[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 09:17:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
82266379 by Salvatore Bonaccorso at 2026-08-28T09:27:02+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,479 @@
+CVE-2026-80677 [driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/e9506871a8ea304cde48ff4a57226df2aadddae3 (7.2-rc1)
+CVE-2026-80675 [libbpf: Reject non-exclusive metadata maps in the signed loader]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0fb6c9ed6493b4af01be8bb0a384574eba7df636 (7.2-rc1)
+CVE-2026-80674 [ntfs: validate resident attribute lists and harden the validator]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7d19e1ffee084c4f7d321a360c14ba43404f7cc8 (7.2-rc1)
+CVE-2026-80673 [ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/344b18f389f9934d59c7b0cf3d20541ea2e0da58 (7.2-rc1)
+CVE-2026-80672 [ntfs: fix u16 truncation of restart-area length check]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/390936fb15053d8d8991ca3a22776e251a5a7f2f (7.2-rc1)
+CVE-2026-80667 [net/mlx5: LAG, MPESW, Fix missing complete() on devcom error]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d4b85f9a668b9c44216bb78daf4ec1a915cc92d1 (7.2-rc3)
+CVE-2026-80666 [Bluetooth: sco: Fix a race condition in sco_sock_timeout()]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0f8a5dcc66648b6e1458a9f3ba4c5a0463a228fc (7.2-rc3)
+CVE-2026-80665 [KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9f3e83345a56280efffe235c65593c7e544c0fcc (7.2-rc4)
+CVE-2026-80664 [netfilter: xt_nat: reject unsupported target families]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd (7.2-rc4)
+CVE-2026-80663 [tools/power/x86/intel-speed-select: Harden daemon pidfile open]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/607af438e6430893a822964c841a1994b33acccc (7.2-rc1)
+CVE-2026-80661 [ufs: core: tracing: Do not dereference pointers in TP_printk()]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/535fcf4b8a261fbb8cc4f91e4597343c135a90f2 (7.2-rc3)
+CVE-2026-80660 [hwmon: (occ) unregister sysfs devices outside occ lock]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e31408734332b8cc611342cdaaab6ba492180156 (7.2-rc2)
+CVE-2026-80659 [mmc: vub300: defer reset until cmd_mutex is unlocked]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/ee5fb641c4ccac8406c668d3e947eb20ce44f233 (7.2-rc4)
+CVE-2026-80658 [drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9456381d8b60bb7dd42f2f04afe5ee4ce6e0bc12 (7.2-rc1)
+CVE-2026-80656 [hfsplus: Add a sanity check for btree node size]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3f95e2661574ff13f099dd13456751933c280628 (7.2-rc1)
+CVE-2026-80652 [crypto: ccp - Treat zero-length cert chain as query for blob lengths]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/ef8c9dacda2871accd64e3eda951fef6b788b1ea (7.2-rc1)
+CVE-2026-80651 [crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/930d9d36ea618a775985446a125aedeb401db522 (7.2-rc1)
+CVE-2026-80648 [pinctrl: spacemit: fix NULL check in spacemit_pin_set_config]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/09c816e5c4d3a8d6d6e4b7537433e5e98505d934 (7.2-rc1)
+CVE-2026-80647 [RDMA/hns: Fix warning in poll cq direct mode]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/3f19c2a3852e6ba75f3e92dd5edc4e07f3d07f4a (7.2-rc1)
+CVE-2026-80646 [ipv6: guard against possible NULL deref in __in6_dev_stats_get()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/507541c2a8eeb76c02bd2511958f73a8cfa3e1bc (7.2-rc1)
+CVE-2026-80645 [rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/fc15e3a30ddd950f009c76765331783b9af94a87 (7.2-rc1)
+CVE-2026-80644 [ocfs2: don't BUG_ON an invalid journal dinode]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/c0438198c28b1d22c272751af5e717c11d9fa8dd (7.2-rc1)
+CVE-2026-80642 [liveupdate: Reference count incoming FLB data]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d8e47bd066d7e626f9f45d416182d585b7e18b9b (7.2-rc1)
+CVE-2026-80641 [wifi: wlcore: enable the right set of ciphers]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7495adaa0e45e180f4b6b7436675c6266edff1ff (7.2-rc1)
+CVE-2026-80640 [cxl/fwctl: Fix __fortify_panic]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6c9d2e87df40d606f1c85143e9acb1ecff463d5e (7.2-rc1)
+CVE-2026-80639 [cxl/test: Fix __fortify_panic]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/08326b92c7a414a73b5b308d1daf0e91e0134dfc (7.2-rc1)
+CVE-2026-80638 [ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1ec3cca2d8b6b9ff6584ca626d4c8918bbf48d44 (7.2-rc1)
+CVE-2026-80633 [iommufd: Take dma_resv lock before dma_buf_unpin() in release path]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e745cd2c749e557c14a15ac931761c3f58c24489 (7.2-rc1)
+CVE-2026-80632 [wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6794edb55b5f5ef834e03b0b241b1a8b725f82c0 (7.2-rc1)
+CVE-2026-80630 [net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/097f6fc7b1ae362dd7a9444b2572162fda73b284 (7.2-rc1)
+CVE-2026-80627 [MIPS: mm: Fix out-of-bounds write in maar_res_walk()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/1b001b16bc88f3f7817e228acfd91ee01bdcfcce (7.2-rc1)
+CVE-2026-80626 [powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/81e3a86030462824a67d697739cf3f387f4ba350 (7.2-rc1)
+CVE-2026-80625 [RDMA/hns: Fix memory leak of bonding resources]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c0bd03b850d81a8914168d87ddf7f6ffa58875ef (7.2-rc1)
+CVE-2026-80624 [mfd: cs42l43: Sanity check firmware size]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b6ef1a74b3ec254f87a6a3c554fe8f8083ebd37c (7.2-rc1)
+CVE-2026-80622 [char: tlclk: fix use-after-free in tlclk_cleanup()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1 (7.2-rc1)
+CVE-2026-80621 [PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/26b67fa10ef84ea667942491b50e6261a45f098d (7.2-rc1)
+CVE-2026-80620 [Revert "PCI/MSI: Unmap MSI-X region on error"]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f64e03da0d83cb173743888bff4a7e61476a8fc2 (7.2-rc1)
+CVE-2026-80619 [apparmor: fix potential UAF in aa_replace_profiles]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/7b42f95813dc9ceb6bda35afcf914630909a19f9 (7.2-rc1)
+CVE-2026-80618 [drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3f0cc1735273a57c5116710cf0202e12152f59cc (7.2-rc1)
+CVE-2026-80617 [net: airoha: fix foe_check_time allocation size]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5c121ee635680c93d7074becf14cfbaac140f80d (7.2-rc1)
+CVE-2026-80615 [net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4c6d43db2a4d2cef3921e885cf34798f790d34ea (7.2-rc1)
+CVE-2026-80613 [veth: fix NAPI leak in XDP enable error path]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6739027cb72da26890edd424c77080d187b2a92e (7.2-rc1)
+CVE-2026-80612 [net: lwtunnel: Drop skb metadata before LWT encapsulation]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c00320b0e355c4bf0ae4743a53b4180fea237546 (7.2-rc1)
+CVE-2026-80610 [net: enetc: fix potential divide-by-zero when num_vsi is zero]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5da65537792b68b6052ffcab65e04c27aea6dfe4 (7.2-rc1)
+CVE-2026-80609 [qede: fix out-of-bounds check for cqe->len_list[]]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f9ba47fce5932c15891c89c60e76dfaca919cb8d (7.2-rc2)
+CVE-2026-80608 [accel/amdxdna: Fix iommu domain lifetime race during device removal]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b4a0500fdf6e61a6c5f92ff2e61bc91578075803 (7.2-rc2)
+CVE-2026-80606 [drm/xe/userptr: Hold notifier_lock for write on inject test path]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dca6e08c923a44d2d66b955e03dd57a3a38c2b94 (7.2-rc2)
+CVE-2026-80605 [HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/0021eb09041f021c079be1022934a280f7f176c0 (7.2-rc3)
+CVE-2026-80604 [HID: core: Fix OOB read in hid_get_report for numbered reports]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 (7.2-rc3)
+CVE-2026-80603 [netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/ef6400ca25a13fd6dedbe8ef4a1d0979bbbfe88a (7.2-rc1)
+CVE-2026-80601 [batman-adv: gw: acquire ethernet header only after skb realloc]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/77880a3be88d378d60cc1e8f8ec70430e2ed0518 (7.2-rc2)
+CVE-2026-80600 [batman-adv: dat: acquire ARP hw source only after skb realloc]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/48067b2ae4504500a7093d9e1e16b42e70330480 (7.2-rc2)
+CVE-2026-80599 [batman-adv: dat: ensure accessible eth_hdr proto field]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/26560c4a03dc4d607331600c187f59ab2df5f341 (7.2-rc2)
+CVE-2026-80597 [mtd: maps: vmu-flash: fix NULL pointer dereference in initialization]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/357e3b8e3a8769ba36eb8ec5e053e4825f1a9329 (7.2-rc1)
+CVE-2026-80596 [Input: ims-pcu - only expose sysfs attributes on control interface]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/001428ea4d2c371107cb984108e266adf99f1f1e (7.2-rc1)
+CVE-2026-80595 [Input: ims-pcu - add response length checks]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/48c9d92fd4ee3a8f5d2cb46c802a0eff8e67c79c (7.2-rc1)
+CVE-2026-80594 [Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/d4579af29e67ca8722db0a1194227f8015c8981d (7.2-rc1)
+CVE-2026-80593 [hwmon: (asus_atk0110) Check package count before accessing element]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/e2735b39f044bad7bf2017aef248935525bc0b97 (7.2-rc2)
+CVE-2026-80592 [samples/damon/mtier: fail early if address range parameters are invalid]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7746d72c64054976887928d64d2caf25c5a6dcc0 (7.2-rc3)
+CVE-2026-80591 [f2fs: fix listxattr handling of corrupted xattr entries]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.96-1
+ [bookworm] - linux 6.1.180-1
+ [bullseye] - linux 5.10.262-1
+ NOTE: https://git.kernel.org/linus/5ef5bc304f23c3fe255d4936472378dcb74d0e94 (7.2-rc1)
+CVE-2026-80676 [Drivers: hv: vmbus: use generic driver_override infrastructure]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ NOTE: https://git.kernel.org/linus/331d8900121a1d74ecd45cd2db742ddcb5a0a565 (7.2-rc1)
+CVE-2026-80671 [perf sched: Fix register_pid() overflow, strcpy, and BUG_ON]
+ - linux 7.1.5-1
+ NOTE: https://git.kernel.org/linus/5949d339f5ec98752d56dcd4e36f619a59d513a5 (7.2-rc1)
+CVE-2026-80670 [perf tools: Use perf_env__get_cpu_topology() in machine__resolve()]
+ - linux 7.1.5-1
+ NOTE: https://git.kernel.org/linus/5484b43a0ec8231c36fba6ead654cb72dbba8b8f (7.2-rc1)
+CVE-2026-80669 [bpf: Disable xfrm_decode_session hook attachment]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ NOTE: https://git.kernel.org/linus/12091470c6b4c1c14b2de12dcbae2ada6cb6d20b (7.2-rc1)
+CVE-2026-80668 [netfilter: nf_conntrack_expect: use conntrack GC to reap expectations]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b8b09dc2bf35a00d4e0556b5d6308c7b917ebda2 (7.2-rc1)
+CVE-2026-80662 [cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size]
+ - linux 7.1.5-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c268f949e219f9e179558e836f457f6c5fbec416 (7.2-rc1)
+CVE-2026-80657 [accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer]
+ - linux 7.1.5-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/506255d46bdb93a281cf39e72abbca124f5c7a1b (7.2-rc1)
+CVE-2026-80655 [soc: xilinx: Fix race condition in event registration]
+ - linux 7.1.5-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fb445935338405110baca8f541a2df3b4cb8d712 (7.2-rc1)
+CVE-2026-80654 [soc: xilinx: Shutdown and free rx mailbox channel]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ NOTE: https://git.kernel.org/linus/fdee7c66c0d7b6869c36b9f9a915abf29ab5b550 (7.2-rc1)
+CVE-2026-80653 [scsi: hisi_sas: Add slave_destroy interface for v3 hw]
+ - linux 7.1.5-1
+ NOTE: https://git.kernel.org/linus/67b85a88265df19f049241d8c00571a5408f4eeb (7.2-rc1)
+CVE-2026-80650 [media: atomisp: gc2235: fix UAF and memory leak]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ NOTE: https://git.kernel.org/linus/628f763aee0047ff44974388d6f70f75a763026b (7.2-rc1)
+CVE-2026-80649 [firmware: arm_scmi: Fix OOB in scmi_power_name_get()]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ NOTE: https://git.kernel.org/linus/f9ef3f66f4b18078e464b7606f9497e4dbeb9905 (7.2-rc1)
+CVE-2026-80643 [EDAC/igen6: Fix call trace due to missing release()]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ab1f9d466c7d83ab0d2a529e07984e53b5960dcd (7.2-rc1)
+CVE-2026-80637 [netfilter: synproxy: fix unaligned memory access in timestamp adjustment]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ NOTE: https://git.kernel.org/linus/992c20bc8a4aba220c8b95b467d049289778dad6 (7.2-rc1)
+CVE-2026-80636 [netfilter: conntrack: revert ct extension genid infrastructure]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/35e21a4dccc5c255ba59ccfbfeb4629ed21da972 (7.2-rc1)
+CVE-2026-80635 [wifi: wcn36xx: fix OOB read from short trigger BA firmware response]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ NOTE: https://git.kernel.org/linus/b5e6f21923ca89d90256e7346301056f6502691e (7.2-rc1)
+CVE-2026-80634 [netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e052f920773b73be49eb4d8702a9f85de7464363 (7.2-rc1)
+CVE-2026-80631 [btrfs: lzo: reject compressed segment that overflows the compressed input]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b0d27d43791b7a3057c3c4aedf9b4aa033d37c46 (7.2-rc1)
+CVE-2026-80629 [octeontx2-af: npc: Fix size of entry2cntr_map]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f9cd6fabe0e7c7f6fc30c6c192c7ed72aba37232 (7.2-rc1)
+CVE-2026-80628 [ALSA: seq: oss: Serialize readq reset state with q->lock]
+ - linux 7.1.5-1
+ NOTE: https://git.kernel.org/linus/49ce92d207820f588b0406add82f053decfbe5d9 (7.2-rc1)
+CVE-2026-80623 [coresight: ete: Always save state on power down]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2ab4645fe4206c142a5f1491e191c906279686cf (7.2-rc1)
+CVE-2026-80616 [ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()]
+ - linux 7.1.5-1
+ NOTE: https://git.kernel.org/linus/0569f67ed6a7af838e2141da93c68e6b6013f483 (7.2-rc1)
+CVE-2026-80614 [net: emac: Fix NULL pointer dereference in emac_probe]
+ - linux 7.1.5-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f623d38fe6c4e8c40b23f42cc6fe6963fa49997b (7.2-rc1)
+CVE-2026-80611 [ACPI: processor_idle: Mark LPI enter functions as __cpuidle]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ NOTE: https://git.kernel.org/linus/956ca5d72c76504824c8eb601879da9476973e15 (7.2-rc1)
+CVE-2026-80607 [tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg]
+ - linux 7.1.5-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/251a8fe1b9aedccd298b77bc28426d564c5a923f (7.2-rc2)
+CVE-2026-80602 [perf/x86/amd/lbr: Fix kernel address leakage]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2a892294b83f541115c94b0bb637f39bef187657 (7.2-rc3)
+CVE-2026-80598 [ntfs3: fix out-of-bounds read in decompress_lznt]
+ - linux 7.1.5-1
+ [trixie] - linux 6.12.100-1
+ [bookworm] - linux 6.1.180-1
+ NOTE: https://git.kernel.org/linus/7160a57192fb16d7a6fa9b7f5c7ac341d2444a89 (7.2-rc1)
CVE-2026-80590 [inet: frags: strip GSO state from fragments before reassembly]
- linux <unfixed>
NOTE: https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82266379c3fa30a5d21e1e52cdf54c58965d8d8e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82266379c3fa30a5d21e1e52cdf54c58965d8d8e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/1bafd7c9/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list