[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 15:46:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
62ae9f2d by Salvatore Bonaccorso at 2026-07-25T16:46:25+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,50 @@
+CVE-2026-64522 [net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/abe003b33223ff33552f291644bf35d9c2f992fb (7.1-rc5)
+CVE-2026-64521 [pinctrl: meson: amlogic-a4: fix deadlock issue]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e72ce029810390eb987a036fb2c8a5da9a23b685 (7.1-rc5)
+CVE-2026-64519 [NFSD: Fix infinite loop in layout state revocation]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4f8ef58c10bfe5f86a643c7c8331b37e69e3dae1 (7.1-rc4)
+CVE-2026-64518 [tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/03cb001ef87b3f8d859cf7f96329acf3d6235d29 (7.1-rc4)
+CVE-2026-64517 [drm/xe/gsc: Fix double-free of managed BO in error path]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d3ded53fab90996e7d94a39049e11962dd066725 (7.1-rc5)
+CVE-2026-64516 [drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets]
+	- linux 7.0.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3e5a1d5bb2ff061e64c7992f8e5404dfd4c2d0f3 (7.1-rc5)
+CVE-2026-64515 [wifi: mac80211: fix MLE defragmentation]
+	- linux 7.0.12-1
+	[trixie] - linux 6.12.94-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a74e893f30db64cdce0fc7a96d3baa417bcd55f5 (7.1-rc5)
+CVE-2026-64520 [firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies]
+	- linux 7.0.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3974ea1938406f9bfa7c1f48d4e43533f447bb08 (7.1-rc5)
 CVE-2026-64511 [ACPI: NFIT: core: Fix possible NULL pointer dereference]
 	- linux 7.1.4-1
 	[trixie] - linux 6.12.96-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62ae9f2d88b5943ea20cc4e8e7e3f979603b7ed3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62ae9f2d88b5943ea20cc4e8e7e3f979603b7ed3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/467d2a97/attachment.htm>


More information about the debian-security-tracker-commits mailing list