[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 15:35:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a6f6b07e by Salvatore Bonaccorso at 2026-07-19T16:34:30+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,207 @@
+CVE-2026-63874 [net: mctp: usb: fix race between urb completion and rx_retry cancellation]
+	- linux 7.0.13-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/54665dce982689e2fd99b32e9a0dcc204fda8a51 (7.1)
+CVE-2026-63873 [accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()]
+	- linux 7.0.13-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2f41af638c92bac6f1f9275ea2d1901baef578f3 (7.1)
+CVE-2026-63870 [ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()]
+	- linux 7.0.13-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/3a5f3f7aff18bcc36a57839cf50cf0cc8de707f3 (7.1-rc7)
+CVE-2026-63869 [wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap]
+	- linux 7.0.13-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6c0cf89f36ac0c0fd8687a4ccdce2efb23a9c663 (7.1-rc7)
+CVE-2026-63868 [net: garp: fix unsigned integer underflow in garp_pdu_parse_attr]
+	- linux 7.0.13-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/16e408e607a94b646fb14a2a98422c6877ae4b3c (7.1-rc7)
+CVE-2026-63867 [mptcp: close TOCTOU race while computing rcv_wnd]
+	- linux 7.0.13-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8ab24fdebc369c0dfb90f82c1650b1e66662bb45 (7.1-rc7)
+CVE-2026-63866 [wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/88973240dc7c976dd320b36a9e6d925c9be083ae (7.1-rc1)
+CVE-2026-63865 [bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/beaf0e96b1da74549a6cabd040f9667d83b2e97e (7.1-rc1)
+CVE-2026-63864 [bpf: Propagate error from visit_tailcall_insn]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6bd96e40f31dde8f8cd79772b4df0f171cf8a915 (7.1-rc1)
+CVE-2026-63863 [drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d287dee565c3c32e1ed76ec1847af46809c29b90 (7.1-rc1)
+CVE-2026-63862 [PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba (7.1-rc1)
+CVE-2026-63861 [spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ab00febad191d7a4400aa1c3468279fb508258d4 (7.1-rc1)
+CVE-2026-63860 [RDMA/core: Prefer NLA_NUL_STRING]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/6ed3d14fc45d3da6025e7fe4a6a09066856698e2 (7.1-rc1)
+CVE-2026-63852 [drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4532b52b34e4e4310386e6fdf6a643368599f522 (7.1-rc2)
+CVE-2026-63851 [drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/589a254bf3e88204c8402b9cbccd5e23a0af990f (7.1-rc2)
+CVE-2026-63850 [drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8cae0ce77de492d7c31c1532a2e80c0c6e7e58cb (7.1-rc2)
+CVE-2026-63849 [drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8f4954722eab88e10c4ea0c0d3b1269c31421d3a (7.1-rc2)
+CVE-2026-63844 [drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/83e37c0987ca92f9e87789b46dd311dcf5a4a6c8 (7.1-rc2)
+CVE-2026-63843 [drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b65b7f3f3c18f797f81a2af7c97e2079900ad6db (7.1-rc2)
+CVE-2026-63842 [drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ea7c61c5f895e8f9ea0ffffa180498ef9c740152 (7.1-rc2)
+CVE-2026-63841 [drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2f8e3da71a1b469b6e157aa3972f1448b3157840 (7.1-rc2)
+CVE-2026-63840 [drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3b0ea2021351b6b813b34fac940957f1f4fad85b (7.1-rc2)
+CVE-2026-63838 [ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f9e437cddf6cf9e603bdaefe148c1f4792aaf39c (7.1-rc1)
+CVE-2026-63837 [net: ena: PHC: Check return code before setting timestamp output]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/24a08d7d6218d60c033015cf4870b6096446e734 (7.1-rc4)
+CVE-2026-63872 [esp: fix page frag reference leak on skb_to_sgvec failure]
+	- linux 7.0.13-1
+	NOTE: https://git.kernel.org/linus/2982e599fff6faa21c8df147d96fc7af6c1a2f24 (7.1-rc6)
+CVE-2026-63871 [Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls]
+	- linux 7.0.13-1
+	[trixie] - linux 6.12.94-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9ca7053d6215d89c33f28893bfd1625a32919d3f (7.1-rc7)
+CVE-2026-63859 [net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()]
+	- linux 7.0.10-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3309965fe44c00fd65af7cef5016e9e782c021a7 (7.1-rc1)
+CVE-2026-63858 [netfilter: nf_tables: add hook transactions for device deletions]
+	- linux 7.0.10-1
+	NOTE: https://git.kernel.org/linus/10f79dbd7719d1da9f5884d13060322d8729f091 (7.1-rc2)
+CVE-2026-63857 [net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()]
+	- linux 7.0.10-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bde34e84edc8b5571fbde7e941e175a4293ee1eb (7.1-rc2)
+CVE-2026-63856 [drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/8d80b293b41fcb5e9396db93e788b0f4ebcbafb7 (7.1-rc2)
+CVE-2026-63855 [drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/4f317863a3ab212a027d8c8c3cc3af4e3fb95704 (7.1-rc2)
+CVE-2026-63854 [drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/f1e5a6660d7cbf006079126d9babbf0ccf538c6b (7.1-rc2)
+CVE-2026-63853 [drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring]
+	- linux 7.0.10-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/51f694221047c84fa185be98210eb2c354ffb8c6 (7.1-rc2)
+CVE-2026-63848 [drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/e5f612dc91650561fe2b5b76dd6d2898ec9ad480 (7.1-rc2)
+CVE-2026-63847 [drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/79405e774ede411c6b47ed41c651e40b92de64a2 (7.1-rc2)
+CVE-2026-63846 [drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/a2baf12eec41f246689e6a3f8619af1200031576 (7.1-rc2)
+CVE-2026-63845 [drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring]
+	- linux 7.0.10-1
+	[trixie] - linux 6.12.94-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e7e90b5839aeb8805ec83bb4da610b8dab8e184d (7.1-rc2)
+CVE-2026-63839 [platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()]
+	- linux 7.0.10-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0c3887a134f191723b53e2a47e501b534c8723ee (7.1-rc4)
 CVE-2026-63836 [batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd]
 	- linux 7.1.3-1
 	[trixie] - linux 6.12.95-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f6b07e1fb13f824954b47e4edcf2dc6aeddc8d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f6b07e1fb13f824954b47e4edcf2dc6aeddc8d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/8050ac6b/attachment.htm>


More information about the debian-security-tracker-commits mailing list