[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 19 19:07:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ef689d7d by Salvatore Bonaccorso at 2026-07-19T20:06:39+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,978 @@
+CVE-2026-64186 [iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8dfd3d8d74435344ee8dc9237596959c8b2a6cbe (7.1-rc4)
+CVE-2026-64185 [sysfs: don't remove existing directory on update failure]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/237557b8a81ab948e8332f7c0058e758f081c0a3 (7.1-rc5)
+CVE-2026-64184 [mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d4e7b5c4cc353f154d5ab8bb2e1ce7714d77a6e9 (7.1-rc5)
+CVE-2026-64183 [efi: Allocate runtime workqueue before ACPI init]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/13c6da02e767152c9ac4330962247a5e47011035 (7.1-rc5)
+CVE-2026-64182 [drivers/base/memory: fix memory block reference leak in poison accounting]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/03a2cc1756a0570f887d624cd6c535ea0cbd4951 (7.1-rc5)
+CVE-2026-64181 [mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c0c6ccd9828c3a1950623b546fa57292a77b5c73 (7.1-rc5)
+CVE-2026-64180 [mm/memory_hotplug: fix memory block reference leak on remove]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/93866f55f7e292fe3d47d36c9efe5ee10213a06b (7.1-rc5)
+CVE-2026-64179 [net: wwan: iosm: fix potential memory leaks in ipc_imem_init()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c5d93b2c40355e999715262a824965aac025a427 (7.1-rc5)
+CVE-2026-64178 [Bluetooth: bnep: Fix UAF read of dev->name]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/59e932ded949fa6f0340bf7c6d7818f962fa4fd2 (7.1-rc5)
+CVE-2026-64177 [phonet/pep: disable BH around forwarded sk_receive_skb()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/dbc81608e3a653dea6cf403f20cae35468b8ab9c (7.1-rc5)
+CVE-2026-64175 [wifi: iwlwifi: mld: stop TX during firmware restart]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2becb38a3e217ef2b2f42fddd7db7a25905ec291 (7.1-rc5)
+CVE-2026-64174 [wifi: cfg80211: advance loop vars in cfg80211_merge_profile()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/7666dbb1bacc4ba522b96740cba7283d243d16e1 (7.1-rc5)
+CVE-2026-64173 [tracing: Do not call map->ops->elt_free() if elt_alloc() fails]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/8f0f5c4fb9df0e19a341e0c6ed8dc4fda9124f03 (7.1-rc5)
+CVE-2026-64172 [KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9a12fa5213cfc391e0eed63902d3be98f0913765 (7.1-rc5)
+CVE-2026-64171 [i2c: tegra: fix pm_runtime leak on mutex_lock failure]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/57cf4e8d6a57dc2ef5810f4852a23ba4c71b74bb (7.1-rc5)
+CVE-2026-64170 [spi: qup: fix error pointer deref after DMA setup failure]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/a7e8f3efd50a165ba0189f6dc57f7e51a7d149db (7.1-rc5)
+CVE-2026-64169 [spi: ep93xx: fix error pointer deref after DMA setup failure]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5e121a81667a83e9a01d62b429e340f5a4a84abc (7.1-rc5)
+CVE-2026-64168 [spi: sprd: fix error pointer deref after DMA setup failure]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/3d67fffb74267772d461c02c67f1eff893ad547d (7.1-rc5)
+CVE-2026-64167 [kho: skip KHO for crash kernel]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a6715d7ec472a476db17787697a4abda62962284 (7.1-rc4)
+CVE-2026-64166 [firmware: arm_ffa: Check for NULL FF-A ID table while driver registration]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0a5e695095c557d2380131b613dea4e8d90371be (7.1-rc5)
+CVE-2026-64165 [ARM: integrator: Fix early initialization]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/90d77b30a666049ad24df463f52e5d529c44e8cd (7.1-rc5)
+CVE-2026-64164 [btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c73370c677646e86fc4b1780fb07027bdf847375 (7.1-rc4)
+CVE-2026-64162 [idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/da4f76b6a84ede14a71282ef841768299ead0221 (7.1-rc4)
+CVE-2026-64161 [net: ti: icssm-prueth: fix eth_ports_node leak in probe]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6635fa84403c3a59455b66007c019a7cc632db30 (7.1-rc4)
+CVE-2026-64158 [netfs: Fix write streaming disablement if fd open O_RDWR]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/70a7b9193bbbfceaab5974de66834c64ccc875dd (7.1-rc5)
+CVE-2026-64157 [netfs: Fix partial invalidation of streaming-write folio]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6d91acc7fb85d33ea58fca9b964a32a453937f4b (7.1-rc5)
+CVE-2026-64156 [netfs, afs: Fix write skipping in dir/link writepages]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9871938f99cc6cb266a77265491660e2375271f5 (7.1-rc5)
+CVE-2026-64155 [wifi: ath11k: fix error path leaks in some WMI WOW calls]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/55dda532bbc261aef495e403c8900c5e2ab5fa34 (7.1-rc5)
+CVE-2026-64153 [drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/55e0f0d1c1a4ee1e46da7da4d443eb3044fb3851 (7.1-rc5)
+CVE-2026-64152 [iommu: Handle unmap error when iommu_debug is enabled]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0735c54804c709d1b292f3b6947cfb560b2ce552 (7.1-rc4)
+CVE-2026-64151 [iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8ef3f77c440005c7f04229a75976bfc078364247 (7.1-rc4)
+CVE-2026-64150 [netfilter: nft_inner: release local_lock before re-enabling softirqs]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a6cb3ff979855f7f0ee9450a947fe8f96c2ba37a (7.1-rc5)
+CVE-2026-64149 [dma-mapping: move dma_map_resource() sanity check into debug code]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/af0c3f05866237f7592219bfe05387bc3bfc99b5 (7.1-rc5)
+CVE-2026-64148 [pds_core: fix error handling in pdsc_devcmd_wait]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0e46b6635b03d29807f810c3b415c4755a3f958d (7.1-rc5)
+CVE-2026-64147 [pds_core: fix debugfs_lookup dentry leak and error handling]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc416e32baaeb620b9809e9e25fc7b30889686e9 (7.1-rc5)
+CVE-2026-64145 [wifi: wilc1000: fix dma_buffer leak on bus acquire failure]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dd7b6a8671939708cc4b7a46786d8c11297e8f69 (7.1-rc5)
+CVE-2026-64143 [platform/x86: uniwill-laptop: Do not enable the charging limit even when forced]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/26cbe119f99c86dcb4a0136d2bc73c0c716d80e4 (7.1-rc5)
+CVE-2026-64142 [ksmbd: close durable scavenger races against m_fp_list lookups]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bf736184d063da1a552ffeff0481813599a182cc (7.1-rc3)
+CVE-2026-64141 [ksmbd: fix null pointer dereference in compare_guid_key()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4b83cbc4c15f09b000cc06f033f64b0824b6dc87 (7.1-rc5)
+CVE-2026-64140 [ksmbd: fix null pointer dereference in proc_show_files()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/904901561e61a2b559070b20c74a8c95491f30aa (7.1-rc5)
+CVE-2026-64137 [smb: client: require net admin for CIFS SWN netlink]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d1ebfce2c1d161186a82e77590bf7da2ea1bce91 (7.1-rc5)
+CVE-2026-64136 [smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4d8690dace005a38e6dbde9ecce2da3ad85c7c41 (7.1-rc5)
+CVE-2026-64135 [hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/eee213daa1e1b402eb631bcd1b8c5aa340a6b081 (7.1-rc5)
+CVE-2026-64134 [ALSA: pcm: Don't setup bogus iov_iter for silencing]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e4d3386b74fba8e01280484b67ee481ece00201e (7.1-rc5)
+CVE-2026-64133 [ALSA: asihpi: Fix potential OOB array access at reading cache]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f (7.1-rc5)
+CVE-2026-64132 [ipv6: ioam: refresh hdr pointer before ioam6_event()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e46e6bc97fb1f339730ff1ba74267fbf48e7a422 (7.1-rc5)
+CVE-2026-64131 [mm/memory: fix spurious warning when unmapping device-private/exclusive pages]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/be3f38d05cc5a7c3f13e51994c5dd043ab604d28 (7.1-rc5)
+CVE-2026-64130 [mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6a288a4ddb4a994490505ab5f41c445f8e6b6467 (7.1-rc5)
+CVE-2026-64129 [mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/63451de16e0a08be40f9ab5e7c5c8f5c79676fb1 (7.1-rc5)
+CVE-2026-64128 [Bluetooth: ISO: drop ISO_END frames received without prior ISO_START]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/84c24fb151fc1179355296d7ff29129ac7c42129 (7.1-rc5)
+CVE-2026-64127 [Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d (7.1-rc5)
+CVE-2026-64126 [Bluetooth: MGMT: validate Add Extended Advertising Data length]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d3f7d17960ed50df3a6709c5158caff989c8c905 (7.1-rc5)
+CVE-2026-64125 [net: bcmgenet: keep RBUF EEE/PM disabled]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/9a1730245e416d11ad5c0f2c100061d61cc43f60 (7.1-rc5)
+CVE-2026-64124 [net: devmem: reject dma-buf bind with non-page-aligned size or SG length]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4eb82ba543421e9e38cc14e4e82058b78850df50 (7.1-rc5)
+CVE-2026-64122 [net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7d260c5d2d89eb2c8c528d54b576b3aae3e20231 (7.1-rc5)
+CVE-2026-64121 [net: ifb: report ethtool stats over num_tx_queues]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5db89c99566fc4728cc92e941d8e1975711e24b5 (7.1-rc5)
+CVE-2026-64120 [net: ethtool: fix NULL pointer dereference in phy_reply_size]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4908f1395fb1b832ceec11584af649874a2732ea (7.1-rc4)
+CVE-2026-64119 [l2tp: use list_del_rcu in l2tp_session_unhash]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/979c017803c40829b03acd9e5236e354b7622360 (7.1-rc5)
+CVE-2026-64118 [qed: fix double free in qed_cxt_tables_alloc()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/2bccfb8476ca5f3548afbd623dc7a6980d4e77de (7.1-rc5)
+CVE-2026-64116 [ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d4ea0dfd75011b78cebf3808f98ac4c4f51a6fb9 (7.1-rc5)
+CVE-2026-64115 [vsock/vmci: fix UAF when peer resets connection during handshake]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/99e22ddf4edb63dc8382bc028af928056d3450cf (7.1-rc5)
+CVE-2026-64114 [ipv4: raw: reject IP_HDRINCL packets with ihl < 5]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/915fab69823a14c170dbaa3b41978768e0fe62fc (7.1-rc5)
+CVE-2026-64113 [ixgbevf: fix use-after-free in VEPA multicast source pruning]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/5d49b568c188dc77199d8d2b959c91da8cc27cf1 (7.1-rc5)
+CVE-2026-64110 [igc: fix potential skb leak in igc_fpe_xmit_smd_frame()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e935c37b8a94bb256fada6395a5d05e1c0c6bdaf (7.1-rc5)
+CVE-2026-64108 [cifs: Fix busy dentry used after unmounting]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c68337442f03953237a94577beb468ab2662a851 (7.1-rc5)
+CVE-2026-64107 [ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/09e8f9a9aa19aa8c1b0cc7a0ebc68f6ecf86a660 (7.1-rc5)
+CVE-2026-64105 [KVM: arm64: vgic: Free private_irqs when init fails after allocation]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f19c354dbd457759dfcf1195ab4bdba2bb568323 (7.1-rc5)
+CVE-2026-64104 [virt: sev-guest: Explicitly leak pages in unknown state]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fd948c3f96b18ff9ba7d3e8eae13d196593e1aaf (7.1-rc5)
+CVE-2026-64103 [scsi: isci: Fix use-after-free in device removal path]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/b52a8d52c3125ec9a93106ed816582368de34426 (7.1-rc5)
+CVE-2026-64102 [RDMA/siw: Reject MPA FPDU length underflow before signed receive math]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/0ce1bc9e46ecabe84772bb561e373c0d9876d6f2 (7.1-rc5)
+CVE-2026-64101 [fwctl: pds: Validate RPC input size before parsing]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e7537735028c3ad4b0bfc02ff8fa2a1a28aa04fe (7.1-rc5)
+CVE-2026-64100 [drm/msm: Fix shrinker deadlock]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3392291fc509d8ad6e4ad90f15b0a193f721cbc9 (7.1-rc5)
+CVE-2026-64099 [drm/v3d: Fix use-after-free of CPU job query arrays on error path]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b0fe80c0b9250b35e2211bf3117e7aca814a21b0 (7.1-rc5)
+CVE-2026-64096 [batman-adv: mcast: fix use-after-free in orig_node RCU release]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/20c2d6a20ca936f5aaa6dd40f73f262ac45c87cc (7.1-rc5)
+CVE-2026-64095 [batman-adv: bla: avoid double decrement of bla.num_requests]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/83ab69bd12b80f6ea169c8bea6977701b53a043d (7.1-rc5)
+CVE-2026-64094 [batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/f80d3d98d2ff78d9e2fe5d68b1f45948c4f7bd24 (7.1-rc5)
+CVE-2026-64091 [batman-adv: tt: fix TOCTOU race for reported vlans]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/94d27005016be15ffc638b2ecbc4d58805ad7b48 (7.1-rc5)
+CVE-2026-64090 [batman-adv: tt: avoid empty VLAN responses]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/fa1bd704940b5bcbc32c0b28db9167405c8ee5e0 (7.1-rc5)
+CVE-2026-64089 [batman-adv: tt: fix negative last_changeset_len]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/fc92cdfcb295cefa4344d71a527d61b638b7bfc4 (7.1-rc5)
+CVE-2026-64088 [batman-adv: tt: fix negative tt_buff_len]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/b64963a2ceeb7529310b6cf253a1e540784422f4 (7.1-rc5)
+CVE-2026-64087 [hwmon: (pmbus/adm1266) reject implausible blackbox record_count]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/4afca954622d672ea65ed961bed01cf91caa034e (7.1-rc5)
+CVE-2026-64086 [hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/487566cb1ccdf3756fdd7bf8d875e612ff3169bb (7.1-rc5)
+CVE-2026-64085 [hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/43cae21424ff8e33894a0f86c6b80b840c049fd7 (7.1-rc5)
+CVE-2026-64084 [hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/d7834d92251baade796812876e95555e2066fa9f (7.1-rc5)
+CVE-2026-64083 [hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/a7232f68c43ca62f545049b7f5fbfc75137b843b (7.1-rc5)
+CVE-2026-64081 [firmware: arm_ffa: Validate framework notification message layout]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4a1cc9e96b311d2609a6f963a5e35bd4ae730d97 (7.1-rc5)
+CVE-2026-64080 [firmware: arm_ffa: Snapshot notifier callbacks under lock]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/38290b180a4d5746baed796d49f88d56d2f336cd (7.1-rc5)
+CVE-2026-64075 [fprobe: Fix unregister_fprobe() to wait for RCU grace period]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/657b594b2084b39a4bc6d8493aa2140cb00cea49 (7.1-rc4)
+CVE-2026-64074 [fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78 (7.1-rc5)
+CVE-2026-64073 [irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/91840be8f710370607f949a627e070896faeddb8 (7.1-rc4)
+CVE-2026-64072 [nvme: fix bio leak on mapping failure]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2279cd9c61a330e5de4d6eb0bc422820dd6fdf36 (7.1-rc4)
+CVE-2026-64071 [nvme-pci: fix use-after-free in nvme_free_host_mem()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b35a13036755c5803168a7cb93bc66035c3e65b8 (7.1-rc4)
+CVE-2026-64069 [netfs: Fix cancellation of a DIO and single read subrequests]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6f0f7ac1915abc0d202f0eb4b003a6548a5ba60d (7.1-rc5)
+CVE-2026-64065 [netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc7832d05deb4d632e8035e3299e31a3528fa0d0 (7.1-rc5)
+CVE-2026-64064 [netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/156ac2ec2ee77c44c4eb7439d6d165247ba12247 (7.1-rc5)
+CVE-2026-64063 [netfs: Fix streaming write being overwritten]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7b4dcf1b9455a6e52ac7478b4057dbe10359576d (7.1-rc5)
+CVE-2026-64062 [netfs: Fix potential deadlock in write-through mode]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b6a4ae1634b3ad2aaa05222e53d36da532852faf (7.1-rc5)
+CVE-2026-64061 [netfs: Fix early put of sink folio in netfs_read_gaps()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3e5dd91b87a8b1450217b56a336bee315f40da7d (7.1-rc5)
+CVE-2026-64059 [netfs: Fix folio->private handling in netfs_perform_write()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ccde2ac757c713535b224233a296de40efe5212d (7.1-rc5)
+CVE-2026-64056 [net: ethernet: cortina: Make RX SKB per-port]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/06937db21ee311ed07eba47954447245041a982d (7.1-rc4)
+CVE-2026-64055 [net: ethernet: cortina: Carry over frag counter]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/ebd8ec2b309e3a447851b456ccaf8fb39f3661e7 (7.1-rc4)
+CVE-2026-64054 [net: shaper: reject duplicate leaves in GROUP request]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a9a2fa1da619f276580b0d4c5d12efac89e8642b (7.1-rc4)
+CVE-2026-64053 [block: don't overwrite bip_vcnt in bio_integrity_copy_user()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/637ad3a56a3b889527d1dacea6fea2a8bd648140 (7.1-rc4)
+CVE-2026-64052 [block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8582792cf23b3d94674d4d838f7cde9a28d0fcaf (7.1-rc4)
+CVE-2026-64051 [accel/qaic: Add overflow check to remap_pfn_range during mmap]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/aa16b2bc0f02709919e2435f531406531e5bcc69 (7.1-rc4)
+CVE-2026-64050 [drm/msm/dpu: don't mix devm and drmm functions]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c0c70a11365cba7fba25a77463582bcec0f7846e (7.1-rc5)
+CVE-2026-64049 [drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b4abf879360ea00a9e2b46d2d15dcdbc0687eed (7.1-rc5)
+CVE-2026-64047 [net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/285943c6e7ca309bbea84b253745154241d9788a (7.1-rc4)
+CVE-2026-64046 [net: tls: prevent chain-after-chain in plain text SG]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/ff26a0e8377dec07e4a7230db7675bed1b9a6d03 (7.1-rc4)
+CVE-2026-64045 [ovpn: tcp - use cached peer pointer in ovpn_tcp_close()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/775d8d7ad02aa345e1588424a6a8b9ae49fb9012 (7.1-rc5)
+CVE-2026-64044 [ovpn: respect peer refcount in CMD_NEW_PEER error path]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1fef6614673ff0846d30acdeeaf3cf98bb5f6116 (7.1-rc5)
+CVE-2026-64043 [ovpn: fix race between deleting interface and adding new peer]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/982422b11e6f95f766a8cd2c2b1cbdb77e234a61 (7.1-rc5)
+CVE-2026-64042 [vfio/pci: Check BAR resources before exporting a DMABUF]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/702809dabdecca807bdd50cfdcc1c980feb2ba62 (7.1-rc4)
+CVE-2026-64041 [ASoC: codecs: fs210x: fix possible buffer overflow]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0d435a7ebcd4e97e47673c1ab6fb27f973a053ec (7.1-rc5)
+CVE-2026-64039 [drm/msm/snapshot: fix dumping of the unaligned regions]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/76824d2467feb1828b745d6add2541918d7be3da (7.1-rc5)
+CVE-2026-64037 [wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/92cee08dc4f00e77fd1317e4343c5d458b0abab7 (7.1-rc5)
+CVE-2026-64035 [igc: set tx buffer type for SMD frames]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5acc641e590e008caaed480ed9ffae47cf7ecbdf (7.1-rc5)
+CVE-2026-64034 [net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/35f0f0a2536a4d604b4dbad92c85c4a8fdebb870 (7.1-rc5)
+CVE-2026-64033 [RDMA/rtrs: Fix use-after-free in path file creation cleanup]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5b74373390113fba798a76b483837029ab010fef (7.1-rc5)
+CVE-2026-64032 [bridge: mcast: Fix a possible use-after-free when removing a bridge port]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4df78ff02629c7729168f0696a7a2123c389818d (7.1-rc5)
+CVE-2026-64031 [erofs: fix managed cache race for unaligned extents]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/649932fc3815eda2f24eb4de4b3a5e94886ee0b9 (7.1-rc5)
+CVE-2026-64030 [wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f718506edd2d9c6a308ded9d13c632bf7b7d5a2c (7.1-rc5)
+CVE-2026-64029 [ALSA: seq: Serialize UMP output teardown with event_input]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/60a1969fae6209644698fca91c185d153674f631 (7.1-rc5)
+CVE-2026-64028 [tracing: Avoid NULL return from hist_field_name() on truncation]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/576ec047d20b368b43c4d5db98c4f2e0f3c101ec (7.1-rc5)
+CVE-2026-64027 [net: shaper: rework the VALID marking (again)]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b8d7519352ba8c6df83259295d4a3bad093cae90 (7.1-rc5)
+CVE-2026-64023 [gpio: aggregator: fix a potential use-after-free]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/30c073cab97afb31901f94de9605177b6b84367e (7.1-rc5)
+CVE-2026-64022 [gpio: aggregator: remove the software node when deactivating the aggregator]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/61fef83f239ecace1cce716135762a2d9b7b1fc6 (7.1-rc5)
+CVE-2026-64021 [drm/xe/oa: Fix exec_queue leak on width check in stream open]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4d25342543c01310fc4e0cba7cb17c775e2421e2 (7.1-rc5)
+CVE-2026-64018 [net: mana: validate rx_req_idx to prevent out-of-bounds array access]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b809d0409991b75a6cff846a5ac27c3062953f84 (7.1-rc5)
+CVE-2026-64016 [ksmbd: fix durable reconnect error path file lifetime]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3515503322f4819277091839eed46b695096aca5 (7.1-rc5)
+CVE-2026-64176 [wifi: iwlwifi: mvm: fix driver-set TX rates on old devices]
+	- linux 7.0.12-1
+	NOTE: https://git.kernel.org/linus/fb84b5cbcaab3ca0f4e961d92a40ed7f3aac483b (7.1-rc5)
+CVE-2026-64163 [test_kprobes: clear kprobes between test runs]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ef5581bb30efb939cc2bf093475c6cc85258e5cd (7.1-rc4)
+CVE-2026-64160 [netfs: Fix potential for tearing in ->remote_i_size and ->zero_point]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2c8f4742bb76117d735f92a3932d85239b16c494 (7.1-rc5)
+CVE-2026-64159 [netfs: Fix zeropoint update where i_size > remote_i_size]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4543a4d737944134a1394afe797622546fbcc98a (7.1-rc5)
+CVE-2026-64154 [drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e64bca63647db1d5518198d6c5ca2dbcc66b182b (7.1-rc5)
+CVE-2026-64146 [erofs: fix metabuf leak in inode xattr initialization]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/79b09c54c6563df9846ca3094bcfd72082c3e1d7 (7.1-rc5)
+CVE-2026-64144 [Bluetooth: btmtk: fix urb->setup_packet leak in error paths]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd (7.1-rc5)
+CVE-2026-64139 [ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/af92ee994cc7f7e83a41c2025f32257a2f82a7ef (7.1-rc5)
+CVE-2026-64138 [ksmbd: validate SID in parent security descriptor during ACL inheritance]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/69f030cf95488ae1186c72ac8c66fd279664ea7f (7.1-rc5)
+CVE-2026-64123 [net: hsr: defer node table free until after RCU readers]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	[bullseye] - linux 5.10.259-1
+	NOTE: https://git.kernel.org/linus/aaec7096f9961eb223b5b149abe9495525c205d9 (7.1-rc5)
+CVE-2026-64117 [wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d71c841be5d9e586ee7f36c0dc8ed4db0d9a1349 (7.1-rc5)
+CVE-2026-64112 [rbd: eliminate a race in lock_dwork draining on unmap]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/9fc75b71fdd38465c76c6f6a884cdd4ae3c72d90 (7.1-rc5)
+CVE-2026-64111 [lsm: hold cred_guard_mutex for lsm_set_self_attr()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188 (7.1-rc5)
+CVE-2026-64109 [af_unix: Fix UAF read of tail->len in unix_stream_data_wait()]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/be309f8eae8b474a4a617eaae01324da996fc719 (7.1-rc5)
+CVE-2026-64106 [KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/9ce754ed8e7ab4e3999767ce1505f85c449ccb07 (7.1-rc5)
+CVE-2026-64098 [drm/virtio: use uninterruptible resv lock for plane updates]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/9af1b6e175c82daf4b423da339a722d8e67a735a (7.1-rc5)
+CVE-2026-64097 [drm/amd/display: Validate GPIO pin LUT table size before iterating]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/86d2b20644b11d21fe52c596e6e922b4590a3e3f (7.1-rc5)
+CVE-2026-64093 [batman-adv: tp_meter: directly shut down timer on cleanup]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/d5487249a81ea658717614009c8f46acc5b7101a (7.1-rc5)
+CVE-2026-64092 [batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/77098e4bea37af51d3962efa88a5af2ea5e1ac57 (7.1-rc5)
+CVE-2026-64082 [riscv: Fix register corruption from uninitialized cregs on error]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6ebcbb53fc9bc30843054ed99fd60b8e542628f4 (7.1-rc4)
+CVE-2026-64079 [netfilter: x_tables: allocate hook ops while under mutex]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b62eb8dcf2c47d4d676a434efbd57c4f776f7829 (7.1-rc4)
+CVE-2026-64078 [netfilter: x_tables: add and use xtables_unregister_table_exit]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b4597d5fd7d2f8cebfffd40dffb5e003cc78964c (7.1-rc4)
+CVE-2026-64077 [netfilter: ebtables: move to two-stage removal scheme]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b7f0544d86d439cb946515d2ef6a0a75e8626710 (7.1-rc4)
+CVE-2026-64076 [netfilter: bridge: eb_tables: close module init race]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/27414ff1b287ea9a2a11675149ec28e05539f3cc (7.1-rc4)
+CVE-2026-64070 [powerpc/hv-gpci: fix preempt count leak in sysfs show paths]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dbc30a57bd8e026995e9fa8e8c31cffd18542c01 (7.1-rc4)
+CVE-2026-64068 [netfs: Fix missing locking around retry adding new subreqs]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cce18c263e9623872327ba3c956012f73c1179cc (7.1-rc5)
+CVE-2026-64067 [netfs: Fix missing barriers when accessing stream->subrequests locklessly]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b5782e2d462c028096f922abca46318cec890670 (7.1-rc5)
+CVE-2026-64066 [netfs: Fix netfs_read_to_pagecache() to pause on subreq failure]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8a8c0cfdf4658fc5b295b7fc87be56e0d76741f4 (7.1-rc5)
+CVE-2026-64060 [netfs: Fix leak of request in netfs_write_begin() error handling]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5046a34f0643441f05b0253ea64e1a3af87efe14 (7.1-rc5)
+CVE-2026-64058 [netfs: Fix netfs_read_folio() to wait on writeback]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ded0c6f1606061148c202825f7e53d711f9f84cf (7.1-rc5)
+CVE-2026-64057 [afs: Fix the locking used by afs_get_link()]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c0410adf3da6db46f3513411fcf95e63c2f1d1ad (7.1-rc5)
+CVE-2026-64048 [net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/277740023def559a4a2ddc3e8e784ee37a0f16a9 (7.1-rc4)
+CVE-2026-64040 [cachefiles: Fix error return when vfs_mkdir() fails]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8a220d1c312c66194f4a33dd52d1fba42bc2b341 (7.1-rc5)
+CVE-2026-64038 [hwmon: (lm90) Stop work before releasing hwmon device]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b09a45601094c7f4ec4db8090b825fa61e169d93 (7.1-rc4)
+CVE-2026-64036 [cgroup/rstat: validate cpu before css_rstat_cpu() access]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8817005efbdfdf5d4e4814cb5dc52b53d12917d7 (7.1-rc5)
+CVE-2026-64026 [rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/d2bc90cf6c75cb96d2ce549be6c35efa3099d25b (7.1-rc5)
+CVE-2026-64025 [bpf, skmsg: fix verdict sk_data_ready racing with ktls rx]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	NOTE: https://git.kernel.org/linus/ddf8029623a1af20e984c040e89ff918158397ab (7.1-rc5)
+CVE-2026-64024 [tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1bbf0ced1d9db73ac7893c2187f3459288603e0d (7.1-rc5)
+CVE-2026-64020 [nvme-pci: fix dma_vecs leak on p2p memory]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/85686c72966c5ee637893f124ddb31a1cace7bee (7.1-rc5)
+CVE-2026-64019 [nvme-pci: fix dma mapping leak on data setup error]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1bf86336e4b6cf40873fda47a7fe191446864937 (7.1-rc5)
+CVE-2026-64017 [blk-mq: pop cached request if it is usable]
+	- linux 7.0.12-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc278e9bf2b9513a763353e6b9cc21e0f532954e (7.1-rc5)
+CVE-2026-64015 [security/keys: fix missed RCU read section on lookup]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux 6.1.176-1
+	NOTE: https://git.kernel.org/linus/43a1e3744548e6fd85873e6fb43e293eb4010694 (7.1-rc6)
 CVE-2026-64014 [Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size]
 	- linux 7.0.12-1
 	[trixie] - linux 6.12.94-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef689d7dd4e721b0367a897b8ec5b8cf80df6835

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef689d7dd4e721b0367a897b8ec5b8cf80df6835
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260719/70e02647/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list