[Git][security-tracker-team/security-tracker][master] Update status for some Intel related CVEs for Intel NPU firmware

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 15:35:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
be63b0b5 by Salvatore Bonaccorso at 2026-08-16T16:35:28+02:00
Update status for some Intel related CVEs for Intel NPU firmware

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9522,7 +9522,7 @@ CVE-2026-21269 (is affected by a stored Cross-Site Scripting (XSS) vulnerability
 CVE-2026-20913 (Improper input validation for some Intel(R) Neural Compressor software ...)
 	NOT-FOR-US: Intel
 CVE-2026-20908 (Time-of-check time-of-use race condition for the Intel(R) NPU Driver f ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20906 (Protection mechanism failure for some Intel(R) Neural Compressor softw ...)
 	NOT-FOR-US: Intel
 CVE-2026-20903 (Protection mechanism failure for some Intel(R) AI Containers before ve ...)
@@ -9548,9 +9548,19 @@ CVE-2026-20789 (Improper access control for some Intel(R) PROSet/Wireless WiFi S
 CVE-2026-20787 (Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Softwa ...)
 	NOT-FOR-US: Intel
 CVE-2026-20786 (Out-of-bounds read for the Intel(R) NPU Driver for all versions within ...)
-	TODO: check
+	- firmware-nonfree 20260410-1
+	[trixie] - firmware-nonfree <no-dsa> (Minor issue)
+	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01456.html
+	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/6ca0863131571e06cce90bc04e318fc92751890e (20260410)
 CVE-2026-20783 (Improper conditions check in the firmware for the Intel(R) NPU Driver  ...)
-	TODO: check
+	- firmware-nonfree 20260410-1
+	[trixie] - firmware-nonfree <no-dsa> (Minor issue)
+	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01456.html
+	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/6ca0863131571e06cce90bc04e318fc92751890e (20260410)
 CVE-2026-20780 (Uncontrolled resource consumption for some Intel(R) PROSet/Wireless Wi ...)
 	NOT-FOR-US: Intel
 CVE-2026-20778 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for ...)
@@ -9562,7 +9572,12 @@ CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring 0:
 CVE-2026-20770 (Protection mechanism failure for some Cluster Management Toolkit for K ...)
 	NOT-FOR-US: Intel
 CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all versions ...)
-	TODO: check
+	- firmware-nonfree 20260410-1
+	[trixie] - firmware-nonfree <no-dsa> (Minor issue)
+	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01456.html
+	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/6ca0863131571e06cce90bc04e318fc92751890e (20260410)
 CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software before versi ...)
 	NOT-FOR-US: Intel
 CVE-2026-20763 (Incorrect calculation for some Intel(R) TDX Guest software before vers ...)
@@ -9586,7 +9601,12 @@ CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for s
 CVE-2026-20734 (Improper initialization in some firmware for some Intel(R) Active Mana ...)
 	NOT-FOR-US: Intel
 CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for all versi ...)
-	TODO: check
+	- firmware-nonfree 20260410-1
+	[trixie] - firmware-nonfree <no-dsa> (Minor issue)
+	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01456.html
+	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/6ca0863131571e06cce90bc04e318fc92751890e (20260410)
 CVE-2026-20728 (Protection mechanism failure for some Intel Extension for TensorFlow s ...)
 	NOT-FOR-US: Intel
 CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Softwa ...)
@@ -132162,6 +132182,7 @@ CVE-2025-32735 (Improper conditions check in some firmware for some Intel(R) NPU
 	- firmware-nonfree 20251011-1
 	[trixie] - firmware-nonfree <no-dsa> (Minor issue)
 	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01403.html
 	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/d2404284b6ce4ee34ca56351d8741cdc61d81910 (20251011)
 CVE-2025-32467 (Use of uninitialized variable for some TDX Module before version tdx1. ...)
@@ -168414,11 +168435,13 @@ CVE-2025-26694 (Null pointer dereference for some Intel(R) QAT Windows software
 CVE-2025-26405 (Improper control of dynamically-managed code resources for some Intel( ...)
 	- firmware-nonfree 20250410-1
 	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
 	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/495f77c714a65a42fa761cb7064f25cd1f3f1898 (20250410)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01304.html
 CVE-2025-26402 (Protection mechanism failure for some Intel(R) NPU Drivers within Ring ...)
 	- firmware-nonfree 20250410-1
 	[bookworm] - firmware-nonfree <not-affected> (VPU firmware not yet present)
+	[bullseye] - firmware-nonfree <not-affected> (VPU firmware not yet present)
 	NOTE: https://gitlab.com/kernel-firmware/linux-firmware/-/commit/495f77c714a65a42fa761cb7064f25cd1f3f1898 (20250410)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01304.html
 CVE-2025-25216 (Improper input validation in some firmware for some Intel(R) Graphics  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be63b0b555f08af54030e08af560075003c6cca9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be63b0b555f08af54030e08af560075003c6cca9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/e842ad7e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list