[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 20:14:00 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
59917fc9 by security tracker role at 2026-08-28T19:13:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,715 +1,987 @@
-CVE-2026-80724 [ptp: vmclock: prevent read-only mappings from becoming writable]
+CVE-2026-9548 (An improper neutralization of input during web page generation ('Cross ...)
+ TODO: check
+CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in Synolo ...)
+ TODO: check
+CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing a spe ...)
+ TODO: check
+CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
+ TODO: check
+CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
+ TODO: check
+CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
+ TODO: check
+CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
+ TODO: check
+CVE-2026-82260 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
+ TODO: check
+CVE-2026-82259 (SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contai ...)
+ TODO: check
+CVE-2026-82258 (SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition ...)
+ TODO: check
+CVE-2026-82257 (SvelteKit versions before 2.69.1 contain a prototype pollution vulnera ...)
+ TODO: check
+CVE-2026-82256 (SvelteKit before 2.69.1 fails to properly validate remote form functio ...)
+ TODO: check
+CVE-2026-82255 (gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerab ...)
+ TODO: check
+CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delta appl ...)
+ TODO: check
+CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...)
+ TODO: check
+CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the worktree .git ...)
+ TODO: check
+CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ...)
+ TODO: check
+CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic vulnera ...)
+ TODO: check
+CVE-2026-82249 (gitoxide before 0.38.2 fails to validate carriage return characters in ...)
+ TODO: check
+CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of gitoxide) allows writing fil ...)
+ TODO: check
+CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-roll ...)
+ TODO: check
+CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
+ TODO: check
+CVE-2026-82245 (Budibase before 3.41.3 fails to enforce role-based authorization on li ...)
+ TODO: check
+CVE-2026-82244 (Budibase versions before 3.41.3 contain a remote code execution vulner ...)
+ TODO: check
+CVE-2026-82243 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
+ TODO: check
+CVE-2026-82242 (Budibase versions before 3.41.3 contain a missing authorization vulner ...)
+ TODO: check
+CVE-2026-82241 (Budibase backend-core (@budibase/backend-core, as used by @budibase/se ...)
+ TODO: check
+CVE-2026-82240 (Budibase before 3.41.3 fails to validate app-scoped builder role assig ...)
+ TODO: check
+CVE-2026-82239 (Budibase before 3.41.3 fails to enforce per-table role restrictions on ...)
+ TODO: check
+CVE-2026-82238 (filebrowser from version 2.24.0 contains a race condition in the TUS u ...)
+ TODO: check
+CVE-2026-82237 (filebrowser through 2.63.23 does not remove share records when a share ...)
+ TODO: check
+CVE-2026-82236 (File Browser versions from 2.63.6 through 2.63.23 fail to clean up pub ...)
+ TODO: check
+CVE-2026-82235 (filebrowser through 2.63.23 fails to validate named pipes in directory ...)
+ TODO: check
+CVE-2026-82234 (SiYuan versions before v3.8.1 contain a server-side request forgery vu ...)
+ TODO: check
+CVE-2026-82233 (SiYuan before v3.8.1 contains a path traversal vulnerability in the as ...)
+ TODO: check
+CVE-2026-82227 (Contributor SQL Injection in WPBulky <= 1.2.2 versions.)
+ TODO: check
+CVE-2026-82222 (Deserialization of Untrusted Data vulnerability in Liquid Web / Stella ...)
+ TODO: check
+CVE-2026-82220 (Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versi ...)
+ TODO: check
+CVE-2026-82181 (Medical Practice Management System developed by Le-yan has a Sensitive ...)
+ TODO: check
+CVE-2026-82123 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-82112 (A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impac ...)
+ TODO: check
+CVE-2026-82111 (A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The a ...)
+ TODO: check
+CVE-2026-82078 (An unsafe dynamic class loading vulnerability exists in the database c ...)
+ TODO: check
+CVE-2026-81777 (Authentication Bypass by Spoofing vulnerability in WPDeveloper Essenti ...)
+ TODO: check
+CVE-2026-81767 (Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versi ...)
+ TODO: check
+CVE-2026-81761 (Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.)
+ TODO: check
+CVE-2026-81760 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+ TODO: check
+CVE-2026-81759 (Contributor Broken Access Control in WpEvently <= 5.5.0 versions.)
+ TODO: check
+CVE-2026-81757 (Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 version ...)
+ TODO: check
+CVE-2026-81733 (WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a ...)
+ TODO: check
+CVE-2026-81732 (WWBN AVideo through version 30.0 fails to enforce authentication on th ...)
+ TODO: check
+CVE-2026-81578 (An improper access control vulnerability exists in the web management ...)
+ TODO: check
+CVE-2026-81341 (wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 ...)
+ TODO: check
+CVE-2026-81299 (Subscriber Insecure Direct Object References (IDOR) in WP Job Portal < ...)
+ TODO: check
+CVE-2026-81285 (Unauthenticated Denial of Service Attack in Smush Image Compression an ...)
+ TODO: check
+CVE-2026-81284 (Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.)
+ TODO: check
+CVE-2026-81020 (wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce on ...)
+ TODO: check
+CVE-2026-81019 (wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce ...)
+ TODO: check
+CVE-2026-79996 (The User Registration & Membership WordPress plugin before 5.2.6 does ...)
+ TODO: check
+CVE-2026-79995 (The User Registration & Membership WordPress plugin before 5.2.5 does ...)
+ TODO: check
+CVE-2026-79706 (The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a va ...)
+ TODO: check
+CVE-2026-79615 (The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does ...)
+ TODO: check
+CVE-2026-78238 (SOY Gallery contains a cross-site scripting vulnerability. An arbitra ...)
+ TODO: check
+CVE-2026-78073 (Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0 ...)
+ TODO: check
+CVE-2026-78072 (Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Po ...)
+ TODO: check
+CVE-2026-78071 (Joomla Extension - digital-peak.com - Authenticated, privileged stored ...)
+ TODO: check
+CVE-2026-78070 (Joomla Extension - digital-peak.com - Authenticated, privileged blind ...)
+ TODO: check
+CVE-2026-78032 (SOY CMS contains an issue with deserialization of untrusted data. An ...)
+ TODO: check
+CVE-2026-77838 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
+ TODO: check
+CVE-2026-77701 (The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly ...)
+ TODO: check
+CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentic ...)
+ TODO: check
+CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
+ TODO: check
+CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
+ TODO: check
+CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
+ TODO: check
+CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
+ TODO: check
+CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
+ TODO: check
+CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
+ TODO: check
+CVE-2026-6128 (The All-in-One WP Migration Unlimited Extension plugin for WordPress i ...)
+ TODO: check
+CVE-2026-5953 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-5934 (The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site ...)
+ TODO: check
+CVE-2026-5800 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-5510 (The GiveWP \u2013 Donation Plugin and Fundraising Platform plugin for ...)
+ TODO: check
+CVE-2026-5097 (The wpForo Forum plugin for WordPress is vulnerable to SQL Injection v ...)
+ TODO: check
+CVE-2026-5096 (The Everest Forms plugin for WordPress is vulnerable to Server-Side Re ...)
+ TODO: check
+CVE-2026-58107 (CodeChecker'smassStoreRunprocessing path performs one-shot decompressi ...)
+ TODO: check
+CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was f ...)
+ TODO: check
+CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
+ TODO: check
+CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
+ TODO: check
+CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
+ TODO: check
+CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of ...)
+ TODO: check
+CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
+ TODO: check
+CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
+ TODO: check
+CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully ...)
+ TODO: check
+CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
+ TODO: check
+CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
+ TODO: check
+CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy ...)
+ TODO: check
+CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
+ TODO: check
+CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
+ TODO: check
+CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
+ TODO: check
+CVE-2026-40204 (None None None No publicly available exploits are known.)
+ TODO: check
+CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
+ TODO: check
+CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
+ TODO: check
+CVE-2026-40018 (None None None No publicly available exploits are known.)
+ TODO: check
+CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
+ TODO: check
+CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
+ TODO: check
+CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
+ TODO: check
+CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
+ TODO: check
+CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
+ TODO: check
+CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows unauthenticated ...)
+ TODO: check
+CVE-2026-38638 (An issue in the with_argv function (/unistd/mod.rs) of relibc commit 6 ...)
+ TODO: check
+CVE-2026-38636 (An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 6 ...)
+ TODO: check
+CVE-2026-38093 (file_picker (aka flutter_file_picker) for Flutter, all versions throug ...)
+ TODO: check
+CVE-2026-37751 (An OS command injection vulnerability in the killSessionSync function ...)
+ TODO: check
+CVE-2026-37736 (An issue in the JsonSanitizer.sanitize() component of OWASP json-sanit ...)
+ TODO: check
+CVE-2026-37710 (Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote ...)
+ TODO: check
+CVE-2026-37237 (vLLM up to and including 0.17.0 allows remote attackers to cause a Den ...)
+ TODO: check
+CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...)
+ TODO: check
+CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
+ TODO: check
+CVE-2026-33606 (Mail content stored by a user can be crafted so that it is interpreted ...)
+ TODO: check
+CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
+ TODO: check
+CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
+ TODO: check
+CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
+ TODO: check
+CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
+ TODO: check
+CVE-2026-19423 (The Ultimate Member WordPress plugin before 2.13.0 does not validate ...)
+ TODO: check
+CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)
+ TODO: check
+CVE-2026-19084 (The shared-files-pro WordPress plugin before 1.7.70 does not validate ...)
+ TODO: check
+CVE-2026-18918 (In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization che ...)
+ TODO: check
+CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writes bey ...)
+ TODO: check
+CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In versions p ...)
+ TODO: check
+CVE-2026-14942
+ REJECTED
+CVE-2026-14567 (The User Frontend WordPress plugin before 4.3.10 does not restrict ac ...)
+ TODO: check
+CVE-2026-14558 (The User Frontend WordPress plugin before 4.3.10 does not properly va ...)
+ TODO: check
+CVE-2026-13761 (Pega Platform versions 7.1.0 through 25.1.2 are affected by an imprope ...)
+ TODO: check
+CVE-2026-12514 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
+ TODO: check
+CVE-2026-12513 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
+ TODO: check
+CVE-2026-80724 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.12-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
-CVE-2026-80723 [of: reserved_mem: prevent OOB when too many dynamic regions are defined]
+CVE-2026-80723 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/db3dbdfea1b8f38774419c5c2c14e4b81c48708d (7.2-rc6)
-CVE-2026-80720 [iomap: add a separate bio_set for iomap_split_ioend]
+CVE-2026-80720 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c679ce3be6cb63763d68ab9b5d9d73ddc0a40762 (7.2-rc6)
-CVE-2026-80719 [mm: mglru: fix stale batch updates after memcg reparenting]
+CVE-2026-80719 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/de4660898b7aa7e03d3b120a6bfa6b26211e4e77 (7.2-rc6)
-CVE-2026-80713 [io_uring: preserve task restrictions across exec]
+CVE-2026-80713 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/bc0e8faf90e776a2f1f3967a04e8091e6bdb4977 (7.2-rc6)
-CVE-2026-80712 [spi: spi-qpic-snand: write the feature value before executing SET_FEATURE]
+CVE-2026-80712 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8fd62901d6bf03f274a49dd0060793cc07dd51b0 (7.2-rc6)
-CVE-2026-80711 [power: supply: max17040: handle missing status supplier]
+CVE-2026-80711 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/725668c6b6aa3971fe850659102c250d0d676e18 (7.2-rc6)
-CVE-2026-80702 [drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size]
+CVE-2026-80702 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/83195b778f2d109a3a4f3ffaba4dce7e4cdb58aa (7.2-rc6)
-CVE-2026-80701 [drm/vmwgfx: enforce cursor size limits for MOB cursors]
+CVE-2026-80701 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d5ed8749168ad13c0dbaa8300f68d854b6076966 (7.2-rc6)
-CVE-2026-80700 [drm/vmwgfx: validate external BO copy bounds for both stride paths]
+CVE-2026-80700 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/706c93c5813caabbb0d0a576c017d15aeec2c113 (7.2-rc6)
-CVE-2026-80699 [KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context]
+CVE-2026-80699 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8 (7.2-rc6)
-CVE-2026-80696 [hwmon: (ltc4282) Fix reading the minimum alarm voltage]
+CVE-2026-80696 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/00feb1cce93dab948a299b69753d99c681d45a0b (7.2-rc6)
-CVE-2026-80691 [scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE]
+CVE-2026-80691 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9c33222bd387312874fbe36ca8002e5c945b9653 (7.2-rc6)
-CVE-2026-80690 [scsi: ufs: core: Initialize hba->rpmbs list in ufshcd]
+CVE-2026-80690 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0279fd451a9971c0d5b959fc59f3e11b55e1694e (7.2-rc6)
-CVE-2026-80688 [riscv: drop __init from vec_check_unaligned_access_speed_all_cpus]
+CVE-2026-80688 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f51fed61eea0daba2f95f1a6074085e4cd513c7b (7.2-rc6)
-CVE-2026-80687 [iommufd/viommu: Release the igroup lock on the vdevice_size error path]
+CVE-2026-80687 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/339bd11591593ab7ce88136ab7fd01ef3813b724 (7.2-rc6)
-CVE-2026-80685 [mm/util: don't read __page_2 for order-1 folios in snapshot_page()]
+CVE-2026-80685 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7441d6348c70738e9ed307510db171c7a9b3f4bf (7.2-rc6)
-CVE-2026-80683 [Bluetooth: SCO: give the socket its own sco_conn reference]
+CVE-2026-80683 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/abd93c85c8667add738ee82aeab95dd9fc8265a2 (7.2-rc6)
-CVE-2026-80682 [riscv/mm: use physical alignment for vmemmap_start_pfn]
+CVE-2026-80682 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/45ebe4540817cb540a59e4dc04014ac5dddc9990 (7.2-rc6)
-CVE-2026-80722 [wifi: mac80211: validate individual TWT params before driver setup]
+CVE-2026-80722 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0502d5077e419427d80f4d46ba95d0067f5fb916 (7.2-rc6)
-CVE-2026-80721 [Bluetooth: ISO: ensure no dangling hcon references in iso_conn]
+CVE-2026-80721 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/aa9f7cb2bd3a2be998ceb739fc9a2f986eba43eb (7.2-rc6)
-CVE-2026-80718 [mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()]
+CVE-2026-80718 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/89b1b79c308818a715e75f28744b70d8940a07c9 (7.2-rc6)
-CVE-2026-80717 [sctp: validate Adaptation Indication parameter length]
+CVE-2026-80717 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/74b21f52c5c5a71a05c0ff70e513f4f04ff28b17 (7.2-rc6)
-CVE-2026-80716 [ALSA: pcm: wake linked drain waiters on unlink]
+CVE-2026-80716 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/f495b6c4c8594122918552c9be2b51eb71647cd9 (7.2-rc6)
-CVE-2026-80715 [igc: remove napi_synchronize() in igc_down()]
+CVE-2026-80715 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5ffab5b9589c50e4cfc0cf36ffd76c89422d4019 (7.2-rc6)
-CVE-2026-80714 [ipvs: do not propagate one-packet flag to synced conns]
+CVE-2026-80714 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b (7.2-rc6)
-CVE-2026-80710 [s390/dasd: Fix undersized format-check buffer]
+CVE-2026-80710 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/7f40b346462f563a0d6e841a77b5163d2a882a04 (7.2-rc6)
-CVE-2026-80709 [s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs]
+CVE-2026-80709 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/983279d7f86ade73db86f886e09172dd567031b5 (7.2-rc6)
-CVE-2026-80708 [s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()]
+CVE-2026-80708 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/01476391aecef36a3b789ee844357b22fbc90665 (7.2-rc6)
-CVE-2026-80707 [can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer]
+CVE-2026-80707 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/eb96c58907922546e415e545fe9a14ea63b02719 (7.2-rc6)
-CVE-2026-80706 [can: softing: fw_parse(): validate firmware record spans]
+CVE-2026-80706 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/856d6cb04e5407523566b075841dcd6423757d1c (7.2-rc6)
-CVE-2026-80705 [drm/amd/display: check if dml21_add_phantom_plane() is successful]
+CVE-2026-80705 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/000acb4ce7fb9feba3072ce468ad681f6585cd5d (7.2-rc6)
-CVE-2026-80704 [drm/amd/display: use proper context for logging]
+CVE-2026-80704 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/114b42507b6a23d9d24e24e4ef165233332c64d4 (7.2-rc6)
-CVE-2026-80703 [drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE]
+CVE-2026-80703 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/99b2fe4f19e3be0a8d0a0b5ea98d855970889653 (7.2-rc6)
-CVE-2026-80698 [dmaengine: idxd: fix double free of wq, engine, and group structs]
+CVE-2026-80698 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.8-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ec2d428b2e32dd157de8f86a86dd85c5b2c8f45c (7.2-rc6)
-CVE-2026-80697 [erofs: ensure valid f_path for page cache sharing]
+CVE-2026-80697 (In the Linux kernel, the following vulnerability has been resolved: e ...)
- linux 7.1.8-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/96b2dbbe58a1ea5df8d29c2fe24b5f04715f4443 (7.2-rc6)
-CVE-2026-80695 [hwmon: (sht3x) Fix unaligned accesses]
+CVE-2026-80695 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/f46d5ab43a572b84773015a76966f5da56fc1748 (7.2-rc6)
-CVE-2026-80694 [net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller]
+CVE-2026-80694 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/e095f249e2209674f6366f6db0383a2b96e19239 (7.2-rc6)
-CVE-2026-80693 [idpf: bound interrupt-vector register fill to the allocated array]
+CVE-2026-80693 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9f7007ee9858c99aa43101bc8352c672fee85644 (7.2-rc6)
-CVE-2026-80692 [Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks]
+CVE-2026-80692 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.8-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2f5d635ad5906b0235bc0c870e8beba3116e1e98 (7.2-rc6)
-CVE-2026-80689 [tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions]
+CVE-2026-80689 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/12b80cdbc54cf615b4717a4e8180063408091ea2 (7.2-rc6)
-CVE-2026-80686 [mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE]
+CVE-2026-80686 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/63867c82d0c0c2d182016a32b1cc0103116b0ea5 (7.2-rc6)
-CVE-2026-80684 [KVM: s390: pci: Fix NULL dereference on AIBV allocation failure]
+CVE-2026-80684 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8bf09b9b7d3232806df95f409581f8a9fd99a3fa (7.2-rc6)
-CVE-2026-80681 [vxlan: re-fetch eth header after route_shortcircuit()]
+CVE-2026-80681 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/1395a676ec15a0a02a2a6d86602324f2d5fd41d5 (7.2-rc6)
-CVE-2026-80680 [i2c: amd-mp2: Unregister callback on adapter add failure]
+CVE-2026-80680 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/82048795242f04275a3f49ffc66ad851b6120954 (7.2-rc6)
-CVE-2026-80679 [s390/dasd: Fix potential NULL pointer dereference]
+CVE-2026-80679 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/9973026f572db6b67570cadc30942f3014e41079 (7.2-rc6)
-CVE-2026-80678 [i2c: imx: Fix slave registration race and error handling]
+CVE-2026-80678 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.8-1
[trixie] - linux 6.12.105-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d64ec362c369bbc33833f7936d5f3a706b0d5c45 (7.2-rc6)
-CVE-2026-80677 [driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()]
+CVE-2026-80677 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/e9506871a8ea304cde48ff4a57226df2aadddae3 (7.2-rc1)
-CVE-2026-80675 [libbpf: Reject non-exclusive metadata maps in the signed loader]
+CVE-2026-80675 (In the Linux kernel, the following vulnerability has been resolved: l ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0fb6c9ed6493b4af01be8bb0a384574eba7df636 (7.2-rc1)
-CVE-2026-80674 [ntfs: validate resident attribute lists and harden the validator]
+CVE-2026-80674 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7d19e1ffee084c4f7d321a360c14ba43404f7cc8 (7.2-rc1)
-CVE-2026-80673 [ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()]
+CVE-2026-80673 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/344b18f389f9934d59c7b0cf3d20541ea2e0da58 (7.2-rc1)
-CVE-2026-80672 [ntfs: fix u16 truncation of restart-area length check]
+CVE-2026-80672 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/390936fb15053d8d8991ca3a22776e251a5a7f2f (7.2-rc1)
-CVE-2026-80667 [net/mlx5: LAG, MPESW, Fix missing complete() on devcom error]
+CVE-2026-80667 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d4b85f9a668b9c44216bb78daf4ec1a915cc92d1 (7.2-rc3)
-CVE-2026-80666 [Bluetooth: sco: Fix a race condition in sco_sock_timeout()]
+CVE-2026-80666 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0f8a5dcc66648b6e1458a9f3ba4c5a0463a228fc (7.2-rc3)
-CVE-2026-80665 [KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN]
+CVE-2026-80665 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9f3e83345a56280efffe235c65593c7e544c0fcc (7.2-rc4)
-CVE-2026-80664 [netfilter: xt_nat: reject unsupported target families]
+CVE-2026-80664 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/5d1a2240935ea47e2673d0ea17fdb058e4dc91dd (7.2-rc4)
-CVE-2026-80663 [tools/power/x86/intel-speed-select: Harden daemon pidfile open]
+CVE-2026-80663 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/607af438e6430893a822964c841a1994b33acccc (7.2-rc1)
-CVE-2026-80661 [ufs: core: tracing: Do not dereference pointers in TP_printk()]
+CVE-2026-80661 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/535fcf4b8a261fbb8cc4f91e4597343c135a90f2 (7.2-rc3)
-CVE-2026-80660 [hwmon: (occ) unregister sysfs devices outside occ lock]
+CVE-2026-80660 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e31408734332b8cc611342cdaaab6ba492180156 (7.2-rc2)
-CVE-2026-80659 [mmc: vub300: defer reset until cmd_mutex is unlocked]
+CVE-2026-80659 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/ee5fb641c4ccac8406c668d3e947eb20ce44f233 (7.2-rc4)
-CVE-2026-80658 [drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()]
+CVE-2026-80658 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9456381d8b60bb7dd42f2f04afe5ee4ce6e0bc12 (7.2-rc1)
-CVE-2026-80656 [hfsplus: Add a sanity check for btree node size]
+CVE-2026-80656 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3f95e2661574ff13f099dd13456751933c280628 (7.2-rc1)
-CVE-2026-80652 [crypto: ccp - Treat zero-length cert chain as query for blob lengths]
+CVE-2026-80652 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/ef8c9dacda2871accd64e3eda951fef6b788b1ea (7.2-rc1)
-CVE-2026-80651 [crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL]
+CVE-2026-80651 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/930d9d36ea618a775985446a125aedeb401db522 (7.2-rc1)
-CVE-2026-80648 [pinctrl: spacemit: fix NULL check in spacemit_pin_set_config]
+CVE-2026-80648 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/09c816e5c4d3a8d6d6e4b7537433e5e98505d934 (7.2-rc1)
-CVE-2026-80647 [RDMA/hns: Fix warning in poll cq direct mode]
+CVE-2026-80647 (In the Linux kernel, the following vulnerability has been resolved: R ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/3f19c2a3852e6ba75f3e92dd5edc4e07f3d07f4a (7.2-rc1)
-CVE-2026-80646 [ipv6: guard against possible NULL deref in __in6_dev_stats_get()]
+CVE-2026-80646 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/507541c2a8eeb76c02bd2511958f73a8cfa3e1bc (7.2-rc1)
-CVE-2026-80645 [rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()]
+CVE-2026-80645 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/fc15e3a30ddd950f009c76765331783b9af94a87 (7.2-rc1)
-CVE-2026-80644 [ocfs2: don't BUG_ON an invalid journal dinode]
+CVE-2026-80644 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/c0438198c28b1d22c272751af5e717c11d9fa8dd (7.2-rc1)
-CVE-2026-80642 [liveupdate: Reference count incoming FLB data]
+CVE-2026-80642 (In the Linux kernel, the following vulnerability has been resolved: l ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d8e47bd066d7e626f9f45d416182d585b7e18b9b (7.2-rc1)
-CVE-2026-80641 [wifi: wlcore: enable the right set of ciphers]
+CVE-2026-80641 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7495adaa0e45e180f4b6b7436675c6266edff1ff (7.2-rc1)
-CVE-2026-80640 [cxl/fwctl: Fix __fortify_panic]
+CVE-2026-80640 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6c9d2e87df40d606f1c85143e9acb1ecff463d5e (7.2-rc1)
-CVE-2026-80639 [cxl/test: Fix __fortify_panic]
+CVE-2026-80639 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/08326b92c7a414a73b5b308d1daf0e91e0134dfc (7.2-rc1)
-CVE-2026-80638 [ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent]
+CVE-2026-80638 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1ec3cca2d8b6b9ff6584ca626d4c8918bbf48d44 (7.2-rc1)
-CVE-2026-80633 [iommufd: Take dma_resv lock before dma_buf_unpin() in release path]
+CVE-2026-80633 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e745cd2c749e557c14a15ac931761c3f58c24489 (7.2-rc1)
-CVE-2026-80632 [wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()]
+CVE-2026-80632 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6794edb55b5f5ef834e03b0b241b1a8b725f82c0 (7.2-rc1)
-CVE-2026-80630 [net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen]
+CVE-2026-80630 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/097f6fc7b1ae362dd7a9444b2572162fda73b284 (7.2-rc1)
-CVE-2026-80627 [MIPS: mm: Fix out-of-bounds write in maar_res_walk()]
+CVE-2026-80627 (In the Linux kernel, the following vulnerability has been resolved: M ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/1b001b16bc88f3f7817e228acfd91ee01bdcfcce (7.2-rc1)
-CVE-2026-80626 [powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del]
+CVE-2026-80626 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/81e3a86030462824a67d697739cf3f387f4ba350 (7.2-rc1)
-CVE-2026-80625 [RDMA/hns: Fix memory leak of bonding resources]
+CVE-2026-80625 (In the Linux kernel, the following vulnerability has been resolved: R ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c0bd03b850d81a8914168d87ddf7f6ffa58875ef (7.2-rc1)
-CVE-2026-80624 [mfd: cs42l43: Sanity check firmware size]
+CVE-2026-80624 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b6ef1a74b3ec254f87a6a3c554fe8f8083ebd37c (7.2-rc1)
-CVE-2026-80622 [char: tlclk: fix use-after-free in tlclk_cleanup()]
+CVE-2026-80622 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1 (7.2-rc1)
-CVE-2026-80621 [PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability]
+CVE-2026-80621 (In the Linux kernel, the following vulnerability has been resolved: P ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/26b67fa10ef84ea667942491b50e6261a45f098d (7.2-rc1)
-CVE-2026-80620 [Revert "PCI/MSI: Unmap MSI-X region on error"]
+CVE-2026-80620 (In the Linux kernel, the following vulnerability has been resolved: R ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f64e03da0d83cb173743888bff4a7e61476a8fc2 (7.2-rc1)
-CVE-2026-80619 [apparmor: fix potential UAF in aa_replace_profiles]
+CVE-2026-80619 (In the Linux kernel, the following vulnerability has been resolved: a ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/7b42f95813dc9ceb6bda35afcf914630909a19f9 (7.2-rc1)
-CVE-2026-80618 [drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free]
+CVE-2026-80618 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3f0cc1735273a57c5116710cf0202e12152f59cc (7.2-rc1)
-CVE-2026-80617 [net: airoha: fix foe_check_time allocation size]
+CVE-2026-80617 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5c121ee635680c93d7074becf14cfbaac140f80d (7.2-rc1)
-CVE-2026-80615 [net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone]
+CVE-2026-80615 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/4c6d43db2a4d2cef3921e885cf34798f790d34ea (7.2-rc1)
-CVE-2026-80613 [veth: fix NAPI leak in XDP enable error path]
+CVE-2026-80613 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6739027cb72da26890edd424c77080d187b2a92e (7.2-rc1)
-CVE-2026-80612 [net: lwtunnel: Drop skb metadata before LWT encapsulation]
+CVE-2026-80612 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c00320b0e355c4bf0ae4743a53b4180fea237546 (7.2-rc1)
-CVE-2026-80610 [net: enetc: fix potential divide-by-zero when num_vsi is zero]
+CVE-2026-80610 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5da65537792b68b6052ffcab65e04c27aea6dfe4 (7.2-rc1)
-CVE-2026-80609 [qede: fix out-of-bounds check for cqe->len_list[]]
+CVE-2026-80609 (In the Linux kernel, the following vulnerability has been resolved: q ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f9ba47fce5932c15891c89c60e76dfaca919cb8d (7.2-rc2)
-CVE-2026-80608 [accel/amdxdna: Fix iommu domain lifetime race during device removal]
+CVE-2026-80608 (In the Linux kernel, the following vulnerability has been resolved: a ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b4a0500fdf6e61a6c5f92ff2e61bc91578075803 (7.2-rc2)
-CVE-2026-80606 [drm/xe/userptr: Hold notifier_lock for write on inject test path]
+CVE-2026-80606 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/dca6e08c923a44d2d66b955e03dd57a3a38c2b94 (7.2-rc2)
-CVE-2026-80605 [HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()]
+CVE-2026-80605 (In the Linux kernel, the following vulnerability has been resolved: H ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/0021eb09041f021c079be1022934a280f7f176c0 (7.2-rc3)
-CVE-2026-80604 [HID: core: Fix OOB read in hid_get_report for numbered reports]
+CVE-2026-80604 (In the Linux kernel, the following vulnerability has been resolved: H ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/af1a9b65ebe8a948eda805c14b78d4d0767cb1b5 (7.2-rc3)
-CVE-2026-80603 [netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read]
+CVE-2026-80603 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/ef6400ca25a13fd6dedbe8ef4a1d0979bbbfe88a (7.2-rc1)
-CVE-2026-80601 [batman-adv: gw: acquire ethernet header only after skb realloc]
+CVE-2026-80601 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/77880a3be88d378d60cc1e8f8ec70430e2ed0518 (7.2-rc2)
-CVE-2026-80600 [batman-adv: dat: acquire ARP hw source only after skb realloc]
+CVE-2026-80600 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/48067b2ae4504500a7093d9e1e16b42e70330480 (7.2-rc2)
-CVE-2026-80599 [batman-adv: dat: ensure accessible eth_hdr proto field]
+CVE-2026-80599 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/26560c4a03dc4d607331600c187f59ab2df5f341 (7.2-rc2)
-CVE-2026-80597 [mtd: maps: vmu-flash: fix NULL pointer dereference in initialization]
+CVE-2026-80597 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/357e3b8e3a8769ba36eb8ec5e053e4825f1a9329 (7.2-rc1)
-CVE-2026-80596 [Input: ims-pcu - only expose sysfs attributes on control interface]
+CVE-2026-80596 (In the Linux kernel, the following vulnerability has been resolved: I ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/001428ea4d2c371107cb984108e266adf99f1f1e (7.2-rc1)
-CVE-2026-80595 [Input: ims-pcu - add response length checks]
+CVE-2026-80595 (In the Linux kernel, the following vulnerability has been resolved: I ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/48c9d92fd4ee3a8f5d2cb46c802a0eff8e67c79c (7.2-rc1)
-CVE-2026-80594 [Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing]
+CVE-2026-80594 (In the Linux kernel, the following vulnerability has been resolved: I ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/d4579af29e67ca8722db0a1194227f8015c8981d (7.2-rc1)
-CVE-2026-80593 [hwmon: (asus_atk0110) Check package count before accessing element]
+CVE-2026-80593 (In the Linux kernel, the following vulnerability has been resolved: h ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/e2735b39f044bad7bf2017aef248935525bc0b97 (7.2-rc2)
-CVE-2026-80592 [samples/damon/mtier: fail early if address range parameters are invalid]
+CVE-2026-80592 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7746d72c64054976887928d64d2caf25c5a6dcc0 (7.2-rc3)
-CVE-2026-80591 [f2fs: fix listxattr handling of corrupted xattr entries]
+CVE-2026-80591 (In the Linux kernel, the following vulnerability has been resolved: f ...)
- linux 7.1.5-1
[trixie] - linux 6.12.96-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/5ef5bc304f23c3fe255d4936472378dcb74d0e94 (7.2-rc1)
-CVE-2026-80676 [Drivers: hv: vmbus: use generic driver_override infrastructure]
+CVE-2026-80676 (In the Linux kernel, the following vulnerability has been resolved: D ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
NOTE: https://git.kernel.org/linus/331d8900121a1d74ecd45cd2db742ddcb5a0a565 (7.2-rc1)
-CVE-2026-80671 [perf sched: Fix register_pid() overflow, strcpy, and BUG_ON]
+CVE-2026-80671 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/5949d339f5ec98752d56dcd4e36f619a59d513a5 (7.2-rc1)
-CVE-2026-80670 [perf tools: Use perf_env__get_cpu_topology() in machine__resolve()]
+CVE-2026-80670 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/5484b43a0ec8231c36fba6ead654cb72dbba8b8f (7.2-rc1)
-CVE-2026-80669 [bpf: Disable xfrm_decode_session hook attachment]
+CVE-2026-80669 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/12091470c6b4c1c14b2de12dcbae2ada6cb6d20b (7.2-rc1)
-CVE-2026-80668 [netfilter: nf_conntrack_expect: use conntrack GC to reap expectations]
+CVE-2026-80668 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b8b09dc2bf35a00d4e0556b5d6308c7b917ebda2 (7.2-rc1)
-CVE-2026-80662 [cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size]
+CVE-2026-80662 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c268f949e219f9e179558e836f457f6c5fbec416 (7.2-rc1)
-CVE-2026-80657 [accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer]
+CVE-2026-80657 (In the Linux kernel, the following vulnerability has been resolved: a ...)
- linux 7.1.5-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/506255d46bdb93a281cf39e72abbca124f5c7a1b (7.2-rc1)
-CVE-2026-80655 [soc: xilinx: Fix race condition in event registration]
+CVE-2026-80655 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/fb445935338405110baca8f541a2df3b4cb8d712 (7.2-rc1)
-CVE-2026-80654 [soc: xilinx: Shutdown and free rx mailbox channel]
+CVE-2026-80654 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
NOTE: https://git.kernel.org/linus/fdee7c66c0d7b6869c36b9f9a915abf29ab5b550 (7.2-rc1)
-CVE-2026-80653 [scsi: hisi_sas: Add slave_destroy interface for v3 hw]
+CVE-2026-80653 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/67b85a88265df19f049241d8c00571a5408f4eeb (7.2-rc1)
-CVE-2026-80650 [media: atomisp: gc2235: fix UAF and memory leak]
+CVE-2026-80650 (In the Linux kernel, the following vulnerability has been resolved: m ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
NOTE: https://git.kernel.org/linus/628f763aee0047ff44974388d6f70f75a763026b (7.2-rc1)
-CVE-2026-80649 [firmware: arm_scmi: Fix OOB in scmi_power_name_get()]
+CVE-2026-80649 (In the Linux kernel, the following vulnerability has been resolved: f ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/f9ef3f66f4b18078e464b7606f9497e4dbeb9905 (7.2-rc1)
-CVE-2026-80643 [EDAC/igen6: Fix call trace due to missing release()]
+CVE-2026-80643 (In the Linux kernel, the following vulnerability has been resolved: E ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ab1f9d466c7d83ab0d2a529e07984e53b5960dcd (7.2-rc1)
-CVE-2026-80637 [netfilter: synproxy: fix unaligned memory access in timestamp adjustment]
+CVE-2026-80637 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
NOTE: https://git.kernel.org/linus/992c20bc8a4aba220c8b95b467d049289778dad6 (7.2-rc1)
-CVE-2026-80636 [netfilter: conntrack: revert ct extension genid infrastructure]
+CVE-2026-80636 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/35e21a4dccc5c255ba59ccfbfeb4629ed21da972 (7.2-rc1)
-CVE-2026-80635 [wifi: wcn36xx: fix OOB read from short trigger BA firmware response]
+CVE-2026-80635 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/b5e6f21923ca89d90256e7346301056f6502691e (7.2-rc1)
-CVE-2026-80634 [netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag]
+CVE-2026-80634 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e052f920773b73be49eb4d8702a9f85de7464363 (7.2-rc1)
-CVE-2026-80631 [btrfs: lzo: reject compressed segment that overflows the compressed input]
+CVE-2026-80631 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b0d27d43791b7a3057c3c4aedf9b4aa033d37c46 (7.2-rc1)
-CVE-2026-80629 [octeontx2-af: npc: Fix size of entry2cntr_map]
+CVE-2026-80629 (In the Linux kernel, the following vulnerability has been resolved: o ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f9cd6fabe0e7c7f6fc30c6c192c7ed72aba37232 (7.2-rc1)
-CVE-2026-80628 [ALSA: seq: oss: Serialize readq reset state with q->lock]
+CVE-2026-80628 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/49ce92d207820f588b0406add82f053decfbe5d9 (7.2-rc1)
-CVE-2026-80623 [coresight: ete: Always save state on power down]
+CVE-2026-80623 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2ab4645fe4206c142a5f1491e191c906279686cf (7.2-rc1)
-CVE-2026-80616 [ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()]
+CVE-2026-80616 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/0569f67ed6a7af838e2141da93c68e6b6013f483 (7.2-rc1)
-CVE-2026-80614 [net: emac: Fix NULL pointer dereference in emac_probe]
+CVE-2026-80614 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f623d38fe6c4e8c40b23f42cc6fe6963fa49997b (7.2-rc1)
-CVE-2026-80611 [ACPI: processor_idle: Mark LPI enter functions as __cpuidle]
+CVE-2026-80611 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
NOTE: https://git.kernel.org/linus/956ca5d72c76504824c8eb601879da9476973e15 (7.2-rc1)
-CVE-2026-80607 [tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg]
+CVE-2026-80607 (In the Linux kernel, the following vulnerability has been resolved: t ...)
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/251a8fe1b9aedccd298b77bc28426d564c5a923f (7.2-rc2)
-CVE-2026-80602 [perf/x86/amd/lbr: Fix kernel address leakage]
+CVE-2026-80602 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2a892294b83f541115c94b0bb637f39bef187657 (7.2-rc3)
-CVE-2026-80598 [ntfs3: fix out-of-bounds read in decompress_lznt]
+CVE-2026-80598 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/7160a57192fb16d7a6fa9b7f5c7ac341d2444a89 (7.2-rc1)
-CVE-2026-80590 [inet: frags: strip GSO state from fragments before reassembly]
+CVE-2026-80590 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.12-1
NOTE: https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects ex ...)
@@ -721,6 +993,7 @@ CVE-2026-82082 (NUMail developed by Green-Computing has an OS Command Injection
CVE-2026-82081 (wallabag 2 through 2.6.14 allows SSRF because a crafted title or conte ...)
NOT-FOR-US: wallabag
CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allow ...)
+ {DSA-6408-1 DLA-4710-1}
- chromium 151.0.7922.71-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...)
@@ -811,7 +1084,8 @@ CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard Di
NOT-FOR-US: WatchGuard
CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that can be in ...)
NOT-FOR-US: Xiiaozet LK100W
-CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension ...)
+CVE-2026-78195
+ REJECTED
NOT-FOR-US: WatchGuard
CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers for logged ...)
NOT-FOR-US: WatchGuard
@@ -1317,7 +1591,7 @@ CVE-2026-81574 (In CodeMeter Runtime before versions 8.41a and 9.10, the logger
NOT-FOR-US: CodeMeter Runtime
CVE-2026-81573 (If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, t ...)
NOT-FOR-US: CodeMeter Runtime
-CVE-2026-81572 (cmu.exe --create-io --file C: creates a predictable temporary file und ...)
+CVE-2026-81572 (In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 t ...)
NOT-FOR-US: Wibu
CVE-2026-81562 (A security flaw has been discovered in AlexGladkov claude-in-mobile 3. ...)
NOT-FOR-US: AlexGladkov claude-in-mobile
@@ -399077,11 +399351,11 @@ CVE-2023-45560 (An issue in Yasukawa memberscard v.13.6.1 allows attackers to se
NOT-FOR-US: Yasukawa memberscard
CVE-2023-45558 (An issue in Golden v.13.6.1 allows attackers to send crafted notificat ...)
NOT-FOR-US: Golden
-CVE-2023-43902 (Incorrect access control in the Forgot Your Password function of EMSig ...)
+CVE-2023-43902 (Incorrect access control in the Forgot Your Password function of eMudh ...)
NOT-FOR-US: EMSigner
-CVE-2023-43901 (Incorrect access control in the AdHoc User creation form of EMSigner v ...)
+CVE-2023-43901 (Incorrect access control in the AdHoc User creation form of eMudhra em ...)
NOT-FOR-US: EMSigner
-CVE-2023-43900 (Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow atta ...)
+CVE-2023-43900 (Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 al ...)
NOT-FOR-US: EMSigner
CVE-2023-42816 (Kyverno is a policy engine designed for Kubernetes. A security vulnera ...)
NOT-FOR-US: Kyverno
@@ -420180,7 +420454,7 @@ CVE-2023-36675 (An issue was discovered in MediaWiki before 1.35.11, 1.36.x thro
NOTE: https://phabricator.wikimedia.org/T332889
CVE-2023-36666 (INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page ...)
NOT-FOR-US: INEX IXP-Manager
-CVE-2023-36664 (Artifex Ghostscript through 10.01.2 mishandles permission validation f ...)
+CVE-2023-36664 (Artifex Ghostscript before 10.01.2 mishandles permission validation fo ...)
{DSA-5446-1}
- ghostscript 10.01.2~dfsg-1
[buster] - ghostscript <not-affected> (Vulnerable code not present; no path validation at all)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59917fc9605f3558981deb9451b676245d4c348c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59917fc9605f3558981deb9451b676245d4c348c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/ed0d570f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list