[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 16 10:59:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7e05ccff by Salvatore Bonaccorso at 2026-09-16T11:58:57+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,55 @@
+CVE-2026-89791 [perf: Fix use-after-free when perf mmap() revival races with the last munmap()]
+ - linux <unfixed>
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/58a8108bc73de0740d5b88150465d6690ea5f85f (7.3-rc2)
+CVE-2026-89790 [ipv6: avoid divide by zero in rt6_multipath_rebalance]
+ - linux <unfixed>
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d2c26c2911dd1a363c488add4fb63eb5f0f28f87 (7.3-rc1)
+CVE-2026-89789 [gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/d989e22ae9802c52c56ad4284d0caf26696cf6ae (7.3-rc1)
+CVE-2026-89788 [ksmbd: fix tree connection use-after-free in smb2_tree_connect()]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/b5ec6c462aab1062cf5d1e667ba7c6442f737055 (7.3-rc2)
+CVE-2026-89787 [ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/c7e6b863d298f56522d0d08554bbea7f142e6588 (7.3-rc1)
+CVE-2026-89786 [ext4: fix out-of-bounds read in ext4_read_inline_dir()]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/9333cc809f0a89e001b814155a6cb8903a6274df (7.3-rc1)
+CVE-2026-89785 [fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/2064bc663f89e61b8681c1fb9d1ce445de72063d (7.3-rc1)
+CVE-2026-89784 [SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/fd22370226a0d8109045d0831fd5aaadee921693 (7.3-rc1)
+CVE-2026-89783 [xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/5d9e3bf34fec9a5d237e4b7cef4a707bc2e091bc (7.3-rc1)
+CVE-2026-89782 [fs/ntfs3: reject restart table growth beyond U16_MAX entries]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/111f8d74a19d85942ecbb3aba78f6f3c88e59391 (7.3-rc1)
+CVE-2026-89781 [fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/de603b9d377fab57a5e6432fa84a9f36b32c1636 (7.3-rc1)
+CVE-2026-89780 [net: qualcomm: rmnet: restore skb->dev on deaggregated frames]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/a66734a1c5e36525ea07e9f4547fddc51e916de3 (7.3-rc1)
+CVE-2026-89779 [fs/ntfs3: validate ef->size covers the record's name and value]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/c22f91d82cb9a29d22bdffdce6c803467984ad0c (7.3-rc1)
+CVE-2026-89778 [isofs: fix out-of-bounds page array access on empty zisofs block]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/68d4d3e78150c7ed7d1195af63ad1e6ace30c661 (7.3-rc1)
+CVE-2026-89777 [vfio/pci: clear vdev->msi_perm after freeing it on init failure]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/dc77acfeb979dded39b247b60fef0399536bfa77 (7.3-rc1)
+CVE-2026-89776 [vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes]
+ - linux <unfixed>
+ NOTE: https://git.kernel.org/linus/984f831dda31b3a18f47454cf64989f65402879e (7.3-rc1)
CVE-2026-89775 [KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation]
- linux <unfixed>
[trixie] - linux <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e05ccff11a929fce79798a385ac5bdebe857987
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e05ccff11a929fce79798a385ac5bdebe857987
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/d36bf174/attachment.htm>
More information about the debian-security-tracker-commits
mailing list