[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 15:31:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
60a5979f by Salvatore Bonaccorso at 2026-07-19T16:31:20+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,284 @@
+CVE-2026-63836 [batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/33ccd52f3cc9ed46ce395199f89aa3234dc83314 (7.2-rc1)
+CVE-2026-63835 [batman-adv: v: prevent OGM aggregation on disabled hardif]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/d11c00b95b2a3b3934007fc003dccc6fdcc061ad (7.2-rc1)
+CVE-2026-63834 [batman-adv: tp_meter: restrict number of unacked list entries]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/e7c775110e1858e5a7471a23a9c9658c0af9df89 (7.2-rc1)
+CVE-2026-63833 [ntfs3: reject direct userspace writes to reserved $LX* xattrs]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/5b08dccecf825cbf905f348bc6ccb497507e28e2 (7.2-rc1)
+CVE-2026-63832 [wifi: mt76: add wcid publish check in mt76_sta_add]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/20b126920a259df4d7dcae19fcfe2c57a74d6b2e (7.2-rc1)
+CVE-2026-63831 [mac802154: llsec: add skb_cow_data() before in-place crypto]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/84a04eb5b210643bd67aab81ff805d32f62aa865 (7.2-rc1)
+CVE-2026-63830 [net: skmsg: preserve sg.copy across SG transforms]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/406e8a651a7b854c41fecd5117bb282b3a6c2c6b (7.2-rc1)
+CVE-2026-63829 [net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/8165f7ff57d9667d2bb477ef6af83ede7fed4ad7 (7.2-rc1)
+CVE-2026-63828 [apparmor: mediate the implicit connect of TCP fast open sendmsg]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/4d587cd8a72155089a627130bbd4716ec0856e21 (7.2-rc1)
+CVE-2026-63827 [apparmor: fix use-after-free in rawdata dedup loop]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/6f060496d03e4dc560a40f73770bd08335cb7a27 (7.2-rc1)
+CVE-2026-63826 [fbdev: fix use-after-free in store_modes()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/2c1c805c65fb7dc7524e20376d6987721e73a0b1 (7.2-rc1)
+CVE-2026-63825 [gcov: use atomic counter updates to fix concurrent access crashes]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/56cb9b7d96b28a1173a510ab25354b6599ad3a33 (7.2-rc1)
+CVE-2026-63824 [KEYS: fix overflow in keyctl_pkey_params_get_2()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b (7.2-rc1)
+CVE-2026-63823 [keys: Pin request_key_auth payload in instantiate paths]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/fd15b457a86939c38aa12116adabd8ff686c5e51 (7.2-rc1)
+CVE-2026-63822 [wifi: ath11k: fix warning when unbinding]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/8b7a26b6681922a38cd5a7829ace61f8e54df9b7 (7.2-rc1)
+CVE-2026-63821 [wifi: rtw88: usb: fix memory leaks on USB write failures]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6b964941bbfe6e0f18b1a5e008486dbb62df440a (7.2-rc1)
+CVE-2026-63820 [f2fs: fix missing read bio submission on large folio error]
+	- linux 7.1.3-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/74c8d2ec95c59a5651ecd975c466998af1961fd4 (7.2-rc1)
+CVE-2026-63819 [f2fs: fix to do sanity check on f2fs_get_node_folio_ra()]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/8712353ed80f87271d732297567dcdbe4b84e8c7 (7.2-rc1)
+CVE-2026-63818 [f2fs: validate orphan inode entry count]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/846c499a65816d13f1186e3090e825e8bb8bcb8b (7.2-rc1)
+CVE-2026-63817 [f2fs: validate compress cache inode only when enabled]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5073c66a96a9c23c0c2533ed4ed06e42f9021208 (7.2-rc1)
+CVE-2026-63816 [f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode]
+	- linux 7.1.3-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e0288584baa5dc41df4a829a023c4c1b33fe53d7 (7.2-rc1)
+CVE-2026-63815 [f2fs: bound i_inline_xattr_size for non-inline-xattr inodes]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/378acf3cf19b6af6cba55e8dd1154c4e1504bae8 (7.2-rc1)
+CVE-2026-63814 [f2fs: validate ACL entry sizes in f2fs_acl_from_disk()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/c4810ada31e80cbe4011467c4f3b1e93f94134f3 (7.2-rc1)
+CVE-2026-63813 [Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"]
+	- linux 7.1.3-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ccaba785821970f422c47770331c7e3271763f17 (7.2-rc1)
+CVE-2026-63812 [f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1f70ddb28a3c71df124da5fa4040c808116d6bb9 (7.2-rc1)
+CVE-2026-63811 [f2fs: read COW data with the original inode during atomic write]
+	- linux 7.1.3-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a41075acde0124d2f8a5f563068a5d63e8ffd57b (7.2-rc1)
+CVE-2026-63810 [block: Avoid mounting the bdev pseudo-filesystem in userspace]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/f73aa66dffcb8e61e78f01b56163ec16a15d06d2 (7.2-rc1)
+CVE-2026-63809 [bpf: use kvfree() for replaced sysctl write buffer]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/4c21b5927d4364bfe7365f2700da5fea0ed0d004 (7.2-rc1)
+CVE-2026-63808 [exfat: fix potential use-after-free in exfat_find_dir_entry()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/3f5f8ee9917cc2b9076ac533492d8a200edcabb8 (7.2-rc1)
+CVE-2026-63807 [KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ef057cbf825e03b63f6edf5980f96abf3c53089d (7.2-rc1)
+CVE-2026-63806 [KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/f1edbed787ba67988ed34e0132ca128b052b6ce8 (7.2-rc1)
+CVE-2026-63805 [crypto: nx - fix nx_crypto_ctx_exit argument]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/4e67f504ee9ded15e256b64f4fde150e917381d7 (7.2-rc1)
+CVE-2026-63804 [gfs2: fix use-after-free in gfs2_qd_dealloc]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f9c9ec2c319f843b70ecdf939d48b52d189bc081 (7.2-rc1)
+CVE-2026-63803 [hdlc_ppp: sync per-proto timers before freeing hdlc state]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/c78a4e41ab5ead6193ad8a2dd92e8906bae659fa (7.2-rc1)
+CVE-2026-63802 [blk-cgroup: fix UAF in __blkcg_rstat_flush()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0ab5ee5a1badb58cbb2242617cb01a4972b1f2a2 (7.2-rc1)
+CVE-2026-63801 [tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/bda3348872a2ef0d19f2df6aa8cb5025adce2f20 (7.2-rc1)
+CVE-2026-63800 [pNFS: Fix use-after-free in pnfs_update_layout()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/13e198a90ca4050f4bee8a3f23680389a6563ccc (7.2-rc1)
+CVE-2026-63799 [sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path]
+	- linux 7.1.3-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/de3ab9bd3133899efb92e4cd05ba4203e58fc0a3 (7.2-rc1)
+CVE-2026-63798 [irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057 (7.2-rc1)
+CVE-2026-63797 [rpmsg: char: Fix use-after-free on probe error path]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1ff3f528e67d20e2b1483dcaba899dc7832b2e6b (7.2-rc1)
+CVE-2026-63796 [ocfs2: reject oversized group bitmap descriptors]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/9bd541e09dffff27e5bec0f9f45b0228173a5375 (7.2-rc1)
+CVE-2026-63795 [9p: avoid putting oldfid in p9_client_walk() error path]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1a3860d46e3eb47dbd60339783cdad7904486b9f (7.2-rc1)
+CVE-2026-63794 [KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/78ee2d50185a037b3d2452a97f3dad69c3f7f389 (7.2-rc1)
+CVE-2026-63793 [ntfs: serialize volume label accesses]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/e9e50ce4f13dc721014af622613409455c734942 (7.2-rc1)
+CVE-2026-53403 [fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/7f08fc10fa3d3366dc3af723970bd03d7d6d10e3 (7.2-rc1)
+CVE-2026-53402 [fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2 (7.2-rc1)
+CVE-2026-53401 [fbdev: omap2: fix use-after-free in omapfb_mmap]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/7958e67375aa111522086286bba13cfc0816ce8d (7.2-rc1)
+CVE-2026-53400 [i2c: core: fix adapter registration race]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/ba14d7cf2fe7284610a29854bdff22b2537d3ce6 (7.2-rc1)
+CVE-2026-53399 [nfsd: release layout stid on setlease failure]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/30d55c8aabb261bc3f427d6b9aae7ef6206063f9 (7.2-rc1)
+CVE-2026-53398 [NFSD: Fix SECINFO_NO_NAME decode error cleanup]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/9e18e83b8846a5c3fe13fc8a464b4865d33996c6 (7.2-rc1)
+CVE-2026-53397 [nfsd: fix posix_acl leak on SETACL decode failure]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/0853ac544c590880d797b04daa33fcb72b6be0e1 (7.2-rc1)
+CVE-2026-53396 [nfsd: fix posix_acl leak and ignored error in nfsd4_create_file]
+	- linux 7.1.3-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/24c975bbdd564d7d0ad90294bfa69729830345de (7.2-rc1)
+CVE-2026-53395 [nfsd: fix dead ACL conflict guard in nfsd4_create]
+	- linux 7.1.3-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a60f25a800846ab8e5a13f8a9d05111f2aee55a7 (7.2-rc1)
+CVE-2026-53394 [nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/57aee7a35bb12753057c5b65d72d1f46c0e95b07 (7.2-rc1)
+CVE-2026-53393 [nfsd: reset write verifier on deferred writeback errors]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	NOTE: https://git.kernel.org/linus/2090b05803faab8a9fa62fbff871007862cac1b7 (7.2-rc1)
+CVE-2026-53392 [NFSv4/flexfiles: reject zero filehandle version count]
+	- linux 7.1.3-1
+	NOTE: https://git.kernel.org/linus/2c6bb3c40bc24f6aa8dfbe6fe98c3ad6389203f2 (7.2-rc1)
+CVE-2026-53391 [NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	NOTE: https://git.kernel.org/linus/41fe0f7b84f0cb822ae10ab08592996a592b2a25 (7.2-rc1)
+CVE-2026-53390 [ksmbd: fix out-of-bounds read in smb_check_perm_dacl()]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux 6.1.177-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1ef06004ed4bd6d3ed8c840d9d1a376b66d4935b (7.2-rc1)
+CVE-2026-53389 [net/tcp-ao: fix use-after-free of key in del_async path]
+	- linux 7.1.3-1
+	[trixie] - linux 6.12.95-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5ba9950bc9078e19b69cca1e56d1553b125c6857 (7.2-rc1)
 CVE-2026-53383 [ksmbd: reject non-VALID session in compound request branch]
 	- linux 7.0.14-1
 	[trixie] - linux 6.12.95-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a5979fe56437dd53d169e2fc7d4cf7304c70da

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a5979fe56437dd53d169e2fc7d4cf7304c70da
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/76ab1a5c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list