[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 20:12:53 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6e9c8d36 by Salvatore Bonaccorso at 2026-09-04T21:12:27+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,141 @@
+CVE-2026-80853 [KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a33c40b93ccf5177e042253807d40e0b92e7f206 (7.3-rc1)
+CVE-2026-80864 [RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/6f7014237405e7f032b5c53a82d9eccf6161c291 (7.3-rc1)
+CVE-2026-80863 [RDMA/rxe: Fix OOB in free_rd_atomic_resources()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/de329533792a373186d79dca1ca120f8fa0afd05 (7.3-rc1)
+CVE-2026-80862 [nvme-tcp: fix usage of page_frag_cache]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/36ac05f7cfd59d90c597071304b14e98090d5dd1 (7.3-rc1)
+CVE-2026-80861 [usb: xhci: bail out of setup if the controller is inaccessible]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/78203d5b54a40f0e36196ebf31c9c7a380fc8811 (7.3-rc1)
+CVE-2026-80860 [fuse: fix race between interrupt and resend]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ed9c881f3b498383f73c42712b359419da42a7b0 (7.3-rc1)
+CVE-2026-80859 [fuse: fix missing barrier when checking io-uring readiness]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/edb310bc27f0ad83e7fd558a3caf1a94ca511654 (7.3-rc1)
+CVE-2026-80858 [fuse: publish io-uring queues with release semantics]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/42df916e5a5f8fb4b60c8cefb54318d1ec02c580 (7.3-rc1)
+CVE-2026-80857 [fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/64b0b5cacbd2fea88001464cb712c9dfc795b26e (7.3-rc1)
+CVE-2026-80856 [fuse: fix invalidate lock leak on setattr writeback failure]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/9afeca0d569c9fc89d758fe7a9339d1e8afb1546 (7.3-rc1)
+CVE-2026-80855 [fuse: fix invalidate lock leak on open O_TRUNC DAX failure]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/a927f1867e61b78f39f9da0bbba3c98c2ca151fe (7.3-rc1)
+CVE-2026-80854 [usb: gadget: f_tcm: keep port count until LUN teardown completes]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/c39d0916da47d94909391876c9e5bd429ea7b1b9 (7.3-rc1)
+CVE-2026-80852 [tls: device: fix out-of-bounds write in tls_append_frag()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4 (7.3-rc1)
+CVE-2026-80851 [gtp: serialize PDP context updates]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/498386b6d402737db1e2eeed4c385acbf0ef9e34 (7.3-rc1)
+CVE-2026-80850 [tcp: fix AO info use-after-free in tcp_ao_connect_init()]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ea30dc5267e367b8a5e1e06cc074f813bcbf18b2 (7.3-rc1)
+CVE-2026-80849 [net/tcp-ao: fix use-after-free of current_key on reconnect to another peer]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/da4471557f279d0f56605158a625bb6e49ef7d41 (7.3-rc1)
+CVE-2026-80848 [xfrm: espintcp: fix UAF during close]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/deb232e884877bf10b4ce2580909eedec986c284 (7.3-rc1)
+CVE-2026-80847 [tcp: clamp route advmss to TCP_MIN_MSS]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1 (7.3-rc1)
+CVE-2026-80846 [xfrm: drop ESP-in-TCP packets with no ingress device]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/e1d7c5ac1c246ce5775f604515de0a59fbf2116e (7.3-rc1)
+CVE-2026-80845 [xfrm: avoid lock inversion in nat keepalive work]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/763fe700b7c58ad64fe5202c5638848244dd4127 (7.3-rc1)
+CVE-2026-80844 [xfrm: ah6: validate routing header segments_left]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/7bad4bda74dc4713f398d3b7624ff05478e3a568 (7.3-rc1)
+CVE-2026-80843 [xfrm: fix xfrm_state_construct() auth-trunc leak]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/c12cbf56320fb633484ee0ca1fb7d68d6b64b213 (7.3-rc1)
+CVE-2026-80842 [net: bridge: mcast: fix use-after-free of a master VLAN's multicast context]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/50e5c6605cc9c2dd57bd2d1b3459674d19738983 (7.3-rc1)
+CVE-2026-80841 [net/packet: defer vmalloc TX_RING free until skbs finish]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/992cc9f94ca924089a506ba9b327caa9af797529 (7.3-rc1)
+CVE-2026-80840 [ipv6: seg6: clear IPv4 control block on IPIP decapsulation]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/44930446dde45a7a90fe1446fa38eb0e2c561646 (7.3-rc1)
+CVE-2026-80839 [batman-adv: reject unrepresentable multicast TVLV offsets]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f12c2de4f542e3220e17e0606f492110064f04cb (7.3-rc1)
+CVE-2026-80838 [vxlan: keep the last remote linked during FDB flush]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d5d4a7b538b52db63927773a8905fcd9f78a42e2 (7.3-rc1)
+CVE-2026-80837 [netfilter: nf_tables: don't queue packet path object notifications]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/7904b94768e983bcb2be34a8d6d1f3450f5b838b (7.3-rc1)
+CVE-2026-80836 [crypto: virtio - bound the akcipher result length]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/f77a956f6a19f9463ef1527c9d0cda50dded6b92 (7.3-rc1)
+CVE-2026-80835 [crypto: qcom-rng - Remove crypto_rng interface]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2ecdf5c9910e20f73639bc322f0518a3439d17c0 (7.3-rc1)
+CVE-2026-80834 [crypto: sun8i-ce - Remove crypto_rng interface]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/011556f71d094da61379ae3672692cae2795304e (7.3-rc1)
+CVE-2026-80833 [crypto: sun8i-ss - Remove crypto_rng interface]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a78446ee6fae86ac8733f120e3ffce2e5d9384f5 (7.3-rc1)
+CVE-2026-80832 [crypto: qce - fix CCM AAD buffer underallocation]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/7f2345f47dd189625f657cd72437179ab4170ee1 (7.3-rc1)
+CVE-2026-80831 [crypto: mxs-dcp - fix source scatterlist length access]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8 (7.3-rc1)
+CVE-2026-80830 [usb: core: Add lock to usb_wakeup_notification()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6 (7.3-rc1)
+CVE-2026-80829 [ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/1035a8f63bae28e498b0e7b5ac91d749844a7158 (7.3-rc1)
+CVE-2026-80828 [ALSA: usb-audio: Complete cleanup after system-resume errors]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/1739a976312e110c93a8dee66a1cdf893a1b187e (7.3-rc1)
+CVE-2026-80827 [USB: serial: option: fix slab OOB read in interrupt URB callback]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/885d802f544ca7bfa8f3984d94233cce715bb6b3 (7.3-rc1)
+CVE-2026-80826 [USB: c67x00: fix use-after-free in c67x00_add_iso_urb()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/b1e24de475bf2d66fffc9103f3444b783527d55a (7.3-rc1)
+CVE-2026-80825 [wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb]
+	- linux 7.1.13-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ef3e34874d2332d0f63e72c2c35ce5c93568c125 (7.3-rc1)
+CVE-2026-80824 [usb: usbfs: fix use-after-free of usb_device in usbdev_release()]
+	- linux 7.1.13-1
+	NOTE: https://git.kernel.org/linus/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671 (7.3-rc1)
 CVE-2026-80821 [nvmet: pci-epf: put CQ ref on create_cq mapping failure]
 	- linux 7.1.12-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6e9c8d362d2a46210d83be66ff5896bf56d4df9f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6e9c8d362d2a46210d83be66ff5896bf56d4df9f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/773e0be2/attachment.htm>


More information about the debian-security-tracker-commits mailing list