[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 08:03:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ed3b8fbf by Salvatore Bonaccorso at 2026-09-12T09:01:58+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,1565 @@
+CVE-2026-89673 [nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/
+CVE-2026-89635 [ksmbd: only rebind the reopened file's own oplock on durable reconnect]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7 (7.3-rc1)
+CVE-2026-89459 [s390/percpu: Fix MVIY_PERCPU() with older binutils]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/101782f8945a125044347312d74d488c05741c4a (7.3-rc1)
+CVE-2026-89436 [platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/329f10d8be193bf36af124e00b9dd6644cd71724 (7.3-rc1)
+CVE-2026-89773 [drm/amd/display: Skip Update HDCP Config In Transition State]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d5164580a99477dcfe15cea101b153b1e63f1535 (7.3-rc1)
+CVE-2026-89772 [btrfs: write-protect folios during data writeback]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5376c9db45368eb210b4d71104ac00a59dc8b6e0 (7.3-rc1)
+CVE-2026-89771 [ring-buffer: Fix subbuf resize race with ring buffer readers]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8a5f63637890f03177146efddaba5ec7a1b4d61f (7.3-rc1)
+CVE-2026-89770 [iomap: don't free integrity payload that doesn't exist]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8a8685b32c0718cc7b2cb4d6202e5a5b8e0a8e2d (7.3-rc1)
+CVE-2026-89769 [clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/05520e035f8332c8e33f3011b5ca016fde61793d (7.3-rc1)
+CVE-2026-89768 [fs: fix user path of nested backing files]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f2381b546e7e6a35c9fcee0d0ccb6c042a9aeb5d (7.3-rc1)
+CVE-2026-89767 [ovl: fix double end_creating() on the casefold-mismatch path]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/077ab8985ee278c3d8618182d335b0f0cd919e16 (7.3-rc1)
+CVE-2026-89766 [pidfd: hold exec_update_lock around namespace ioctl]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9688a46802939da28f00cb40e8129615d5d4af39 (7.3-rc1)
+CVE-2026-89765 [timers/itimer: Zero-init old itimerval before copy to userspace]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/18c7d85864e554adc8fad1e8d2e9d2cb6c3911c8 (7.3-rc1)
+CVE-2026-89764 [rust: devres: fix race between concurrent revokers]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/acc516dfa1972d31836b50abc0115216cd0fccc5 (7.3-rc1)
+CVE-2026-89763 [KEYS: trusted: Fix TPM teardown ordering]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5e2d672280d97d83de43031d93761b12dadd7b8a (7.3-rc1)
+CVE-2026-89762 [apparmor: fix cred UAF caused by begin_current_label_crit_section()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3f4ae5fab613dca01d6a2a8210dd832e009fcf47 (7.3-rc1)
+CVE-2026-89761 [apparmor: fix out-of-bounds write when null terminating a label vec]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9f1e40193eef7f047e6b77cfb4b4cafdecd7a123 (7.3-rc1)
+CVE-2026-89760 [mm, swap: don't free a hibernation slot that is in the swap cache]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/10d9012e83efedde8718ceaa5053f836e0c8596c (7.3-rc1)
+CVE-2026-89759 [mm/kmemleak: avoid soft lockup when scanning task stacks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5d10d4e19e6daa487f0cd0ea6cba472325de92f9 (7.3-rc1)
+CVE-2026-89758 [mm/mempolicy: skip non-present PMDs when queueing folios]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2858b4027f491e6fdb8ee2d8923798b619bf2791 (7.3-rc1)
+CVE-2026-89757 [mm/mglru: fix and remove redundant unevictable folio handling]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f7e698e326b239a91ea15844817551921209e826 (7.3-rc1)
+CVE-2026-89756 [mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/efe8f86c0916f0f74eea74ae21a3b37f728c6bad (7.3-rc1)
+CVE-2026-89755 [mm/migrate_device: clear stale mapping after freeing swapcache]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/34a00895d032a414830d41106a09329ae6c251b6 (7.3-rc1)
+CVE-2026-89754 [mm/pagewalk: fix stale walk->action escaping walk_pmd_range()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/aedf2efd18977e0cef7eb963166e2b1fcc0aa321 (7.3-rc1)
+CVE-2026-89753 [mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/25f52e81216884a7444bf07a606691feb09a94e3 (7.3-rc1)
+CVE-2026-89752 [mm: memcg: stop reclaim when a limit update is superseded]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9477820c63cbf4d97114238f3d1ff10dfd6bee3f (7.3-rc1)
+CVE-2026-89751 [x86/tdx: Fix off-by-one in port I/O handling]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0f63e656b1c679d32ac595de29d10c03efca6a25 (7.3-rc1)
+CVE-2026-89750 [tracing/user_events: Clear copied tracing state before fork duplication]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/390f6bd8583d177029d9df4bea6667509e55a765 (7.3-rc1)
+CVE-2026-89749 [tracing: Fix crash passing ERR_PTR to kthread_stop()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/649bc7df3e5d7be6f7996a95084037dbf3cad1e5 (7.3-rc1)
+CVE-2026-89748 [tracing: Fix retry exhaustion in simple ring buffer reader swap]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e0d3aed7b12cf37b74c7cc5265073d0263b49cde (7.3-rc1)
+CVE-2026-89747 [tracing: Fix use-after-free in trace_pipe read on sub-buffer order change]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/372f8534244d632ad5118e8a87a11291b01712d3 (7.3-rc1)
+CVE-2026-89746 [tracing: Fix use-after-free with same-name named triggers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a7318172aa332a161fb9618286e64454c827f8fd (7.3-rc1)
+CVE-2026-89745 [debugfs: Fix lockdown check for mmap_prepare]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f81808de37338aac8e167f99bfae647b1b835c70 (7.3-rc1)
+CVE-2026-89744 [device property: fix infinite loop in fwnode_for_each_child_node()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1900692555826753adab8799a1a8d50bb1ee200c (7.3-rc1)
+CVE-2026-89743 [misc: nsm: bound the device-reported response length]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/808e530654a5354e6df78863a5d61e4d44e67235 (7.3-rc1)
+CVE-2026-89742 [rapidio: mport_cdev: fix use-after-free in dma_req_free()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5cbef379a94b161726c5f504598bf4791d45cedc (7.3-rc1)
+CVE-2026-89741 [Revert "media: v4l2-dev: fix error handling in __video_register_device()"]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e7600f5cee5de14065f950807931d6e6d40fb2d7 (7.3-rc1)
+CVE-2026-89740 [serial: imx: serialize imx_uart_ports[] lifetime]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8b0b29fdcb47907ae0296b8fe829e918e05e300f (7.3-rc1)
+CVE-2026-89739 [usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9c855832790cd488d87de1885974f4c37cfe7358 (7.3-rc1)
+CVE-2026-89738 [usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c27d13ce4bab80fbdf6523928071b6c24b37606c (7.3-rc1)
+CVE-2026-89737 [usb: typec: thunderbolt: Disable work before freeing tbt on remove]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3 (7.3-rc1)
+CVE-2026-89736 [usb: gadget: u_audio: Fix use-after-free on sound card disconnect]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/858965947081d10d41d9a1010a540d3d5eea958b (7.3-rc1)
+CVE-2026-89735 [usb: gadget: midi2: remove default configfs groups on teardown]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0f6bffb5008f0cba9cad5ded2caccc64466a6e54 (7.3-rc1)
+CVE-2026-89734 [usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5b1da38592efdc1a263d4c0353298cba19e9d6fc (7.3-rc1)
+CVE-2026-89733 [usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc (7.3-rc1)
+CVE-2026-89732 [usb: gadget: f_fs: Prevent deadlock during ep0 read loop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/569dd7e5dcffe1e1c6b26ca2cd3be57eb433e082 (7.3-rc1)
+CVE-2026-89731 [cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/29458e62d0829cbc99435f3e44fd560f9bbf1da7 (7.3-rc1)
+CVE-2026-89730 [fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9da70a43b5fea60d758137f7f0ccfe19356cb5bb (7.3-rc1)
+CVE-2026-89729 [HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c92693f3ed099401d0383ef35ca1fe1e6ba033de (7.3-rc1)
+CVE-2026-89728 [i3c: renesas: Fix out-of-bounds access for newdevs mask]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/50dec95c9d1f1f82819bc898ef2b60fa83fd4ccd (7.3-rc1)
+CVE-2026-89727 [KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c6d9c8ac6521d3049ec90ac58bebd23ed03ac496 (7.3-rc1)
+CVE-2026-89726 [lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cec0d03fe785380540dc1b4d07c80f67ae2ffc78 (7.3-rc1)
+CVE-2026-89725 [media: cec: stm32: prevent out-of-bounds write on RX overflow]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fb9dda38d4b9e90db07ed9a0ee2d35bf85494035 (7.3-rc1)
+CVE-2026-89724 [media: vicodec: fix out-of-bounds write in FWHT encoder]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cf4500ebf6fb57bf4ab83c3dd349a40257dbe2a9 (7.3-rc1)
+CVE-2026-89723 [nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/45662dedb8f272ef7f16e69f13424c4bd0399240 (7.3-rc1)
+CVE-2026-89722 [PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/dc76258d0132df1d831a5a29758bd448ca9c566e (7.3-rc1)
+CVE-2026-89721 [phy: rockchip-samsung-dcphy: fix out-of-range max_register]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4486e75ba647bd8b98fc1f053101b40caceeed4b (7.3-rc1)
+CVE-2026-89720 [ubifs: fix out-of-bounds read in signature length check]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/95d27c1708bb6e8823c8e7c623f9abc2a91bf4bf (7.3-rc1)
+CVE-2026-89719 [zram: fix out-of-bounds access in read_block_state()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/391f057f44a51cc9418da5cba78b014324174264 (7.3-rc1)
+CVE-2026-89718 [zram: fix out-of-bounds access in writeback_store()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/894913e2d35c46ff19a77530907771ae57862b96 (7.3-rc1)
+CVE-2026-89717 [zram: set default primary compressor in zram_destroy_comps()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dde75313eed0b014c437f48dd75c0308b592cbf9 (7.3-rc1)
+CVE-2026-89716 [zram: validate deflate params]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ec7607ac4717ff521c9c1e9d8271c26293345513 (7.3-rc1)
+CVE-2026-89715 [NFS/localio: fix ref leak on nfs_uuid_add_file failure]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ca018c19e0ba38975e5ddc3ef8117d5b734313aa (7.3-rc1)
+CVE-2026-89714 [NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2092f5b38f88be306140c77aeeeb43fc1adacacc (7.3-rc1)
+CVE-2026-89713 [NFSD: check truncate permission under inode lock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b778e0e0a16759f22a70579c3cf8d254a40d4a7f (7.3-rc1)
+CVE-2026-89712 [NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/036c1b182f4da65363e79ec0ac276edc6b7296e5 (7.3-rc1)
+CVE-2026-89711 [NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/aa0cf48a448c5a9fe1a1e880899ecd589ce39e6e (7.3-rc1)
+CVE-2026-89710 [NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ee5a386cfe60f3f8286de16a9db8e1a08f0bc124 (7.3-rc1)
+CVE-2026-89709 [lockd, nfsd: RCU-protect nlmsvc_ops dispatch]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/641e5e20852359b8c31149be4598884e30652f60 (7.3-rc1)
+CVE-2026-89708 [nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/01c5d5f58a5db9b0ee5afba2e49d3157788687b2 (7.3-rc1)
+CVE-2026-89707 [nfsd: release path refs on follow_down() error]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6cba08dc1922140d260cfeb30bbda4ee1bf869d8 (7.3-rc1)
+CVE-2026-89706 [nfsd: Reset write verifier when async COPY writeback fails]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f5cb2276954cb80987a93ef9f9dfbfdbfc0f10b9 (7.3-rc1)
+CVE-2026-89705 [nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f6045886fe3f14f269f683d64021b004a50d0efa (7.3-rc1)
+CVE-2026-89704 [nfsd: sample writeback error cursor before async COPY loop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/20a67a7d18221af736f124770c2c5e859b479046 (7.3-rc1)
+CVE-2026-89703 [nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/650d370cfbc66a96dd14d517bd704689b5bda4e5 (7.3-rc1)
+CVE-2026-89702 [nfsd: size fh_verify server sockaddr slot by xpt_locallen]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/71d068490098b1d23c63b2345e40675d3a1ca763 (7.3-rc1)
+CVE-2026-89701 [nfsd: validate nseconds in TIME_DELEG decode paths]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0f4a767340fad392bd656115b8752005518c9065 (7.3-rc1)
+CVE-2026-89700 [nfsd: validate sockaddr length per family in listener_set]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bdcc85c2b05a9378d8bd2d65f9fc41440a3cf464 (7.3-rc1)
+CVE-2026-89699 [nfsd: validate symlink target length in NFSv4 CREATE]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/041f57056e5fb9c80adc088269322d2c61074406 (7.3-rc1)
+CVE-2026-89698 [nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a99d720ed2a5258564e5e9d5f39f3184a030d354 (7.3-rc1)
+CVE-2026-89697 [nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4e475be769aa9f7a2c1ce55a2b8592cfccacddcc (7.3-rc1)
+CVE-2026-89696 [nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c59738a00aa51b16adc1b5ceb7c80877168efb4d (7.3-rc1)
+CVE-2026-89695 [nfsd: cap decoded POSIX ACL count to bound sort cost]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4bc1108e876153a2dd6d874052b99182c3603135 (7.3-rc1)
+CVE-2026-89694 [nfsd: check client ownership when cancelling a copy-notify stateid]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6bdbfab96e0cf25e5f57dac5c09dc1749751a4bf (7.3-rc1)
+CVE-2026-89693 [nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2c7912732184773dbd371a411da87af1cc080b86 (7.3-rc1)
+CVE-2026-89692 [nfsd: clear CALLBACK_RUNNING on failed delegation recall queue]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b036727d334b1b7cd4c1f1fba3b59ba93a6bbe96 (7.3-rc1)
+CVE-2026-89691 [nfsd: clear opcnt on compound arg release to prevent OOB read]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ae4c38555e81563b8dc5eae55ffd70f0ea97aa5a (7.3-rc1)
+CVE-2026-89690 [nfsd: defer vfree of compound ops to fix rpc_status UAF]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fca26a3fc19ed02278aa2a150af82d43db0302cb (7.3-rc1)
+CVE-2026-89689 [nfsd: don't free session slots that are still in use]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f5d22e372f4ac3eb287037a488c29691d52a6330 (7.3-rc1)
+CVE-2026-89688 [nfsd: drop the stateid, not the stateowner, on seqid_op replay retry]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5e4627d3513e60accfce9d5f4c7fa95251ef93d6 (7.3-rc1)
+CVE-2026-89687 [nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5859cc01fee06a2cd7458905a9593082fbab06e1 (7.3-rc1)
+CVE-2026-89686 [nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ca94ba36172046be6a694a7986f6931e47ed4d51 (7.3-rc1)
+CVE-2026-89685 [nfsd: fix clock domain mismatch in clients_still_reclaiming()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/09ea3eb9a518565f5bca386e81b993ed8825f5e8 (7.3-rc1)
+CVE-2026-89684 [nfsd: fix cpntf publish race in nfs4_init_cp_state]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/be3a5c1d857b0dcbc11796cea603ef25834f75b2 (7.3-rc1)
+CVE-2026-89683 [nfsd: fix dentry ref leak on V4ROOT export filehandle lookup]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6247023fbbec1325029f2d5f2a7cdc0f9f9ea15a (7.3-rc1)
+CVE-2026-89682 [nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bbf13732f74351d21c5e0e8dd9bd8e1c48dc35d4 (7.3-rc1)
+CVE-2026-89681 [nfsd: fix layout fence worker double-reference race]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8580571227451384399b3fa53fcde19848c48e5a (7.3-rc1)
+CVE-2026-89680 [nfsd: fix nfsd_file leak on inter-server COPY setup failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/88a76145451d703eedd867b5989bf73d17340399 (7.3-rc1)
+CVE-2026-89679 [nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fe456c8c0931bb3e8a03d429920e87fd85747fba (7.3-rc1)
+CVE-2026-89678 [nfsd: fix partial-write detection in nfsd_direct_write]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/250ec14932d5cfe102f68a57892bb566eee7f83e (7.3-rc1)
+CVE-2026-89677 [nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3e2c79360c6a89975ec5b5a7d4ef937e4db91a27 (7.3-rc1)
+CVE-2026-89676 [nfsd: fix stale s2s_cp_stateids IDR entry for async COPY]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d0beaee498e11880e72826026db0e9c9890fc114 (7.3-rc1)
+CVE-2026-89675 [nfsd: fix UAF in async copy cancel and shutdown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/62c0f6eaf050bb9284c1f9cac6ed1770092e6b95 (7.3-rc1)
+CVE-2026-89674 [nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f9868174af49d207fbaf0c5e055d088a983684af (7.3-rc1)
+CVE-2026-89672 [nfsd: gate nfs2 setacl by argp->mask]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a3a7e20ed66d3f04d37883c398da8a113b430769 (7.3-rc1)
+CVE-2026-89671 [nfsd: gate nfs3 setacl by argp->mask]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/453d7198a0ab07a12d46e0575861ac7b932da17e (7.3-rc1)
+CVE-2026-89670 [nfsd: hold rcu across localio cmpxchg retry]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/58884694978a3d7d111edb433d7fd6a6c5af2f34 (7.3-rc1)
+CVE-2026-89669 [nfsd: initialize copy-notify stateid before publishing it]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/129643893b79f8a3c6b72045f933fbab5ee424ca (7.3-rc1)
+CVE-2026-89668 [nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2c390c8a1764d67095fe444401861fac4c049362 (7.3-rc1)
+CVE-2026-89667 [nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/40162cfea79b9510380decfdd1795b754dc9f972 (7.3-rc1)
+CVE-2026-89666 [nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/eb0eca7720662ba5847df1510e73801f7f473094 (7.3-rc1)
+CVE-2026-89665 [nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/26709c8ffe73772eb69e68d553ac71d91228dccc (7.3-rc1)
+CVE-2026-89664 [nfsd: release OPEN-decoded posix ACLs via op_release]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8215892993ea9f5231da4fa9eb42428a286fce8b (7.3-rc1)
+CVE-2026-89663 [nfsd: revoke copy-notify stateids before dropping their reference]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3b0c3595db99bb4bebd7c8aa8a36f3c50e411bb7 (7.3-rc1)
+CVE-2026-89662 [NFSD: Prevent lock owner use-after-free during client teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5e2fa29d223a9a1e6a948e40b109d09081d1decd (7.3-rc1)
+CVE-2026-89661 [NFSD: Prevent post-shutdown use-after-free in unlock_filesystem]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/292d915d3ba6fd15eeb88351fa10581683073109 (7.3-rc1)
+CVE-2026-89660 [NFSD: Prevent client use-after-free during admin state revocation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e270e5a0778e5bff852c8862ce9576ce70359393 (7.3-rc1)
+CVE-2026-89659 [NFSD: Prevent client use-after-free during delegation revoke]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4683ca76b3b7e5808338491c6eb3c20e6b4894d5 (7.3-rc1)
+CVE-2026-89658 [NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55 (7.3-rc1)
+CVE-2026-89657 [libceph: validate OSD extent maps before cursor advance]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9ec08b7499a62c6d4afa93d36ab47a43fcad57d1 (7.3-rc1)
+CVE-2026-89656 [libceph: reject buckets with mismatched CRUSH ids]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3cde4a8302301679937474a5f7a851394cc1bd11 (7.3-rc1)
+CVE-2026-89655 [ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7af4c4f01305b0935adf6d4301b1ec407025485d (7.3-rc1)
+CVE-2026-89654 [ceph: fix UAF in check_new_map() on session freed during unlock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ee611a7509554c4ca1f54f6aefe592fb1df7ea70 (7.3-rc1)
+CVE-2026-89653 [ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/aedc9053d909508a5f56c3f49f885fc030df4730 (7.3-rc1)
+CVE-2026-89652 [ceph: bound copied dentry name length in NFS export get_name]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/eff8013c5a8916613c742ae5a2cc341cb605c0ae (7.3-rc1)
+CVE-2026-89651 [ceph: bound MDSCapAuth path and fs_name decode in handle_session()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/77933e22adfe813be2bd10be08d6e950103c3967 (7.3-rc1)
+CVE-2026-89650 [ceph: bound num_export_targets array for mds info v2/v3]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a3eb169ee297aa99670ba927c659990bd1e453f3 (7.3-rc1)
+CVE-2026-89649 [ceph: bound xattr value length in __build_xattrs()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/68d541754d6cd3bb98d1fd8314f57e5eb533557d (7.3-rc1)
+CVE-2026-89648 [ceph: cap delegated inode count in ceph_parse_deleg_inos()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4bd3158bd62466d57ed72a3f7bc5f205fedd6919 (7.3-rc1)
+CVE-2026-89647 [ceph: do not repeat ceph_trim_dentries() if no progress possible]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e7d7aa7b730178278109c41fa1b17b06873065d5 (7.3-rc1)
+CVE-2026-89646 [ceph: fix leaked inode reference on writeback abort at umount]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c25aee9c630fb86f98d79eccb75765067079b972 (7.3-rc1)
+CVE-2026-89645 [btrfs: drop recovered reloc root refs on recovery failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6d8ba4572922e336f0b59a80751b018e1e135164 (7.3-rc1)
+CVE-2026-89644 [btrfs: fix extent map leak in NOCOW direct I/O write]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3f950867c307c5413d628a153ac44915bd117ffd (7.3-rc1)
+CVE-2026-89643 [audit: avoid dropping live tree ref on fsnotify rule autoremove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/783f0f0974c156aca630f4ffff248671082a098d (7.3-rc1)
+CVE-2026-89642 [cifs: call pagecache_isize_extended() in cifs_setsize() when extending]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c510edb9734af1c274d18f4f31a471a166bbc7e8 (7.3-rc1)
+CVE-2026-89641 [cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b96db32fed8dfb2478d7c208f89bf383beed1535 (7.3-rc1)
+CVE-2026-89640 [cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6c322f5cf7476ded7a9a20f7be72462065a03c68 (7.3-rc1)
+CVE-2026-89639 [cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/364b183230586a62660a7280c1eb20138338eeb5 (7.3-rc1)
+CVE-2026-89638 [smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b8e5dc4f95e5484159b343903f302eb6d783f2e6 (7.3-rc1)
+CVE-2026-89637 [smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/730d0bb19507b9e19c2fe5343109ac618e2fbce5 (7.3-rc1)
+CVE-2026-89636 [smb: client: clear ce->tgthint in free_tgts()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b1b741cf8e7ce1b91d937e23decd3d3358748700 (7.3-rc1)
+CVE-2026-89634 [smb: client: fix ALIGN() overflow in symlink_data() error context loop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/62656b024efc21c3230eade1a847f25871c3d2bb (7.3-rc1)
+CVE-2026-89633 [smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6343c1da561962688f203362d80d6a3bfa39fa1b (7.3-rc1)
+CVE-2026-89632 [smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/
+CVE-2026-89631 [smb: client: reject a tree connect response whose byte count is too small]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/65deb18359341141d37dc86fc7853511be3c87a7 (7.3-rc1)
+CVE-2026-89630 [smb: client: restore the data_offset bound in is_valid_oplock_break()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ba22f575de9deeae4ae0859ca4315a7698226237 (7.3-rc1)
+CVE-2026-89629 [HID: corsair-void: Check size of status and firmware events before reading them]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/08d8814521885e67b1bdf6a3036ee264e3e58377 (7.3-rc1)
+CVE-2026-89628 [HID: picolcd: clamp eeprom debugfs read to bytes actually received]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e9c667395ac1f8024f623250b32bae4c7af9caa0 (7.3-rc1)
+CVE-2026-89627 [HID: roccat: free buffered reports when destroying device]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bbff0ccbff360a5498075525005f6a913239a3d7 (7.3-rc1)
+CVE-2026-89626 [HID: sensor: custom: Fix field sysfs group cleanup on failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3789d0802ddb4b3be04062caf4bfadd23496e9a7 (7.3-rc1)
+CVE-2026-89625 [HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a26705bd2e2728833e7a538ce91e58a5eeff496a (7.3-rc1)
+CVE-2026-89624 [HID: universal-pidff: stop the device when force-feedback init fails]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ce08c5555cabcd444d8b77fa69a7cb68bb05f611 (7.3-rc1)
+CVE-2026-89623 [HID: mcp2221: stop device IO before hid_hw_stop]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/
+CVE-2026-89622 [HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/db2333f88729c8aae062cb171ed058725ff5c901 (7.3-rc1)
+CVE-2026-89621 [HID: mcp2221: validate report size in mcp2221_raw_event()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2c9a6998c19503626c57a2267bf279e204113079 (7.3-rc1)
+CVE-2026-89620 [HID: intel-thc-hid: intel-quickspi: validate report size before copy]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a59cf84441f9a17323c89452cec2bf16724c48a9 (7.3-rc1)
+CVE-2026-89619 [HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/035ec4a71cb8020a927c123bbe75c2f88d614986 (7.3-rc1)
+CVE-2026-89618 [eventfs: Initialize ei->children and ei->list in init_ei()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1704aaaf5d22bc765c168402350d191e24e245bc (7.3-rc1)
+CVE-2026-89617 [fs/ntfs3: validate dirty page table on log replay]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/006cb7713dec10368e699abc4367e5faa334c9a5 (7.3-rc1)
+CVE-2026-89616 [fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/35d1ea92c7d946e2ebdbe36cdb2c969c8704bebd (7.3-rc1)
+CVE-2026-89615 [fs/ntfs3: bound page_lcns[] index by the log record]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6f7b9dbdc1b7520206abce0049bdd143eb536e75 (7.3-rc1)
+CVE-2026-89614 [ntfs: bound the free-cluster bitmap scan to the volume]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/19cac7902a8ab748e15f98ddaafcf5f8882be21d (7.3-rc1)
+CVE-2026-89613 [ntfs: reject invalid empty mapping pairs]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/766062a82e1ce4087c7dc077224144dfd34b3661 (7.3-rc1)
+CVE-2026-89612 [ntfs: reject invalid MFT LCNs from boot sector]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cc9d09fef78410bcd37ac05168cbd5f6dd75d3d2 (7.3-rc1)
+CVE-2026-89611 [ntfs: validate non-resident attribute offsets]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a83e82b0ec3ae523028e24813f23f18b43e8fc1c (7.3-rc1)
+CVE-2026-89610 [ntfs: verify run length exceeding volume boundary]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fea9e4488f384c0ef1c0e3d96b565127c1b98447 (7.3-rc1)
+CVE-2026-89609 [ecryptfs: hold msg ctx list lock when cleaning daemon queue]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/779972513c2fa8c7938e54976f686091dafff22f (7.3-rc1)
+CVE-2026-89608 [ecryptfs: pass packet set buffer size to parser]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2602b79c5b3e2f6fce12e38a670f8e3fda4e46a2 (7.3-rc1)
+CVE-2026-89607 [ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5babe9c177c364521e3e682b949c5a8c47f4a441 (7.3-rc1)
+CVE-2026-89606 [ecryptfs: reject too-small tag 70 packets]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e97bbe1b2bd82ec2ae37ad2e4965b4d3e78bbf7f (7.3-rc1)
+CVE-2026-89605 [ecryptfs: release message context on send failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/219644a3ad5518217b2d62cad6d2c36a2308c949 (7.3-rc1)
+CVE-2026-89604 [efivarfs: Rate limit statfs() handler]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b2326338dc683e8c1067c0cbf7a47986c4190902 (7.3-rc1)
+CVE-2026-89603 [entry: Fix seccomp bypass after ptrace with TSYNC]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4a3591287fb7f808e209b4974ed337f609a2006b (7.3-rc1)
+CVE-2026-89602 [erofs: skip sufficiently large global buffers when resizing]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a7d097cf01301c5da37927c8f26123d006f0fd8a (7.3-rc1)
+CVE-2026-89601 [ext2: Fix lost inode updates for IS_SYNC inodes]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/356984d1a5c32e94810cbb6c8dc7d8ff2d4d919a (7.3-rc1)
+CVE-2026-89600 [fanotify: fix use-after-free of file range info]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d7f1cf5be33ef0175a4e8ed8687aeb98fb00a851 (7.3-rc1)
+CVE-2026-89599 [fbdev: omapfb: panel-dsi-cm: initialize lock before registering display]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f8e43fe0f22b7137ce456e6fe3581d3098174f74 (7.3-rc1)
+CVE-2026-89598 [fbdev: ssd1307fb: defer I2C transfers from damage callbacks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9ad709afdfa32509ed64938a6d9cd00db3cd54c2 (7.3-rc1)
+CVE-2026-89597 [fbdev: uvesafb: unregister connector callback on init failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/de8db23aa7c337e606fca9faf48b3ba72968597a (7.3-rc1)
+CVE-2026-89596 [forcedeth: fix off-by-one when saving/restoring non-PCI config space]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9393f1d656a79693e0c123ff7bc7c5c0f708046d (7.3-rc1)
+CVE-2026-89595 [fsnotify: Fix stale object mask after concurrent mark updates]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e422777fdd4746de1109575c51e65038d4c5c1be (7.3-rc1)
+CVE-2026-89594 [hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e81250ec6b69248b00d38c523dc6a13efaf38aab (7.3-rc1)
+CVE-2026-89593 [hugetlb: only adjust reservation during unmapping if mapcount is 0]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5120b1e048d48596ffaec1a8412012a91adba73b (7.3-rc1)
+CVE-2026-89592 [accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a85402bff218f2b8f0d806e46c16c2f3d49cdda7 (7.3-rc1)
+CVE-2026-89591 [accel/rocket: initialize job domain before cleanup paths]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/70e6a33d68a9b03335c5426332666e52d07f45d6 (7.3-rc1)
+CVE-2026-89590 [accel/rocket: Fix error path handling in rocket_job_run()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9b2dedadf6a91ac3fc9fae268bb556a041222711 (7.3-rc1)
+CVE-2026-89589 [acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6625ca499c3131ef63be3215f8f942d7a097ea3a (7.3-rc1)
+CVE-2026-89588 [ACPI: APEI: GHES: fix ARM section length accounting after header]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/903308ea40adf0577d82eab69882faf8836326ce (7.3-rc1)
+CVE-2026-89587 [ACPI: pfr_update: fix stack buffer overflow in query_capability()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ced45be0073a8a31b30b4a7f68cd3a15734515de (7.3-rc1)
+CVE-2026-89586 [ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/79cce911e623c0baa0fde307ce3a434e084b881a (7.3-rc1)
+CVE-2026-89585 [auxdisplay: charlcd: cancel backlight work on registration failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e3e3bf40916c1e810df03958cfa7ba6883cdce79 (7.3-rc1)
+CVE-2026-89584 [block: validate user space vectors during extraction]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/14b007e178811db72fbb1ebb3535160db6ec1e6a (7.3-rc1)
+CVE-2026-89583 [Bluetooth: eir: Fix OOB read in eir_get_service_data()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4beb198bc59b242404a47c21990bc84165052c8a (7.3-rc1)
+CVE-2026-89582 [bnx2x: fix double free in bnx2x_init_firmware() error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d2796ffe38cb4155afe0eab23636295b096c27a5 (7.3-rc1)
+CVE-2026-89581 [bpf, x86: Fix per-CPU address resolution into an extended register]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5bbbce02e500d47d8e259a45be5a7be9741d0533 (7.3-rc1)
+CVE-2026-89580 [bpf: Disable preemption in __bpf_get_stack]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b1a47b2708d4e95dbd23aee2ec83752190897b3f (7.3-rc1)
+CVE-2026-89579 [bpf: Harden bloom filter sizing and indexing on 32-bit kernels]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/11c1e836710dcba03e50454a4eedfdbaf8d3050e (7.3-rc1)
+CVE-2026-89578 [dm-io: clone the source bio instead of copying its biovec]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/62dc37a819a5a5de5cba989ad9e96ee214b9253e (7.3-rc1)
+CVE-2026-89577 [dm-io: report non-retryable errors separatedly]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/47a5e62f39875f371bded6e34ffb9cf15ccd813d (7.3-rc1)
+CVE-2026-89576 [dm-era: fix shadowed superblock leak on take-snap failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/39c5aa3bd8ec3912d2cd0b3fe092642b0d2b0713 (7.3-rc1)
+CVE-2026-89575 [dm raid1: reserve space for NUL-terminator in build_constructor_string()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/73c37fe54cd056d07461b142ab0b8b81e1ef6ad8 (7.3-rc1)
+CVE-2026-89574 [dm array: validate array block headers on read]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2965787723084835b18dfe993cd450ebf5bd4540 (7.3-rc1)
+CVE-2026-89573 [dm array: reject an array block whose value size is not the caller's]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4538a287bdf5d0f9a379c678e5262b9f5783f547 (7.3-rc1)
+CVE-2026-89572 [cpufreq: apple-soc: Fix OPP table cleanup]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d87cb889dc7ab1f2deecadf2a5e9023184bd7900 (7.3-rc1)
+CVE-2026-89571 [cxl/features: bound fwctl command payload to the input buffer]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f687394af983df5660b6afae7e0d06969f3af206 (7.3-rc1)
+CVE-2026-89570 [cxl/mce: Make the MCE notifier per-region]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/775d0f4558f4cec0ee0c8966595d1add1791f36e (7.3-rc1)
+CVE-2026-89569 [Bluetooth: RFCOMM: serialize security confirmation handling]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/759c185d0bbdb131357408f50b8735e04ed3caff (7.3-rc1)
+CVE-2026-89568 [kho: fix size calculation in kho_preserved_memory_reserve()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3a0b8fa2eb36afc88b62a95f33f0c77c71fa5ded (7.3-rc1)
+CVE-2026-89567 [jbd2: bound shrinker scans by examined checkpoint buffers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/15cb16496446b94e67f7abcb049b8e2c75cd3d02 (7.3-rc1)
+CVE-2026-89566 [jbd2: check need_resched() when skipping busy checkpoint buffers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f213e12ff5c9590b1034ae8da0e6d09665c772d0 (7.3-rc1)
+CVE-2026-89565 [ipip: fix skb leak in collect_md mode when metadata_dst allocation fails]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6776efe4a52f289a3fc18f8adf19b035a7d8e1bb (7.3-rc1)
+CVE-2026-89564 [ip: orphan prefetched skbs before multicast forwarding]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e36ce6e78fe3fc3c071a26750783b7ba081ce10d (7.3-rc1)
+CVE-2026-89563 [ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/87f21b59ddc618eff9670c174842964ad65fdade (7.3-rc1)
+CVE-2026-89562 [ip6_gre: fix hardware header length for NBMA tunnels]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/505b6d296c486ef7d1274f279d4c43a172f63224 (7.3-rc1)
+CVE-2026-89561 [ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f826df95332c07380206dbd54178b6eefb311aba (7.3-rc1)
+CVE-2026-89560 [landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/672fa082d48b21e1fb62cdb184fee41513e53421 (7.3-rc1)
+CVE-2026-89559 [libnvdimm/labels: Prevent integer overflow in __nd_label_validate()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/037770686126155eafc44501312989e2837b9659 (7.3-rc1)
+CVE-2026-89558 [md/raid10: fix still_degraded being inverted in raid10_sync_request()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/47f1441b281decde6954a2fa82b4131637d685ac (7.3-rc1)
+CVE-2026-89557 [md: do overflow check for sb->bblog_shift in super_1_load()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/35d522bd32462afcf1981dab6da8a9256c26c1e0 (7.3-rc1)
+CVE-2026-89556 [module: validate string table section types]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9a5ff45689329835f874cefe5174e577d141d423 (7.3-rc1)
+CVE-2026-89555 [mpls: reload header after pskb_may_pull()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/29e63b8d9fc150cc191b1c6eb7e16e1247e1b650 (7.3-rc1)
+CVE-2026-89554 [mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b878dfdd12d7a5b8722a78d35e313506140ca3d9 (7.3-rc1)
+CVE-2026-89553 [nouveau/gem: reserve the bo in the info ioctl around the vma lookup]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5e17160d41d92823f3379c1982e1369680c5ce4d (7.3-rc1)
+CVE-2026-89552 [params: fix charp corruption on allocation failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3dfaae04243cde460d82dfc2a7dd0bb6664d20ae (7.3-rc1)
+CVE-2026-89551 [SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3f491306dcb673ff5e78e1044ba450c58978774e (7.3-rc1)
+CVE-2026-89550 [SUNRPC: svcauth_gss: enforce krb5 token minimum length]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a919c5c88769cf8fb3ec071e6078d830bf512489 (7.3-rc1)
+CVE-2026-89549 [sunrpc: route to a populated pool in svc_pool_for_cpu()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f6310491c4cdb88af73aa551ec9df1f10a90c709 (7.3-rc1)
+CVE-2026-89548 [SUNRPC: always drain cache_cleaner before destroying a cache_detail]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f42d0fda0c67695db6bc704b04b7c10240805377 (7.3-rc1)
+CVE-2026-89547 [SUNRPC: Check svc pool percpu counter allocation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/43e11e164704dde975c9edb370de1a06bec67270 (7.3-rc1)
+CVE-2026-89546 [SUNRPC: close backchannel before destroying callback service]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3674f780f47d2906b5a0f7199b66973067bdfeca (7.3-rc1)
+CVE-2026-89545 [sunrpc: defer rq_argp and rq_resp free until after RCU grace period]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c479bde671cbe2f9e152834a8b0eb7c3c295bbaf (7.3-rc1)
+CVE-2026-89544 [SUNRPC: fix gssx_dec_option_array error path bugs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5e9a94539b1ec17a89177d952badfd0d844d694a (7.3-rc1)
+CVE-2026-89543 [sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/932a8cf6abb2b2f8677b79153a823108d8861fe2 (7.3-rc1)
+CVE-2026-89542 [SUNRPC: harden gss_krb5_unwrap_v2 against short tokens]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6959297aaa9572783d620a226d73c3fb94494888 (7.3-rc1)
+CVE-2026-89541 [SUNRPC: harden gss_unwrap_resp_priv length checks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/87831b92112c81db251d46756d65daa4f91af6a2 (7.3-rc1)
+CVE-2026-89540 [sunrpc: init gssp_lock before publishing proc entry]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5ce1ed6159731a41fdd0b03eedbed4e147036a5a (7.3-rc1)
+CVE-2026-89539 [SUNRPC: reject duplicate CREDS_VALUE options]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2e4ce62385c1b8a887c5370af058ac7b52a8eaf9 (7.3-rc1)
+CVE-2026-89538 [SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ad484748eec0a66eac0f13ab53b3fbedb7333c91 (7.3-rc1)
+CVE-2026-89537 [SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b94f6719dcd9f7a609bc5f459f85795900e77d25 (7.3-rc1)
+CVE-2026-89536 [SUNRPC: wait for in-flight client TLS handshake callback]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a89dd597458848b463d284b15e42a8078beeb046 (7.3-rc1)
+CVE-2026-89535 [svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4488e912973773d64368828acf3b8e39d93650ae (7.3-rc1)
+CVE-2026-89534 [svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/01500306e1d50de7ca7a2cdcdfa28ac0523eb747 (7.3-rc1)
+CVE-2026-89533 [svcrdma: Fix offset arithmetic in read_chunk_range]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4a44c140cc2f3643a39e258bb0c0ab9d0f494f5e (7.3-rc1)
+CVE-2026-89532 [svcrdma: Fix pcl_for_each_segment for empty chunks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b7713a784c59515d0aba558c8f5df6a0164dd3a9 (7.3-rc1)
+CVE-2026-89531 [svcrdma: Reject connection when transport allocation fails]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0944462247dcb7de7622cdaaadf5f05c52707dab (7.3-rc1)
+CVE-2026-89530 [svcrdma: Reject inline replies that overflow the pull-up buffer]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0fbe20dfe74b783d255bf389a6ea77aa25dc7860 (7.3-rc1)
+CVE-2026-89529 [svcrdma: Reject oversized Read segments at decode time]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/af6f0e06bed818ee7fc8b869915964410020a1c5 (7.3-rc1)
+CVE-2026-89528 [svcrdma: Reject Read lists that exceed the page budget]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0ca487abb3bdf581851664b5db21f364caf57682 (7.3-rc1)
+CVE-2026-89527 [svcrdma: Use svc_xprt_put to free listener on create failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e346ef7bcb137f50c49f969330ab7dcf64ea1654 (7.3-rc1)
+CVE-2026-89526 [svcrdma: Validate Read chunk positions before reconstruction]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b (7.3-rc1)
+CVE-2026-89525 [udf: reject VAT indexes equal to the entry count]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cac0cb07f29ccfb373fd4a36c81e908ef3ce608c (7.3-rc1)
+CVE-2026-89524 [wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3bbd05723d15dd06f0560bcd94fbf9a91b5f5613 (7.3-rc1)
+CVE-2026-89523 [wifi: mt76: mt7925: cancel pending mlo_pm_work]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2889e84282dda147f10b10d94cf0efd90a349c53 (7.3-rc1)
+CVE-2026-89522 [media: staging/ipu7: fix async notifier UAF on probe error path]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d7f48aa7d60c65d3e6d5312c27f17d5525a245fb (7.3-rc1)
+CVE-2026-89521 [sched/core: Handle pick_task() releasing the rq lock]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c10b216a072ff5c57bc880a05f87eb519aecc529 (7.3-rc1)
+CVE-2026-89520 [sched/core: Make core-sched flips wait for in-flight selections]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f3629c63a4af3e491381780bc6c123cb498c4c40 (7.3-rc1)
+CVE-2026-89519 [sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ffaab58d217581cb75353168f8812a16e10463fc (7.3-rc1)
+CVE-2026-89518 [sched_ext: Fix this_rq() assumptions in dispatch kfuncs]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3dd52416e44a70bc993adb96d2e0d71b9ea21359 (7.3-rc1)
+CVE-2026-89517 [sched_ext: Fix rq->core_pick corruption under core scheduling]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d954004205c1a1d3f59ce8482b559266c15600fa (7.3-rc1)
+CVE-2026-89516 [sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8d8dd8ae89eaa78b37fc85528e926029f5facbdf (7.3-rc1)
+CVE-2026-89515 [scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/626147717bea776b61ed3631d2c26283760c4cc4 (7.3-rc1)
+CVE-2026-89514 [scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9639c6324524ea3f934908bd51f02430000954ab (7.3-rc1)
+CVE-2026-89513 [RISC-V: KVM: Fix PMU event info array size overflow]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/735bc20c24187ca419c9d5e63860a54b91be34bd (7.3-rc1)
+CVE-2026-89512 [remoteproc: scp: Fix device reference leak on failed lookup]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/22f9efb3ae07f966a1901d929d16df1388cce65c (7.3-rc1)
+CVE-2026-89511 [qede: Fix NULL pointer dereference in TPA fragment processing]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/06aa3d26327f24edd039ff249672fdf6f2ba5695 (7.3-rc1)
+CVE-2026-89510 [RDMA/cxgb4: Cancel reg_work before freeing device on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a7100601aa1a39f799a566acce10db20eaf4b7f2 (7.3-rc1)
+CVE-2026-89509 [RDMA/ionic: Embed counter driver data in rdma_counter allocation]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cf3ebd89e754015625fee90aa938f6bc79a2c974 (7.3-rc1)
+CVE-2026-89508 [RDMA/ucma: Lock the handler in ucma_set_ib_path()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ecbe7d36dc2de07e5dfbb4a8ff5b315ab43de820 (7.3-rc1)
+CVE-2026-89507 [RDMA/ucma: Lock the handler in ucma_write_cm_event()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f4cc21c6a8e9d392871477f9fd98d68e5ad80272 (7.3-rc1)
+CVE-2026-89506 [RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/011199f46f44a9fd93a9e5ab5d7fd1328d80e9bf (7.3-rc1)
+CVE-2026-89505 [RDMA/uverbs: Guard legacy bundles without method_elm]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/60a42d510113f46de47e86a84bf5758597644487 (7.3-rc1)
+CVE-2026-89504 [regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f9324d670ae0b88cbfb0aa48fcaefa5baeb8da4c (7.3-rc1)
+CVE-2026-89503 [ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e743527c5bfdceda1095bc0a9e596e2aebb6a9c3 (7.3-rc1)
+CVE-2026-89502 [ring-buffer: Free cpu_buffer::free_page with subbuf_order]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/234b1a72e9706fe20c08c96f4374ec8e83b934cb (7.3-rc1)
+CVE-2026-89501 [ring-buffer: Hold cpu_buffer::lock when resizing a subbuf]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/24974bd0da1b47fd56c975533ead50abf754e74d (7.3-rc1)
+CVE-2026-89500 [ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7a1fb95de5404134f8758c1295ce88986bdf117c (7.3-rc1)
+CVE-2026-89499 [ring-buffer: Stop remote reader update when page swap fails]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5eab74874d11160725c42ab676ba97a797a362eb (7.3-rc1)
+CVE-2026-89498 [orangefs: fix double-free of trailer_buf on readdir copy failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f574296be7f46eb60beca851240b526df232f480 (7.3-rc1)
+CVE-2026-89497 [orangefs: skip leading spaces before parsing client debug masks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d410cd5303ec59c7cf23dd61423752ce8e9ecb59 (7.3-rc1)
+CVE-2026-89496 [ocfs2: always run deallocs on copy-on-write completion]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/82ea9d4fc05fb7a387db547c6a7c0aa6a3719616 (7.3-rc1)
+CVE-2026-89495 [ocfs2: bound namelen in dlm_migrate_request_handler]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ea5b5609305a8437bc955a0834a530c12246d78f (7.3-rc1)
+CVE-2026-89494 [ocfs2: validate lengths in dlm_mig_lockres_handler]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b54e03d9b3697d25f4a0063cf717d459c5e3ad94 (7.3-rc1)
+CVE-2026-89493 [ocfs2: validate rl_used against rl_count in refcount block validator]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4ca62df6bc0708947b48da3f6a712ecb8e73929c (7.3-rc1)
+CVE-2026-89492 [ocfs2: validate directory-index entry counts when reading metadata]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bc70726ddad53c7e9a9a85915bf2415b0d4f42f9 (7.3-rc1)
+CVE-2026-89491 [ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/af09df89db9a68a1d76df0f75667998135bc8d65 (7.3-rc1)
+CVE-2026-89490 [ocfs2: fix readdir position truncation on 32-bit kernels]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a63308ab426f3a3c7e33b02c150ea59054620261 (7.3-rc1)
+CVE-2026-89489 [openrisc: fix arbitrary kernel memory access via or1k_atomic syscall]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/78004e9a87f240df03e2f73120d291763c32e0a7 (7.3-rc1)
+CVE-2026-89488 [openvswitch: Fix CT limit teardown use-after-free]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/403f96c32c9e24600093d7d0c61c17daeedca957 (7.3-rc1)
+CVE-2026-89487 [openvswitch: only skb_tx_error() a packet we are about to drop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0dbc2398fca3bb33eda963849f865ddb1b3aa05e (7.3-rc1)
+CVE-2026-89486 [ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/05ec76cfbce653e07cec19b9b8b20e33449d5d87 (7.3-rc1)
+CVE-2026-89485 [lockd: pin next file across nlm_inspect_file lock-drop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/526c49cff3f72c3ec74752016380c7567040581b (7.3-rc1)
+CVE-2026-89484 [lockd: fix NULL dereference on lockowner allocation failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4c7fc129db061c7daab841c4f3c342d894832362 (7.3-rc1)
+CVE-2026-89483 [nvme: zero the discard fallback page]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bededeaaeff404978a5a8e2a605a6c3017cddd3e (7.3-rc1)
+CVE-2026-89482 [nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3a4aa9e6ad3e35f8e24d5eaf38ee4d437075fb36 (7.3-rc1)
+CVE-2026-89481 [nvme-tcp: fix host memory disclosure on R2T for a read command]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6efbc52237facda35d2d874fe1765bb4839275d8 (7.3-rc1)
+CVE-2026-89480 [nvme-tcp: reject a read that transferred too few bytes]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7fa3f73f6c8ddc5f0425b50fb2a626a782ef7d12 (7.3-rc1)
+CVE-2026-89479 [sctp: stop processing a packet once its association is deleted]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/47e15a8d12e366d0d261bcbc394394f44418938d (7.3-rc1)
+CVE-2026-89478 [sctp: drop a chunk if its transport was removed]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/03a9d10ecf71f54b2af8020935f2033d4a132be5 (7.3-rc1)
+CVE-2026-89477 [sctp: fix NULL deref on untransmitted RECONF completion]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2db9bfa3e27bdea15e05ea70b56bad3d21e570ec (7.3-rc1)
+CVE-2026-89476 [sctp: fix stream->outcnt underflow on duplicate RECONF responses]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3faf13aff243ca9f78d08b1a2956ef5a6fc77b6e (7.3-rc1)
+CVE-2026-89475 [power: supply: bq24257: fix use-after-free on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9d34c9d660c3d0931d2cc749c46c47cf31f96e48 (7.3-rc1)
+CVE-2026-89474 [power: supply: bq256xx: drain usb_work before freeing the charger]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2dd6cd823777bea6d9a880a12a92a73ec76aee0b (7.3-rc1)
+CVE-2026-89473 [power: supply: bq25890: Fix power_supply reference leak]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/863c32a83e4235eb0cbf6106f2b124e645302156 (7.3-rc1)
+CVE-2026-89472 [power: supply: charger-manager: register regulators before exposing sysfs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c57cb36f76eb7ced45f57af1a890d8f3a6d76342 (7.3-rc1)
+CVE-2026-89471 [power: supply: cros_usbpd-charger: bound the EC-reported port count]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/48355ce49359740f52e94d3623f6fc557ce341f0 (7.3-rc1)
+CVE-2026-89470 [power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/657cd3a42e937276262c0a8ae6b01a87004309de (7.3-rc1)
+CVE-2026-89469 [power: supply: lp8727: fix use-after-free in lp8727_release_irq()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ceb6ac43b0f591722401922ceb958ce2616935e0 (7.3-rc1)
+CVE-2026-89468 [power: supply: lp8788-charger: fix use-after-free on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/831c29a12d560f8a3225f43050b3fbb5dfd79c66 (7.3-rc1)
+CVE-2026-89467 [power: supply: qcom_battmgr: fix use-after-free]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4e40befedfc8ed86f44e1f81df92d13c149c9f8d (7.3-rc1)
+CVE-2026-89466 [power: supply: qcom_battmgr: terminate the strings from firmware]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ab1112df8f4ffa88cb024dd370c432ced80f77d8 (7.3-rc1)
+CVE-2026-89465 [power: supply: rt9455: quiesce delayed work before teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3e7a1ebc32fad5a558254a478efd401c17a24381 (7.3-rc1)
+CVE-2026-89464 [power: supply: twl4030_charger: cancel workers via devm]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6eba34732524067da2aad5ddfdfbc641ded10e9e (7.3-rc1)
+CVE-2026-89463 [power: supply: ucs1002: fix use-after-free on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/609af0ceeaefdfa42cd01dd060b20f2e41f9a232 (7.3-rc1)
+CVE-2026-89462 [power: supply: max17040: propagate register read errors]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/659cc3d8d5ef246263873fce72c8cadeeed073cc (7.3-rc1)
+CVE-2026-89461 [power: supply: max17040: synchronize work cancellation on suspend]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/86a3a8a926aa5969c329d1df2d3259f189961bbc (7.3-rc1)
+CVE-2026-89460 [s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/337bd95507a16063687cfc286ea90de5cca48c37 (7.3-rc1)
+CVE-2026-89458 [s390/dasd: Do not complete a failed ESE read as successful]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cddb447c62466f3076938ce120028d7b591f9f37 (7.3-rc1)
+CVE-2026-89457 [s390/dasd: Guard sysfs discipline callbacks against unallocated private data]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2a1780f9fc2493bd34c418a0be6fc58943afcecf (7.3-rc1)
+CVE-2026-89456 [s390/dasd: Propagate partial completion length across ERP recovery]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6fb5ba2e7e43173a3761e46f091070a8185efa14 (7.3-rc1)
+CVE-2026-89455 [PCI: plda: Fix use-after-free of event IRQs during teardown]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/26b73bae01d6eb81a4a38f36101812f20b2639de (7.3-rc1)
+CVE-2026-89454 [PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/19a30bbb6477bfd7e3109b7a2943e6597ee9de37 (7.3-rc1)
+CVE-2026-89453 [iommu/amd: Put PCI device after handling PPR faults]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/af3b69b16383fbc8fe5f61b5b0150d2e41ede71f (7.3-rc1)
+CVE-2026-89452 [iommu/msm: Unwind probe state on registration failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/535a200220ca2c83bc8bf54bd2cbe045d6ee70c4 (7.3-rc1)
+CVE-2026-89451 [iommu/sva: Set handle->dev before the SVA handle is visible]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/530f8f9c3546cb3ebee1b135375aaee08a073ebb (7.3-rc1)
+CVE-2026-89450 [iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4379610c79bd88ddbea10e7f6c21e16d4b338c6b (7.3-rc1)
+CVE-2026-89449 [iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b7b0b3851474883d4aba6ed72da87141204b23e5 (7.3-rc1)
+CVE-2026-89448 [iommu/vt-d: Force requesting ACS when tboot is enabled]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/607432b2618b61df81134be0ef2562b8300c1216 (7.3-rc1)
+CVE-2026-89447 [iommufd: Avoid locking internal accesses during unmap]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0dbcdf4473a614adbd732d567c9b39ac0e040e0c (7.3-rc1)
+CVE-2026-89446 [iommufd: Release current IOAS on xa_store() failure]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4ac2ce123824d5f885c868fa1f9f4d463141a2ba (7.3-rc1)
+CVE-2026-89445 [iommufd: Fix UAF in selftest IOPF reporting]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8c07df7cdfcf52f1ff276c588612aabc6c6b8399 (7.3-rc1)
+CVE-2026-89444 [platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/83c80495e45eddf64c6525fb582d8db68f256b71 (7.3-rc1)
+CVE-2026-89443 [platform/x86: ISST: Validate level in perf mask ioctls]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/80e0d353c86a9a168ad6d213f494796294381538 (7.3-rc1)
+CVE-2026-89442 [platform/x86: ISST: Validate socket ID in clos_assoc ioctl]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a89f07db0cb95c54dac4a8406c79a04e44a73c3c (7.3-rc1)
+CVE-2026-89441 [mmc: via-sdmmc: cancel card-detect work on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5 (7.3-rc1)
+CVE-2026-89440 [mmc: via-sdmmc: stop card-detect handling on probe failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/088eaa92fcebaa6b957ccf9635afdf39643a577d (7.3-rc1)
+CVE-2026-89439 [platform/x86: ISST: Add a NULL check for sst_inst[]]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3de2776e9d7073765c10c2326c2bda5926811ea6 (7.3-rc1)
+CVE-2026-89438 [platform/x86: ISST: Validate logical CPU id and clos id]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/124e2dbabe460c2a6e7440f4ad8af560131295c9 (7.3-rc1)
+CVE-2026-89437 [platform/x86: int1092: Fix potential memory leak in sar_probe()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/30c906cff490c3601ee9ff110fe8115fabe75fd4 (7.3-rc1)
+CVE-2026-81018 [platform/x86: think-lmi: Free system certificate signatures]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/abca989604f60fe29d7170431f819e28ec7d868a (7.3-rc1)
+CVE-2026-81017 [platform/chrome: sensorhub: Bound the EC-reported sensor number]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/833740a2333c2e4db4e02e3d0ffba04e8718a5f3 (7.3-rc1)
+CVE-2026-81016 [platform/x86/amd/pmc: Propagate SMU errors and validate S2D address]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0225c1d637687b03726f00ac65b6def843d2c464 (7.3-rc1)
+CVE-2026-81015 [platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/76f650a76d6a36a4bee79d94db90a0e935a95477 (7.3-rc1)
+CVE-2026-81014 [platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a7508c7959ff8d037327d377ed21a9c0eabe4674 (7.3-rc1)
+CVE-2026-81013 [platform/x86: hp-bioscfg: fix heap OOB read on empty password write]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b2ec354f905c14e3270e8ec3ab50f7d8ad73bab (7.3-rc1)
+CVE-2026-81012 [platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc03f05e419f3460342fb7564884f244622634b6 (7.3-rc1)
+CVE-2026-81011 [platform/x86: hp-bioscfg: pass validated element count to package parsers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e0ddfd77c0c320b7d12b6c9169303b140b798775 (7.3-rc1)
+CVE-2026-81010 [io_uring/waitid: honor task_work cancellation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/14572de82e5022899e5856008bc9cac97004a88c (7.3-rc1)
+CVE-2026-81009 [io_uring/query: cap user size passed to copy_struct_to_user]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ba77efee1b95b4ad7559b1cdbe7cd7fa36dca95b (7.3-rc1)
+CVE-2026-81008 [interconnect: Fix use after free in icc_get() and of_icc_get_by_index()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/25c7e242aca084fdc1098248194032317dca625d (7.3-rc1)
+CVE-2026-81007 [ipmi: ipmb: validate write message length]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/53637506884dbd5c91a89b1a3547d99d80f8ed2c (7.3-rc1)
+CVE-2026-81006 [ipmi: Remove all sysfs files on registration failure]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b6c46ab0bdee90c238e96ea4a74972118c97900d (7.3-rc1)
+CVE-2026-81005 [ipmi: si: Fix NULL pointer dereference after failed registration]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6d920a75df9a83ab096b3cde7a643b656e4fdfeb (7.3-rc1)
+CVE-2026-81004 [ipmi:msghandler: Cancel work cleanly on an error]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ae84a2536577057e97f23f75a202e26d0e86cf01 (7.3-rc1)
+CVE-2026-81003 [net/iucv: filter frames in afiucv_hs_rcv() by ingress device]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/80230a18c164a4b5bbc048fe2768b219ac17bc5a (7.3-rc1)
+CVE-2026-81002 [xdp: fix zero-copy frame layout]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/71283aaa6c65b3cec84caf1dc78560985737641f (7.3-rc1)
+CVE-2026-81001 [slip: fix use-after-free in sl_sync()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d (7.3-rc1)
+CVE-2026-81000 [net: tun: bound receive headroom]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/447c9303942c439a117d9b76ce6d6e2116b38ee7 (7.3-rc1)
+CVE-2026-80999 [net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fb58b6a696b30bcbfbe0cfc0a91b19c816a955fc (7.3-rc1)
+CVE-2026-80998 [net: bnxt: ring the doorbell when SW USO exits early]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4e15e89faac9f308baeb01f46c13a051814d2449 (7.3-rc1)
+CVE-2026-80997 [net: ipa: fix stalled modem TX queue after runtime resume]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3cbfd627ee720f3d2460d2cbe2fe9e4130240db6 (7.3-rc1)
+CVE-2026-80996 [net: l2tp: do not propagate multicast notification errors]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/af20e269f7459d2ce69887fdf2fad7caf986c865 (7.3-rc1)
+CVE-2026-80995 [net: mctp: hold a reference to the route device in mctp_route_lookup()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/408da1df18116c971c3392e21e50586688cd3fbf (7.3-rc1)
+CVE-2026-80994 [net: openvswitch: fix flow mask use-after-free on flow deletion]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4e30317ff67a2eb12b4d890d39f72fd7e7117d48 (7.3-rc1)
+CVE-2026-80993 [net: phylink: correctly validate returned PCS in phylink_inband_caps]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f2849b1fd059ec9b3281b771e6ac5aad9feee851 (7.3-rc1)
+CVE-2026-80992 [net: ravb: avoid dereferencing an invalid PTP clock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1f77af0aaf277413ff32f6ff8c2c4282bd64c897 (7.3-rc1)
+CVE-2026-80991 [net: ravb: serialize PTP clock teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1cb9663789c5b7a12fcd419fcca6d6254c398252 (7.3-rc1)
+CVE-2026-80990 [net: thunderbolt: Release the Rx HopID that was handed out on mismatch]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2f1463554d0561a2fead81e3888604e5c1125e29 (7.3-rc1)
+CVE-2026-80989 [net: thunderbolt: Mark the connection down when bringing it up fails]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3c8b26ebf525ba5960510f48c6e9936a79ebe76f (7.3-rc1)
+CVE-2026-80988 [NTB: ntb_transport: Fail TX enqueue when the QP link is down]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/873ce713fef5dde0939220f04f3484ec86a16fba (7.3-rc1)
+CVE-2026-80987 [NTB: ntb_transport: Reject oversized TX buffers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a4f2387db6f1cc2f03abba7f3a6807ad61e26ff7 (7.3-rc1)
+CVE-2026-80986 [net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2d1e7c5aaa3326e95e2058457f172ca99a9a4577 (7.3-rc1)
+CVE-2026-80985 [net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8d3c1ab82c11d4fadebf817a825fd221b3e197ea (7.3-rc1)
+CVE-2026-80984 [net/smc: do not dereference an unset send buffer on the SMC-D teardown path]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b395dd319cea422239cb45b998fb38d7e373af87 (7.3-rc1)
+CVE-2026-80983 [net/smc: fix socket refcount leak in smc_switch_conns()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/719296c4aa8213d4ac8002e77d5956d436bc98d0 (7.3-rc1)
+CVE-2026-80982 [net/smc: fix use-after-free in smc_rx_pipe_buf_release()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c924884743e948e25625b7fbf3ee2a9325a204a7 (7.3-rc1)
+CVE-2026-80981 [net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a42a459ef0e54cb0c4b3e43e21cb0e658e664f64 (7.3-rc1)
+CVE-2026-80980 [net/smc: stop killed, freed and out_of_sync sharing a byte]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/db51a8658c11a82432b64999519a269c3aabb447 (7.3-rc1)
+CVE-2026-80979 [net/smc: unregister the connection before draining the rx tasklet]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/36cdf5d48ca191dcd71c28cadbe0981b1d25318d (7.3-rc1)
+CVE-2026-80978 [net: cap advertised IP tunnel headroom]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6b222adeb9340306e2ff97127c76117abb9b3df8 (7.3-rc1)
+CVE-2026-80977 [net: skbuff: don't touch shared zerocopy state in skb_tx_error()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f66bdb1cc0fcd227a062378f8be0b5873aa5600a (7.3-rc1)
+CVE-2026-80976 [seg6: reset IP6CB after IPv6 decapsulation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f967455fb2a5a2079b9eb5823e9ccf359174bf9f (7.3-rc1)
+CVE-2026-80975 [mfd: qnap-mcu: keep the reply buffer alive past a command timeout]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/47504742cea7878ebd1bf1491bbed923df6b90b1 (7.3-rc1)
+CVE-2026-80974 [mfd: sm501: Fix potential memory leaks during remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/83feedd9d83c0c5199f98c72df0a6196b4aefb4d (7.3-rc1)
+CVE-2026-80973 [ALSA: 6fire: bound the MIDI event length from the device]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a478893b59e36cfe7d77a76b352f2db55502e879 (7.3-rc1)
+CVE-2026-80972 [ALSA: aloop: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/819b106a9fd2ef3fd8abf898b9a8e4524eca8f48 (7.3-rc1)
+CVE-2026-80971 [ALSA: bcd2000: clear the URB pointers on disconnect]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/459d3a64766f5ca2f1886daeaf24582831a5f5ab (7.3-rc1)
+CVE-2026-80970 [ALSA: FCP: do not copy out an uninitialised init response]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4335e387786479889e6db691fe06d345e52ea536 (7.3-rc1)
+CVE-2026-80969 [ALSA: mpu401: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd (7.3-rc1)
+CVE-2026-80968 [ALSA: mts64: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8 (7.3-rc1)
+CVE-2026-80967 [ALSA: pcxhr: initialize mutexes before requesting threaded IRQ]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6c97817e20598e5473094e0e38d1f51f1cf4dfff (7.3-rc1)
+CVE-2026-80966 [ALSA: portman2x4: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3690ef20469d5959378260e2752f2314a2572913 (7.3-rc1)
+CVE-2026-80965 [ALSA: serial-u16550: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e0fb960b227fcdebe22e4f26c9486d60943c0424 (7.3-rc1)
+CVE-2026-80964 [ALSA: virmidi: Check card index validity at probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b65d5182ecd6b7a24a83d980a0d06e809ef876c5 (7.3-rc1)
+CVE-2026-80963 [dm-stats: fix a crash if allocation of per-cpu data fails]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cc87e26d9cce22061dc21e51e11afef29dbbc36a (7.3-rc1)
+CVE-2026-80962 [dm-pcache: validate geometry fields from on-disk cache_info]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/32d1809da31094ef76fd98dc1f1a8b55ca1295dd (7.3-rc1)
+CVE-2026-80961 [dm-pcache: validate kset key_num and intra-segment bounds]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f11deb032fd84081e7831cffcba895d893054a22 (7.3-rc1)
+CVE-2026-80960 [dm-pcache: validate on-media seg_num against the cache device size]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/62d92e45abe9e087370f9fc5d876b95673aced34 (7.3-rc1)
+CVE-2026-80959 [dm-pcache: bound the persisted tail-position offset]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d1898576090a10d2ac2715218a652e78fb65a6b0 (7.3-rc1)
+CVE-2026-80958 [dm-pcache: clamp the tail kset read to the segment data region]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/becf07e2b0053027495ecd671b1f82fb2e615f68 (7.3-rc1)
+CVE-2026-80957 [dm-pcache: detect a cycle in the last-kset chain during replay]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/16c3b3a326e70f246a605b3dc27b7f83ba4743e3 (7.3-rc1)
+CVE-2026-80956 [dm-pcache: only hand out initialized cache segments]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2df0fc042e299bae3c0f60ea5cd2af9285658e9f (7.3-rc1)
+CVE-2026-80955 [dm-pcache: fix use-after-free and invalid seg operations in kset_replay()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c2e894eac398b258f12fdec73ed6ba081047f7b3 (7.3-rc1)
+CVE-2026-80954 [i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8bed7f4fa710914b7f05fd59998316bfb4d43385 (7.3-rc1)
+CVE-2026-80953 [i3c: master: adi: initialize the lock before enabling interrupts]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8a53f9102a0d3eeb8784999f925028acf339c276 (7.3-rc1)
+CVE-2026-80952 [i3c: master: Fix info leak and UAF in device unregister path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d2c743efd2d1ee64e94324664808f623dd865872 (7.3-rc1)
+CVE-2026-80951 [i3c: master: svc: bound IBI payload to the requested max_payload_len]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e2bda39d7f9f285ec803e200b5c1f17143d0b483 (7.3-rc1)
+CVE-2026-80950 [i3c: renesas: Check that the transfer is valid before accessing it]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5f1a76ecfe90544a28d657306c9b3caa66ba0e63 (7.3-rc1)
+CVE-2026-80949 [wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0d10db8e94fcb23a799789aaa696b4d8f937e207 (7.3-rc1)
+CVE-2026-80948 [wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/67105abd6195a685a84dcb8a5daf54a1f4bfdb60 (7.3-rc1)
+CVE-2026-80947 [wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6c080026ecc17eecb103f8927c64ea73a74bb818 (7.3-rc1)
+CVE-2026-80946 [fuse: copy request headers via a stack buffer for io-uring]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fd10f40af314f07b6d6e028b1ca25c8b49903aab (7.3-rc1)
+CVE-2026-80945 [crypto: iaa - unmap dst before software fallback on decompress]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/94a25930477113730372e0fa2985da4c5ac95c9a (7.3-rc1)
+CVE-2026-80944 [wifi: mwifiex: Detach sync cmd buffer on interrupted wait]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ef06882c7d8a7400b67d0d003b1008093dd589ed (7.3-rc1)
+CVE-2026-80943 [wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ed4f05d9f2f42fd866f55108db8123eefcc5fb33 (7.3-rc1)
+CVE-2026-80942 [wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6496ce90845df2d22fb8e8ed235cd2936fad41c8 (7.3-rc1)
+CVE-2026-80941 [wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9f2948010764d708bda27369d09ce6f194abe8e3 (7.3-rc1)
+CVE-2026-80940 [wifi: rtw88: pci: fix resource leak on failed NAPI setup]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e779df4806cd29cbcca5c9dc0a1073662c76b889 (7.3-rc1)
+CVE-2026-80939 [wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/667c12782aaf8dd3cb2213e528fe63a73cb63345 (7.3-rc1)
+CVE-2026-80938 [wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bda8324270b1ac91bfba1df8928e0570e29759e8 (7.3-rc1)
+CVE-2026-80937 [wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/44b5adfe49499f53002737f5fe81d608c08122fc (7.3-rc1)
+CVE-2026-80936 [wifi: mt76: mt7925: cancel mlo_pm_work on stop]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/81faf578320df2dfc682a96baa6e85851dd68b6f (7.3-rc1)
+CVE-2026-80935 [wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/13b3c29a782033ce4a230be9e5618032813dbcd4 (7.3-rc1)
+CVE-2026-80934 [wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/deaa2e3656937fbbe312f0ee2616c756c6e2511f (7.3-rc1)
+CVE-2026-80933 [wifi: mt76: mt7996: validate default EEPROM firmware size]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/653c6e289b13cc6942f3e8f8e3c568e70fa42d1f (7.3-rc1)
+CVE-2026-80932 [vsock/virtio: flush works in dependency order]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/728836ebca239810f164262b10211ef59182f811 (7.3-rc1)
+CVE-2026-80931 [w1: ds28e17: reject an oversize length on an I2C block read]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/169ae5e65e5aaf213b6a578f6478a9fd2e523606 (7.3-rc1)
+CVE-2026-80930 [tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/705c4ed0643366963547b2616d53165f2519c81f (7.3-rc1)
+CVE-2026-80929 [sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7170ca01623b399c97f2ae9d3e228badc1f25ea3 (7.3-rc1)
+CVE-2026-80928 [smack: fix cred UAF in smack_file_send_sigiotask()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fedc88e38ce979a720cd2de042578cb5df3dc8de (7.3-rc1)
+CVE-2026-80927 [timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4b61084b11bcecce86d03804ff30f8d7b465593c (7.3-rc1)
 CVE-2026-80926 [ksmbd: fix use-after-free in oplock break notification]
 	- linux <unfixed>
 	[bookworm] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed3b8fbffe06ce40dfa02a8e237772e8b48185eb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed3b8fbffe06ce40dfa02a8e237772e8b48185eb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/9031a191/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list