[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Jul 19 15:26:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
39d12d48 by Salvatore Bonaccorso at 2026-07-19T16:26:29+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,36 @@
+CVE-2026-53372 [iommu/vt-d: Block PASID attachment to nested domain with dirty tracking]
+ - linux 7.0.7-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cc5bd898ff70710ffc41cd8e5c2741cb64750047 (7.1-rc1)
+CVE-2026-53371 [RDMA/ionic: bound node_desc sysfs read with %.64s]
+ - linux 7.0.7-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/654a27f25530d052eeedf086e6c3e2d585c203bd (7.1-rc1)
+CVE-2026-53370 [perf/x86/intel: Improve validation and configuration of ACR masks]
+ - linux 7.0.7-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5ad732a56be46aabf158c16aa0c095291727aaef (7.1-rc3)
+CVE-2026-53369 [udf: reject descriptors with oversized CRC length]
+ - linux 7.0.7-1
+ [trixie] - linux 6.12.88-1
+ [bookworm] - linux 6.1.176-1
+ [bullseye] - linux 5.10.259-1
+ NOTE: https://git.kernel.org/linus/55d41b0a20128e86b9e960dd2e3f0a2d69a18df7 (7.1-rc2)
+CVE-2026-53367 [selinux: fix avdcache auditing]
+ - linux 7.0.7-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f92d542577db878acfd21cc18dab23d03023b217 (7.1-rc2)
+CVE-2026-53368 [f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage]
+ - linux 7.0.7-1
+ NOTE: https://git.kernel.org/linus/019f9dda7f66e55eb94cd32e1d3fff5835f73fbc (7.1-rc1)
CVE-2026-9323 (The urwid web display backend (urwid/display/web.py) generates web ses ...)
- urwid <unfixed>
NOTE: https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/39d12d48a2802e9c82197738e5e4c9548b224ba1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/39d12d48a2802e9c82197738e5e4c9548b224ba1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/fd02ac62/attachment.htm>
More information about the debian-security-tracker-commits
mailing list