[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 15:26:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
39d12d48 by Salvatore Bonaccorso at 2026-07-19T16:26:29+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,36 @@
+CVE-2026-53372 [iommu/vt-d: Block PASID attachment to nested domain with dirty tracking]
+	- linux 7.0.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cc5bd898ff70710ffc41cd8e5c2741cb64750047 (7.1-rc1)
+CVE-2026-53371 [RDMA/ionic: bound node_desc sysfs read with %.64s]
+	- linux 7.0.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/654a27f25530d052eeedf086e6c3e2d585c203bd (7.1-rc1)
+CVE-2026-53370 [perf/x86/intel: Improve validation and configuration of ACR masks]
+	- linux 7.0.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5ad732a56be46aabf158c16aa0c095291727aaef (7.1-rc3)
+CVE-2026-53369 [udf: reject descriptors with oversized CRC length]
+	- linux 7.0.7-1
+	[trixie] - linux 6.12.88-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/55d41b0a20128e86b9e960dd2e3f0a2d69a18df7 (7.1-rc2)
+CVE-2026-53367 [selinux: fix avdcache auditing]
+	- linux 7.0.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f92d542577db878acfd21cc18dab23d03023b217 (7.1-rc2)
+CVE-2026-53368 [f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage]
+	- linux 7.0.7-1
+	NOTE: https://git.kernel.org/linus/019f9dda7f66e55eb94cd32e1d3fff5835f73fbc (7.1-rc1)
 CVE-2026-9323 (The urwid web display backend (urwid/display/web.py) generates web ses ...)
 	- urwid <unfixed>
 	NOTE: https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/39d12d48a2802e9c82197738e5e4c9548b224ba1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/39d12d48a2802e9c82197738e5e4c9548b224ba1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/fd02ac62/attachment.htm>


More information about the debian-security-tracker-commits mailing list