[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 16 19:31:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bee3418e by Salvatore Bonaccorso at 2026-09-16T20:29:23+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,912 @@
+CVE-2026-90038 [NFSD: Prevent client use-after-free during export state revocation]
+	- linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2108de53568a64936a0da3e04d85c35df98d3fb6 (7.3-rc1)
+CVE-2026-90049 [net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8ece906150128d5ec2462aabcc978c568433eca4 (7.3-rc1)
+CVE-2026-90048 [fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7c4841e2a62794a3bab7c1ff0540580f387e377f (7.3-rc1)
+CVE-2026-90047 [drm/xe: Don't hand out the flat CCS storage as usable VRAM]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/818bebeb63dd6bf5f4e07e145f6cdbace520a34c (7.3-rc1)
+CVE-2026-90046 [mm/page_alloc: don't spin_trylock() in NMI on UP]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3105ae628fb785d48b49256468be4f21a7b3cfc0 (7.3-rc1)
+CVE-2026-90045 [USB: gadget: ffs: fix mm lifetime handling]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8 (7.3-rc1)
+CVE-2026-90044 [usb: gadget: f_fs: Fix Use-After-Free in AIO error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e78dcb1f7ec271449c54984dc90c62a5ba272de7 (7.3-rc1)
+CVE-2026-90043 [zram: fix slot lock bit position on big-endian 64-bit]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a8b5875741d416703e19ad8eeac6fce8a12bd6e4 (7.3-rc1)
+CVE-2026-90042 [ceph: properly decrypt filenames in vmalloc() buffers]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e939fc6a7bd969a58a150b7f188c1047138403e3 (7.3-rc1)
+CVE-2026-90041 [HID: sony: clean up device list on probe failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7c65699a3a311198a07659a614fe64d45924839e (7.3-rc1)
+CVE-2026-90040 [KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d1a3c216233413f57f5341a9b878b7e2dde7e785 (7.3-rc1)
+CVE-2026-90039 [NFSD: Guard admin state-revocation walks with NFSD_NET_UP]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378 (7.3-rc1)
+CVE-2026-90037 [NFSD: Prevent client use-after-free during close_lru reaping]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2330b788d732f43668b965b3105b37ceb276dfea (7.3-rc1)
+CVE-2026-90036 [NFSD: Prevent client use-after-free during blocked-lock reaping]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9026932ac8be4d0ae01db47f23619a98cc57b671 (7.3-rc1)
+CVE-2026-90035 [drm/amd/display: fix division by zero in get_estimated_bw()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f63de9054da858d57054474c32464106f8375e0d (7.3-rc2)
+CVE-2026-90034 [usb: image: mdc800: change kmalloc() to kzalloc()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2430eb81e44111b30eeb5273bbcf8b24ca517ef9 (7.3-rc2)
+CVE-2026-90033 [ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e4637ce34607f1733a34a57294966d26b263e626 (7.3-rc2)
+CVE-2026-90032 [media: usbtv: keep device alive while ALSA card exists]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fc530fe168bb2b745a93f553ad21fc25fd9cba3d (7.3-rc1)
+CVE-2026-90031 [usb-storage: ene_ub6250: fix race between scan work and probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/445fc368c6bc73eff0aeb3818cf5f355facfbb16 (7.3-rc2)
+CVE-2026-90030 [usb: dwc3: clear forceRM when issuing EndTransfer]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b58e6200450d350314db0ecda7d6d1bde3281e80 (7.3-rc2)
+CVE-2026-90029 [usb: storage: realtek_cr: fix use-after-free on disconnect]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4ffee1aebb0c0ffcda9faffd17834ea9b00d42cc (7.3-rc2)
+CVE-2026-90028 [usb: typec: hd3ss3220: track VBUS enable state per consumer]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c9a48db776d7184981630ecc01a3ad30a8f7dc24 (7.3-rc2)
+CVE-2026-90027 [usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/263f7d61a4201cde16849b2d016251806e7418be (7.3-rc2)
+CVE-2026-90026 [usb: typec: qcom-pmic: cancel reset_work on stop]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7b0df6efd143f8085bdb68778a013a46f1349913 (7.3-rc2)
+CVE-2026-90025 [usb: typec: ucsi: displayport: Fix OOB altmode array index]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/04cec690b1fd9d1c4c314b91a10d8c68a3acfe18 (7.3-rc2)
+CVE-2026-90024 [usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f0efaf1872949e96d213c8e910fd9517f7d7c406 (7.3-rc2)
+CVE-2026-90023 [usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2c0f5ca48674a5b5f9fa4a9c3325aa48053af0bc (7.3-rc2)
+CVE-2026-90022 [usb: gadget: f_midi2: fix use-after-free in string attribute show path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b (7.3-rc2)
+CVE-2026-90021 [usb: gadget: f_midi: initialize work in f_midi_alloc()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7e07d3e4c389217d7d7171d80edf2e23ac70f1ea (7.3-rc2)
+CVE-2026-90020 [USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/dd0eed9e165b1a6292f49e622e3dd0b7d99b106d (7.3-rc2)
+CVE-2026-90019 [usb: gadget: fix null pointer dereference in usb_put_function_instance()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6e74ac5c596fd246e37eadfc354567179ccbe9aa (7.3-rc2)
+CVE-2026-90018 [staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/99aa998dec83ba180822f70e6d48a514fc81c20d (7.3-rc2)
+CVE-2026-90017 [staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ff917923f4fb9c83717ba135ee47d7e4c1567bb7 (7.3-rc2)
+CVE-2026-90016 [staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852 (7.3-rc2)
+CVE-2026-90015 [xhci: fix lost bounce buffers on TDs spanning several ring segments]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ff44dfb03a293bf30e31f98772a1dd316a6071d1 (7.3-rc2)
+CVE-2026-90014 [tracing: Have show_event_filters/triggers files take trace array ref]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f4a771cc684c7354b6200147f7252c58d17408ff (7.3-rc2)
+CVE-2026-90013 [tracing: Take trace_array reference when opening options file]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f2951ebd15c36a1ea4820a7f0cbb0b5f1c028b73 (7.3-rc2)
+CVE-2026-90012 [spi: Fix DMA mapping ownership on partial map failure]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/367cea239fc93094e5c16a72724800e0358f5c46 (7.3-rc1)
+CVE-2026-90011 [scsi: target: iscsi: Reserve a terminator byte for the login payload]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f4825922d2fb371e2b969697d792077f1b62b62c (7.3-rc2)
+CVE-2026-90010 [scsi: bsg: Cap io_uring sense copy to max_response_len]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ece06de726737e887dc0225c8283477624f8ae21 (7.3-rc2)
+CVE-2026-90009 [scsi: bsg: Fix TOCTOU in io_uring passthrough command setup]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4b3c5965fca99f62d31c963294bd5b23cc488e97 (7.3-rc2)
+CVE-2026-90008 [scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/af8c27375733fb6a6df9fa484cda77cc3dd0cb80 (7.3-rc2)
+CVE-2026-90007 [scsi: pm8001: Use rollback index when freeing MSI-X vectors]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3f92a64545165bdbb36dee8fa35626b295463313 (7.3-rc2)
+CVE-2026-90006 [samples/damon/mtier: handle damon_stop() failure]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9dc5b6d66fd51b103eff21ed0df3e292f489ebc0 (7.3-rc1)
+CVE-2026-90005 [samples/damon/wsse: handle damon_start() failure]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e4742be45ea45bf554399ce89a09f71e525d7981 (7.3-rc1)
+CVE-2026-90004 [mm/damon/core: handle region split failure in apply_min_nr_regions()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c608748607620f331196ed0ba9fe4017892c1457 (7.3-rc1)
+CVE-2026-90003 [futex: Prevent rcuwait use-after-free during requeue PI]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a3b8d46fe401cba3a5c46dea610e6eb3dc15370e (7.3-rc2)
+CVE-2026-90002 [ftrace: Take trace_array reference before accessing its ftrace_ops]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9100191e5acb2e5ea2313f436667bb5fce129f47 (7.3-rc2)
+CVE-2026-90001 [HID: bpf: serialize device reference release in struct_ops destroy path]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9cdc7e6dc7a99ad7311ad5e7c145f2b9ce4e24b0 (7.3-rc2)
+CVE-2026-90000 [HID: rmi: fix OOB access with undersized RMI reports]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4956993bb3befdf791d71a4952d8d13bcfd44c7b (7.3-rc2)
+CVE-2026-89999 [HID: wacom: validate report length in wacom_intuos_pro2_bt_irq]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a8e04f3f894ccb52cfcd7e60125a9f35da4a616d (7.3-rc2)
+CVE-2026-89998 [dm: fix race when loading and unloading a table]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5380c7f6335cc6d77eb77d065105e81155c4d9d3 (7.3-rc1)
+CVE-2026-89997 [dm: fix resume-vs-remove race]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5 (7.3-rc1)
+CVE-2026-89996 [dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/30d0aff2c65a277135cfd8ea28fa1ee75e0ea4e0 (7.3-rc2)
+CVE-2026-89995 [dma-direct: return struct page from dma_direct_alloc_from_pool()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/94a04ad732c9f8b9554270fc4038a06737de5c22 (7.3-rc1)
+CVE-2026-89994 [dmaengine: fsl-edma: tracing: no ptr dereference during log output]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2ea04dca8e627f722caa7a2037cfbae0257f3501 (7.3-rc1)
+CVE-2026-89993 [dmaengine: dw-edma: Initialize IRQ data before requesting IRQs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/647217abea849d3d45f8cb0b8ee5b78d50f26985 (7.3-rc1)
+CVE-2026-89992 [cpuidle: dt_idle_genpd: kfree() the original name allocation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2b0ac85512b7f67479127b2713254490662eb13d (7.3-rc2)
+CVE-2026-89991 [bpf: Fix infinite loop in pcpu_freelist push with one possible CPU]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/efebf6496685c93150df5bb0794363ae70c5f58a (7.3-rc2)
+CVE-2026-89990 [ceph: lock mutex in ceph_mds_check_access()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a61c6ae1dae2611082b831b4aaa780878099c012 (7.3-rc2)
+CVE-2026-89989 [ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8861f6d5c0678a7c5089c7b272509fc5931b8437 (7.3-rc2)
+CVE-2026-89988 [kprobes: Protect kprobe_blacklist with RCU]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0c4256196b3a105307e2235fbfd85e768bbcdd0f (7.3-rc2)
+CVE-2026-89987 [mm/huge_memory: transfer the pmd dirty bit to the folio on zap]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fe6cf984939d8e12cb33a99673c8d026c5135e68 (7.3-rc2)
+CVE-2026-89986 [mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/540e583b66d6402bf556fde5e53c817a54c1afe5 (7.3-rc2)
+CVE-2026-89985 [memcg: keep folio's objcg same as its node]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bf4ade7dbd76d4ec8697840e4ebb15ed77c5ec26 (7.3-rc1)
+CVE-2026-89984 [perf/x86/intel: Fix kernel address leakages in LBR stack]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e2b0575900ff72aa82748af96e7bd564ade5157a (7.3-rc1)
+CVE-2026-89983 [i2c: core: fix debugfs UAF on adapter removal]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b15b548d52b43ba8ac4652bc2c7244a8dd1e9622 (7.3-rc1)
+CVE-2026-89982 [i2c: mux: Fix channel node leak on adapter add failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/385c7af4e3b95d0769fd211831674e83b16a2ebf (7.3-rc1)
+CVE-2026-89981 [arm64: Don't read GMID_EL1 when MTE is disabled]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5445d64199626974269fcdf347769ad44b0bb53b (7.3-rc2)
+CVE-2026-89980 [ALSA: harmony: initialize locks before requesting IRQ]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/33abb7491e89285a41565670945293dda841afc4 (7.3-rc2)
+CVE-2026-89979 [ALSA: pcm: Fix race between non-atomic ops and trigger-start]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/acac7b5e07349a9d10d78873afb4b93cd1dc721f (7.3-rc2)
+CVE-2026-89978 [accel/amdxdna: return early from a zero-length flush]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc14753664240cedf669623b27ae9922b0618b25 (7.3-rc2)
+CVE-2026-89977 [accel/ethosu: check MMIO mapping errors in probe]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7ab64476a610fe65858fdc37c7a30caa13e334ac (7.3-rc2)
+CVE-2026-89976 [accel/ethosu: fix job completion fence cleanup]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2d2a3adc91950f9a18829dadc7317fb5180a15c5 (7.3-rc2)
+CVE-2026-89975 [nvme-fabrics: fix DHCHAP secret leak on parse failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/afdee49a1b88ed9bb44e2b30e855297c169bcc53 (7.3-rc2)
+CVE-2026-89974 [nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/56e6279266f6962bb2d38a54397e3c605165b0c5 (7.3-rc2)
+CVE-2026-89973 [nvme-tcp: check the data direction of a C2HData PDU]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f83af377c148f6ad94b41c0e8313f12adf45e1c1 (7.3-rc2)
+CVE-2026-89972 [nvme: add missing SRCU grace period in error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ef248d5de4469fb6bbaf8dbe0c4c47800080d648 (7.3-rc2)
+CVE-2026-89971 [nvme: skip the zoned limits update if the zone info query failed]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3838e80fcfb32e62baffb63c6dc0a60153665a4d (7.3-rc2)
+CVE-2026-89970 [nvmet-auth: Synchronize timeout work during SQ teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/eaa948c0e19b1bb2d93262207bca0c3d19cc3406 (7.3-rc2)
+CVE-2026-89969 [nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/14cc5a7e77731497d5bea70f3bb05df7eda982e4 (7.3-rc2)
+CVE-2026-89968 [nvmet-tcp: reject unsolicited H2CData PDUs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/db62b35cbca052860c519cbcabe7650708528738 (7.3-rc2)
+CVE-2026-89967 [mm/migrate_device: avoid out-of-bounds writes for compound folios]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc41e961a269f2ca4196e669d6d8e05480899cd4 (7.3-rc2)
+CVE-2026-89966 [mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7b8a8ae4dd176a232e973017d2aa3c536a7275e2 (7.3-rc2)
+CVE-2026-89965 [nvdimm/btt: reject an arena whose nfree is below the lane count]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6a1f2e5ed9267ca19187038ac635393c165213ac (7.3-rc1)
+CVE-2026-89964 [parisc: eisa: Fix infinite loop when parsing invalid IRQ value]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8b585431a16cfb9d8f2955a9fa0787ce3dceb3c2 (7.3-rc1)
+CVE-2026-89963 [powerpc/kexec_file: Fix null-ptr-def in extra size calculation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/761eda315a6e1fda3e8e2185b28430771fb1ac29 (7.3-rc1)
+CVE-2026-89962 [powerpc/kexec_file: Prevent kexec range truncation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fa40f9dbdd4af53e7445d9135b5b207eb8adf372 (7.3-rc1)
+CVE-2026-89961 [powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/89a4ae32764172468dea303eb6ae90fe6c859712 (7.3-rc1)
+CVE-2026-89960 [s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4400270ec0348d05dc0439d8f0130853ce7f9e20 (7.3-rc1)
+CVE-2026-89959 [s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6b8a02e216f6b520cc029e43ddc83956605135d5 (7.3-rc1)
+CVE-2026-89958 [s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/d50346801b4f144e42b49cd4f1496010498ab114 (7.3-rc1)
+CVE-2026-89957 [s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/917f509bfb88048094dbb85c4e9dbc4d6fe4a886 (7.3-rc1)
+CVE-2026-89956 [s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7fa61c29850d05e40ca9ed41bfdf57673023f581 (7.3-rc1)
+CVE-2026-89955 [s390/vfio-ap: Fix NULL deref in status_show() during queue probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/dd6f4ef6f8a37412909ad787c837332fb070159c (7.3-rc1)
+CVE-2026-89954 [mtd: afs: validate v2 image info bounds]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e9290031f736e99ad17c25c00311c92c266843b7 (7.3-rc1)
+CVE-2026-89953 [mtd: mtdoops: free page bitmap when the backing MTD is removed]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/956e7da12c114f13c63d126ab1d79c3b6a819060 (7.3-rc1)
+CVE-2026-89952 [mtd: rawnand: validate ONFI extended parameter page sections]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e5e415262330bd70f983e091d8919d9dcd99e475 (7.3-rc1)
+CVE-2026-89951 [batman-adv: fix stale receive device on merged fragments]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ad46c907d7d9975a285c1e89a4adde652eaa93f5 (7.3-rc1)
+CVE-2026-89950 [batman-adv: mcast: linearize skbuff for packet generation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6a30a59e2660afd03c975f1b8eae6a2301161197 (7.3-rc1)
+CVE-2026-89949 [batman-adv: dat: avoid unaligned fault in IP extraction]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0121afa52cdb88cfb4d5d7bd126a23a9100121d8 (7.3-rc1)
+CVE-2026-89948 [batman-adv: bla: fix freeing of claims on meshif deletion]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8d128c932bced74e3b1625ba3d7c78ef122a88a7 (7.3-rc1)
+CVE-2026-89947 [clk: meson: align gxbb_32k_clk_sel number of parents with actual count]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/628b6fee9fca292f12d07f0f1bcf1edefa949d81 (7.3-rc1)
+CVE-2026-89946 [ASoC: cs35l33: drain threaded IRQ before runtime suspend]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e074c12c428c633e079154301207a6079a208583 (7.3-rc1)
+CVE-2026-89945 [ASoC: cs35l34: drain threaded IRQ before runtime suspend]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4105a4c0678b2808fc8046b60321b4f1cc7dae75 (7.3-rc1)
+CVE-2026-89944 [ASoC: hdac_hda: Fix hlink refcount leak on component registration failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6ad4892c4f5cb437a928a02f5b7d37d496aa9268 (7.3-rc1)
+CVE-2026-89943 [ASoC: loongson: Fix error handling in ACPI property parsing]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0eb0e3c623ac1da8b85d518043fef7660af7805d (7.3-rc1)
+CVE-2026-89942 [iio: buffer: Fix potential use-after-free in anonymous buffer release]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6288b593e76eb10329326f2cd51e32557203b9e5 (7.3-rc1)
+CVE-2026-89941 [iio: buffer: Make IIO DMA fence release RCU-safe]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8662e56c31cf23b61ca3d11b516efb94c35b8026 (7.3-rc1)
+CVE-2026-89940 [iio: buffer: Tie IIO dma fence lock lifetime to the fence]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f25ec4627d935dedfb5fe83bd2c2678cdcc19611 (7.3-rc1)
+CVE-2026-89939 [iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bcd3f72e26314edfce7eaf8d7160b3119c7b7fed (7.3-rc1)
+CVE-2026-89938 [iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/be61c8c6252671ecf1fee0ad90f87669e0be1e20 (7.3-rc1)
+CVE-2026-89937 [iio: chemical: sgp30: Handle IAQ thread creation failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1135d6875d2dbda3f6ec718f3421a6ce4378bd63 (7.3-rc1)
+CVE-2026-89936 [iio: dac: m62332: Fix regulator reference count imbalance]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a130404ce0b69ca1438126bd81c1985d3b4d2e6f (7.3-rc1)
+CVE-2026-89935 [iio: light: apds9306: fix PM reference leak in apds9306_read_data()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d378fceaafd79e0dc59d3546bda251a3058062c0 (7.3-rc1)
+CVE-2026-89934 [iio: light: ltrf216a: fix runtime PM reference leak in error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c132aef0e757a39036b1d40faf0569f2e343b13e (7.3-rc1)
+CVE-2026-89933 [iio: pressure: dps310: fix NULL pointer dereference on ACPI probe]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/26e9213898fc949923188ef0aeea31fc87708836 (7.3-rc1)
+CVE-2026-89932 [KVM: nVMX: Always flush vpid02 on first use]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f0772389413dce9657c7d6950abf3edbbd511356 (7.3-rc1)
+CVE-2026-89931 [KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/11722439fb206c88e6f31be54173efa9880b4ccb (7.3-rc1)
+CVE-2026-89930 [KVM: nVMX: Service local TLB flushes on failed nested VM-Enter]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/05a0b701d1089fb57beeb8982f23c3bbafe0fa8b (7.3-rc1)
+CVE-2026-89929 [KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6d00e67326d831e6e610933a3800712f4ffe6ec1 (7.3-rc1)
+CVE-2026-89928 [KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e428f9779a43737d830111238816f1928b07aefb (7.3-rc1)
+CVE-2026-89927 [KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0ca49fbd2883cd53d32d85b50feef17fa04d0fbf (7.3-rc1)
+CVE-2026-89926 [KVM: s390: Fix length check __import_wp_info()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4c07680a467e2f7697245bcd11691bffb2a6f0ed (7.3-rc1)
+CVE-2026-89925 [KVM: s390: Fix memory leak in guest debug handling]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/121ea1de927c8b9bfdf53c31cad27b86d5de0293 (7.3-rc1)
+CVE-2026-89924 [KVM: s390: Fix old_data leak in guest debug error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/aa9c8e8baf1e765fa65b93212522c636f25d846f (7.3-rc1)
+CVE-2026-89923 [KVM: s390: Free guest debug data on vcpu destroy]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e7f698b09d4a7c36b299acf680fc50fe868e2bcd (7.3-rc1)
+CVE-2026-89922 [KVM: s390: Take srcu when importing watchpoint data]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a4e482def8533ebace517d9f67f1465841b1f982 (7.3-rc1)
+CVE-2026-89921 [KVM: s390: Zero initialize data structures for inject_pfault_token]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4e2c7f7cbc27418f9a290399b986c1b85ff93b90 (7.3-rc1)
+CVE-2026-89920 [KVM: s390: Fix memory corruption by not reinjecting CK machine checks]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/546dde823a36d7283dcf46127c2f3d093443860f (7.3-rc1)
+CVE-2026-89919 [KVM: s390: keyop: use mmu_lock to read gmap->asce]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/da07a751efa4583385f9f0f47113549fe8871242 (7.3-rc1)
+CVE-2026-89918 [KVM: arm64: Correctly handle end of VA space TLBI invalidation]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/34af2c3e31f91a739dc175459fdbd99ed952b457 (7.3-rc1)
+CVE-2026-89917 [KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/38640bc32be3fcf9526d477155bc19d3f146231f (7.3-rc1)
+CVE-2026-89916 [KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b7324f3a0c1072b9d578b8d42f199506753f26e (7.3-rc1)
+CVE-2026-89915 [KVM: arm64: Remove VM-wide VNCR mapping counter]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c55bc773b6e814406658fae7dc5c15f639ed816e (7.3-rc1)
+CVE-2026-89914 [KVM: arm64: Sign-extend VA for range-based TLBI invalidation]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2393470085649f0b973ecceb26fe8fc71edde0c1 (7.3-rc1)
+CVE-2026-89913 [KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f5b8f203bfc07a5a257dff859e66d2c500f9f509 (7.3-rc1)
+CVE-2026-89912 [KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c6c156d931c33b92362383cf76f6d6e1291dcbfe (7.3-rc1)
+CVE-2026-89911 [KVM: arm64: Correctly cap TLBI Range to the architural limit]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/69a598288195947a1662b53de702eb6976af96b7 (7.3-rc1)
+CVE-2026-89910 [LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/81aa3a58b542ed88819115c80a17acd86eacb89d (7.3-rc1)
+CVE-2026-89909 [LoongArch: KVM: Free init resources if kvm_init() fails]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f7a1064cce3b100b54780c68529176232d8eb01e (7.3-rc2)
+CVE-2026-89908 [LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/27a9bfee3bbcb3cabb77797354f07e0e44e49831 (7.3-rc2)
+CVE-2026-89907 [LoongArch: KVM: Validate MSI data before routing it to EIOINTC]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/501514d6ebd2111c353a1296f25dbe22fbd64657 (7.3-rc2)
+CVE-2026-89906 [LoongArch: BPF: Refactor jump offset calculation in tail call]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/37d545d12f21c4d50612ecaebd7ae1e5bf91b2d8 (7.3-rc1)
+CVE-2026-89905 [LoongArch: BPF: Move arena register slot below TCC context]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cd7e356b07a27e91394838cf3fb655862b519294 (7.3-rc1)
+CVE-2026-89904 [LoongArch: Fix acpi_package_ids[] array overflow]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2a2367d46d7a4ee4122b7a86e57125542dbbe963 (7.3-rc1)
+CVE-2026-89903 [LoongArch: Do not save/restore percpu base register in rethook trampoline]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c3f2feace5e4f4b01b68b9f947b19adb4155c32e (7.3-rc2)
+CVE-2026-89902 [LoongArch: Avoid preempt count underflow without probe]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/72ce4b24676e8b3b75376c4c559dd81c1ac52d5a (7.3-rc2)
+CVE-2026-89901 [media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/2f378dc45e685fc825d2dd08e7864666d6fcc009 (7.3-rc1)
+CVE-2026-89900 [media: cec: core: Fix kmemleak due to missed rc_free_device() call]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a24ba0653f7154e671dc8d2bf64682ab2d042792 (7.3-rc1)
+CVE-2026-89899 [media: cec: disable delayed work before freeing an interrupted transmit]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0fbd5c2327020858c45b2d1c65775d64cdeca523 (7.3-rc1)
+CVE-2026-89898 [media: cec: extron-da-hd-4k-plus: add sanity check]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3 (7.3-rc1)
+CVE-2026-89897 [media: cec: Serialize exclusive follower delivery]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1924d0788caa6c66fd320dd4704fae99487fd2c7 (7.3-rc1)
+CVE-2026-89896 [media: cedrus: fix memory leak in cedrus_init_ctrls()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9df2fbe563194da1967a5db083442186c1323efe (7.3-rc1)
+CVE-2026-89895 [media: cobalt: Avoid freeing ALSA private data twice]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1 (7.3-rc1)
+CVE-2026-89894 [media: cx231xx: reject geometry changes while the VBI queue is busy]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/627a121c15fe05a541f44d86016294b80bada75d (7.3-rc1)
+CVE-2026-89893 [media: cx23885: cancel NetUP CI work before teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4e143d662ca94888b494b2427fc9e34494eb933a (7.3-rc1)
+CVE-2026-89892 [media: em28xx: defer audio-only extension registration]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/95f76f51937fdfb0fc1e14cae606b1ef574a56f3 (7.3-rc1)
+CVE-2026-89891 [media: em28xx: fix use-after-free of dev_next->devlist on disconnect]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/826915b6b65e2d3251e7248ea54289a22d748c84 (7.3-rc1)
+CVE-2026-89890 [media: go7007: defer the ALSA v4l2 put until card release]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/1bd456afeb8a515137e567967069fce6f8fcd23e (7.3-rc1)
+CVE-2026-89889 [media: i2c: imx415: Release runtime PM reference on VBLANK error]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bea3001e0f32527a291444e527e84a7ea9b546d4 (7.3-rc1)
+CVE-2026-89888 [media: i2c: ov02a10: fix endpoint parsing use-after-free]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/94971ba0592ca77ec99b292226a4b398763315b8 (7.3-rc1)
+CVE-2026-89887 [media: i2c: ov7740: fix use-after-destroy in remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5d1b3dea5a44124bab6c14a2d71b977dabed54e7 (7.3-rc1)
+CVE-2026-89886 [media: intel/ipu6: fix async notifier cleanup leak on parse error]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/abb1f808ceab5a3275f8a6b4e37cff17f9f781c1 (7.3-rc1)
+CVE-2026-89885 [media: platform: mtk-mdp3: Fix SCP device refcounting]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/55793e4665b7f15151e6f5ab51ca980e73abed5d (7.3-rc1)
+CVE-2026-89884 [media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/90368323fb244da0504e3da37a182f8e89bcc3b9 (7.3-rc1)
+CVE-2026-89883 [media: rc: sunxi-cir: Unregister rc device on probe failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/479aa6fa8c50f1052f1451326ef7d4d586d340c3 (7.3-rc1)
+CVE-2026-89882 [media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/052c5ed5a1d96a6b24fd50ccda16fc6841ee7ca3 (7.3-rc1)
+CVE-2026-89881 [media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/dabb047c62668f280998e29117c55e41aabac336 (7.3-rc1)
+CVE-2026-89880 [media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4 (7.3-rc1)
+CVE-2026-89879 [media: s2255: bound JPEG frame size before copying into the buffer]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e504cc888f42999dd76b6a43788c422610f2aad2 (7.3-rc1)
+CVE-2026-89878 [media: s2255: check firmware size before reading trailing marker]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/330f2936ab768c7215322a476f033143e8891d28 (7.3-rc1)
+CVE-2026-89877 [media: saa7164: fix cleanup on resource allocation failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/28e84c6e2e6753ed238ea097b2842a32a6a6879b (7.3-rc1)
+CVE-2026-89876 [media: tda18250: fix possible integer overflow]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4 (7.3-rc1)
+CVE-2026-89875 [media: ti: vpe: quiesce overflow recovery before freeing streams]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/aeaacc3001449d44b4ab7da56331121d1f3b137b (7.3-rc1)
+CVE-2026-89874 [media: v4l2-async: avoid deleting unlinked ASC entry on link error]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/47d82b605351c0e04f6365e42c8ffe2fcfdba615 (7.3-rc1)
+CVE-2026-89873 [media: v4l2-ctrls: validate HEVC EXT SPS RPS counts]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e (7.3-rc1)
+CVE-2026-89872 [media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a6e86efd7f85e519bf48417f41923f8bd51f1597 (7.3-rc1)
+CVE-2026-89871 [media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/76e379754ba618989f6215be608d5c04774a611d (7.3-rc1)
+CVE-2026-89870 [media: zoran: Avoid freeing a registered video_device twice]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0735e0b5a96761a9ce277a238e834008ad92a0a5 (7.3-rc1)
+CVE-2026-89869 [media: qcom: iris: use disable_irq() during power-off]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b9c2215bdedc9c532a7e9d57ec49ee1b6381f863 (7.3-rc1)
+CVE-2026-89868 [media: chips-media: wave5: Add timeout while stop_streaming]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2ae7faed2e60d6d07d9efdd962d20dcb15330ced (7.3-rc1)
+CVE-2026-89867 [media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b694ba0a5526a69f78a6924982b1553154ccfd73 (7.3-rc1)
+CVE-2026-89866 [media: chips-media: wave5: Resume device before setting EOS flag]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a52e6f7923c17a672135b485ffd96fbd72f46267 (7.3-rc1)
+CVE-2026-89865 [scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc (7.3-rc1)
+CVE-2026-89864 [scsi: qla2xxx: Bound i2c->length in I2C bsg handlers]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59 (7.3-rc1)
+CVE-2026-89863 [scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/c20ee380ca59c5a8646750c4849969a815924e2e (7.3-rc1)
+CVE-2026-89862 [scsi: qla2xxx: Fix BSG job leak on validate flash image error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0fb52cc632464b0cd07f970341330466d772efe1 (7.3-rc1)
+CVE-2026-89861 [scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/793cedee296fd819bfadc2a7ec4d52faf9c09a0a (7.3-rc1)
+CVE-2026-89860 [scsi: qla2xxx: Initialize NVMe abort_work once at submission]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/7e85f6dbc85616de2172bce8eaf84b387a723cd1 (7.3-rc1)
+CVE-2026-89859 [scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/a152edab3854f01dd2daf3eaf8f32cbabdb3834e (7.3-rc1)
+CVE-2026-89858 [scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/de62cf265dbe309f34f144a6cdbca9240317727e (7.3-rc1)
+CVE-2026-89857 [scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f743488e4a203049f27ec5d8cd0caccc483af01e (7.3-rc1)
+CVE-2026-89856 [scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ebfd35c64433821bd5619a6d07ccc2df8b5b1de3 (7.3-rc1)
+CVE-2026-89855 [scsi: qla2xxx: Serialize flash version read in reset handler]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/f606ed93de0c4f1e7e3618779e9fad731455314a (7.3-rc1)
+CVE-2026-89854 [scsi: qla2xxx: Fix cs84xx use-after-free on host teardown]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/33d102102d925357c5fd172dd6672a27d74b3215 (7.3-rc1)
+CVE-2026-89853 [scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/53298efcbbb0f0438366d45cb7ed7e6d93dd5531 (7.3-rc1)
+CVE-2026-89852 [scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/9efaa782845b4d5fb3e01242be0d06ebc7428d8f (7.3-rc1)
+CVE-2026-89851 [scsi: qla2xxx: Fix FCE trace enable parsing in debugfs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b7368687e3d11f51392d3c4774ec0263d5fbf31f (7.3-rc1)
+CVE-2026-89850 [scsi: qla2xxx: Don't query firmware state while chip is down]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e0cebe20dcffbed9c078fe30e2d18cd5046d9eff (7.3-rc1)
+CVE-2026-89849 [scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/0f41d07d72f2245208c45374ca8d0a1846cad667 (7.3-rc1)
+CVE-2026-89848 [scsi: qla2xxx: Quiesce response IRQ before freeing request queue]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/505753ec2594c6af09a601f0dd60be7d840c1d2d (7.3-rc1)
+CVE-2026-89847 [scsi: qla2xxx: Avoid double completion in async IOCB timeout]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/bb45bc4bd53c95a7bf6f782577b5ede94c0f8aa8 (7.3-rc1)
+CVE-2026-89846 [scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ca6d880d6c70cb7946e7b3e05d7285f271b6d99e (7.3-rc1)
+CVE-2026-89845 [scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/deb8abde83a799d2501f3977f6d6051000253f5e (7.3-rc1)
+CVE-2026-89844 [scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7944039ba9cb5c3a935d17c91004e3b8649ff58e (7.3-rc1)
+CVE-2026-89843 [scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b93d3bb3afe1b44489927de1eb4e66e8536a5935 (7.3-rc1)
+CVE-2026-89842 [scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f7e46ebffc5781aab3f1f5a5d4350addbb5833f4 (7.3-rc1)
+CVE-2026-89841 [f2fs: only redirty pinned folios in redirty_blocks]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/85171332742e741ccd6f401c69b6e0d698119e72 (7.3-rc1)
+CVE-2026-89840 [f2fs: validate MOVE_RANGE destination size]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e533889fc26aea0cd83c90327063f272061dd820 (7.3-rc1)
+CVE-2026-89839 [f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a54ffce4637acb0db8e695188a6c7f99f14c3576 (7.3-rc1)
+CVE-2026-89838 [f2fs: limit recovery filename logging to stored length]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/01027b2fcb74dade59fb833b51023f6593b6a9a2 (7.3-rc1)
+CVE-2026-89837 [f2fs: fix dentry folio leak in find_in_level]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/cca7d3e30bf30333314e31bc70b9a739f1342167 (7.3-rc1)
+CVE-2026-89836 [f2fs: fix folio_nr_pages() race after put in large folio invalidate]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0dab71381f1b4d12dc2056f8bd5aaa9d93ce9082 (7.3-rc1)
+CVE-2026-89835 [f2fs: avoid NULL checkpoint thread access in sysfs]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f (7.3-rc1)
+CVE-2026-89834 [f2fs: fix to migrate all curseg types during free_segment_range]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/8ec06f50ddd8d201bd7e55b896ae28ed9d4cb7d1 (7.3-rc1)
+CVE-2026-89833 [f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/ce366bfa821ec81dd45bde547ee31e659306cc61 (7.3-rc1)
+CVE-2026-89832 [f2fs: fix to clear dirty flag on folio in error path]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/5b86eab84ac8e9289b5afc52ef88ab18ba5bacab (7.3-rc1)
+CVE-2026-89831 [f2fs: protect critical_task_priority updates with s_umount]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8e4692c6c165e81b2cbb847d8da4b45a53483b33 (7.3-rc1)
+CVE-2026-89830 [f2fs: fix valid block count leak on data block allocation failure]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0f9af07ecc1ab486038373db6ae0436c5d674b19 (7.3-rc1)
+CVE-2026-89829 [f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7e188e9f9437ab47c3237d609f1b26348d6fea1a (7.3-rc1)
+CVE-2026-89828 [drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e773798e14ac0aea54ca9676083b91f445e5bc59 (7.3-rc1)
+CVE-2026-89827 [drm/amdgpu: avoid force-completing uninitialized UVD rings]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6760f5cb12d2366ddd58a2d8637f7583d73f596b (7.3-rc1)
+CVE-2026-89826 [drm/panthor: harden firmware build-info bounds checks]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8321b093fa6c297b80586460ce6914d9655df170 (7.3-rc1)
+CVE-2026-89825 [drm/panthor: fix firmware control interface bounds checks]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6a47f9fd2d970674ed9dedc52fc7ab76fd015785 (7.3-rc1)
+CVE-2026-89824 [drm/panel-edp: fix i2c adapter leak on probe failure]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/e2a9e291275a74e309a21cbb1def6296a72d6aed (7.3-rc1)
+CVE-2026-89823 [drm: fix race between partial drm_dev_register() failure and ioctl]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/eb197f7d60f00d0f5b1b3505dfc86a7e36045a3e (7.3-rc1)
+CVE-2026-89822 [drm/i915: Guard against NULL driver_data in i915_pci_probe()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/3785d40831ba5601296283e0197e10e089392757 (7.3-rc2)
+CVE-2026-89821 [drm/amd/display: avoid divide-by-zero in __is_lut_linear()]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4f40873f8a4107df2b9c8e68c947c4fd0cd519d2 (7.3-rc1)
+CVE-2026-89820 [drm/amd/display: fix dc_lock leak on GPU reset error paths]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/92a9eebd2a1f892fe482154d83f9f1626bc73d3b (7.3-rc1)
+CVE-2026-89819 [drm/amd/display: validate plane degamma LUT size for private color prop]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e4c3ab59021e7c146a84b6671f0d530972bd58b4 (7.3-rc1)
+CVE-2026-89818 [drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4d7390530853eb7befda9cc786e4c86e8ad7ac9e (7.3-rc1)
+CVE-2026-89817 [drm/gud: NUL-terminate TV mode names read from the device]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/500cb24cd61bad8a2747ddfc49b7034899c82d94 (7.3-rc2)
+CVE-2026-89816 [drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/4d4be202165e832d74849b4a68e289a2a377039c (7.3-rc2)
+CVE-2026-89815 [drm/ttm: Drop tt->restore after successful restore]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/941ac10529b3be5965a88d432a161ab459672ba8 (7.3-rc1)
+CVE-2026-89814 [drm/amdgpu: clamp the isolation index for rings outside a partition]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/b30900566642ceb2c9e12b56c2afec28d0fd91a0 (7.3-rc1)
+CVE-2026-89813 [drm/amdgpu: force complete the KIQ ring fences on reset]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/fd65d1742992361fc2201ecb4e43411e6e417fcb (7.3-rc1)
+CVE-2026-89812 [drm/amdgpu: force complete the MES ring fences on reset]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/48dc279c3010ac8f91b1845b2abb3a1e9943a0f5 (7.3-rc1)
+CVE-2026-89811 [drm/amdkfd: Add TLB flush after MES queue eviction/suspension]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/94e25cb6ab7f4f025bcdcd8ea79fda30f12843a4 (7.3-rc2)
+CVE-2026-89810 [drm/amdkfd: Fix error path at svm_migrate_copy_to_ram]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/960c4a8069bfd352c48cc88592618f1ebe24c69e (7.3-rc1)
+CVE-2026-89809 [drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/012a026bae0212952b423a842b7e2c0bf21f8e7a (7.3-rc2)
+CVE-2026-89808 [drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/520e345ffe05aabef1db82beda4288afb1757ff2 (7.3-rc1)
+CVE-2026-89807 [drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6aa530642f95d5c48aa336416f94a35e7949b647 (7.3-rc1)
+CVE-2026-89806 [drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c6f48e59ece0123f6a11527ad4d89b21c2d65b87 (7.3-rc2)
+CVE-2026-89805 [drm/pagemap: Fix folio allocation fallback and use-after-put]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/df72e55e754c8d449321ddddad19a8bd3cb8d032 (7.3-rc2)
+CVE-2026-89804 [drm/nouveau/dmem: fix mismatched DMA unmap size for large folios]
+	- linux <unfixed>
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/caa1bc2a0a6ca19dcb90bbf88208b0fe2decd66f (7.3-rc2)
+CVE-2026-89803 [drm/nouveau: unsubscribe the channel-kill event before the fence context]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/511585987d27d8cb668acebd399fc4deda23404c (7.3-rc2)
+CVE-2026-89802 [drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/412a6ceb56d501ef2f8202e26ab4b5d4dfbca566 (7.3-rc2)
+CVE-2026-89801 [drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ccf930812f23b8259ef64fd3394d53b093e4651a (7.3-rc2)
+CVE-2026-89800 [drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/38a62306c4266bcb3cd89e33c7111ee33096ebb3 (7.3-rc2)
+CVE-2026-89799 [bpf: Disable preemption in bpf_get_stackid]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/15f1bd8574662f1b7b26aaa2e23ebf4066f0117d (7.3-rc1)
+CVE-2026-89798 [rpcrdma: arm rn_done before publishing the notification]
+	- linux <unfixed>
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5b06f706374c37375bdff9d21cc10e61df925a92 (7.3-rc1)
+CVE-2026-89797 [power: supply: ab8500_fg: fix use-after-free on remove]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/75b1e88d34254f4fb7753345e21bfee47abddd7f (7.3-rc1)
+CVE-2026-89796 [mm/damon/core: avoid infinite kdamond_merge_regions() internal loop]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/123e4619ab6c8ab1c4cb1d7a58311a2af13929cd (7.3-rc1)
+CVE-2026-89795 [PCI: Allow per function PCI slots to fix slot reset on s390]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/dcc5bec09e23bbc4f9de055a11fce9937244f2c8 (7.3-rc1)
+CVE-2026-89794 [ksmbd: zero pipe read compound padding]
+	- linux <unfixed>
+	NOTE: https://git.kernel.org/linus/73f860489e3be2245598d1819226304fc5b87291 (7.3-rc2)
 CVE-2026-89793 [ublk: clear VM_MAYWRITE on read-only ublk char device mmap]
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/6e2b571b0a54755b06e092501913e1dfefe75d6c (7.3-rc2)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bee3418e350b7b8040e399798dd365dd34b82b09

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bee3418e350b7b8040e399798dd365dd34b82b09
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/bd0d1fbf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list