CVE-2026-74557 [scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer]
+CVE-2026-74557 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/98b87885de4b7f605533a2860685f5689fce8e82 (7.2-rc6)
-CVE-2026-74556 [scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer]
+CVE-2026-74556 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/c1dea15f819cded9b3faf58f8bec72323568b6e6 (7.2-rc6)
-CVE-2026-74555 [scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race]
+CVE-2026-74555 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 (7.2-rc6)
-CVE-2026-74553 [hwmon: (nct6775-core) Fix number of temperature registers for NCT6116]
+CVE-2026-74553 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/b0e8adb2ccb43009796897ced09f91636685c9d3 (7.2-rc6)
-CVE-2026-74552 [hwmon: (lm90) Only report alarms if driver is ready]
+CVE-2026-74552 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 (7.2-rc6)
-CVE-2026-74551 [hwmon: (nzxt-smart2) DMA-align output buffer]
+CVE-2026-74551 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8 (7.2-rc6)
-CVE-2026-74550 [net: do not send ICMP/NDISC Redirects when peer allocation fails]
+CVE-2026-74550 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/dbc3791e3b2472e1ccc08947e0f83b443470ff4f (7.2-rc6)
-CVE-2026-74549 [hwmon: (nct6775-core) Prevent access to unsupported weight registers]
+CVE-2026-74549 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/d0b704e569ac3b8416d8e02270cdc9bf830ed395 (7.2-rc6)
-CVE-2026-74548 [forcedeth: fix UAF of txrx_stats in nv_remove]
+CVE-2026-74548 (In the Linux kernel, the following vulnerability has been resolved: f ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/22666ba1420164753d7b0f5a841986b25ace5435 (7.2-rc6)
-CVE-2026-74547 [hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread]
+CVE-2026-74547 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/cb0b7f9c43b0abbd422a7e4c2c85e91db429207c (7.2-rc6)
-CVE-2026-74546 [hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read]
+CVE-2026-74546 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3 (7.2-rc6)
-CVE-2026-74545 [rtase: fix double free of multi-frag skb on DMA map failure]
+CVE-2026-74545 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6fb7b769d6ed6d1d2e02af4a80e57a2477f35086 (7.2-rc6)
-CVE-2026-74544 [net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds]
+CVE-2026-74544 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/aef96eead2860cbfa371e4471d4f04412213b958 (7.2-rc6)
-CVE-2026-74543 [net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()]
+CVE-2026-74543 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/080695e6f005e2396f1207fd69d24c442cb230c6 (7.2-rc6)
-CVE-2026-74542 [netfs: Fix folio_queue ENOMEM in writeback by adding a mempool]
+CVE-2026-74542 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1d78d56c43ef3768183e8370e7367b162700e049 (7.2-rc6)
-CVE-2026-74541 [Bluetooth: ISO: clear iso_data always when detaching conn from hcon]
+CVE-2026-74541 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d57e506f6a1e3929611340fae87c1e4823f4d85c (7.2-rc6)
-CVE-2026-74540 [Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp]
+CVE-2026-74540 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/c4740e7f23ff9a8210198d8b4703259e21b9f69d (7.2-rc6)
-CVE-2026-74538 [Bluetooth: ISO: lock sk in iso_connect_ind]
+CVE-2026-74538 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/4311fd6f429065a8ba208660360a895627a00cf3 (7.2-rc6)
-CVE-2026-74537 [Bluetooth: ISO: hold sk properly in iso_conn_ready]
+CVE-2026-74537 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0d255e63fcf3f13a570d7ac11678fa1164ac015c (7.2-rc6)
-CVE-2026-74536 [Bluetooth: ISO: fix leaking sk after socket release]
+CVE-2026-74536 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ce57442a379212fe3fda59c9437ee8217eceb5b1 (7.2-rc6)
-CVE-2026-74535 [Bluetooth: ISO: avoid deadlocks in iso_sock_timeout]
+CVE-2026-74535 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/200fa1629c57a3ca2b03d3ca63fd3a9bfd910c43 (7.2-rc6)
-CVE-2026-74534 [Bluetooth: ISO: fix refcounting of iso_conn]
+CVE-2026-74534 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/fdfde532ab1caa165fcd8985001157ac8b4db365 (7.2-rc6)
-CVE-2026-74533 [Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero]
+CVE-2026-74533 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/af24e338bf5dafb80f42baa9a0b9e9b57b1c5d9c (7.2-rc6)
-CVE-2026-74532 [Bluetooth: btintel: Validate length before parsing diagnostics TLV]
+CVE-2026-74532 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b640ff9af3c809ff5ea2077fbba17df1594ec1e4 (7.2-rc6)
-CVE-2026-74531 [Bluetooth: hci_conn: hold conn reference in abort_conn_sync()]
+CVE-2026-74531 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5761d003daa987ac81463f570713ce9c9dd204e5 (7.2-rc6)
-CVE-2026-74530 [Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback]
+CVE-2026-74530 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/56e78b670356caab0b607e8aad4cf819a1909d07 (7.2-rc6)
-CVE-2026-74529 [Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback]
+CVE-2026-74529 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/44fc74069d8988f2825246f9401218e29de2c0ab (7.2-rc6)
-CVE-2026-74527 [octeontx2-af: Block VFs from clobbering special CGX PKIND state]
+CVE-2026-74527 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/3bd438a58e910db5dc369aa25dfed1fc95f1b596 (7.2-rc6)
-CVE-2026-74525 [net: sxgbe: free TX rings on RX allocation failure]
+CVE-2026-74525 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/c870f7e2890b9f78ac84515a9809cc5c183c975e (7.2-rc6)
-CVE-2026-74524 [riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove]
+CVE-2026-74524 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a0188cc133696627857d16054e43f9ebc7efc821 (7.2-rc6)
-CVE-2026-74523 [qede: sync udp_tunnel ports outside qede_lock in the recovery path]
+CVE-2026-74523 (In the Linux kernel, the following vulnerability has been resolved: q ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/451c9075d6c53f2438d110addbeeeea6fac18567 (7.2-rc6)
-CVE-2026-74522 [ksmbd: fix use-after-free in __close_file_table_ids()]
+CVE-2026-74522 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e7188199eff46a636f3436356f0aae039be6dd66 (7.2-rc6)
-CVE-2026-74521 [ksmbd: use memcmp() to compare ClientGUIDs]
+CVE-2026-74521 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e8bb506e6ef749ac0336f3e579d8d02396b7d832 (7.2-rc6)
-CVE-2026-74520 [iommu/iommufd: Fix IOPF group ownership UAF]
+CVE-2026-74520 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/738e6f32e61d80b554e37015ecb7bc620b88001c (7.2-rc6)
-CVE-2026-74519 [pinctrl: devicetree: don't free uninitialized dev_name on error path]
+CVE-2026-74519 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/015b5bcbcb622b32317642be91a7f79aa5413649 (7.2-rc6)
-CVE-2026-74518 [mm/hugetlb: fix list corruption in allocate_file_region_entries()]
+CVE-2026-74518 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/dd9623f58ec702a07b2d67179d6fcea79c52231a (7.2-rc6)
-CVE-2026-74517 [KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs]
+CVE-2026-74517 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9910e835580fef3bef53b70241dd00c4bffad693 (7.2-rc6)
-CVE-2026-74516 [KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active]
+CVE-2026-74516 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7d3aae206663c4e006b25a1c7a20a4029e67da76 (7.2-rc6)
-CVE-2026-74515 [KVM: s390: pci: Reject adapter interrupt forwarding if already enabled]
+CVE-2026-74515 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8fa01be5a6149404adb82c0979a78f6347edd3ef (7.2-rc6)
-CVE-2026-74514 [KVM: s390: pci: Fix memory accounting for pinned/unpinned pages]
+CVE-2026-74514 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/36f6999ecde3976731a8bfc0b8e667da6f593069 (7.2-rc6)
-CVE-2026-74513 [dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister]
+CVE-2026-74513 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a10ea943356b9d70c5616a0a06f6fa97cfdaccb1 (7.2-rc6)
-CVE-2026-74512 [audit: fix potential use-after-free in audit_del_rule()]
+CVE-2026-74512 (In the Linux kernel, the following vulnerability has been resolved: a ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/246df90b5f1a8a6e6abbd2f058b029558720adec (7.2-rc6)
-CVE-2026-74511 [Bluetooth: mgmt: fix pending command UAF in EIR updates]
+CVE-2026-74511 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8f2f62855a41d1730fb9e8122912bd2c8d6bed5d (7.2-rc6)
-CVE-2026-74510 [Bluetooth: mgmt: fix UAF in pair command cancellation]
+CVE-2026-74510 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd (7.2-rc6)
-CVE-2026-74509 [Bluetooth: hci_sync: Fix advertising data UAFs]
+CVE-2026-74509 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cdc36db204ffd97b947d64374cf23a210dc74777 (7.2-rc6)
-CVE-2026-74508 [Bluetooth: HIDP: reject frames without a transaction header]
+CVE-2026-74508 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/47778d2c2087b5d192398f6fddf692d16a5431cf (7.2-rc6)
-CVE-2026-74507 [Bluetooth: HIDP: validate numbered report payloads]
+CVE-2026-74507 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/34f53d27b81a16a02828c8fdfa4e02badc326f17 (7.2-rc6)
-CVE-2026-74506 [afs: Fix UAF when sending a message]
+CVE-2026-74506 (In the Linux kernel, the following vulnerability has been resolved: a ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/4af1ec68d54b3871155914d584fb10669c41a861 (7.2-rc6)
-CVE-2026-74505 [ALSA: 6fire: Fix UAF at error handling during probe]
+CVE-2026-74505 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/a54bf16965f896415c3337bc4fbb40fb11941d99 (7.2-rc6)
-CVE-2026-74504 [ALSA: seq: Fix division by zero in initialize_timer()]
+CVE-2026-74504 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/21e19688433452dfbbbe6b2bb670dea6eb92f0f6 (7.2-rc6)
-CVE-2026-74503 [ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes]
+CVE-2026-74503 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c2744d5f3aea474513fd2298daecb94a952ce441 (7.2-rc6)
-CVE-2026-74502 [ALSA: ump: fix double free of out_cvts on rawmidi error]
+CVE-2026-74502 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/70c977815af0d997feb2d0c5d284d55689bf7051 (7.2-rc6)
-CVE-2026-74501 [ALSA: usb-audio: fix use-after-free in ump_to_endpoint()]
+CVE-2026-74501 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/4a05b2d1b4642df74f30b6f54843e825c4a2bfd3 (7.2-rc6)
-CVE-2026-74500 [ALSA: usb-audio: fix stack info leak in RME Digiface status]
+CVE-2026-74500 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/441aaad150c57edaf57ee482a79a3bf4c5b7e353 (7.2-rc6)
-CVE-2026-74499 [ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()]
+CVE-2026-74499 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/0970274613fb463d376211450cab066d34ebfe6a (7.2-rc6)
-CVE-2026-74498 [ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set]
+CVE-2026-74498 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5 (7.2-rc6)
-CVE-2026-74497 [ALSA: usb-audio: Clamp frame size in implicit-feedback mode]
+CVE-2026-74497 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/8d7a30c50c2e58a6839634ed0acde14466d1dc61 (7.2-rc6)
-CVE-2026-74496 [fou: Fix use-after-free in fou_create()]
+CVE-2026-74496 (In the Linux kernel, the following vulnerability has been resolved: f ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/b14361aca6350ff7907b0e9903c7b94dc7d5d4a0 (7.2-rc6)
-CVE-2026-74495 [igbvf: Fix leak in TX DMA error cleanup]
+CVE-2026-74495 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/0565052b7e2f436b7f1541f4849da96dc0aa7a0e (7.2-rc6)
-CVE-2026-74494 [ksmbd: reject repeated SMB2 NEGOTIATE requests]
+CVE-2026-74494 (In the Linux kernel, the following vulnerability has been resolved: k ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cb469993b3a61a72653770856d37af616d72d05f (7.2-rc6)
-CVE-2026-74493 [net/smc: fix socket use-after-free during link group termination]
+CVE-2026-74493 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/f621d6ebeebb6374342571e4ddf45fdbc420f6cd (7.2-rc6)
-CVE-2026-74492 [netfilter: ipset: do not update comments from kernel-side hash adds]
+CVE-2026-74492 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/f30415929be8aeb002d557c8d3f7ab2d2188003a (7.2-rc6)
-CVE-2026-74490 [tipc: avoid use-after-free in poll trace queue dumps]
+CVE-2026-74490 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/b4f1719dfea023220e0e6bd892b087d76b2a6a49 (7.2-rc6)
-CVE-2026-74488 [wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames]
+CVE-2026-74488 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/99a948382af8a225e2d5e54a7052158cd6281cc6 (7.2-rc6)
-CVE-2026-74487 [binfmt_misc: restore write access when removing an entry]
+CVE-2026-74487 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/db1856ea9196cf6e015d12199a34c0b9313c7bfa (7.2-rc6)
-CVE-2026-74485 [binfmt_misc: reject a flag character as the field delimiter]
+CVE-2026-74485 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/8e85d50ba1117fd446bf9a250bd8a97d48384bdc (7.2-rc6)
-CVE-2026-74484 [binfmt_misc: don't let an 'F' entry pin its own instance]
+CVE-2026-74484 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/79055d82772b9584f259b747fe40ff56a076678d (7.2-rc6)
-CVE-2026-74483 [binfmt_misc: don't leak the user namespace when the mount fails]
+CVE-2026-74483 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b8206f516fe7cbe785cf44bf09c17c438d7c3cad (7.2-rc6)
-CVE-2026-74482 [mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios]
+CVE-2026-74482 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/e923bd21058ea02fd0dcd3549d151d143fd036e5 (7.2-rc6)
-CVE-2026-74481 [mm/page_reporting: use system_freezable_wq to fix UAF during suspend]
+CVE-2026-74481 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/0b45f6927a14914ff685fe0e6f9d11232a1e03df (7.2-rc6)
-CVE-2026-74480 [net: bridge: stop fast-leave after deleting a port group]
+CVE-2026-74480 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/a39789f211b8a4125f0c70e05b30cf715f4f187d (7.2-rc6)
-CVE-2026-74479 [net: pktgen: fix proc entry use-after-free]
+CVE-2026-74479 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/817ff6efdb7f484ea547218e11e17d8e43daa3b4 (7.2-rc6)
-CVE-2026-74478 [um: vector: fix use-after-free in vector_mmsg_rx()]
+CVE-2026-74478 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/af421e9aed3920c7ac88c24daa48606c7112feca (7.2-rc6)
-CVE-2026-74476 [veth: convert frag_list skbs before running XDP]
+CVE-2026-74476 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d0d6415963040c401e7a7e4e482a698ba52448cb (7.2-rc6)
-CVE-2026-74475 [vxlan: use neigh_ha_snapshot() in route_shortcircuit()]
+CVE-2026-74475 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d (7.2-rc6)
-CVE-2026-74474 [vxlan: use pskb_network_may_pull() for transmit path header pulls]
+CVE-2026-74474 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/b9553558b48db54ac9273e6b98d7263ef5c1a329 (7.2-rc6)
-CVE-2026-74473 [vxlan: use pskb_network_may_pull() in route_shortcircuit()]
+CVE-2026-74473 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb (7.2-rc6)
-CVE-2026-74472 [ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()]
+CVE-2026-74472 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e65848e4ce352bac9e3465099354c8b8f845391f (7.2-rc6)
-CVE-2026-74471 [tracing: Check return value of __register_event() in trace_module_add_events()]
+CVE-2026-74471 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/ac8719969e6c3c54e939834df812bc41f25453cf (7.2-rc6)
-CVE-2026-74470 [scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write]
+CVE-2026-74470 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/93dde0bf2f39a0f9f57fd610aa3201ce5b753433 (7.2-rc6)
-CVE-2026-74469 [sctp: prevent peer transport count overflow]
+CVE-2026-74469 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/bd0e9289e2642f6a5c54faad304ce0f41e926d22 (7.2-rc6)
-CVE-2026-74468 [gpio: pch: use raw_spinlock_t for the register lock]
+CVE-2026-74468 (In the Linux kernel, the following vulnerability has been resolved: g ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/a02b8950d619123da64f69b70fe1dadef217dfe4 (7.2-rc6)
-CVE-2026-74467 [s390/qeth: Check CAP_NET_ADMIN for private ioctls]
+CVE-2026-74467 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d211028bac1bd0fff0026bfa2a8328e5b78cd0e6 (7.2-rc6)
-CVE-2026-74466 [s390/zcrypt: Close speculative mem read possibility]
+CVE-2026-74466 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb (7.2-rc6)
-CVE-2026-74465 [net: openvswitch: fix potential UAF on meter attach failure]
+CVE-2026-74465 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/a58a2b0ce354df531ebc71fc870058c2feb59f6b (7.2-rc6)
-CVE-2026-74464 [net: openvswitch: fix skb leak on flow key update failure during ct]
+CVE-2026-74464 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/bc62e843bc48f933da765ce47079fd992e535794 (7.2-rc6)
-CVE-2026-74463 [i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock]
+CVE-2026-74463 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/d99607c888f26e8a4e9fe9772860cef4aff86bb4 (7.2-rc6)
-CVE-2026-74461 [i2c: imx: Cancel hrtimer before clearing slave pointer]
+CVE-2026-74461 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f (7.2-rc6)
-CVE-2026-74460 [can: ems_usb: validate CPC message lengths]
+CVE-2026-74460 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/02925f51377f2a42a6724f00549167499c9302e5 (7.2-rc6)
-CVE-2026-74459 [can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure]
+CVE-2026-74459 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7a0cf2b2497c757c3cb1286eddf2986abb0d387b (7.2-rc6)
-CVE-2026-74458 [can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents]
+CVE-2026-74458 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee (7.2-rc6)
-CVE-2026-74457 [can: peak_usb: add bounds check for USB channel index]
+CVE-2026-74457 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/39132f166ca8ce00ae60d8a9068e06a60943cc4b (7.2-rc6)
-CVE-2026-74456 [can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error]
+CVE-2026-74456 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9 (7.2-rc6)
-CVE-2026-74455 [can: peak_usb: validate uCAN receive record lengths]
+CVE-2026-74455 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/93fcab2c6968446316bbb49548848df604d6346f (7.2-rc6)
-CVE-2026-74454 [drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size]
+CVE-2026-74454 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/6395789e4739aa5177bbec0fa0f07ccc38d249b0 (7.2-rc6)
-CVE-2026-74453 [drm/vc4: Zero the tile state data array before each BIN job]
+CVE-2026-74453 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/48a570c964d8e37d353381e4195106277e17f5cb (7.2-rc6)
-CVE-2026-74452 [drm/panthor: reject firmware sections with oversized data]
+CVE-2026-74452 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a3caaa06809248b996254be5b47e10804a3494e2 (7.2-rc6)
-CVE-2026-74451 [drm/panthor: validate firmware interface structure sizes]
+CVE-2026-74451 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b921b8613790a3f9e78ab64017fa7149ef0b750c (7.2-rc6)
-CVE-2026-74450 [drm/amd/pm: fix pptable use-after-free]
+CVE-2026-74450 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/bb493058c35c8676e48269ab6732688ea733d23c (7.2-rc6)
-CVE-2026-74449 [drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport]
+CVE-2026-74449 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/f327e389c07cfc3a2f6ff54f6214e1a52d457edc (7.2-rc6)
-CVE-2026-74448 [drm/amdkfd: fix QID bit leak in pqm_create_queue()]
+CVE-2026-74448 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/38b73293f38658a4685ffcea666462024f858ad9 (7.2-rc6)
-CVE-2026-74447 [drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment]
+CVE-2026-74447 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/83463a96ea3c7d8ae636a4d6a0ba63c9ce410724 (7.2-rc6)
-CVE-2026-74446 [drm/amdkfd: hold event_mutex while checkpointing CRIU events]
+CVE-2026-74446 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 (7.2-rc6)
-CVE-2026-74445 [drm/vmwgfx: reject DX_BIND_QUERY without a DX context]
+CVE-2026-74445 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db (7.2-rc6)
-CVE-2026-74444 [drm/vmwgfx: validate DRAW_PRIMITIVES header size before division]
+CVE-2026-74444 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/85891d174707d8bddcec7a888fb4e1d17def34f3 (7.2-rc6)
-CVE-2026-74443 [drm/vmwgfx: bound DMA command body size against suffix pointer]
+CVE-2026-74443 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/f4f1db96bfd68b81053693ba53405b6f510ac16c (7.2-rc6)
-CVE-2026-74442 [drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure]
+CVE-2026-74442 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/05eaa887e7b4f40fba425f8a1d7a5a8a043092a6 (7.2-rc6)
-CVE-2026-74441 [usb: typec: ucsi: Fix race condition and ordering in port unregistration]
+CVE-2026-74441 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261 (7.2-rc5)
-CVE-2026-74440 [drm/xe: Wait on external BO kernel fences in exec IOCTL]
+CVE-2026-74440 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3c68a48823f2b2dc7c763dcbb18dcb4fb600a057
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3c68a48823f2b2dc7c763dcbb18dcb4fb600a057
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/eeb59732/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list