[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 21:17:37 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c84e4664 by Salvatore Bonaccorso at 2026-07-27T22:17:08+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,66 @@
+CVE-2026-64555 [KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()]
+	- linux 7.1.5-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ff1022c3de46753eb7eba2f6efd990569e66ff95 (7.2-rc4)
+CVE-2026-64554 [netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d (7.2-rc4)
+CVE-2026-64553 [net: psample: fix info leak in PSAMPLE_ATTR_DATA]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390 (7.2-rc1)
+CVE-2026-64552 [virtio-net: fix len check in receive_big()]
+	- linux 7.1.5-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9e5ad06ea826322ce8c58b4a68442a96f600c3c4 (7.2-rc1)
+CVE-2026-64551 [sctp: validate STALE_COOKIE cause length before reading staleness]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/1cd23ca80784223fa2204e16203f754da4e821f8 (7.2-rc4)
+CVE-2026-64550 [net: qualcomm: rmnet: validate MAP frame length before ingress parsing]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/f0f1887a9e30712a1df03e152dce6fb91344b1f3 (7.2-rc3)
+CVE-2026-64549 [Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/dd068ef044128db655f48323a4acfd5907e04903 (7.2-rc3)
+CVE-2026-64548 [bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/0c0a8ed85349dae298712d79cb276acfeb794d82 (7.2-rc1)
+CVE-2026-64547 [net: usb: net1080: validate packet_len before pad-byte access in rx_fixup]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/03f384bc0cb8d4a1301d4f5b0baef2d980258383 (7.2-rc3)
+CVE-2026-64546 [drm/edid: fix OOB read in drm_parse_tiled_block()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db (7.2-rc1)
+CVE-2026-64545 [net, bpf: check master for NULL in xdp_master_redirect()]
+	- linux 7.1.5-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e82d8cc4321c373dc46e741cd2dfdaa7921fddb7 (7.2-rc1)
+CVE-2026-64544 [crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/f7dd32c5179d7755de18e21d5674b08f9e5cb180 (7.2-rc1)
+CVE-2026-64543 [tipc: fix use-after-free of the discoverer in tipc_disc_rcv()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/1579342d71133da7f00daa02c75cebec7372097b (7.2-rc1)
+CVE-2026-64542 [ipv6: ndisc: fix NULL deref in accept_untracked_na()]
+	- linux 7.1.5-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d186e942365acece7c56d39da05dd63bf95b280a (7.2-rc1)
+CVE-2026-64541 [net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/9d160b35cc34a2ba8229d07651468a7848325135 (7.2-rc3)
+CVE-2026-64540 [usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a (7.2-rc2)
+CVE-2026-64539 [Bluetooth: eir: Fix stack OOB write when prepending the Flags AD]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286 (7.2-rc1)
+CVE-2026-64538 [ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().]
+	- linux 7.1.5-1
+	NOTE: https://git.kernel.org/linus/46c3b8191aad3d032776bf3bebf03efdf5f4b905 (7.2-rc1)
+CVE-2026-64537 [bridge: cfm: reject invalid CCM interval at configuration time]
+	- linux 7.1.5-1
+	[bullseye] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f3e02edd8322b31b8e6517faa6ba053bf29d1e26 (7.2-rc1)
 CVE-2026-66759 (A flaw was found in the file-icns plugin in GIMP. When applying a deco ...)
 	- gimp <unfixed>
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c84e4664300887227fb5e0606ce784eacd313b5b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c84e4664300887227fb5e0606ce784eacd313b5b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/644d17eb/attachment.htm>


More information about the debian-security-tracker-commits mailing list