[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 27 07:52:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d86fb1fb by Salvatore Bonaccorso at 2026-07-27T08:52:08+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,25 @@
+CVE-2026-64536 [staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop]
+ - linux 7.1.4-1
+ [trixie] - linux 6.12.96-1
+ NOTE: https://git.kernel.org/linus/3bf39f711ff27c64be8680a8938bcc5001982e81 (7.2-rc3)
+CVE-2026-64535 [nvmet-tcp: Fix potential UAF when ddgst mismatch]
+ - linux 7.1.3-1
+ NOTE: https://git.kernel.org/linus/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a (7.1-rc4)
+CVE-2026-64534 [nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path]
+ - linux 7.1.3-1
+ NOTE: https://git.kernel.org/linus/4606467a75cfc16721937272ed29462a750b60c8 (7.1-rc2)
+CVE-2026-64533 [fs/ntfs3: validate lcns_follow in log_replay conversion]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6a4c53a2e26a865565bd6a460961e8d6fcb32329 (7.2-rc1)
+CVE-2026-64532 [fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3e127829e57f5190f612412ece4541cb96d5ec7a (7.2-rc1)
+CVE-2026-64531 [net: openvswitch: reject oversized nested action attrs]
+ - linux 7.1.5-1
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
CVE-2026-49478
- golang-github-sigstore-fulcio 1.8.7-1
NOTE: https://github.com/sigstore/fulcio/pull/2354
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d86fb1fbe6a68354d0f41ec48cd4812287b81626
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d86fb1fbe6a68354d0f41ec48cd4812287b81626
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/e62745bb/attachment.htm>
More information about the debian-security-tracker-commits
mailing list