[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Mar 20 15:33:17 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4b8b6452 by Salvatore Bonaccorso at 2026-03-20T16:32:52+01:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,30 @@
+CVE-2026-23278 [netfilter: nf_tables: always walk all pending catchall elements]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/7cb9a23d7ae40a702577d3d8bacb7026f04ac2a9 (7.0-rc4)
+CVE-2026-23277 [net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/0cc0c2e661af418bbf7074179ea5cfffc0a5c466 (7.0-rc4)
+CVE-2026-23276 [net: add xmit recursion limit to tunnel xmit functions]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/6f1a9140ecda3baba3d945b9a6155af4268aafc4 (7.0-rc4)
+CVE-2026-23275 [io_uring: ensure ctx->rings is stable for task work flags manipulation]
+ - linux <unfixed>
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ [bullseye] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/96189080265e6bb5dde3a4afbaf947af493e3f82 (7.0-rc4)
+CVE-2026-23274 [netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf (7.0-rc4)
+CVE-2026-23273 [macvlan: observe an RCU grace period in macvlan_common_newlink() error path]
+ - linux 6.18.14-1
+ NOTE: https://git.kernel.org/linus/e3f000f0dee1bfab52e2e61ca6a3835d9e187e35 (7.0-rc1)
+CVE-2026-23272 [netfilter: nf_tables: unconditionally bump set->nelems before insertion]
+ - linux 6.19.8-1
+ NOTE: https://git.kernel.org/linus/def602e498a4f951da95c95b1b8ce8ae68aa733a (7.0-rc3)
+CVE-2026-23271 [perf: Fix __perf_event_overflow() vs perf_remove_from_context() race]
+ - linux 6.19.8-1
+ NOTE: https://git.kernel.org/linus/c9bc1753b3cc41d0e01fbca7f035258b5f4db0ae (7.0-rc2)
CVE-2026-4478 (A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1 ...)
NOT-FOR-US: Yi Technology YI Home Camera 2
CVE-2026-4477 (A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b8b64524e5d7eba22b528fd155c30105fb1f597
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b8b64524e5d7eba22b528fd155c30105fb1f597
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260320/006a0f67/attachment.htm>
More information about the debian-security-tracker-commits
mailing list