[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 19:03:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a795e9b1 by Salvatore Bonaccorso at 2026-07-19T20:02:43+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,811 @@
+CVE-2026-64014 [Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/2905281cbda52ec9df540113b35b835feb5fafd3 (7.1-rc6)
+CVE-2026-64012 [net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/1b9bc71153b01dbde8045b9edede4240f4f5520e (7.1-rc3)
+CVE-2026-64011 [nfc: llcp: Fix use-after-free in llcp_sock_release()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/f4268b466190dae95a7585f69b4f1f8ad097632c (7.1-rc6)
+CVE-2026-64010 [nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77 (7.1-rc6)
+CVE-2026-64009 [xfrm: Check for underflow in xfrm_state_mtu]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/742b04d0550b0ec89dcbc99537ec88653bd1ad90 (7.1-rc6)
+CVE-2026-64008 [accel/rocket: fix UAF via dangling GEM handle in create_bo]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f706e6a4ce75585af979aec3dcbdce68bc76306b (7.1-rc6)
+CVE-2026-64007 [netfilter: synproxy: refresh tcphdr after skb_ensure_writable]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/92170e6afe927ab2792a3f71902845789c8e31b1 (7.1-rc6)
+CVE-2026-64005 [net/smc: Do not re-initialize smc hashtables]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9e4389b0038781f19f97895186ed941ff8ac1678 (7.1-rc6)
+CVE-2026-64004 [net/iucv: fix locking in .getsockopt]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/3589d20a666caf30ad100c960a2de7de390fce88 (7.1-rc6)
+CVE-2026-64003 [scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7205b58702273baf21d6ba7992e6ba15852325f7 (7.1-rc6)
+CVE-2026-64002 [ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/87a1e0fe7776da7ab411be332b4be58ac8840d10 (7.1-rc6)
+CVE-2026-64000 [net: hsr: fix potential OOB access in supervision frame handling]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f229426072fc865654a60978bb7fda790a051ff3 (7.1-rc6)
+CVE-2026-63997 [ethtool: module: avoid leaking a netdev ref on module flash errors]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fb7f511d62692661846c47f199e0afe25c2982db (7.1-rc6)
+CVE-2026-63996 [ethtool: cmis: require exact CDB reply length]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6c3f999a9d1338c6c89a9ff4549eafe72bc2e7b1 (7.1-rc6)
+CVE-2026-63995 [ethtool: cmis: validate start_cmd_payload_size from module]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/12c2496a71f82f63617971ca9b730dffa05cf58b (7.1-rc6)
+CVE-2026-63994 [tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/b4bc94353050b1fa7b702bd4c6600710dd926cff (7.1-rc6)
+CVE-2026-63993 [vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/7d9ef0cb271555d8cf39fefe6c981e1493b25ecf (7.1-rc6)
+CVE-2026-63992 [tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/509323077ef79a26ba0c60bb556e45c12c398b2d (7.1-rc6)
+CVE-2026-63991 [Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/3c40d381ce04f9575a5d8b542898183c3b4b38dc (7.1-rc6)
+CVE-2026-63989 [bridge: Fix sleep in atomic context in netlink path]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5eec4427b89c2fb2beac54920101e55a2f1c0c21 (7.1-rc6)
+CVE-2026-63988 [bridge: Fix sleep in atomic context in sysfs path]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6d34594cc619d0d4b07d5afcad8b5984f3526dcf (7.1-rc6)
+CVE-2026-63987 [ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7281b096b072f6c6e30420e3467d738f2e4c4b57 (7.1-rc6)
+CVE-2026-63986 [ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c3fc9976f686f9a95baf87db9d387f218fd65394 (7.1-rc6)
+CVE-2026-63985 [ethtool: eeprom: add more safeties to EEPROM Netlink fallback]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/67cfdd9210b99f260b3e0afeb9525e0acc7be31e (7.1-rc6)
+CVE-2026-63984 [ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9d5e7a46a9f6d8f503b41bfefef70659845f1679 (7.1-rc6)
+CVE-2026-63982 [net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/db875221ab08d213a83bf30196ae8b64d55a3403 (7.1-rc6)
+CVE-2026-63981 [net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a005fa5d7502eefec7ee6e1c01adadc06de2f9ad (7.1-rc6)
+CVE-2026-63980 [net/handshake: Use spin_lock_bh for hn_lock]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cc993e0927ec8bd98ea33377ada03295fcda0f24 (7.1-rc6)
+CVE-2026-63976 [Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/00e1950716c6ed67d74777b2db286b0fa23b4be9 (7.1-rc6)
+CVE-2026-63975 [Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/41c2713b204e6cb6a94587bc6bf6935107df5479 (7.1-rc6)
+CVE-2026-63973 [net: mana: Add NULL guards in teardown path to prevent panic on attach failure]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/17bfe0a8c014ee1d542ad352cd6a0a505361664a (7.1-rc6)
+CVE-2026-63972 [net: mana: Skip redundant detach on already-detached port]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5b05aa36ee24297d7296ca58dfd8c448d0e4cda3 (7.1-rc6)
+CVE-2026-63971 [sctp: fix race between sctp_wait_for_connect and peeloff]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/f14fe6395a8b3d961a61e138ad7b36ba3626dd4e (7.1-rc6)
+CVE-2026-63969 [ipv6: fix possible infinite loop in rt6_fill_node()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9f72412bcf60144f252b0d6205106abf14344abc (7.1-rc6)
+CVE-2026-63968 [ipv6: fix possible infinite loop in fib6_select_path()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9c7da87c2dc860bb17ca1ece942495d28b1ce3b9 (7.1-rc6)
+CVE-2026-63967 [iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/c9d8e9adaa63150ef7e833480b799d0bab83a276 (7.1-rc6)
+CVE-2026-63966 [iio: imu: adis16550: fix stack leak in trigger handler]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/474f8928d50b09f7dcf507049f08732640b88b49 (7.1-rc6)
+CVE-2026-63965 [iio: pressure: bmp280: fix stack leak in bmp580 trigger handler]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/387c86b582e0782ab332e7bfcd4e6e3f93922961 (7.1-rc6)
+CVE-2026-63964 [usb: typec: ucsi: ccg: reject firmware images without a ':' record header]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/d7486952bf74e546ee3748fb14b2d07881fa6273 (7.1-rc6)
+CVE-2026-63961 [usb: typec: altmodes/displayport: validate count before reading Status Update VDO]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/8a18f896e667df491331371b55d4ad644dc51d60 (7.1-rc6)
+CVE-2026-63960 [usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/4af7ad0e6d7aa4403dbb1dac7b9659b0421efcaa (7.1-rc6)
+CVE-2026-63957 [USB: serial: safe_serial: fix memory corruption with small endpoint]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/438061ed1ad85e6743e2dce826671772d81089ec (7.1-rc6)
+CVE-2026-63956 [USB: serial: cypress_m8: fix memory corruption with small endpoint]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/e1a9d791fd66ab2431b9e6f6f835823809869047 (7.1-rc6)
+CVE-2026-63955 [mm/vmalloc: do not trigger BUG() on BH disabled context]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/04aa71da5f35aacdc9ae9cb5150947daa624f641 (7.1-rc6)
+CVE-2026-63954 [hpfs: fix a crash if hpfs_map_dnode_bitmap fails]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/974820a59efde7c1a7e1260bcfe9bb81f833cc9f (7.1-rc6)
+CVE-2026-63953 [mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2c6f81d58741349298f51ff697d988cb42881453 (7.1-rc6)
+CVE-2026-63952 [memfd: deny writeable mappings when implying SEAL_WRITE]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3b041514cb6eae45869b020f743c14d983363222 (7.1-rc6)
+CVE-2026-63951 [zram: fix use-after-free in zram_writeback_endio]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bf62f69574b19720ae5fbbbcdf24a0c4e3e05e43 (7.1-rc6)
+CVE-2026-63950 [mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3f8968e9cbf95d5d87d32218906cab0b9b9eddbe (7.1-rc6)
+CVE-2026-63949 [auxdisplay: line-display: fix OOB read on zero-length message_store()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6 (7.1-rc7)
+CVE-2026-63948 [Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9dbd84990394c51f5cee1e8871bb5ff8af5ed939 (7.1-rc6)
+CVE-2026-63946 [Bluetooth: ISO: fix UAF in iso_recv_frame]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/47f23a259517abbdb8032c057a1e8a6bf3734878 (7.1-rc6)
+CVE-2026-63945 [Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4b5f8e608749b7e8fa386c6e4301cf9272595859 (7.1-rc6)
+CVE-2026-63944 [Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bfea6091e0fffb270c20e74384b660910277eb6c (7.1-rc6)
+CVE-2026-63943 [Input: xpad - fix out-of-bounds access for Share button]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6cdc46b38cf146ce81d4831b6472dbf7731849a2 (7.1-rc6)
+CVE-2026-63942 [parport: Fix race between port and client registration]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/ef15ccbb3e8640a723c42ad90eaf81d66ae02017 (7.1-rc6)
+CVE-2026-63939 [KVM: SEV: Compute the correct max length of the in-GHCB scratch area]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5867d7e202e09f037cefe77f7af4413c7c0fa088 (7.1-rc6)
+CVE-2026-63938 [KVM: SEV: Check PSC request indices against the actual size of the buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/121d88de56bc5c0ba0ce2f6381af67f948a7e7c1 (7.1-rc6)
+CVE-2026-63937 [KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c8cc238093ca6c99267032f6cfe78f59389f3157 (7.1-rc6)
+CVE-2026-63936 [iio: adc: mt6359: fix unchecked return value in mt6358_read_imp]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f9bbd943c34a9ad60e593a4b99ce2394e4e2381b (7.1-rc6)
+CVE-2026-63935 [iio: adc: nxp-sar-adc: fix division by zero in write_raw]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a9aba21a539c668a66b58eeb08ad3909e5a54c2a (7.1-rc6)
+CVE-2026-63934 [iio: gyro: itg3200: fix i2c read into the wrong stack location]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae (7.1-rc6)
+CVE-2026-63933 [iio: gyro: adis16260: fix division by zero in write_raw]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/761e8b489e6cf166c574034b70637f8a7eadd0ee (7.1-rc6)
+CVE-2026-63932 [iio: chemical: mhz19b: reject oversized serial replies]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/673478bc29cf72010faaf293c1c8c667393335a0 (7.1-rc6)
+CVE-2026-63931 [iio: chemical: scd30: fix division by zero in write_raw]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/5aba4f94b225617a55fed442a70329b2ee19c0a5 (7.1-rc6)
+CVE-2026-63930 [iio: buffer: hw-consumer: fix use-after-free in error path]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/6f5ed4f2c7c83f33344e0ba179f72a12e5dad4a4 (7.1-rc6)
+CVE-2026-63929 [iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a093999355084bdbfe6e97f1dd232e58a1525f0b (7.1-rc6)
+CVE-2026-63928 [USB: serial: omninet: fix memory corruption with small endpoint]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/60df93d30f9bdd27db17c4d80ed80ef718d7226b (7.1-rc6)
+CVE-2026-63927 [usb: dwc2: Fix use after free in debug code]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9ea06a3fbf9f16e0d98c52cb3b99642be15ec281 (7.1-rc6)
+CVE-2026-63926 [bpf: sockmap: fix tail fragment offset in bpf_msg_push_data]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/f72eed9b84fb771019a955908132410a9ba9ea3f (7.1-rc6)
+CVE-2026-63925 [macsec: fix replay protection at XPN lower-PN wrap]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/e68842b3356471ba56c882209f324613dac47f64 (7.1-rc6)
+CVE-2026-63924 [ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/d47548a36639095939f4747d4c43f2271366f565 (7.1-rc6)
+CVE-2026-63921 [ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/8b484efd5cb4eeef9021a661e198edc5349dacf6 (7.1-rc6)
+CVE-2026-63920 [ipv6: validate extension header length before copying to cmsg]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/dd433671fef381fdaf7b530c631e6b782d66e224 (7.1-rc6)
+CVE-2026-63919 [xfrm: input: hold netns during deferred transport reinjection]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/c16f74dc1d75d0e2e7670076d5375deda110ebeb (7.1-rc6)
+CVE-2026-63918 [l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/05f95729ca844704d15e49ce14868af4b403b32b (7.1-rc6)
+CVE-2026-63917 [ip6: vti: Use ip6_tnl.net in vti6_changelink().]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/11b326fb0a374f4654f9be22d0f0f7abd9f7d3fe (7.1-rc6)
+CVE-2026-63916 [HID: wacom: Fix OOB write in wacom_hid_set_device_mode()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/c0a8899e02ddebd51e2589835182c239c2e224ae (7.1-rc6)
+CVE-2026-63915 [nfc: hci: fix out-of-bounds read in HCP header parsing]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/f040e590c035bfd9553fe79ee9585caf1b14d67b (7.1-rc6)
+CVE-2026-63914 [xfrm: route MIGRATE notifications to caller's netns]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/7e2a4f7ca0952820731ef7bdadfc9a9e9d3571b4 (7.1-rc6)
+CVE-2026-63913 [netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/bed6e04be8e6b9133d8b16d5a42d0e0ce674fa9a (7.1-rc6)
+CVE-2026-63912 [xfrm: esp: restore combined single-frag length gate]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40 (7.1-rc6)
+CVE-2026-63911 [xfrm: iptfs: reset runtime state when cloning SAs]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7f83d174073234839aea176f265e517e0d50a1d2 (7.1-rc6)
+CVE-2026-63910 [dma-buf: fix UAF in dma_buf_fd() tracepoint]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ead6680f354f83966c796fc7f9463a3171789616 (7.1-rc6)
+CVE-2026-63909 [ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0e60dafe97eca61721f3db456f97d97a80c6c8ae (7.1-rc6)
+CVE-2026-63908 [Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/baa0210fb6a9dc3882509a9411b6d284d88fe30e (7.1-rc6)
+CVE-2026-63907 [uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f74c8696f14149d5e43cc28b015326a759c48f00 (7.1-rc6)
+CVE-2026-63906 [usb: musb: omap2430: Fix use-after-free in omap2430_probe()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e194ce048f5a6c549b3a23a8c568c6470f40f772 (7.1-rc6)
+CVE-2026-63905 [usbip: vudc: Fix use after free bug in vudc_remove due to race condition]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/d96209626a29ea64666be98c30b30ac82e5f1be6 (7.1-rc6)
+CVE-2026-63904 [usb: usbtmc: check URB actual_length for interrupt-IN notifications]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd (7.1-rc6)
+CVE-2026-63903 [USB: serial: belkin_sa: validate interrupt status length]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65 (7.1-rc6)
+CVE-2026-63902 [USB: serial: cypress_m8: validate interrupt packet headers]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9f9bfc80c67f35a275820da7e83a35dface08281 (7.1-rc6)
+CVE-2026-63901 [USB: serial: digi_acceleport: fix memory corruption with small endpoints]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/cb3560e8eab1dfa1cac1ed52631adf8ec6ff2cd5 (7.1-rc6)
+CVE-2026-63900 [USB: serial: keyspan: fix missing indat transfer sanity check]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/ab8336a7e414f018430aa1af3a46944032f7ff96 (7.1-rc6)
+CVE-2026-63899 [USB: serial: mxuport: fix memory corruption with small endpoint]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/4085f0dbb1ce2251c9a5938d693de6593f0ab2bd (7.1-rc6)
+CVE-2026-63898 [USB: serial: mct_u232: fix memory corruption with small endpoint]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/915b36d701950503c4ea0f6e314b10868e59fce3 (7.1-rc6)
+CVE-2026-63897 [USB: serial: mct_u232: fix missing interrupt-in transfer sanity check]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/245aba83e3c288e176ed037a1f6b618b09e92ed8 (7.1-rc6)
+CVE-2026-63896 [usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6c5dbc104dadd79fc2923497c20bae759a18758c (7.1-rc6)
+CVE-2026-63894 [usb: gadget: f_fs: serialize DMABUF cancel against request completion]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2796646f6d892c1eb6818c7ca41fdfa12568e8d1 (7.1-rc6)
+CVE-2026-63893 [thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/01deda0152066c6c955f0619114ea6afa070aaec (7.1-rc6)
+CVE-2026-63892 [thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/de21b59c29e31c5108ddc04210631bbfab81b997 (7.1-rc6)
+CVE-2026-63891 [thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/928abe19fbf0127003abcb1ea69cabc1c897d0ab (7.1-rc6)
+CVE-2026-63890 [scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9eed1bd59937e6828b00d2f2dfef631d964f3636 (7.1-rc6)
+CVE-2026-63889 [scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153 (7.1-rc6)
+CVE-2026-63888 [scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/778c2ab142c625a8a8afa570e0f9b7873f445d99 (7.1-rc6)
+CVE-2026-63887 [scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/bf33e01f88388c43e285492a63e539df6ffed64c (7.1-rc6)
+CVE-2026-63886 [scsi: target: iscsi: Validate CHAP_R length before base64 decode]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/85db7391310b1304d2dc8ae3b0b12105a9567147 (7.1-rc6)
+CVE-2026-63885 [drm/gem: fix race between change_handle and handle_delete]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7164d78559b0ff29931a366a840a9e5dd53d4b7c (7.1-rc6)
+CVE-2026-63884 [drm/i915: Fix potential UAF in TTM object purge]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5c4063c87a619e4df954c179d24628636f5db15f (7.1-rc6)
+CVE-2026-63883 [serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/452d6fa37ae9b021f4f6d397dbae077f7296f6f4 (7.1-rc6)
+CVE-2026-63880 [drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2e7f55eb408c3f72ee1957a0d0ad11d8648a6379 (7.1-rc6)
+CVE-2026-63878 [drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a1ba4594232c87c3b8defd6f89a2e40f8b08395d (7.1-rc6)
+CVE-2026-63877 [serial: dz: Convert to use a platform device]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5d7a49d60b8fda66da60e240fd7315232fa1754f (7.1-rc6)
+CVE-2026-63876 [serial: zs: Convert to use a platform device]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7cac59d08a73cb866ec51a483a6f3fe0f531947c (7.1-rc6)
+CVE-2026-63875 [arm64: tlb: Flush walk cache when unsharing PMD tables]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/c2ff4764e03e7a8d758352f4aceb8fe1be6ac971 (7.1-rc5)
+CVE-2026-64013 [ACPI: button: Fix ACPI GPE handler leak during removal]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fe80251152fed5b185f795ef2cd9f7fe9c3162e0 (7.1-rc6)
+CVE-2026-64006 [netfilter: nf_tables: fix dst corruption in same register operation]
+	- linux 7.0.12-1
+	NOTE: https://git.kernel.org/linus/18014147d3ee7831dce53fe65d7fc8d428b02552 (7.1-rc6)
+CVE-2026-64001 [ALSA: pcm: oss: Fix setup list UAF on proc write error]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/4cc54bdd54b337e77115be5b55577d1c58608eae (7.1-rc6)
+CVE-2026-63999 [ethtool: rss: fix indir_table and hkey leak on get_rxfh failure]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/266297692f97008ca48bc311775c087c59bd7fe3 (7.1-rc6)
+CVE-2026-63998 [ethtool: module: call ethnl_ops_complete() on module flash errors]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/84371fb58423f997939aacdcbc02d128d76a54e5 (7.1-rc6)
+CVE-2026-63990 [bonding: refuse to enslave CAN devices]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/8ba68464e4787b6a7ec938826e16124df20fd23d (7.1-rc6)
+CVE-2026-63983 [net/sched: fix packet loop on netem when duplicate is on]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/9552b11e3edabc97cfcd9f29103d5afbce7ae183 (7.1-rc6)
+CVE-2026-63979 [net/handshake: hand off the pinned file reference to accept_doit]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f4251190e58b209999c1ba9e6d2976136a1be055 (7.1-rc6)
+CVE-2026-63978 [net/handshake: Drain pending requests at net namespace exit]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ea5fe6a73ca57e5150b8a38b341aef2636eb72f0 (7.1-rc6)
+CVE-2026-63977 [dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d733f519f6443540f8359461a34e3b0042099bbe (7.1-rc6)
+CVE-2026-63974 [Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/525daaea459fc215f432de1b8debbd9144bf97b0 (7.1-rc6)
+CVE-2026-63970 [vsock/virtio: bind uarg before filling zerocopy skb]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1e584c304cfb94a759417130b1fc6d30b30c4cce (7.1-rc6)
+CVE-2026-63963 [usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/8fbc349e8383125dd2d8de1c1e926279d398ab17 (7.1-rc6)
+CVE-2026-63962 [usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/3389c149c68c3fea61910ad5d34f7bf3bff44e32 (7.1-rc6)
+CVE-2026-63959 [usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/aa2f716327be1818e1cb156da8a2844804aaec2f (7.1-rc6)
+CVE-2026-63958 [usb: typec: ucsi: validate connector number in ucsi_connector_change()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/288a81a8507052bcfbf884d39a463c44c42c5fd9 (7.1-rc6)
+CVE-2026-63947 [Bluetooth: HIDP: fix missing length checks in hidp_input_report()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6 (7.1-rc6)
+CVE-2026-63941 [KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/83726330748981372bde86ed5411d7b306612991 (7.1-rc6)
+CVE-2026-63940 [KVM: SEV: Ignore Port I/O requests of length '0']
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.95-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3988bd2723de407ae90fa7a6f6029b4e60238c58 (7.1-rc6)
+CVE-2026-63923 [octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2156a29aecfffa2eb7c558255690084efbe9f3b0 (7.1-rc6)
+CVE-2026-63922 [ipv6: exthdrs: refresh nh after handling HAO option]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/f7b52afe3592eae66e160586b45a3f2242972c63 (7.1-rc6)
+CVE-2026-63895 [usb: gadget: f_fs: copy only received bytes on short ep0 read]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/4e036c10e7f4df5d951c69cc3697bc8e209c6d02 (7.1-rc6)
+CVE-2026-63882 [drm/amdkfd: fix NULL pointer bug in svm_range_set_attr]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/e984d61d92e702096058f0f828f4b2b8563b88ce (7.1-rc6)
+CVE-2026-63881 [drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/93f5534b35a05ef8a0109c1eefa800062fee810a (7.1-rc6)
+CVE-2026-63879 [drm/amdgpu: fix amdgpu_hmm_range_get_pages]
+	- linux 7.0.12-1
+	NOTE: https://git.kernel.org/linus/962d684b5dc0741dcd93485d41b450de402d5592 (7.1-rc6)
 CVE-2026-63874 [net: mctp: usb: fix race between urb completion and rx_retry cancellation]
 	- linux 7.0.13-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a795e9b1dcdd0977cf4cbb499054c5a6d52aaf81

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a795e9b1dcdd0977cf4cbb499054c5a6d52aaf81
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/7ac3e313/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list