[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 20:08:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0403ef2b by Salvatore Bonaccorso at 2026-09-04T21:08:25+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,264 @@
+CVE-2026-80818 [iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9ff145a25c5c8a26b06ef7cf558fb536b18bba6d (7.3-rc1)
+CVE-2026-80817 [iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d616de490ec0242dcf78f02f1adf7baa035c4d0d (7.3-rc1)
+CVE-2026-80816 [ALSA: FCP: Use a private URB for the notification endpoint]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/918b8d231c571c50a00efe92ffc8404a537a0490 (7.3-rc1)
+CVE-2026-80815 [ALSA: scarlett2: Use a private URB for the notification endpoint]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cd17d6ff7b7d2b1dd9bcc80ae7b4a83773f918c6 (7.3-rc1)
+CVE-2026-80813 [nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/79aba4c9403419d822972d2851f2a96a2c0531cf (7.3-rc1)
+CVE-2026-80811 [io_uring/cmd: fix iovec leak when the async cmd is not recycled]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bb34ae5da3365699d53a756f4c96b6ea9f8ba0c1 (7.3-rc1)
+CVE-2026-80810 [io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3f3a6a16bbe8bde76532d9415438f8cdef439e5d (7.3-rc1)
+CVE-2026-80804 [xfs: restore nofs context unconditionally in xfs_trans_roll]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0241ea5fb0fe86d2a673163b2f5815111aadc7f7 (7.3-rc1)
+CVE-2026-80787 [nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c9e9bb757971485b4e8414b1744507af186d72c9 (7.3-rc1)
+CVE-2026-80779 [net/ionic: avoid OOB TX partner lookup for hwstamp RXQ]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d92255b405fb6f5acca408239ccd742e0a42c9cb (7.3-rc1)
+CVE-2026-80778 [futex/pi: Reject cross-mm private futex owners]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/59b3732f95dda1fbd2234514d35f4fb6b5bb6d85 (7.3-rc1)
+CVE-2026-80777 [futex/pi: Plug private futex exec() race]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc (7.3-rc1)
+CVE-2026-80776 [futex: Fix race in futex_pivot_pending() during private hash resize]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8e7ff730dd96519a333d1570edf1c3fabb6d3629 (7.2-rc7)
+CVE-2026-80775 [futex: Fix race on the initial mm->futex.phash.ref allocation]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bde0238083647381d4747355c5a19115a3422b96 (7.3-rc1)
+CVE-2026-80773 [HID: huawei: fix missing hid_is_usb() check]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4cdb6b4b34d7823254f6e1b22faf56c96ac57fb9 (7.3-rc1)
+CVE-2026-80769 [HID: rapoo: fix missing hid_is_usb() check]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b57af2448268c30c25509a832b6ff6dc27176b28 (7.3-rc1)
+CVE-2026-80760 [Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5d95286b6d6e8f1d304da7522bfa6860fc017e48 (7.3-rc1)
+CVE-2026-80759 [Bluetooth: hci_aml: validate firmware segment lengths]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4 (7.3-rc1)
+CVE-2026-80758 [futex: Avoid private hash use-after-free on final put]
+	- linux 7.1.12-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1c7efabfbaf796f11000a46094a69955a01ec6cc (7.3-rc1)
+CVE-2026-80820 [xfs: don't livelock in scrub on a circular unlinked list]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/527eaaefddb6ec5c83a06c9a1559960dd6361753 (7.2-rc7)
+CVE-2026-80819 [Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/43a556b2fd43f2df6dded59c2e26560a27874c24 (7.3-rc1)
+CVE-2026-80814 [rndis_host: add overflow check in rndis_rx_fixup()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/965a251f23ff69cfb4486974d4532e9bb551c7fc (7.3-rc1)
+CVE-2026-80812 [ALSA: dummy: Check card index validity at probe]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd (7.3-rc1)
+CVE-2026-80809 [ocfs2: fix missing metadata reservation for large xattrs]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/0cdc7dde00ec63ac714271fa8b2918d630b8da1a (7.3-rc1)
+CVE-2026-80808 [ext4: stop retrying saturated xattr cache entries]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/54b6bd40898de7906acb2bccc9a96d1b8e6b4323 (7.3-rc1)
+CVE-2026-80807 [nilfs2: reject invalid block index in GC ioctl]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/a1735eae55448bc79c2da6593455791e886f6ed8 (7.3-rc1)
+CVE-2026-80806 [ext4: don't enable DAX on new encrypted files]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/da32af420d6d466e247c43ac0b829edeac7ae0ad (7.3-rc1)
+CVE-2026-80805 [xfs: validate attr entry pointer before field access]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/b7eea80be25f3334f131d52982b3131aba77b97d (7.3-rc1)
+CVE-2026-80803 [nfc: digital: clamp SENSF_RES length to the destination buffer]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16 (7.3-rc1)
+CVE-2026-80802 [nfc: fdp: bound the device-reported read length and fix an skb leak]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1 (7.3-rc1)
+CVE-2026-80801 [nfc: microread: validate target discovery payload lengths]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/25519469972ef57c3edb1805dabd6c5612b90211 (7.3-rc1)
+CVE-2026-80800 [nfc: llcp: bound the connect_sn TLV walk to the skb]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8 (7.3-rc1)
+CVE-2026-80799 [nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911 (7.3-rc1)
+CVE-2026-80798 [nfc: llcp: reject PDUs shorter than the LLCP header]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/95674f506c6376d6722a23144c9acd26609771ed (7.3-rc1)
+CVE-2026-80797 [nfc: pn533: purge fragmented skbs during cleanup]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/5718fc62198c38c2de5316020a90506f9e75e0bb (7.3-rc1)
+CVE-2026-80796 [nfc: nci: add data_len bound checks to activation parameter extractors]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/0428fa2c22e2ba0cff766d3b80d461e149102045 (7.3-rc1)
+CVE-2026-80795 [nfc: nci: fix out-of-bounds write in nci_target_auto_activated()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/ac200079db50af81e6b04d058b33ec92901d8edd (7.3-rc1)
+CVE-2026-80794 [nfc: nci: fix uninit-value in the RF discover/activated NTF handlers]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/8cbe06c1e699c0a165dae5093a2550e65f914818 (7.3-rc1)
+CVE-2026-80793 [ipv4: reject undersized MTUs in ip_do_fragment()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/c0726f0caf8c6b3208552949e17d23634a2f3129 (7.3-rc1)
+CVE-2026-80792 [ipv6: fix use-after-free in ip6_finish_output2()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e (7.3-rc1)
+CVE-2026-80791 [nvmet-auth: zero the AUTH_RECEIVE response buffer]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/3ddcfb013322aa37eaa7a0d344b73079c38dfa21 (7.3-rc1)
+CVE-2026-80790 [nvmet-fc: fix invalid free in LS IOD error path]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/ba98d6796d12258e837ece065d2ecb59d76ce4ff (7.3-rc1)
+CVE-2026-80789 [nvmet-tcp: bound SGL data length before allocating command buffers]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/4a3f00262a044e8e15064b1a6860968bf0500bf4 (7.3-rc1)
+CVE-2026-80788 [nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/737a3b535247226f6e1a7988fd9d6e63e7d6fc71 (7.3-rc1)
+CVE-2026-80786 [fbdev: Wrap user-invoked calls to fb_set_var() in helper]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/6f611e5e5f3327cf2e2daabe6ee5acac58cc784e (7.2-rc1)
+CVE-2026-80785 [fbdev: serialize mode sysfs access with lock_fb_info()]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2 (7.2-rc7)
+CVE-2026-80784 [mptcp: pm: fix memory leak from alloc-during-teardown race]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/efc33b5102ff859bacd390a5f30112d8e0c084c0 (7.2-rc7)
+CVE-2026-80783 [HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/db8d634128d2ba88d79c0b601e983ebe14bb0519 (7.3-rc1)
+CVE-2026-80782 [HID: magicmouse: do not keep a stale msc->input if no input is claimed]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/0af3b89705688af01aa06025b84fa7a1e06ba6cc (7.3-rc1)
+CVE-2026-80781 [HID: core: fix OOB read of field->usage in hid_set_field()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/a13cdb19fcb223ed41bdab3bab42b98dba87e90b (7.3-rc1)
+CVE-2026-80780 [HID: pidff: fix OOB write when hid->inputs is empty]
+	- linux 7.1.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/67bb1074e3d2d12fa059a9cc707e89398a4e4704 (7.3-rc1)
+CVE-2026-80774 [HID: asus: fix missing hid_is_usb() check]
+	- linux 7.1.12-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/02bf61dfb44f17ec187d1da1a82495951bbd12df (7.3-rc1)
+CVE-2026-80772 [HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/27b376b945c0aac46fcdfcc950b14a85b874b557 (7.3-rc1)
+CVE-2026-80771 [HID: nintendo: register input device after capabilities are set]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/d723bc1fe2e72b9252234e94c11af644ec477bf7 (7.3-rc1)
+CVE-2026-80770 [HID: nintendo: stop device IO before hid_hw_stop on probe failure]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/1f74d3bff6fe04a64e02ab3661d2e0d554565aa6 (7.3-rc1)
+CVE-2026-80768 [HID: ft260: fix stack-use-after-return write in I2C read race]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/bf3e39df3a397fd82967a31d17c4e02c7feab221 (7.3-rc1)
+CVE-2026-80767 [HID: sensor: custom: Fix use-after-free in enable_sensor]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/ad8fb82b04422f49530d2aa2753cc81d1c60102c (7.3-rc1)
+CVE-2026-80766 [HID: uclogic: fix use-after-free of inrange_timer on remove]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/506fd50a9027340f0e9dcc587d10ccb03312dba6 (7.3-rc1)
+CVE-2026-80765 [HID: hyperv: validate initial device info bounds]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/934b7778aa7b7c8f6bb073d2a73ba3674885bae0 (7.3-rc1)
+CVE-2026-80764 [Bluetooth: hci_event: fix LE list UAF on reset]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/33af47e847fe4a28b109673affb5874015d54f5a (7.3-rc1)
+CVE-2026-80763 [Bluetooth: hci_event: validate LE Set CIG Parameters response]
+	- linux 7.1.12-1
+	[trixie] - linux 6.12.107-1
+	NOTE: https://git.kernel.org/linus/0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899 (7.3-rc1)
+CVE-2026-80762 [Bluetooth: hci_sync: Fix accept list UAF during suspend]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/f57b399c4fa1501b2d5451f52d861ece86bcf3db (7.3-rc1)
+CVE-2026-80761 [Bluetooth: ISO: zero the sockaddr before returning it in getname]
+	- linux 7.1.12-1
+	NOTE: https://git.kernel.org/linus/884cf2cc957da7ac178a0e6c6c69ddfec0481cc8 (7.3-rc1)
 CVE-2026-XXXX [freeciv Heap buffer overflow in worklist_load() via unbounded wl_length from save file]
 	- freeciv <unfixed>
 	[trixie] - freeciv <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0403ef2b516ba848bf85f3181ccc13138d358f47

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0403ef2b516ba848bf85f3181ccc13138d358f47
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/2b103894/attachment.htm>


More information about the debian-security-tracker-commits mailing list