[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 15:30:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
00c39f4d by Salvatore Bonaccorso at 2026-07-19T16:30:01+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,42 @@
+CVE-2026-53383 [ksmbd: reject non-VALID session in compound request branch]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/609ca17d869d04ba249e32cdcbf13c0b1c66f43c (7.2-rc1)
+CVE-2026-53388 [fuse: re-lock request before replacing page cache folio]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/a078484921052d0badd827fcc2770b5cfc1d4120 (7.2-rc1)
+CVE-2026-53387 [iio: light: veml6075: add bounds check to veml6075_it_ms index]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/307dc4240bd41852d9e0912921e298160db1c109 (7.2-rc1)
+CVE-2026-53386 [iio: adc: ti-ads1298: add bounds check to pga_settings index]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/95e8a48d7a85d4226934020e57815a3316d3a14b (7.2-rc1)
+CVE-2026-53385 [vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/a287620312dc6dcb9a093417a0e589bf30fcf38a (7.2-rc1)
+CVE-2026-53384 [serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/10fc708b4de7f86002d2d735a2dbf3b5b7f65692 (7.2-rc1)
+CVE-2026-53382 [media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/7d8bf3d8f91073f4db347ed3aa6302b56107499c (7.2-rc1)
+CVE-2026-53381 [virtiofs: fix UAF on submount umount]
+	- linux 7.0.14-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/06b41351779e9289e8785694ade9042ae85e41ea (7.2-rc1)
 CVE-2026-53380 [media: rzv2h-ivc: Fix concurrent buffer list access]
 	- linux 7.0.9-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/00c39f4d49766a7e6c556833014948d81ea3e1e8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/00c39f4d49766a7e6c556833014948d81ea3e1e8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/a52d8eb7/attachment.htm>


More information about the debian-security-tracker-commits mailing list