[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 17 19:22:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
703411d5 by Salvatore Bonaccorso at 2026-09-17T20:21:58+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,6 +3,2156 @@ CVE-2026-8674 [Assertion failure in the DNS stub resolver with a long search dom
[trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/17/4
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a
+CVE-2026-93198 [dm-pcache: validate the persisted dirty_tail chain at load]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b (7.3-rc1)
+CVE-2026-93197 [memcg: move LRU size accounting on reparenting instead of copying it]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0e0ac326c511d514817cc7b6d7741afd59098ce2 (7.3-rc1)
+CVE-2026-93195 [drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ed04e8e2307f35b3d8d49a554faf5e72d3d224e6 (7.3-rc1)
+CVE-2026-93194 [drm/rockchip: dw_dp: Release core resources]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cc6d7aca2f37a1525a94ef97eb3ce361732c876c (7.3-rc1)
+CVE-2026-93193 [drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/87e060521371257ddbb77964b66e60d80afcc7b2 (7.3-rc1)
+CVE-2026-93187 [ASoC: SOF: ipc4-topology: Return error for invalid number of formats]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/11e828cd6b0f283ebe9dc6b4cffd38e3321e7725 (7.3-rc1)
+CVE-2026-93180 [drm/panthor: Fix NPD issue on partial unmap of an evicted BO]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5fb40edc7439b99d001988da63485ca51dbd3550 (7.3-rc1)
+CVE-2026-93171 [leds: lp5860: Fix a potential double-unlock]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/10a5a70c02277a1c12999b669a1bd1922558338a (7.3-rc1)
+CVE-2026-93169 [dmaengine: zynqmp_dma: fix race between runtime PM and device removal]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/516ba2d8b7aac4238f9fcbd58579c43c71b9b695 (7.3-rc1)
+CVE-2026-93166 [wifi: rtw89: debug: fix off by on in rtw89_ppdu_str()]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1908534deb53a018580309be84a4f7dcc9cb1af3 (7.3-rc1)
+CVE-2026-93157 [hwrng: xilinx-trng - propagate timeout before any data is read]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ba088974419326daf46c5dc03e2cf6ab6ab701f7 (7.3-rc1)
+CVE-2026-93153 [RDMA/bng_re: return a timeout when firmware responses stall]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5f9576c6734abca88a02db72c466e09d2eddf160 (7.3-rc1)
+CVE-2026-93147 [s390/bpf: Replace ly instruction with llgf]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5f6cc299938b561cb01e343bab7042611fcee12a (7.3-rc1)
+CVE-2026-93143 [staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b298b80814dd0fc3cb1c8c0e0082fc14fdb5fecf (7.3-rc1)
+CVE-2026-93139 [drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2c256086a363f01f9840a57949506eccf5c990a6 (7.3-rc1)
+CVE-2026-93127 [bpf: Drop scalar id on sign-extending narrowing stack fills]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2cb5f4ca695ebe552647e5ba4aad6934d6a43bae (7.3-rc1)
+CVE-2026-93124 [platform/x86: asus-wireless: Fail probe when there is no ACPI match]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4aefd66ef7822cf7d3f53146dcee0b71021ed2b7 (7.3-rc1)
+CVE-2026-93112 [bpf: Require a BPF cpumask for bpf_cpumask_populate()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8740156ad33be5071b588b594c55f279457f667c (7.3-rc1)
+CVE-2026-93111 [bpf: Mark tracing_multi trampolines as ftrace managed]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/30bdd6d1384d894931f113eb595636092d8e650c (7.3-rc1)
+CVE-2026-93106 [crash_dump: release keyring reference at the correct time]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ada2e5a44e99113e08ad9b7b71396c6c572204da (7.3-rc1)
+CVE-2026-93094 [wifi: ath12k: fix dp_link_peer dangling references on AP vdev rollback]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f066e1a93703c5be0fd905109d00587541711c97 (7.3-rc1)
+CVE-2026-93080 [firmware: arm_scmi: Fix transport device teardown lookup]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a14dd8fe0a95db638c550ed984cfe2a7428c783d (7.3-rc1)
+CVE-2026-93079 [cxl/features: Reject Get Feature count larger than the output buffer]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4bf6bac375076ced2fa4b3fef8739bd985f93456 (7.3-rc1)
+CVE-2026-93078 [cxl/features: Reject Set Features output buffer smaller than the header]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cde18d6c1d913a67ab0afd3d9475ece4be79da50 (7.3-rc1)
+CVE-2026-93077 [cxl/features: Clamp Get Feature output size to the remaining buffer]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2aeb21fe557ef154f0cdf4f9745ebd8d5b31ca83 (7.3-rc1)
+CVE-2026-93076 [dax/fsdev: clear vmemmap_shift when binding static pgmap]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e0239229931faf9ca3367e3befcf16f77b2cd45b (7.3-rc1)
+CVE-2026-93075 [dax/fsdev: clear pgmap ops and owner on unbind]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f48884ac31b6bfc99f36b3f207b8c0cbe5d54bd7 (7.3-rc1)
+CVE-2026-93074 [dax/fsdev: use __va(phys) for kaddr in direct_access]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ff7c73fca793bd5c29a15ba735b0886f62f3a840 (7.3-rc1)
+CVE-2026-93069 [OPP: Fix cleanup ordering]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ce46fede7792cedd247e34b48bc8a02eb90c7848 (7.3-rc1)
+CVE-2026-93068 [drm/amd/display: Fix DM I2C teardown race]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e4ae30a12aa95942814957d8bc1ce7366a7107d7 (7.3-rc1)
+CVE-2026-93066 [x86/mm/pat: Take cpa_lock around large-page collapse]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1aac65f3e651334259ecb2a5f5ddb81c01f02599 (7.3-rc1)
+CVE-2026-93060 [drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b8a9c9c5787bed1243e5364c89ca66c26b4e4d83 (7.3-rc1)
+CVE-2026-93059 [drm/msm: Fix task_struct reference leak in recover_worker]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/40b793714ad8f393ab3d469f9d00b20ebda46257 (7.3-rc1)
+CVE-2026-93057 [scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/760fc6f0e25a72832c2fcf37ecf5f1b770ec8374 (7.3-rc1)
+CVE-2026-93043 [bpf: Disallow interpreter fallback for gotox insn]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/905f716362e1186c1a23447ca279e6d21f795cdb (7.3-rc1)
+CVE-2026-93038 [iio: dac: ad5686: missing NULL check on match data]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/572a008526359cdac2fa935dad75e9d50a79792f (7.3-rc1)
+CVE-2026-92517 [bpf, riscv: Fix extable handling for arena load_acquire]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5eb8921371c6fd117d4a328b6053dfda38707df8 (7.3-rc1)
+CVE-2026-92516 [bpf: Fix offset warn check for bpf_res_spin_lock]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/04e19012efaec2bfd8c3b37fd8a6c3f1fe731ffc (7.3-rc1)
+CVE-2026-92513 [RDMA/mana_ib: drain QP references after partial table insertion]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/97f7c2262c28ebcae64fc957ee978646684a5ed9 (7.3-rc1)
+CVE-2026-92505 [iommu/amd: Fix undefined behavior in devid_write debugfs function]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/843e149989665f8309ad2efe6048dc76591e1f94 (7.3-rc1)
+CVE-2026-92492 [cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/39c0cf62fc7851a17782e7efe8dfb2948739c681 (7.3-rc1)
+CVE-2026-92487 [exfat: fix valid_size extension over a shared writable mapping]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1135704ed22f54873eb0498a232611d9eca30dd4 (7.3-rc1)
+CVE-2026-92486 [bpf: Fix CFI mismatch in task work callback]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2805abd089576799b15092949420e3f8ba97fabd (7.3-rc1)
+CVE-2026-92483 [liveupdate: Remember FLB retrieve() status]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5c4a03afcb21783987ffc64562b76ddd5a21b12b (7.3-rc1)
+CVE-2026-92479 [scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/331bda797e6afc143127ce72b1469d73316f49b4 (7.3-rc1)
+CVE-2026-92478 [scsi: ufs: core: Validate connected lane counts]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9e6dd452f1affb5c412ca64bf5809ce9fde3174d (7.3-rc1)
+CVE-2026-90432 [sched_ext: Abort directly from the hardlockup handler]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3c4b38064937a761ebbf85b1649e812db85eb59e (7.3-rc1)
+CVE-2026-90429 [iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a491be376abd1c80a314cdd658632c85cd660b73 (7.3-rc1)
+CVE-2026-90425 [iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fb292bfc9be936dade7eef7ec5762de1201983d8 (7.3-rc1)
+CVE-2026-90423 [RDMA/rxe: Fix UAF in ODP init error-handling path]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/51f2c8d2c99fc1f452f7113c08a35edcc4bf8732 (7.3-rc1)
+CVE-2026-90406 [media: qcom: iris: handle runtime PM resume failure in core deinit]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/75d79879ec3cbfd288144b0ae4c3e3fa7700c5fc (7.3-rc1)
+CVE-2026-90405 [media: stm32: dcmi: fix some error handling bugs in probe()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f1d1ed39ced825615aeac61f0b6a322178756632 (7.3-rc1)
+CVE-2026-90396 [block: fix dio leak on metadata mapping error]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/702a2a9f3dfe066a7481698c858371112f3cb697 (7.3-rc1)
+CVE-2026-90384 [iomap: release the folio batch on iomap callback failures]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/31e3d833d522746a93d135e8b465d16f8ad33453 (7.3-rc1)
+CVE-2026-90377 [wifi: mt76: fix RX data queuing of RRO 3.0]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/86897f106669c07eea4c34b54c3268d448d41426 (7.3-rc1)
+CVE-2026-90376 [wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ce35ecffc96e6d097d27b6fe30677a2cfe2e0461 (7.3-rc1)
+CVE-2026-90371 [wifi: mt76: fix RXDMAD_C buffer recycling race]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e1f97c10a4ec2b9db69a134b757304399ca903ce (7.3-rc1)
+CVE-2026-90369 [wifi: mt76: fix out-of-bounds access in mmio copy helpers]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6689b4a65e88d7b019e687fa9d6943ca070f3e43 (7.3-rc1)
+CVE-2026-90356 [wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7 (7.3-rc1)
+CVE-2026-90350 [wifi: mt76: reject out-of-range link ids in mt76_vif_link()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9ba744a28c26eaa5cae930688a22e01888395308 (7.3-rc1)
+CVE-2026-90349 [wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4330a0ef9f75a54fde3548432a9a698f06bab635 (7.3-rc1)
+CVE-2026-90342 [bpf: Fix mmap_lock deadlock on arena lock failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0b10b945479c954393d62ee3229d2f224a4ca91c (7.3-rc1)
+CVE-2026-90340 [pinctrl: generic: free maps on pinctrl_generic_to_map() failure]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/17007cd700601777d9ee203a13d97e64ece3a10f (7.3-rc1)
+CVE-2026-90339 [powerpc/syscall: Fix syscall skip handling for seccomp and ptrace]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/69cb2be898be6d5826cacd1a628f6945a24480b6 (7.3-rc1)
+CVE-2026-90338 [serial: amba-pl011: keep console clock enabled for atomic writes]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c0e8cfef754645856374e82c8effd54b7d82002b (7.3-rc1)
+CVE-2026-90332 [PCI: dwc: ep: Flush cached MSI write before unmapping the iATU]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1b01d725d8b42450b86a857bab3c46856c740166 (7.3-rc1)
+CVE-2026-90331 [HID: asus: refactor the two workqueues and init sequence]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/47669bec44fe12fe2c7adf2b299e980d7935a2ce (7.3-rc1)
+CVE-2026-90312 [bpf: Check load-acquire src ptr type before the load]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b87803391baa7e0bef60549d8841f12e549ad057 (7.3-rc1)
+CVE-2026-90310 [xen/xenbus: check otherend_id only after it has been initialized]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c76cbf348c7df077f93fa99a1225a527ce64cfa1 (7.3-rc1)
+CVE-2026-90305 [ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8a58a41100ea377e978d99600ec24a9bd0273662 (7.3-rc1)
+CVE-2026-90304 [ARM: 9484/1: enable interrupts when unhandled user faults are triggered]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e79ca91165d4fd18549c536abdb86101e889052f (7.3-rc1)
+CVE-2026-90299 [bpf: Fix sleepable check for tracing/lsm prog]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/00244bdaa423d93f4571f3f6854378ce3365e524 (7.3-rc1)
+CVE-2026-90288 [phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b780b8929c759cfa7a892d58625a5ad46cb1cbd2 (7.3-rc1)
+CVE-2026-90278 [md: wait for behind writes before destroying bitmap]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2a79365b2278f16e163e4024086105693b421601 (7.3-rc1)
+CVE-2026-90277 [md/md-llbitmap: prevent create failure bitmap UAF]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2116c2f0a0e547615886900e2ed8c529c016499b (7.3-rc1)
+CVE-2026-90276 [md/md-llbitmap: stop daemon timer rearm on destroy]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5553d64e01d9a995be6c3de38501c6dd4ceede3b (7.3-rc1)
+CVE-2026-90272 [perf: arm_pmuv3: Zero initialize hw_id branch stack field]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7c3b63386c27bed8d59a4b4c283d02860420eb0a (7.3-rc1)
+CVE-2026-90271 [arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fc996c39689bb15aa80e5366809434f7258fb703 (7.3-rc1)
+CVE-2026-90270 [arm_mpam: Disable driver unbind to avoid UAF]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bb1a0f582d519c0461b0940116e2b52c5ba31459 (7.3-rc1)
+CVE-2026-90269 [bpf: Reject load-acquire from pointers requiring fault protection]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7db0a00445f1a40bacfe9b747405c11cb5f10fc9 (7.3-rc1)
+CVE-2026-90268 [scsi: sd: Fix error handling in sd_probe() after large pool creation failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e3cc6ea1a745e7f5d326f919a428b244fa119d8f (7.3-rc1)
+CVE-2026-90266 [btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e549093c11a2fff8430df3dfbdb45eb9811a69a5 (7.3-rc1)
+CVE-2026-90258 [pinctrl: airoha: add missed IRQ resource helpers]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a02fa031b9520e46e98bff17e12b472eba770670 (7.3-rc1)
+CVE-2026-90252 [Bluetooth: MGMT: free the HCI command when it is cancelled]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/414b365ecea6c30357adee6b8a7c5edc03a03575 (7.3-rc1)
+CVE-2026-90246 [apparmor: fix integer overflow in verify_tags() bounds check]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/465946d3c560c0137e6a180ba054dddc4d049f5a (7.3-rc1)
+CVE-2026-90244 [iommu/dma: Restore locking around msi_page_list]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5a9e89ea34e0e34ac5d7e949042d665533549e40 (7.3-rc1)
+CVE-2026-90239 [media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem()]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fea97ee13c5332f67850733d6cefc1fe99460bde (7.3-rc1)
+CVE-2026-90238 [media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ef46d80a7015269a98c9505b5912a83798799199 (7.3-rc1)
+CVE-2026-90236 [NFSD: Release the export reference when reaping open stateids]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6480bd703684ed3f760e9e36c4a699033c0806ae (7.3-rc1)
+CVE-2026-90233 [nvme-pci: release descriptor pools on probe failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cb144c2f67128abfa5c7ba33318617d19f192156 (7.3-rc1)
+CVE-2026-90212 [arm64/efi: Avoid voluntary preemption with efi_mm installed]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e98a9d0146372b046d863164025a66ab4488b972 (7.3-rc1)
+CVE-2026-90210 [bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0253073fb7d79a2dd2eae9581ea16db2aef395a6 (7.3-rc1)
+CVE-2026-90197 [HID: haptic: don't write an uninitialized value to unhandled usages]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3efb7f6491526f5012f9ec94769e9ed832feeef8 (7.3-rc1)
+CVE-2026-90191 [mailbox: riscv-sbi-mpxy: validate RPMI notification lengths]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/11d5af151bcbe78f5a579e0faecd3be9cea0399a (7.3-rc1)
+CVE-2026-90181 [ublk: avoid teardown retry loop on xarray allocation failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4fd66a7f829f3f38f92a79081f0f2688aed644f0 (7.3-rc1)
+CVE-2026-90173 [smb: smbdirect: free completion queues with ib_free_cq()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fe2c0cacbcff9d56c03b296f68f22151c4223b04 (7.3-rc1)
+CVE-2026-90172 [smb: smbdirect: destroy QP before mem pools on accept failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/383a9480f5f40bc46454cce27ccfad532cedad9c (7.3-rc1)
+CVE-2026-90171 [smb: smbdirect: release pending child sockets outside the handler lock]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/db82fbe4bb68e68e4aef00ef5b79f92991d8ef8e (7.3-rc1)
+CVE-2026-90164 [smb/server: abort initialization when proc setup fails]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/db97f3763727d652112ae70038d4e17b3ce277bb (7.3-rc1)
+CVE-2026-90163 [smb/server: call ksmbd_proc_cleanup() on module init failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f43cbe3b58ce989ce420c3bc875d48e7754c8aba (7.3-rc1)
+CVE-2026-90145 [hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d0c2bed6927cbfa2cb51f240b4812bf6916bce0e (7.3-rc1)
+CVE-2026-90136 [platform/x86/amd/hsmp: Reject negative power cap writes in hwmon]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3921bb8635ff2836622df1cdf3194d4f3c1835a4 (7.3-rc1)
+CVE-2026-90134 [ntfs: fix kmap_local_page() usage in compress]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6e03fbd5f772ad24ea64f7632e4d0d73184787ca (7.3-rc1)
+CVE-2026-90133 [ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dc09bf79b76f9a7157e225f449655f3f62f96c9c (7.3-rc1)
+CVE-2026-90132 [ntfs: reject unprivileged writes to reserved $LX* xattrs]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ea6a67ef64451d2da298f15baa35865b4bb6372a (7.3-rc1)
+CVE-2026-90131 [ntfs: serialize resident iomap reads with mrec_lock]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d9e00c457d4ab8ab59c6e4b8554c921260e4e16c (7.3-rc1)
+CVE-2026-90129 [virtio_balloon: quiesce balloon work before device shutdown]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7e17eef04600c399c7e0f5ce765da5cf9d40d8e1 (7.3-rc1)
+CVE-2026-90127 [virtio: rtc: time out alarm requests]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/68e00d9212929805b40dcb9166755610f4f4acee (7.3-rc1)
+CVE-2026-90123 [irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b76eee9c2157223aa4aac42ceebb563288e078aa (7.3-rc1)
+CVE-2026-90120 [irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/328affc639ce9873a7a0a3fd6b8339f19767529b (7.3-rc1)
+CVE-2026-90118 [ntfs: fix off-by-one page overflow in ntfs_decompress()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/98716c9fce21f6c8a9d71e08cf53e7504fa562f4 (7.3-rc1)
+CVE-2026-90117 [ntfs: validate usa_ofs before preserving the update sequence number]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/81684340963da2e898eabb8c1e274433d9375bc6 (7.3-rc1)
+CVE-2026-90113 [netdevsim: update queue NAPI association on queue reset]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/07e98a4d5e9c292eae97c9cc5ab0937384e48492 (7.3-rc1)
+CVE-2026-90100 [ptp: netc: fix period truncation and potential divide-by-zero in PEROUT]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/777dbc9914b2f003f1d44af80c7a4a395c5961b2 (7.3-rc1)
+CVE-2026-90096 [fuse: invalidate the correct range after O_APPEND direct write]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2 (7.3-rc1)
+CVE-2026-90094 [arm64: process: Fix context switching MTE store-only tag check]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b8f070ac3167595069feb1f794c127b805115645 (7.3-rc1)
+CVE-2026-90089 [Bluetooth: btnxpuart: Validate the FW dump header length]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/060fa7592bdc043a93b6b7870f5b8551206d315d (7.3-rc1)
+CVE-2026-90080 [octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b09a0503c755b6609fad59a84cc7f05b6843a03c (7.3-rc1)
+CVE-2026-90077 [net: fix a resource leak in copy_net_ns() error handling path]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3220b62fbb8a55feebd2a826d5ead0f49f09ed5a (7.3-rc1)
+CVE-2026-90069 [crypto: acomp - allocate async request context when cloning]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ee440d4fc0d2f15894ab1f64c474a3adbc858880 (7.3-rc1)
+CVE-2026-90064 [drm/xe: Reject page faults from non-fault-mode scratch VMs]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5e977521d21717edb8e91d004434697d6e3f248c (7.3-rc1)
+CVE-2026-90059 [net: stmmac: restore NET_IP_ALIGN in the RX DMA offset]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/23680bf5f8c69c923546b84a8e6c401bef8b88fe (7.3-rc1)
+CVE-2026-90052 [dm-integrity: fix buffer overflow with keyed discard]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/59e6f919d77d72ec79cbf171256f2f7819737580 (7.3-rc2)
+CVE-2026-90051 [tcp: reject non zerocopy devmem tx]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/125755776bc6d4dd53eaf551c87e3d460625d638 (7.3-rc3)
+CVE-2026-90050 [net/sched: fq: clamp quantum and initial_quantum in change path]
+ - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/094cc07f98dfe70a34e2a1923af17fd29b8cf622 (7.3-rc3)
+CVE-2026-93204 [batman-adv: dat: atomically update mac addresses]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e6de568d3eda3e3c01c868fabd7a9535d5ee4a73 (7.3-rc1)
+CVE-2026-93203 [batman-adv: bla: avoid CRC corruption due to parallel claim add]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/08645ab95768b88e2ff85a89211994651710465b (7.3-rc1)
+CVE-2026-93202 [i3c: master: Fix recursive locking during device registration]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/456f832e5fc26fbfd3b8200fd4553eee520cc377 (7.3-rc1)
+CVE-2026-93201 [dm-pcache: validate seg_id fields from persistent memory]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/90c990a68460d7b5720e5634cf650eccdf0f4098 (7.3-rc1)
+CVE-2026-93200 [i3c: master: Fix use-after-free of master->this]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/feb0ed76601f3c2f91f08688c5a7d8b9d382f720 (7.3-rc1)
+CVE-2026-93199 [i3c: master: Do not treat master device as a duplicate target]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4dc1b3eeba7991905a5b5b8129ebea51be7d87b7 (7.3-rc1)
+CVE-2026-93196 [nvdimm: virtio_pmem: refcount requests for token lifetime]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e57140944b5a47a7fd5a142faab29a02af040bc8 (7.3-rc1)
+CVE-2026-93192 [drm/v3d: Clear queue->active_job when v3d_fence_create() fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/25a1669907512e927fab9ad4d4fb74ff57f63cd9 (7.3-rc1)
+CVE-2026-93191 [smack: fix incorrect task context in smack_msg_queue_msgrcv]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 (7.3-rc1)
+CVE-2026-93190 [platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a0a8cd9fc9c48b95095bcec4b146f7a99486f58e (7.3-rc1)
+CVE-2026-93189 [HID: core: quiesce input in hid_hw_stop() to prevent use-after-free]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a4bc41504690b7d7064931909874f5b98cd148b6 (7.3-rc1)
+CVE-2026-93188 [HID: roccat: bound device-supplied profile index]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/43fae42628a8c10fa8981773d7ec9f1a367821a7 (7.3-rc1)
+CVE-2026-93186 [cxl/mbox: Clamp mailbox output allocation to the payload size]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8a13db9f899d149c3aab24abcb668121cfda5a4f (7.3-rc1)
+CVE-2026-93185 [ASoC: rt700-sdw: always drain jack work on remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/612ccf42acd14bb2685fa60c3495ca13e63e8989 (7.3-rc1)
+CVE-2026-93184 [ASoC: fsl_audmix: rework runtime PM handling in probe]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3359ba93d01a23b2e4249e9e44ccfe48eb9c5d71 (7.3-rc1)
+CVE-2026-93183 [drm/lima: call drm_mm_init() with a valid allocation range]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 (7.3-rc1)
+CVE-2026-93182 [sched/fair: Fix overflow in update_tg_cfs_runnable()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4f166adb5cb0525d9e32d45729fd8f28c80acbee (7.3-rc1)
+CVE-2026-93181 [perf/x86/intel/uncore: Fix uncore_box ref/unref ordering]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/174f0582e38abe03b88e15f04bfe58490f88cb19 (7.3-rc1)
+CVE-2026-93179 [drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5d3cc8e388464f485d0944b87b8f9426e637d082 (7.3-rc1)
+CVE-2026-93178 [drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3a8a05477cda6c8293e2b629495b42981dcaba32 (7.3-rc1)
+CVE-2026-93177 [drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6fa33f594e46e775a94097f71b486d7b006b6917 (7.3-rc1)
+CVE-2026-93176 [drm/amd/display: Fix dangling pointer in plane reset function]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/98cad4bd1443975d972f4c7f705980da03722a22 (7.3-rc1)
+CVE-2026-93175 [drm/amd/display: Fix dangling pointer in CRTC reset function]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0aeed866cb938943908c3ba46422128e49d2d080 (7.3-rc1)
+CVE-2026-93174 [bpf: Copy per-CPU map value padding in copy_map_value_long()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7cf9cd98cf6f0df3befc167ca6b54c07014d71de (7.3-rc1)
+CVE-2026-93173 [bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8 (7.3-rc1)
+CVE-2026-93172 [mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2ebce860bdd7ae5e13002811bc9bbbf33fcfc221 (7.3-rc1)
+CVE-2026-93170 [dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0b6d055edb55ecadadf54e930c2b4fab76fa9a5a (7.3-rc1)
+CVE-2026-93168 [dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/aa99c4d1d63bbc26a5fc4c667d89b2595743c19d (7.3-rc1)
+CVE-2026-93167 [csky: Fix a4/a5 restoration in syscall trace path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/abb81e5ce7d995baa41556b8125fa59e28ba3be8 (7.3-rc1)
+CVE-2026-93165 [platform/chrome: sensorhub: Fix memory overread in ring handler]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d1ceb2b2324717fa30b44d56ef0c52813e239569 (7.3-rc1)
+CVE-2026-93164 [uprobes/x86: Move optimized uprobe from nop5 to nop10]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/554ba38456dad8053a1a80afe6ae6da9eff745cc (7.3-rc1)
+CVE-2026-93163 [hwrng: core - fix rng list on registration error]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3a5834db2b1ce25649f330e78efe1ccde78967fd (7.3-rc1)
+CVE-2026-93162 [crypto: qat - cancel work on re-enable SR-IOV timeout]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/455b0f3ac9e254edab9f5a873d337abe5e6e3604 (7.3-rc1)
+CVE-2026-93161 [crypto: qat - clear AES key schedule from stack]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9 (7.3-rc1)
+CVE-2026-93160 [crypto: atmel-ecc - reject hardware ECDH without a public key]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f240f9b588f4e2de89822adebf560a96b5d263ed (7.3-rc1)
+CVE-2026-93159 [crypto: atmel-sha204a - fix heap info leak on I2C transfer failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/72bbf11ba14bd7d5fbf31a1ec42fff608b657f74 (7.3-rc1)
+CVE-2026-93158 [crypto: sa2ul - stop probe if context pool creation fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d03f980a25853f6a380895119a572a3bb1194e8d (7.3-rc1)
+CVE-2026-93156 [crypto: rk3288 - fail ahash requests on HASH idle timeout]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ae150db7826f21e8d19e54fb6243169628809c4d (7.3-rc1)
+CVE-2026-93155 [crypto: keembay - Fix AEAD unregister count in error path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e264401ce4776a288524e5b87593d4d864147115 (7.3-rc1)
+CVE-2026-93154 [RDMA/irdma: Add refcounting to user ring MRs]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f67d8a08f60c9217df6d40da56422d2049f5e334 (7.3-rc1)
+CVE-2026-93152 [nvme-apple: Use acquire/release for queue enabled state]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f61c934aa084b7440fec681be3f4b481eb5a8609 (7.3-rc1)
+CVE-2026-93151 [nvmet-rdma: fix response resource leak on queue teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0114dd303b373522dea06053aabae34bdd33a7c4 (7.3-rc1)
+CVE-2026-93150 [cgroup/cpuset: Make nr_deadline_tasks an atomic_t]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/95220e1f18f6321008f021abc7d6f581f64bcb82 (7.3-rc1)
+CVE-2026-93149 [wifi: mac80211_hwsim: avoid NULL skb in stop queue drain]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/158438cd6ad69d6dd7d871582c38baf22169fede (7.3-rc1)
+CVE-2026-93148 [bpf: Reject MEM_ALLOC BTF accesses past object bounds]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9c9ee0324c774490ae953162aaaf4561d222bd93 (7.3-rc1)
+CVE-2026-93146 [time/namespace: Validate nanosecond field in proc_timens_set_offset()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/06aba58e58492d2b8eae059274caed29025ea96e (7.3-rc1)
+CVE-2026-93145 [clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/86b23609d5e17a770d03037e53c6a443e742a6e6 (7.3-rc1)
+CVE-2026-93144 [bpf: Reject writes through untrusted BTF pointers]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ac65c710cc643cbc52b899627577357867249530 (7.3-rc1)
+CVE-2026-93142 [thermal/drivers/rcar: Fix error checking in probe()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dd04ad1cdabcad51e34b74b4e91b9aeb7180d05d (7.3-rc1)
+CVE-2026-93141 [usb: gadget: r8a66597: avoid double free of ep0_req in probe error path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/41d541e3718db01668a4cd29815ee4b3b55f76d2 (7.3-rc1)
+CVE-2026-93140 [udf: Mark LVID buffer as uptodate before marking it dirty]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fb0601134c7e51728bd098abc6909315de1e5d86 (7.3-rc1)
+CVE-2026-93138 [bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/92863e678070f57c17c868e4bfa2441a5c61ad2b (7.3-rc1)
+CVE-2026-93137 [bpf: Fix use-after-free on mm_struct in bpf_find_vma()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/47b079e2117a2ee52e21f8b72935900c702fc0b5 (7.3-rc1)
+CVE-2026-93136 [bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6f12862600bb70e599a614d706a095ea5f8f9858 (7.3-rc1)
+CVE-2026-93135 [bpf: Reject programs with inlined helpers if JIT is not available]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f1c27922576edccb99d0257827d09bd05c0304a6 (7.3-rc1)
+CVE-2026-93134 [printk: Fix possible console use-after-free]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/36630cafbeede0b64c370edb2f7b4094327ee1e0 (7.3-rc1)
+CVE-2026-93133 [ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/20435bda13f1219891ed0ce41207e320a916ff9c (7.3-rc1)
+CVE-2026-93132 [ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3a56321d0aceee2a0bd80d23366401c131ff8350 (7.3-rc1)
+CVE-2026-93131 [platform/x86: dell-privacy: Fix race condition]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ca9338dbc64759b30741b12017c050b33c94dfa2 (7.3-rc1)
+CVE-2026-93130 [platform/x86: dell-wmi-base: Fix resource leak on module load failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/072841e02cf9c00a7e8a9c567a14239e02ca47ad (7.3-rc1)
+CVE-2026-93129 [platform/x86: dell-wmi-base: Fix handling of ultra performance key]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/adfd6846bea13667ff28f8aaf00c32fbd69825ab (7.3-rc1)
+CVE-2026-93128 [platform/x86: lg-laptop: Fix LED resource handling]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3e91964aa74ab261aa15d9d96318eded2fd9d22a (7.3-rc1)
+CVE-2026-93126 [remoteproc: qcom_q6v5_adsp: Fix reference leak for device node]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8c952807c2cebd5e9e9b37146c9383229794c129 (7.3-rc1)
+CVE-2026-93125 [bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2aaf67f0516fde29620d0edfc29c01b9ea7ad430 (7.3-rc1)
+CVE-2026-93123 [serial: qcom-geni: do not advance stale DMA completions]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7ea38c49e7178960926657863299face6dc0e1b0 (7.3-rc1)
+CVE-2026-93122 [usb: gadget: uac: validate rate list length before storing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/844d83d5964b87919b958ff48405188c6ddae9cc (7.3-rc1)
+CVE-2026-93121 [usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/621707dc67c9846fd876d7579ec951d92aa033f1 (7.3-rc1)
+CVE-2026-93120 [usb: gadget: configfs: fix out-of-bounds read of qw_sign]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f63edb54d8f738f9c21e2068c777ae1c097df6b7 (7.3-rc1)
+CVE-2026-93119 [usb: ljca: bound bank_num in ljca_enumerate_gpio()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dd9483726d0f16c1a56879c3edb65128259a4e2b (7.3-rc1)
+CVE-2026-93118 [usb: gadget: aspeed_udc: check endpoint DMA allocation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/97cee53a94be3bd4fd8fbed6071bd2f32dad1ab1 (7.3-rc1)
+CVE-2026-93117 [usb: fix UAF when probe runs concurrent to dyn ID removal]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ef8154d8b52d60338c1fd8d793cd8e891c604c14 (7.3-rc1)
+CVE-2026-93116 [platform/x86: asus-wmi: fix resource leaks on probe failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ef3daa2b84a2b8499ce9e2ce1c865dca36d39f95 (7.3-rc1)
+CVE-2026-93115 [platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c38cce70adef874c2a7b5132c14d6c221401deff (7.3-rc1)
+CVE-2026-93114 [platform/surface: acpi-notify: Check ACPI companion before use]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2b3a5dabe89e330413af403246b648c1890f368f (7.3-rc1)
+CVE-2026-93113 [clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/499b4cb6710f9a351d8b57a2132f9b4389d8464a (7.3-rc1)
+CVE-2026-93110 [RDMA/core: Wait for RCU callbacks before unloading ib_core]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7d75592114d1664623c8cf191a12b38052c04483 (7.3-rc1)
+CVE-2026-93109 [RDMA/mlx5: Drain RCU callbacks during module teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e37cdd75f8d61c1123d324ae5667ac3da562290e (7.3-rc1)
+CVE-2026-93108 [RDMA/ipoib: Drain RCU callbacks during module teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/31b7c700670830a0e8a4cdcd451c88a13cc5dc48 (7.3-rc1)
+CVE-2026-93107 [RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/15ae32c4a3551c4c9da457370bdfdd65d171e512 (7.3-rc1)
+CVE-2026-93105 [esp: do not unref managed frag pages in esp_ssg_unref()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/21697720ff43b8dfa25b8e8d9ca7f56f4597fc80 (7.3-rc1)
+CVE-2026-93104 [RDMA/rvt: Return NULL after port allocation failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2982eaf3b9d2d953318c74cd6f1b7576ea6d7b1f (7.3-rc1)
+CVE-2026-93103 [RDMA/hfi1: Preserve unit 0 on allocation failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2e3809ad8911f5d5581b3f046bd628417bface76 (7.3-rc1)
+CVE-2026-93102 [RDMA/hfi1: Free RX data on late probe failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8e17e101e04a3dc062e2719da57ff78c1c060632 (7.3-rc1)
+CVE-2026-93101 [media: v4l2-async: Unregister sub-device if asc_list is empty]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4e72f13d58c4245c177a9d5f54579345554f354d (7.3-rc1)
+CVE-2026-93100 [fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f5bcf539484d2d604c2f2330e09487ea090b21c7 (7.3-rc1)
+CVE-2026-93099 [fs/resctrl: Fix UAF from worker threads when domains are removed]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2566b5cd6a275c124e8f154fef6e815f92ec8d5c (7.3-rc1)
+CVE-2026-93098 [rpmsg: glink: fix deadlock in endpoint destroy during driver detach]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5a5a48e788e02fd8a8eb7188ce440572d6c12418 (7.3-rc1)
+CVE-2026-93097 [cxl/mbox: Break poison list loop on an empty payload]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8b301c4afbce4bc3f94528441d8d5ce1366504ad (7.3-rc1)
+CVE-2026-93096 [cxl/features: Serialize multi-part Get/Set Feature transfers]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/77b814c1832fde018c30357b4ec3fcdaa91a1c10 (7.3-rc1)
+CVE-2026-93095 [hfsplus: validate thread record before delete key rebuild]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e2ea5cac61acfc11dad22f1d2d4bc71d56c52a20 (7.3-rc1)
+CVE-2026-93093 [firmware: arm_scmi: Publish channel state before callbacks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0314900dcdde044af0208fed212035dbfaa55843 (7.3-rc1)
+CVE-2026-93092 [firmware: arm_scmi: Unregister device notifier before IDR teardown]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/66a0bbf30cc14140fe13f63cd594a7c1ee352b75 (7.3-rc1)
+CVE-2026-93091 [firmware: arm_scmi: Quiesce notifications before teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8e49055d0d495c9c07575ad8e111d9eaf0efb13f (7.3-rc1)
+CVE-2026-93090 [firmware: arm_scmi: Clean up channels on setup failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/687d67be3d87894ef12e8a164434612e0b53cfae (7.3-rc1)
+CVE-2026-93089 [firmware: arm_scmi: Free transport channel on IDR failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d72e7e5f24687c0490aabf317653caffe0447aeb (7.3-rc1)
+CVE-2026-93086 [firmware: arm_scmi: Avoid IDR updates while cleaning channels]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c38b1e19485aaa820e52cfe162525a8af67563da (7.3-rc1)
+CVE-2026-93085 [firmware: arm_scmi: Reject out of range DT protocol IDs]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/59407ccb52130f2c81f4b3cbe4f14114afceb54f (7.3-rc1)
+CVE-2026-93084 [firmware: arm_scmi: Drop handle on protocol bind failures]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e3a5c30d233ca5d3e799a80da806554c703bda13 (7.3-rc1)
+CVE-2026-93083 [firmware: arm_scmi: Unwind TX receiver mailbox setup failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6f7c06744d53dc8e047725d411d7f915d9ec35ae (7.3-rc1)
+CVE-2026-93082 [firmware: arm_scmi: Unwind P2A receiver mailbox setup failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f3e3773c4e5e96549d7540d8ddeb4fcd534f6f1d (7.3-rc1)
+CVE-2026-93081 [firmware: arm_scmi: Fix SCMI device destroy lifetimes]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6abe8fe36b29ff51d1a42c2f338972883f4751a5 (7.3-rc1)
+CVE-2026-93073 [dax: read holder_ops once in dax_holder_notify_failure()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7ae9d15bdcde0f2955ae13b6a95587f9e23b2359 (7.3-rc1)
+CVE-2026-93072 [irqchip/renesas-irqc: Fix generic interrupt chip leak on remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba (7.3-rc1)
+CVE-2026-93071 [media: bcm2835-unicam: Fix asc leaked in error/remove path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/253c9659e25131b0169f718e7d094ac1aa0d9279 (7.3-rc1)
+CVE-2026-93070 [media: ipu6: Do not free aux device pdata after init]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9be07216af4cfc4813e1a46ce26407d31ea845de (7.3-rc1)
+CVE-2026-93067 [drm/bridge: tc358767: clamp the reported AUX read size to the request]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ec6444a00c49e6c2b5e9a507272a28126677f9ee (7.3-rc1)
+CVE-2026-93065 [wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/71e67b4b59337b2f9f4fef976a27de2dad7aabf2 (7.3-rc1)
+CVE-2026-93064 [wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab (7.3-rc1)
+CVE-2026-93063 [wifi: iwlwifi: mei: check SAP message length before reading it]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7d8cc301bcba233f31b589a45f4c1c97f2bb90d6 (7.3-rc1)
+CVE-2026-93062 [wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9318bc0c41b24705690cf80d1596cf6b711e7027 (7.3-rc1)
+CVE-2026-93061 [gpu: host1x: Avoid stack over-read in debug output helpers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bc17ac285fb708f22a8fa2c0ed32eceb1d37e6d6 (7.3-rc1)
+CVE-2026-93058 [drm/msm: Only fini scheduler after successful init]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e2332abed2a4d3caa59052095dc16e4ce44791ea (7.3-rc1)
+CVE-2026-93056 [usb: gadget: f_uac1_legacy: remove broken string configfs attributes]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/590d74ec8f488e06b9f1c0f8f0941f45531f3a55 (7.3-rc1)
+CVE-2026-93055 [UDF symlink pathComponent header OOB read]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d23eb7380d1594cda31a5dc8487dd2a5c8def8c7 (7.3-rc1)
+CVE-2026-93054 [uio: Fix stale info pointer in failed registration path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/67b6fc084b034a91c3ec7907a3fed89a2450f30b (7.3-rc1)
+CVE-2026-93053 [speakup: keyhelp: guard letter_offsets possible out-of-range indexing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6a19ad4d68c95185308cd9e5d169b10a2cf236c8 (7.3-rc1)
+CVE-2026-93052 [misc: bcm-vk: Use acquire/release for msgq_inited]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/61b101c6a150057b6d512421ed108aed16e822ea (7.3-rc1)
+CVE-2026-93051 [misc: ad525x_dpot: use driver core groups for sysfs files]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e3a8557e88eb26278eda60bf64f2ef33ce7de8bf (7.3-rc1)
+CVE-2026-93050 [ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b6b5d64cb161a28347d64dc3168a636c4abb68d5 (7.3-rc1)
+CVE-2026-93049 [mtd: mtdswap: Avoid freeing registered blktrans device twice]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/779aa4c66a96bf43d2d62982ea1a9096a9128d87 (7.3-rc1)
+CVE-2026-93048 [mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b759d5bb6265419344ee9729fd0dc07ad85719d8 (7.3-rc1)
+CVE-2026-93047 [drm/v3d: Associate BOs with every job that accesses them]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fa98563ab00dbe62fcedfef6bdd34ded7a860d9f (7.3-rc1)
+CVE-2026-93046 [software node: Fix software_node_get_reference_args() with index -1]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ba3dedcf3bd47017307595a7e54924198f018246 (7.3-rc1)
+CVE-2026-93045 [bpf: Reject arena frees below the arena base]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b5a71cb2db6d84ac0042549dcec266b18429d41e (7.3-rc1)
+CVE-2026-93044 [bpf: Disallow interpreter fallback for arena-related insns]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/34746b5a84ec37c0ea2bf6808c65c5ed8790eb51 (7.3-rc1)
+CVE-2026-93042 [dmaengine: dw-edma: Terminate all descriptors without callbacks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/99109a51efd28c9a661fbfb9469b023c517b31d1 (7.3-rc1)
+CVE-2026-93041 [dmaengine: dw-edma: Serialize abort state updates]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dd80e259f65d932634e26d366570d71669ef6654 (7.3-rc1)
+CVE-2026-93040 [dmaengine: dw-edma: Serialize channel state checks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f7d1619f3e10c619b62c6cd6d95371b5c526c85a (7.3-rc1)
+CVE-2026-93039 [ASoC: meson: Keep link pointers valid on realloc failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2aaa41cf974f83a6fb105422bac4e2f107150774 (7.3-rc1)
+CVE-2026-93037 [RDMA/hfi1: Propagate sdma_txinit_ahg() errors]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/091c6162c022cbdfb64219708a71728cfd1d4600 (7.3-rc1)
+CVE-2026-92525 [RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/126c757e4cd46f866ddc283143b58eb4d9bf52cd (7.3-rc1)
+CVE-2026-92524 [irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/325ff3e78c64cd619d52b99f7c8b09a3f31e1495 (7.3-rc1)
+CVE-2026-92523 [RDMA/nldev: validate dynamic counter attribute length]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/74f49255492a62658f36bf2578d7916f1c6ffad1 (7.3-rc1)
+CVE-2026-92522 [ACPI: processor: validate MADT IOAPIC entry bounds]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2c50ffdc73f3a70d745d249f509fc290754121e6 (7.3-rc1)
+CVE-2026-92521 [ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8a742141f7ab84975aa758b775567ef4740ef0cf (7.3-rc1)
+CVE-2026-92520 [bpf: Zero queue and stack outputs on lock failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7ac6e1ae41a09f1dd4baeeff1d028ae49ee01232 (7.3-rc1)
+CVE-2026-92519 [riscv, bpf: Fix memory leak in bpf_jit_free]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/369e4635d04801f394d5bd42556f21029e95ff93 (7.3-rc1)
+CVE-2026-92518 [riscv, bpf: Fix kernel stack corruption in tailcall with CFI]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/52fb1756ea1d2759dfef2d86245be00b05dac3a2 (7.3-rc1)
+CVE-2026-92515 [bpf: Preserve unique-field state across nested structs]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f08619f060468076e4acbdc10e0713af20d60e65 (7.3-rc1)
+CVE-2026-92514 [RDMA/erdma: Fix CEQ tasklet use-after-free on removal]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0ca79979384f031d710c4b3bae065dcb5d95aca3 (7.3-rc1)
+CVE-2026-92512 [RDMA/core: Fix use after free in ib_query_qp()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/709ba0e5311bd034eb4d9c1c00cc4e1109d6dc3e (7.3-rc1)
+CVE-2026-92511 [RDMA/core: Fix potential use after free in ib_destroy_cq_user()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3481bec4dfc4aee24ffea5a547ee95b70b67d9d5 (7.3-rc1)
+CVE-2026-92510 [RDMA/core: Fix potential use after free in ib_destroy_srq_user()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/88244ecc71cc0b3ed200f5ef7ddea6686adfd730 (7.3-rc1)
+CVE-2026-92509 [RDMA/core: Fix potential use after free in counter_release()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/235ef2d0e750885c29340b0fc40620a7a4f52e12 (7.3-rc1)
+CVE-2026-92508 [RDMA/core: Fix potential use after free in ib_free_cq()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/29dc2f8e1c97372c2871a70088707933515fbd5b (7.3-rc1)
+CVE-2026-92507 [RDMA/core: Fix potential use after free in ib_dealloc_pd_user()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8b90e701342275f414e36e7421c502237df241ad (7.3-rc1)
+CVE-2026-92506 [firmware: arm_scmi: Fix requested device removal race]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2c4097e6c4aed276c5e9ec2ab331ab397ea780bf (7.3-rc1)
+CVE-2026-92504 [thermal: intel: int3400: clean up ODVP on probe failures]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d83dc9ce57a746a6dca28439bcc0575d26fa6986 (7.3-rc1)
+CVE-2026-92503 [ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/03438084a7b8621fb5c762dd3d04cff5f2630fb2 (7.3-rc1)
+CVE-2026-92502 [ext4: clear stale xarray tags on folios skipped during writeback]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ec524aae479b4b2078c47492b90ec21200bce434 (7.3-rc1)
+CVE-2026-92501 [ext4: drain in-flight DIO before buffered write fallback]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/15cdefd0c0522f9d5e12d947fa04f4c11649b699 (7.3-rc1)
+CVE-2026-92500 [ext4: use fsdata to track inline data write state and fix race]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7edbb323bab2b2a609016014caafdb651c898249 (7.3-rc1)
+CVE-2026-92499 [ext4: validate readdir offset before accessing dirent]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bc4b7b0414c33b2c8898eb04386df0d21a13dad8 (7.3-rc1)
+CVE-2026-92498 [wifi: ath6kl: avoid buffer overreads in WMI event handlers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f57314aade9d74d30f3360ec5ef85a83654748be (7.3-rc1)
+CVE-2026-92497 [wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7698656a2f7b045af5a6859766238cefea1b1945 (7.3-rc1)
+CVE-2026-92496 [wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9ef9dd30058cc9223c72f711dca1a28a5947d0c5 (7.3-rc1)
+CVE-2026-92495 [RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16 (7.3-rc1)
+CVE-2026-92494 [ext4: fix buffer_head leak in ext4_init_orphan_info]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/05704335803b69c1bfa8637b7ada942bf2ee8a41 (7.3-rc1)
+CVE-2026-92493 [cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8d31bb1451643f328db0cea0e21e63ef54b4faf2 (7.3-rc1)
+CVE-2026-92491 [firmware: arm_scmi: Roll back partial protocol table registration]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2224b622260ba590ab56ea1585d6bf7610be25b2 (7.3-rc1)
+CVE-2026-92490 [firmware: arm_scmi: Unrequest devices if driver registration fails]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86 (7.3-rc1)
+CVE-2026-92489 [xfrm: Fix skb double-free in xfrm_dev_direct_output()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2aed51fc58d9ce450e2c116efb956160fd06fa02 (7.3-rc1)
+CVE-2026-92488 [RDMA/erdma: complete object teardown when the destroy command fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/652befcba956ef357f480525ccbe25c59bc81d4d (7.3-rc1)
+CVE-2026-92485 [bpf: Fix WARNING in bpf_tracing_link_release]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/61aaa8782bec59ecffd22e030f54ef9351bcabf9 (7.3-rc1)
+CVE-2026-92484 [cxl/region: Fix use-after-free in find_pos_and_ways() error path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/15da704b732332cc1e8f121f624e5e6c05124c5d (7.3-rc1)
+CVE-2026-92482 [pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9c650317ba553d297f3fc5f0ae40ec53d86f9dab (7.3-rc1)
+CVE-2026-92481 [pinctrl: mediatek: free EINT resources on unbind]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/88292b7103d260e3e606eb3bb2794060a5fde48e (7.3-rc1)
+CVE-2026-92480 [scsi: ufs: core: Validate string descriptors]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d96e83d028d7d8762e424e49c671d49ac2ecf14f (7.3-rc1)
+CVE-2026-92477 [scsi: ufs: debugfs: Reserve space for a string terminator]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/abd26e6b53c4169122d61fdd4cabe09bdd916aac (7.3-rc1)
+CVE-2026-92476 [crypto: keembay - Initialize completion before requesting IRQ]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fce20289dd622cc7ab78d72c8a979a9f8b7cb10e (7.3-rc1)
+CVE-2026-90435 [RDMA/mlx5: Fix integer overflow of user QP buffer size]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dec47e4b0fe34afdf38caa72b4408ba95502e5de (7.3-rc1)
+CVE-2026-90434 [isofs: release zisofs block pointer buffer head]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2f7dd9b86fe4076059e6a4a2a2c5d565afd76b9e (7.3-rc1)
+CVE-2026-90433 [spi: oc-tiny: switch to managed controller allocation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d710f43ce30975d197f73c543bfe47b958d8ba17 (7.3-rc1)
+CVE-2026-90431 [remoteproc: Prevent crash handling to race with rproc_del()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/74ee3b2f5767447c57959994341e5b95f1079977 (7.3-rc1)
+CVE-2026-90430 [iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cbc41aacd49e695338940196e7084770365e1b68 (7.3-rc1)
+CVE-2026-90428 [iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5acd67ceb38debe2fbf70ea35e2dec9f7ab01bbd (7.3-rc1)
+CVE-2026-90427 [iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d4d05f55e9da646ec03adfa77260eb46f4163749 (7.3-rc1)
+CVE-2026-90426 [iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/61f0d437988e5730b04442f6a7d30a9907339f2a (7.3-rc1)
+CVE-2026-90424 [iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f40f3144477314b489e4bc209c06cb51679fe82b (7.3-rc1)
+CVE-2026-90422 [clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/540d91480bcb1b28a62d7023aa70947ea44c55b9 (7.3-rc1)
+CVE-2026-90421 [PCI: Fix UAF when probe runs concurrent to dyn ID removal]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3ffc4c9690c33ee28cdb3d0182b12f9c623e3acc (7.3-rc1)
+CVE-2026-90420 [nilfs2: fix infinite loop in nilfs_clean_segments()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18 (7.3-rc1)
+CVE-2026-90419 [nilfs2: prevent out-of-bounds read in super root block parsing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7cb2f76a6a2ba2130b577cb8ac13e1e46c4fc689 (7.3-rc1)
+CVE-2026-90418 [nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/66f4ad3ce158902e5f98afea93189972ed8750c2 (7.3-rc1)
+CVE-2026-90417 [RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/373f3716a2de7adc739269ebb4d87e5bf4dc180c (7.3-rc1)
+CVE-2026-90416 [RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/03826bc1fa6c90405bf05831f2b501a8368dcd27 (7.3-rc1)
+CVE-2026-90415 [RDMA/cxgb4: free STAG index when TPT entry write fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fdfb5cea4bf070cdb31d997efd87bb684df041fd (7.3-rc1)
+CVE-2026-90414 [IB/isert: reject PDUs declaring more data than was received]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/957f92ea4022fb6af4618271615a2a21a7b5bef9 (7.3-rc1)
+CVE-2026-90413 [IB/isert: reject login PDUs declaring more data than was received]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2488b5b4827e5415768afc8daf097e8eb83c98df (7.3-rc1)
+CVE-2026-90412 [nvmet: fix return status of RMI log page on allocation failure]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/581d8bb556dd3e5567bcf322aa5e3e4b6a200c08 (7.3-rc1)
+CVE-2026-90411 [nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f49d0c3a8d56a7cda1628ae17341a4a42063563c (7.3-rc1)
+CVE-2026-90410 [spi: davinci: switch to managed controller allocation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ea408a05dc8f18b4a184b88d6e19d2fd1acc1527 (7.3-rc1)
+CVE-2026-90409 [drm/panthor: Add vm_bind region with kbo range overlap check]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/985f5e12f3cdf43030e13c2bbd154913133b5c3f (7.3-rc1)
+CVE-2026-90408 [wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/878654eb78c6aa0ff585baf1376567c775ca28ec (7.3-rc1)
+CVE-2026-90407 [wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/208d7fdb85976a737a715b81d54efaff6703880c (7.3-rc1)
+CVE-2026-90404 [platform/chrome: cros_ec_debugfs: Unregister panic notifier]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e5954d3031fb55dd31aa59bae477d63c68e941c0 (7.3-rc1)
+CVE-2026-90403 [wifi: rtlwifi: pci: fix error path in rtl_pci_probe()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3c2999d13eeb222ae56631aeb7ca248090f2b210 (7.3-rc1)
+CVE-2026-90402 [bus: mhi: host: Fix controller cleanup on EDL sysfs failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0d5b9e66591d4e2a4376ac82c8cda889a29ba3ee (7.3-rc1)
+CVE-2026-90401 [md: remove REQ_NOWAIT support from raid1/10/456]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3fe5b7c9fb72ccc29bfd0f955b124892af7e3674 (7.3-rc1)
+CVE-2026-90400 [md: recheck spare changes before starting sync]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c7d34d17ea43ebc86b45d439ebb435e11ca44bca (7.3-rc1)
+CVE-2026-90399 [wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4c6eb712a91fa079be6f9f1419c96e0ad2227081 (7.3-rc1)
+CVE-2026-90398 [wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7a246c72132eb943b5844ba79dad597b47429dba (7.3-rc1)
+CVE-2026-90397 [firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/966d23c7e68ea32679275a7e3d2383181002c868 (7.3-rc1)
+CVE-2026-90395 [power: supply: isp1704_charger: cancel work on remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/60c5b8a9ef4dbc5d69bbc1a960fe55826cb3b643 (7.3-rc1)
+CVE-2026-90394 [power: supply: sc2731_charger: cancel work on remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dfc859bb8d332c525872f1a44028137724fa1998 (7.3-rc1)
+CVE-2026-90393 [bpf: Fix potential UAF in bpf_netns_link_update_prog]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5c5997836381010fc5907b36bc17d3b19407e933 (7.3-rc1)
+CVE-2026-90392 [bpf: Fix potential UAF when reading bpf link info]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/863f3ddd0b8ac65abfb50d3be0869268ac0e277b (7.3-rc1)
+CVE-2026-90391 [lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6a8024511ddf4877435c34fb3d6028aa8e590649 (7.3-rc1)
+CVE-2026-90390 [md/bitmap: resume array on backlog_store() error path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2911cd0a0f4366a7e06832bc5f0a7fdcc138e4dc (7.3-rc1)
+CVE-2026-90389 [md: scope memalloc_noio to allocation critical sections]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bace2010dd7ac07bc980575afb135c406730a7fe (7.3-rc1)
+CVE-2026-90388 [iommu/dma: Check atomic pool allocation result directly]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/af95a0ebc0a0db0762be75f51eadf770bad01aaa (7.3-rc1)
+CVE-2026-90387 [swiotlb: Preserve allocation virtual address for dynamic pools]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/57d29044d0f29a76c6ec0c112c8c7371d5608dc7 (7.3-rc1)
+CVE-2026-90386 [i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/038cf48b3170af26a70bf2dee4f8c3ac910f5176 (7.3-rc1)
+CVE-2026-90385 [md/raid1: create serial pool adding rdev to array with serialize_policy=1]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/140234b2380ffb8ffb0cfc46fee0e822f43adef7 (7.3-rc1)
+CVE-2026-90383 [misc: sgi-gru: remove interrupt-context page-table walks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/928a8e9f523df845fc496bcb9811013b67aabec5 (7.3-rc1)
+CVE-2026-90382 [wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/81497634d9f872fd3e8b03aada55574afff6f174 (7.3-rc1)
+CVE-2026-90381 [wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/70869cc429fffc77de51e7777c0ecb651e8fca07 (7.3-rc1)
+CVE-2026-90380 [wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/217f9e7bb02558759be9d9ecfe532e9708741c50 (7.3-rc1)
+CVE-2026-90379 [wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/915672c5ae32deeb72f4572856d123f314791136 (7.3-rc1)
+CVE-2026-90378 [wifi: mt76: mt792x: Fix memory leak in SDIO TX path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/808f2767d4217a5b96f674288573b9b89d432eed (7.3-rc1)
+CVE-2026-90375 [wifi: mt76: fix non-AQL packet accounting for MLO stations]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8ae659743ba936b22ecb4620815887728e2820d6 (7.3-rc1)
+CVE-2026-90374 [wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2243778a5fae8329ab5f18e7adcd7e03b911a1b7 (7.3-rc1)
+CVE-2026-90373 [wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba (7.3-rc1)
+CVE-2026-90372 [wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4a2f4be532e3ea4e2b536e411793a05aaa51af25 (7.3-rc1)
+CVE-2026-90370 [wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/44af52467e72094351a362bf69effd52f1d9c186 (7.3-rc1)
+CVE-2026-90368 [wifi: mt76: mt7915: unwind state on add_interface failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2fb6480c52f611338e1b0abe5e6219be1fc9ab75 (7.3-rc1)
+CVE-2026-90367 [wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6190db312b8230813f529f014b26247c6d9800d0 (7.3-rc1)
+CVE-2026-90366 [wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/50c66bab321140c49aa2ed779a3ec9d2f085b458 (7.3-rc1)
+CVE-2026-90365 [wifi: mt76: cancel reset and rc work on device unregister]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e995d3dccc9d980af13a60ad37409ed1561f9eeb (7.3-rc1)
+CVE-2026-90364 [ACPI: processor: Unregister cpufreq notifier on init failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/06f32dd67e6b23a05bef0d8183c5335af91c0c3b (7.3-rc1)
+CVE-2026-90363 [drm/msm: don't tear down KMS twice when KMS init fails]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/93c125e4ea98fb25f927ba5a334d85845127d667 (7.3-rc1)
+CVE-2026-90362 [drm/msm/dsi: Drop dev_pm_opp_set_rate(0)]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/06b7ba206561619bb34116f49e0ef26b867ce3aa (7.3-rc1)
+CVE-2026-90361 [wifi: ath11k: fix leak in ath11k_service_ready_ext_event()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0293be2212d319d59589082461abf2a9b626cd1c (7.3-rc1)
+CVE-2026-90360 [regulator: core: use system_freezable_wq for init complete work]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/03eab318cedd6ae34ecd34533cd986edf5237164 (7.3-rc1)
+CVE-2026-90359 [bpf: Reject >8 byte return values on return-reading trampoline paths]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c48796aa6c392cde93946e5d5a9a1f1b1cf72feb (7.3-rc1)
+CVE-2026-90358 [bpf, x86: Fix trampoline stack size for 128-bit arguments]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/814cba835ef648e0c5eb79505c96c0493b29eea6 (7.3-rc1)
+CVE-2026-90357 [wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/16a04441eab0dcd4d7126a6f66b370adbf28f96d (7.3-rc1)
+CVE-2026-90355 [wifi: mt76: mt7996: clear stale link state on full reset]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/75d2a4e2129b58bb0ddb842387299038495aad2a (7.3-rc1)
+CVE-2026-90354 [wifi: mt76: mt7915: fix double hif2 init on the non-WED path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3ae8ad277e2819a281b0e36b55633c8515c16ce7 (7.3-rc1)
+CVE-2026-90353 [wifi: mt76: mt7915: fix ext PHY use-after-free on register error path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/15b960014f24dce5388d4a2e7274e6490cb3c421 (7.3-rc1)
+CVE-2026-90352 [wifi: mt76: mt7915: release hif2 reference on probe IRQ failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8370aebd26a9dfa2e0de665e3ab504c0e97ee730 (7.3-rc1)
+CVE-2026-90351 [wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/7c1924332e986019c6bcddf55c843361cccac73f (7.3-rc1)
+CVE-2026-90348 [wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4f25071afe9218aaae1c63fbf75e229aa6405319 (7.3-rc1)
+CVE-2026-90347 [arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/88b839ce497ccb1ff92f7ae742c78dd2937ba572 (7.3-rc1)
+CVE-2026-90346 [wifi: nl80211: clean up color-change beacon data on errors]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/927ee844c47ac2aef22c8f7a35f098ff576b398b (7.3-rc1)
+CVE-2026-90345 [wifi: brcmfmac: fix P2P action frame handling without device vif]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1b1edb9ebed49099bdc924cef49a9aea8b552199 (7.3-rc1)
+CVE-2026-90344 [wifi: mac80211: disconnect on CSA to channel 0]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cf57f0a674cc3e3cda1a789359cc1238b61b9d7d (7.3-rc1)
+CVE-2026-90343 [wifi: cfg80211: stop PMSR before P2P and NAN teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6c5fc504d0d6934132637aa3db4b9b58148eaa78 (7.3-rc1)
+CVE-2026-90341 [firmware: coreboot: Validate table bounds]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a58a57a1076f8c5dae0327e3710899478c3be901 (7.3-rc1)
+CVE-2026-90337 [serial: core: do fallible allocations before the console can be registered]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1a0e4fbce5d9c1bc179a35a2fd9ed142664299e3 (7.3-rc1)
+CVE-2026-90336 [serial: core: clear freed pointers on uart_register_driver() failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/61a2fb25551be0375bc16ef2a70c987dfca26183 (7.3-rc1)
+CVE-2026-90335 [tty: skip cdev_del() when no cdev is registered]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c3b5623fd97648f2747444aa8932ae604662df93 (7.3-rc1)
+CVE-2026-90334 [tty: clear cdev pointer after cdev_add() failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6645856f0df3aeecd45519cb611415b4b89c2223 (7.3-rc1)
+CVE-2026-90333 [dm-integrity: replace forgeable discard filler with a keyed sector marker]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/68c5c42567bc462139128968ebbfadd0aefff519 (7.3-rc1)
+CVE-2026-90330 [HID: logitech-hidpp: Fix FF device cleanup on init failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dd5be4d9ce2dfc4d4a4527ef7d31d21a78e3cdac (7.3-rc1)
+CVE-2026-90329 [HID: synchronize input before cleaning up a failed probe]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/207853d46f7ef2e28042344a1468da8754c3ddbf (7.3-rc1)
+CVE-2026-90328 [HID: steam: Reject short reads]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/33ff7b49c38b39b1f3d27db508ac0720fb25c08a (7.3-rc1)
+CVE-2026-90327 [phonet: pep: do not write beyond optlen in getsockopt]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/77e5eb0e192aec6710c03ca8144582fd2af36ca4 (7.3-rc1)
+CVE-2026-90326 [blk-cgroup: fix race between policy activation and blkg destruction]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5313d4d41739b0cb63000747c97bb1217ac45f3e (7.3-rc1)
+CVE-2026-90325 [blk-cgroup: skip dying blkg in blkcg_activate_policy()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5e9220389920f33b6a804d50c548cd0cd1b04634 (7.3-rc1)
+CVE-2026-90324 [ublk: check import_ubuf() return value]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3831568792af75b6523fa93bb91560e29189cf55 (7.3-rc1)
+CVE-2026-90323 [ublk: validate auto buf reg before taking uring_cmd]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ca5a01eee34c7cbe0f531a613b0292a3ad1a419b (7.3-rc1)
+CVE-2026-90322 [ocfs2/cluster: keep heartbeat local node stable]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/688bc88e2046dd6ce81ce18079b5254cb8dadc0e (7.3-rc1)
+CVE-2026-90321 [ocfs2: validate inline xattrs during inode block validation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8914a3330b72378136c2c02d6328a826f6abdad7 (7.3-rc1)
+CVE-2026-90320 [ocfs2: validate external xattr entries when reading metadata]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6 (7.3-rc1)
+CVE-2026-90319 [rapidio: clear mport->net when rio_add_net() fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b74030fbf187b43c1f85b66a7082e9946511cb5d (7.3-rc1)
+CVE-2026-90318 [fat: release buffer head after rebuilding parent]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/83e98dbf19ab64e8528e101e20f8d50e1aaa68a8 (7.3-rc1)
+CVE-2026-90317 [bpf: Invalidate RCU pointers after final spin unlock]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/180c7000712db77063b3a26f4c97e7dd9038f449 (7.3-rc1)
+CVE-2026-90316 [drm/omap: dsi: Do not copy isr table]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/97c03b32b28a9f7f13f768f2b06e1eaafe850e66 (7.3-rc1)
+CVE-2026-90315 [PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/747b9bbbbdfdee51aee2456388f9b94b5086de4d (7.3-rc1)
+CVE-2026-90314 [remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bb840ea69347aff7bde5a208e7b5b180669a7656 (7.3-rc1)
+CVE-2026-90313 [bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6655c409707ec8ce9ce0850ffe4fe02331fd4d9c (7.3-rc1)
+CVE-2026-90311 [thermal: hwmon: Remove hwmon class device along with its parent]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2b57e24d34b2dfc43c81942bb359d6315bf302fb (7.3-rc1)
+CVE-2026-90309 [RDMA/erdma: Hold CQ references when processing EQ events]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/98df2aee1459ee1c62c70cbe9b370d2a532aea36 (7.3-rc1)
+CVE-2026-90308 [RDMA/erdma: Hold QP references for AE and CM processing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a52eeff32024f190b3bdc99088c7becccd4fa60b (7.3-rc1)
+CVE-2026-90307 [RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/961ac0f0c5e414abdd6b33fae84b311d9fde0bd0 (7.3-rc1)
+CVE-2026-90306 [ARM: 9481/2: breakpoint: CFI breakpoints only on demand]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8ed9bff906cf8036531d1559f10e82733a52b41f (7.3-rc1)
+CVE-2026-90303 [ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1039bffd6ae9c75b42b7d148d6c1106134107b66 (7.3-rc1)
+CVE-2026-90302 [ocfs2: synchronize heartbeat callbacks with o2net teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3e326f3bf16506873777444608e8b715aab74a7a (7.3-rc1)
+CVE-2026-90301 [ocfs2: o2hb: quiesce negotiate handlers and timeout work]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/011291b70ba4832e136b7b581825b2bc0f525bf6 (7.3-rc1)
+CVE-2026-90300 [bpf: Clear buf on error in __bpf_get_task_stack]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f5d242825ca417bb6afe35fde6e8880f97ca43fb (7.3-rc1)
+CVE-2026-90298 [drm/sun4i: tcon: Drop TCON TOP device reference]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8208832a38ff3d2560eb8a77a9d7a2f17d8ebcdc (7.3-rc1)
+CVE-2026-90297 [drm/sun4i: crtc: Propagate layer initialization error]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7061ff05ed4a3cf16e83f7e3ad09cbd212508a32 (7.3-rc1)
+CVE-2026-90296 [cpufreq: imx6q: fix devres accumulation across driver rebind]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/22c23c72c3b21fa3ec3db5070dfc0582794e0ef9 (7.3-rc1)
+CVE-2026-90295 [cpufreq: imx6q: fix out-of-bounds write when probed more than once]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8c3afcf27fa4582c1ab912503dc8a4ebb8dc0f82 (7.3-rc1)
+CVE-2026-90294 [IB/isert: delay the final Login Response until the session is registered]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/464f5afa92d071a226f88424803b0fcf88093ede (7.3-rc1)
+CVE-2026-90293 [IB/isert: post the full-feature receive buffers after session registration]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5247dde9daac7e107853b6fea043f7f47be033f7 (7.3-rc1)
+CVE-2026-90292 [RDMA/siw: Fix use-after-free in siw_accept()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a9394971825933074032794a5feee5211509c774 (7.3-rc1)
+CVE-2026-90291 [module/dups: Fix use-after-free in kmod_dup_req lifetime handling]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/5eecb11b543f9f417bcf0dea239ff99c6af65dbd (7.3-rc1)
+CVE-2026-90290 [arm64: hibernate: Restore DAIF state on error]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/541549827889d0380fd73f8aacb5de6ef7a5a1ac (7.3-rc1)
+CVE-2026-90289 [drm/amd/display: Resize MST HDCP per-connector arrays to 32]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/261e0fe4e2c99f687114b64b10b98db964b475f4 (7.3-rc1)
+CVE-2026-90287 [phy: sunplus: fix error handling in sp_uphy_init()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8b2683bc4cc18c581b7cd24f227cbe61abca7f4d (7.3-rc1)
+CVE-2026-90286 [drm/amdgpu/gfx6: Use PFP on the compute queues too]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/60f20946cd318518ddc2c0da12103c666b2b9564 (7.3-rc1)
+CVE-2026-90285 [scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5cbc49d5c4cd20c18041e86958103045216d2190 (7.3-rc1)
+CVE-2026-90284 [firmware_loader: do not queue completed sysfs fallback requests]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b48373c901951fad1a26bd7c33ad91172b3945b5 (7.3-rc1)
+CVE-2026-90283 [hugetlbfs: release subpool on fill_super failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/308ab73e97c87bd0e142b11758faab7f88d82854 (7.3-rc1)
+CVE-2026-90282 [phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8e3687f7e18fe84372e86875709d56c37e7525a8 (7.3-rc1)
+CVE-2026-90281 [phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c271a6926ea7d3c9566b033d63fd4e8c488dc860 (7.3-rc1)
+CVE-2026-90280 [phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/142c5593379273264474f31d5956b1a0065cd576 (7.3-rc1)
+CVE-2026-90279 [md/raid5: round bitmap stripes with sector division]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/17ea021ae74987d6064c8195c4922fa025753892 (7.3-rc1)
+CVE-2026-90275 [md/raid1: don't set array_frozen in raid1_takeover()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/dc386aa0ac0a3ec06c9a3ea9b064b073fb72a916 (7.3-rc1)
+CVE-2026-90274 [coresight: etm4x: fix underflow for usage of (nrseqstate - 1)]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1674d9bff8073bdee5dbc200f56fc3caa28d0566 (7.3-rc1)
+CVE-2026-90273 [coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0a47f0be6557b4a851addd430383a4dc7ee08752 (7.3-rc1)
+CVE-2026-90267 [scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bb31844d88b77138b67aa20c3600203baff40140 (7.3-rc1)
+CVE-2026-90265 [btrfs: defrag: fix deadlock between defrag and delalloc space reservation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ba02eab28041f9a4bbe9fc90c7249644fef6de0f (7.3-rc1)
+CVE-2026-90264 [btrfs: always wait for ordered extents to avoid OE races]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ec78575dde998c21be7e0cb2503b5620f34b6255 (7.3-rc1)
+CVE-2026-90263 [btrfs: check if root is readonly when setting posix acl]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/01c2f41fc441f75b3f9326443372faceb1cb6638 (7.3-rc1)
+CVE-2026-90262 [btrfs: retry verity reads for not-uptodate Merkle folios]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/8cc569696dac51fc62bb39b3b8f530582b916d29 (7.3-rc1)
+CVE-2026-90261 [btrfs: zoned: flush active metadata block group at btree_writepages() start]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ecc05eda9a346848ae01a6c8bfa3f0bec133bd8b (7.3-rc1)
+CVE-2026-90260 [btrfs: zoned: don't clobber the extent buffer when zeroing it out]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/db4b9eefc8ee0bcaeee4d5e6a7313905f6a2fe7c (7.3-rc1)
+CVE-2026-90259 [btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9102b179512e11644fb0489ae62010a09afa199c (7.3-rc1)
+CVE-2026-90257 [Bluetooth: virtio_bt: avoid OOB read of build info string]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/502adc06ba76dee19c292ae4a07d74d202fe734d (7.3-rc1)
+CVE-2026-90256 [Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2b66c83ff1751d6bd3201b3017206262ab46dc05 (7.3-rc1)
+CVE-2026-90255 [Bluetooth: hci_conn: fix the SCO setup context lifetime]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/42de40abe25db9211107af8896d0fd741f10648d (7.3-rc1)
+CVE-2026-90254 [Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/120d8dc042e3d45073bb6e50ee7b058a0b182627 (7.3-rc1)
+CVE-2026-90253 [Bluetooth: MGMT: free the mesh send cancel command when it is cancelled]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3c742feda8fcabf741a17bcf668b63c8f606f9c5 (7.3-rc1)
+CVE-2026-90251 [Bluetooth: MSFT: validate evt_prefix_len against the response length]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0079e1a944634ab2dc1c7cdec1144486d096407e (7.3-rc1)
+CVE-2026-90250 [bpf, cgroup: Fix storage null-ptr-deref after replacing prog]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3f562c537e9ecf4bc5e206cfffc2cc047f1b7e94 (7.3-rc1)
+CVE-2026-90249 [iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/579c049b4cb6fc72ce2c505fc5334540be0efcd3 (7.3-rc1)
+CVE-2026-90248 [net/sched: cls_api: fix teardown of an adopted proto on insert-race loss]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d4e359b3608a0e184bbe8d61a5c3b50d0831c44a (7.3-rc1)
+CVE-2026-90247 [bpf: Fix mmap_lock leak in irq_work path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fa9dcacdcdf487f0ffef64bf67622f1caed509f1 (7.3-rc1)
+CVE-2026-90245 [fbdev: kyro: Validate overlay viewport coordinates]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7b5c7bc55e13e7f5ac7b1eaf5c6d690389ea5ee3 (7.3-rc1)
+CVE-2026-90243 [iommu/vt-d: Clear Present bit before tearing down copied context entry]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f532c57985b1a7d6b7e37e05506b46d413e5cca4 (7.3-rc1)
+CVE-2026-90242 [iommu/vt-d: Fix iopf_refcount leak on RID domain replacement]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/236dd58fabd2e951b940a6ad88b81147899ed311 (7.3-rc1)
+CVE-2026-90241 [iommu/vt-d: Tear down scalable-mode context on probe failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c509fb73a1093a15accd7d43a61645d4b520f6ac (7.3-rc1)
+CVE-2026-90240 [iommu/vt-d: Flush context cache with correct SID when tearing down aliases]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c54e4ae971b98e8d650400137d332cee56c03f55 (7.3-rc1)
+CVE-2026-90237 [netfilter: nft_ct: move custom expectation support to helper]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3679da4ad8be84cddaf40bc307fef1fe13e051ff (7.3-rc1)
+CVE-2026-90235 [sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/33930840b5f0a79f826e7c69dc6cd78f72a67481 (7.3-rc1)
+CVE-2026-90234 [NFS: Return a delegation the client fails to record]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/220af23d863995091f0edeb1e6aa0945b3db8b37 (7.3-rc1)
+CVE-2026-90232 [amt: Don't support cross-netns setup.]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06 (7.3-rc1)
+CVE-2026-90231 [apparmor: fix unconfined user namespace restriction forced stack]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/08c2f7c8d4b1434cfae006f3daf4d1bce330b57b (7.3-rc1)
+CVE-2026-90230 [nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5bb96cc218835769ab74ec7f3ea2bf81fbffe955 (7.3-rc1)
+CVE-2026-90229 [nvme-apple: Destroy the admin queue on removal]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/87d5b9864c8118d26f54de4b66d2bddf2c659272 (7.3-rc1)
+CVE-2026-90228 [nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f594863967d87b7fcbff6e724d51135fd701a13d (7.3-rc1)
+CVE-2026-90227 [nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b53d495c7f0db46b6748b5ade48371a10dd5d3bc (7.3-rc1)
+CVE-2026-90226 [nfc: llcp: avoid userspace overflow on invalid optlen]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/99985bfa8336fadcc69190ba2dcbd5386af3d661 (7.3-rc1)
+CVE-2026-90225 [nfc: llcp: read llcp_sock->local under the socket lock in getsockopt]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/36812527052c5bfb1ec6c1e292d67a5bf76b750f (7.3-rc1)
+CVE-2026-90224 [nfc: nci: fix double completion race in nci_data_exchange_complete]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8265a626cc14a48e46e6dc8c47667e72b4232ac2 (7.3-rc1)
+CVE-2026-90223 [nfc: llcp: bound SNL TLV parsing to the skb and add length checks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f4c7f37f0ab990952539dc68d931d65c3657600a (7.3-rc1)
+CVE-2026-90222 [nfc: pn533: hold a reference to the request skb during send_frame]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/47792358a624ea066455ef86b744159928cd7716 (7.3-rc1)
+CVE-2026-90221 [nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d56575a2595ee1f597f39e8a1cfb67ed3501678d (7.3-rc1)
+CVE-2026-90220 [ALSA: seq: Don't leak the extension cell pointer in the bounce payload]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/59e1592d3c270ff4642d5d6dc55c545306eb0693 (7.3-rc1)
+CVE-2026-90219 [RDMA/cxgb4: Free debugfs on registration failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fe5c16bb6252dea6025b748257ddc3b2665495b0 (7.3-rc1)
+CVE-2026-90218 [RDMA/cma: Fix WARNING in res_to_rt]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c6d1ec4fbe56492bb88987d577f04a5fb6955f26 (7.3-rc1)
+CVE-2026-90217 [bpf: Compare iterator types during state pruning]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/83608e303b95d07afba1c15da0b5d9e513c2f15a (7.3-rc1)
+CVE-2026-90216 [ubi: Fix rollback for explicit UBI device numbers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5b0a6b554e12a97f9771a9a9f4ea1f5457373c73 (7.3-rc1)
+CVE-2026-90215 [mtd: ubi: Release device reference on busy detach]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/31dd710cd84d5dd63c49f640d3a9f36c9699ca95 (7.3-rc1)
+CVE-2026-90214 [ASoC: xilinx: formatter_pcm: fix stream_data leak on open error]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b992511180e126150c6ad3580a6fd568c385f4c6 (7.3-rc1)
+CVE-2026-90213 [firewire: core: fix memory leak in error path of build_tree()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/05bfb1327dc5fb61528bab31cd8f0c1e4bddec23 (7.3-rc1)
+CVE-2026-90211 [bpf, s390: Clear fetch destination on faulting arena atomic]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cc3e12330599f097f0e1f792435686ddc276f26d (7.3-rc1)
+CVE-2026-90209 [s390/debug: Fix deadlock during unregister]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/445c31ac638fd1af203d79bdf25fc0cb3149fbbc (7.3-rc1)
+CVE-2026-90208 [clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3b212f9d70805d91febae01d618868f4860e267c (7.3-rc1)
+CVE-2026-90207 [ALSA: seq: midi: Serialize input teardown with event_input]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/403f7f3ad3808a0096d84cf228fab68dc253fd9d (7.3-rc1)
+CVE-2026-90206 [nvmet: fix max_qid race between configfs and controller allocation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f1a8846e06388113dfdbb89dee005083fa9afdf9 (7.3-rc1)
+CVE-2026-90205 [ocfs2: validate orphan slot during inode read]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b2d31acbd3b182755b019183fb46949ba5e39b9f (7.3-rc1)
+CVE-2026-90204 [ocfs2: validate DIO orphan slot during inode read]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bb88131c9831075b8dc08cdd375743e5d44c7ca2 (7.3-rc1)
+CVE-2026-90203 [Squashfs: check block offset is not negative]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e300eb5002925b29be803d2661af07266cfa267e (7.3-rc1)
+CVE-2026-90202 [scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b9f679dfe629004b593f018df33b330d799bcee4 (7.3-rc1)
+CVE-2026-90201 [net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/24ef02f934eeb48830cff6b739abc3c62b1d107b (7.3-rc1)
+CVE-2026-90200 [fs/ntfs3: fix integer overflow in MFT cluster validation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c510c63873103a5da6a498fe537bdb5d6f8d03a2 (7.3-rc1)
+CVE-2026-90199 [fs/ntfs3: reject out-of-range evcn in mi_enum_attr()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3 (7.3-rc1)
+CVE-2026-90198 [ALSA: core: Fix use-after-free in snd_card_do_free()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5ae1a690c522fea2900ff56c8c2ace7b059f5e04 (7.3-rc1)
+CVE-2026-90196 [ASoC: SOF: validate topology volume range before allocation]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a698e4a60fa54268a38f4e66378851a196cb139b (7.3-rc1)
+CVE-2026-90195 [riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/f2aaa621591093cfe8224a25ef2f04a3b1e304b0 (7.3-rc1)
+CVE-2026-90194 [ACPI: scan: fix bus ID cleanup on device_add() failures]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a414485ebc2aa50907d0ce97cde2b1a353696897 (7.3-rc1)
+CVE-2026-90193 [mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c (7.3-rc1)
+CVE-2026-90192 [mailbox: qcom-cpucp: handle NULL data in send_data callback]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/fc4f2f99530298a1739226947aa76525142d421d (7.3-rc1)
+CVE-2026-90190 [null_blk: use DEFINE_MUTEX for the file-scope mutex]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/017dac7670909eaea3eb36e6b3b5a8be9ce0a14d (7.3-rc1)
+CVE-2026-90189 [null_blk: register configfs subsystem after creating default devices]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c9d293d6bb0575fcb1f3408129453187e2a28a4e (7.3-rc1)
+CVE-2026-90188 [null_blk: free global tag_set on init error path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5a1c5ff3a49ba93a1fd0b70537e7a0164071760d (7.3-rc1)
+CVE-2026-90187 [null_blk: free zones array on device power-off]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2a6357a9b935a34f5508618fee8a7fffbf7722a8 (7.3-rc1)
+CVE-2026-90186 [null_blk: reject per-device queue resize for shared tag set]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1cdfe2fa62b48728a9b436fbbd3dbe4c11593e24 (7.3-rc1)
+CVE-2026-90185 [null_blk: serialize configfs attribute stores with the lock]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7e7fff51808237703a3a1df6dd5cae1dfd1db86d (7.3-rc1)
+CVE-2026-90184 [null_blk: serialize configfs attribute updates with device setup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4e1f23f9c33c156be7e313b40695af5a3a834739 (7.3-rc1)
+CVE-2026-90183 [blk-iolatency: clear delay state when freeing policy data]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8935bf22c0a0db517a7f72f7097300e05dd852f5 (7.3-rc1)
+CVE-2026-90182 [blk-iocost: clear delay state when freeing policy data]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/97cb95d2148835ae86ff916b145aef332d40439d (7.3-rc1)
+CVE-2026-90180 [block: mtip32xx: synchronize ioctls with device removal]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/68940f841d013192086a0f6d7cfbac2cd079e228 (7.3-rc1)
+CVE-2026-90179 [apparmor: fix deadlock in complain-mode change_hat]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4ec11f14d1d6fdda787d991b142537be7841d395 (7.3-rc1)
+CVE-2026-90178 [hwmon: (coretemp) Fix core_data leak on CPUs without PTS]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0cd8450c257faa0cece0e0c43d3b55d1a389acc7 (7.3-rc1)
+CVE-2026-90177 [bpf: Check pointer type for all atomic RMW paths]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/4bc49ae344d65cfcef738f281ac575cf73ca2fc5 (7.3-rc1)
+CVE-2026-90176 [ksmbd: Do not skip lock checks for single-byte ranges]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d40c24634fe077a0dc91fd11fccf44ce12b454d5 (7.3-rc1)
+CVE-2026-90175 [smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1c3ebf832d010c08afe1359215d4121cb1ed2de5 (7.3-rc1)
+CVE-2026-90174 [ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7405d0ba294306721843bc551611775e6edef516 (7.3-rc1)
+CVE-2026-90170 [ksmbd: validate ipc response length before dereferencing its fields]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e9b33376bd07bca4175f7bcc2d6034ef250f8181 (7.3-rc1)
+CVE-2026-90169 [ksmbd: free preauth sessions on connection teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/06c7b1d731bc105a8644f1b70165ba8b9416cbab (7.3-rc1)
+CVE-2026-90168 [ksmbd: retain connection for pending notify work]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f495154703cbcc0050cfd53469bd56965791616b (7.3-rc1)
+CVE-2026-90167 [ksmbd: serialize oplock close with pending break ownership]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b0148dc5625dbfd50596ac63c7487c12e8a8ab03 (7.3-rc1)
+CVE-2026-90166 [smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d2ccf905f47d2344270749f4dfa905afcd3edeb0 (7.3-rc1)
+CVE-2026-90165 [smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bef46b604732d83f8da29f782868de4d25bf972c (7.3-rc1)
+CVE-2026-90162 [ksmbd: defer publishing granted locks to prevent UAF/double-free race]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/29f74f0f2e6df3b393b7b66e810136d0c64e3c59 (7.3-rc1)
+CVE-2026-90161 [erofs: fix interlaced ztailpacking pclusters]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/862427ebb81d1f6abbf74d799790e1694b37b187 (7.3-rc1)
+CVE-2026-90160 [lwt_bpf: Restore reserved headroom after xmit program]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5fe7007aed9ad069b2bd77e5d0c875c64f5c0269 (7.3-rc1)
+CVE-2026-90159 [bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/84473a7e1813a2da7b759ab1d098a84998c8d3f5 (7.3-rc1)
+CVE-2026-90158 [m68k: nfcon: Do not call console_is_registered() in nfcon_device()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2f8e3cad53b5c36ab0ed5d3195bfc55c59ea61a5 (7.3-rc1)
+CVE-2026-90157 [bpf: Reject negative optlen in cgroup getsockopt hook]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1b5aacd5b2419b0790e955e466d389a61c79b4b1 (7.3-rc1)
+CVE-2026-90156 [ksmbd: safely discard unregistered deferred locks]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/054bcca4cd9f00719b01f7108b51a2168fb94f15 (7.3-rc1)
+CVE-2026-90155 [ksmbd: detach blocked lock requests before freeing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/215e8816b1ac25176d911abb8704390413ccee4b (7.3-rc1)
+CVE-2026-90154 [ksmbd: scope session state changes to bound connections]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c50e628122aed077695669e25b842e778511a43d (7.3-rc1)
+CVE-2026-90153 [ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/79decd88dd3f0d42e7fb0689b1a7853bfa302459 (7.3-rc1)
+CVE-2026-90152 [smb/server: fix session leak in ksmbd_session_register()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/99b25b046e47e4904373cfeb445c5483f1633d88 (7.3-rc1)
+CVE-2026-90151 [NFSv4: remove callback IDR entry on client allocation failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d05c2007b3d84ccba11dc6e9cb3202768cc72f14 (7.3-rc1)
+CVE-2026-90150 [pnfs/blocklayout: Fix device leaks on parse failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c056f817e4200fb18079d5052c273a22f191ff0a (7.3-rc1)
+CVE-2026-90149 [NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2b03ebbf8d5e8f6af4ecd6c65375232dd1ec32cc (7.3-rc1)
+CVE-2026-90148 [NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/468e458ffde907ba19acd2102ca1fbb8f6fbede2 (7.3-rc1)
+CVE-2026-90147 [clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/0d4d262c1664365e17e0a5ba2ab79f4db484b44e (7.3-rc1)
+CVE-2026-90146 [bpf, xdp: move offload check into dev_xdp_install()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ad27ed7d2309419a129078d781504f486b1b469a (7.3-rc1)
+CVE-2026-90144 [dpll: fix NULL deref in dpll_device_ops() during teardown race]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/33f016b23a219fe034213849b51436b8e79df251 (7.3-rc1)
+CVE-2026-90143 [net: kcm: Hold RCU read lock while running BPF parser]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b0346dd64e4905291cc9c479f2e6cf1884ced4e6 (7.3-rc1)
+CVE-2026-90142 [virtio_net: Fix resize of the RX ring]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d09c98a6da215bce2173a292e4b95c8de6ea5d51 (7.3-rc1)
+CVE-2026-90141 [ipvs: fix integer overflow in ftp helper port/address parsing]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/e625a9477d12baaff4025c5f9989184a907ea8fc (7.3-rc1)
+CVE-2026-90140 [cuse: wait for pending RCU callbacks on module exit]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4deb3edead0c0e172cc7349e8855d741d3c5e162 (7.3-rc1)
+CVE-2026-90139 [fuse: check for NULL root inode in fuse_fill_super_submount]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/928f659a3e3650978a5b4829cc982324f72b474b (7.3-rc1)
+CVE-2026-90138 [vsock: don't check the listener's sk_err in vsock_accept()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b8c899cf5e7be29840a172c183dedd8d3e7a0287 (7.3-rc1)
+CVE-2026-90137 [platform/x86: hp-bioscfg: fix password encoding bounds check]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615 (7.3-rc1)
+CVE-2026-90135 [net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/0b1c2af8a22c35cb099c735c2f63ea3ba757557d (7.3-rc1)
+CVE-2026-90130 [vdpa_sim: fix cleanup after worker creation failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/bd670e5dfd2b01fd9692f61fa1456434c54026a4 (7.3-rc1)
+CVE-2026-90128 [vdpa/mlx5: fix wrong list iterated in add_direct_chain error path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/23ae56d9e74c122f95cae71ae3b9fc259fb88446 (7.3-rc1)
+CVE-2026-90126 [rtc: pcf8563: fix clock provider leak on unbind]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9c48a53685040bb0de45a640b34055cbbfc69d4f (7.3-rc1)
+CVE-2026-90125 [smb: client: fix request buffer leak in smb2_new_read_req()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/deb6468f4164640e4dc875f008aa449cf55987a5 (7.3-rc1)
+CVE-2026-90124 [irqchip/renesas-rzg2l: Fix loss of interrupt]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/50b10bd0c2d721ad38abd1abe3acdefb6caa0944 (7.3-rc1)
+CVE-2026-90122 [clk: visconti: Make sure clk_init_data is fully initialized]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/39c0e6c844a14945040cca4ccf6997792ab764c4 (7.3-rc1)
+CVE-2026-90121 [irqchip/gic-v5: Clear per-CPU IRS data on teardown]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3dfc0ab5fefd052c6028c4632b1fad8bdaf7967e (7.3-rc1)
+CVE-2026-90119 [ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d736eba9c453fedce664fdf592c8b71ecff1932b (7.3-rc1)
+CVE-2026-90116 [ALSA: mtpav: shut down output timer before card teardown]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c73cb5b7c159246dd572277c668851a56e516019 (7.3-rc1)
+CVE-2026-90115 [xsk: fix NULL pointer dereference in __xsk_rcv()]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e37b2abca80473e106176e41712a369fd2f72117 (7.3-rc1)
+CVE-2026-90114 [net: bridge: Reject descending VLAN tunnel ranges]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b74a072d8fb71d3c9ffba4a17d5943e63266fb38 (7.3-rc1)
+CVE-2026-90112 [net: qlcnic: validate unified ROM sections before loading]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5e8076e4e4124dae75a3e080ddc20404700d7585 (7.3-rc1)
+CVE-2026-90111 [ip6mr: do not clone dst in ip6mr_cache_report()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/235b42b5860189eb8c27c36435ad932cae65a734 (7.3-rc1)
+CVE-2026-90110 [inetpeer: randomize RB-tree node comparison using SipHash]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2ee66e9487172fcd189bc52a767c30dad7141c09 (7.3-rc1)
+CVE-2026-90109 [net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/4c660ee8c809637909f4f7eb1017f7b9401c75c4 (7.3-rc1)
+CVE-2026-90108 [net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/036322025d6e440cb75fc6fecbba9a16b271a2ae (7.3-rc1)
+CVE-2026-90107 [net/smc: free pending qentry in smc_llc_flow_stop() before memset]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5ee0ceddc7785c6dcf4a8107fef01f0414a354f4 (7.3-rc1)
+CVE-2026-90106 [net: bridge: arp/nd proxy: fix reading neigh ha]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/57549ab9079122991dfa0f8248ca00e101e8e69b (7.3-rc1)
+CVE-2026-90105 [vxlan: fix reading neigh ha]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b824059a673b2283e78c7aae2c7d257aad7f0e1d (7.3-rc1)
+CVE-2026-90104 [NFSv4.1: zero referring call lists before decoding]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8fa4804fe62ca4155a2d8fc2789d630376cbf2fc (7.3-rc1)
+CVE-2026-90103 [NFSv4.2: fix LAYOUTSTATS send buffer exhaustion]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c75ef2137e749f2673f0617cfdaae53b2bb7195a (7.3-rc1)
+CVE-2026-90102 [NFSv4/pnfs: key the data server cache on the NFS version]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/13c23c5cb977f66390795437fd3837887ce1fd75 (7.3-rc1)
+CVE-2026-90101 [bnxt_en: Fix call to hardware monitoring event handler]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/622d698df4239fef3e0eb51fe59f4198f957f28a (7.3-rc1)
+CVE-2026-90099 [net/sched: account classifier filter allocations to memcg]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/1beb81947eb486716af80db7a584f9e9fef7e003 (7.3-rc1)
+CVE-2026-90098 [net: sparx5: fix sleep in atomic context in MAC table access]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b62793a7baeea9cf20209c9fd2e333311aaf3b8d (7.3-rc1)
+CVE-2026-90097 [Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/cee0d90bceae1dee3bcc70f8d6b2ceb5b87deb42 (7.3-rc1)
+CVE-2026-90095 [fuse: Fix the condition to enable over-io-uring]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/1f59015e958174e89be58cc8db16d70a60d17255 (7.3-rc1)
+CVE-2026-90093 [Bluetooth: L2CAP: access chan->conn safely in get/setsockopt]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ca2c4c26498643f421d35ffe258fafbd3ed461c3 (7.3-rc1)
+CVE-2026-90092 [Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d4bfa78fd67929b62b02013c107973e0c5b7aa9a (7.3-rc1)
+CVE-2026-90091 [Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/66d6ef18548ae6d7dd452b84115fc82c0a73a4ea (7.3-rc1)
+CVE-2026-90090 [Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/fa0ad2d277c7adead61d1c22411c55cea6990c2a (7.3-rc1)
+CVE-2026-90088 [Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/44c98fd082eafd49d55a8a4077ff488175b2fe24 (7.3-rc1)
+CVE-2026-90087 [Bluetooth: do not leak an hci_conn when a second LE connect is rejected]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/7e1e4047200fd7519f9bdfe8a001437715e618b4 (7.3-rc1)
+CVE-2026-90086 [xsk: honor XDP_TX_METADATA in zero-copy path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/a6e4b9a6deb9362ef7a0706c70d674e92fe1411a (7.3-rc1)
+CVE-2026-90085 [octeontx2-af: fix NULL deref in NIX TM tree debugfs read path]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ec65631bd5ec251cdf67a4919fac7a3149a6e235 (7.3-rc1)
+CVE-2026-90084 [octeontx2-vf: fix workqueue and netdev race in probe/remove]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/3ba97ff4f873481d370bee7f7dfb87f8296af9be (7.3-rc1)
+CVE-2026-90083 [net/sched: act_ife: Only operate on Ethernet frames]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5b483f7791b079bb97d411f1066652ff659207ff (7.3-rc1)
+CVE-2026-90082 [net: mana: Cap MSI-X vectors to the device MSI-X table size]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/2c7493f980140a5c40eb4f98f97c557193a2c330 (7.3-rc1)
+CVE-2026-90081 [net/rds: use wq_has_sleeper() in rds_cong_map_updated()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d4f484661961636eb90d287050959e613795f73a (7.3-rc1)
+CVE-2026-90079 [octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/3b11a77f69980932c3924054d66e565c9a135747 (7.3-rc1)
+CVE-2026-90078 [net/sched: act_skbmod: fix length calculations and avoid invalid header warnings]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/81d0d1e64f30d9989c829c0953cd6e6c68d9c5fb (7.3-rc1)
+CVE-2026-90076 [net/sched: fq: add overflow bounds to quantum and initial quantum]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/709f34f7c28dc4dd6c40343d101850f11e172312 (7.3-rc1)
+CVE-2026-90075 [net/sched: fq_codel: clamp default quantum and mtu]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d9ebd8f9aa8b2773235889cb903fafd61f2d8585 (7.3-rc1)
+CVE-2026-90074 [net/sched: fq_pie: clamp default quantum to avoid signed overflow]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c86cd7ed0b0e44779a3d1683f03e4353baf4bdc9 (7.3-rc1)
+CVE-2026-90073 [net/sched: hhf: clamp quantum before hhf_change() to avoid overflow]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2164b512b97bb053e8ce4d6e95576f11bed6a005 (7.3-rc1)
+CVE-2026-90072 [net/sched: sfq: clamp quantum to avoid signed overflow soft lockup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/816e90057ab1879562a5b7cc688e35bb9027ae97 (7.3-rc1)
+CVE-2026-90071 [net/sched: sch_teql: restore skb->dev on the slave failure path]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dc4b95b8fee95113587e93ca116356032d271371 (7.3-rc1)
+CVE-2026-90070 [tpm: st33zp24: Return zero on status read failure]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8b92687708f5ef980de01c2042dbd76d11f78547 (7.3-rc1)
+CVE-2026-90068 [ASoC: dapm: Fix off-by-one check on the second enum channel]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/14511c9b54ceeeef487409d73947c89ee8563590 (7.3-rc1)
+CVE-2026-90067 [libceph: validate banner payload length]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f374967fcdf04001c9b66df1c19106fa83cd91f7 (7.3-rc1)
+CVE-2026-90066 [samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6727b7618f49401acf373fa3ec5712e2ec52e5cf (7.3-rc1)
+CVE-2026-90065 [net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/cec261b0b4c5c0b044165303198d10ffcdf3414c (7.3-rc1)
+CVE-2026-90063 [virtio-net: Ensure that TCP packets don't overflow gso_segs]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/c27c449d455aafd9018a3cbab150f1c42c87923f (7.3-rc1)
+CVE-2026-90062 [netfilter: nf_tables: move hardware offload step after building the chain blob]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/b1881d362e1924b66f6016c3efd28807032b41bf (7.3-rc1)
+CVE-2026-90061 [netfilter: nf_tables: skip double clone set expressions on element insert]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/43559058d21e0493aa220ac167e0279334dea5f9 (7.3-rc1)
+CVE-2026-90060 [ALSA: control: Don't add invalid kcontrols to LED layer]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/74e3b979ce8b78a690f8b94ccf2e2c965f7f5c11 (7.3-rc1)
+CVE-2026-90058 [net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8f735d64382dcf162f4276d6699d03ad2f859c0b (7.3-rc1)
+CVE-2026-90057 [slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/23c53269f2baaedf2d92784290cb9ef6db2a3bce (7.3-rc1)
+CVE-2026-90056 [net: fec: only stop PTP if it was initialized]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/dd890ae29299636fb037276fc1b5238698d08b03 (7.3-rc1)
+CVE-2026-90055 [usb: atm: usbatm: fix invalid ci_range initialization]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a60fd8c6dbaa76da4163cf225ed2b9e982540f39 (7.3-rc1)
+CVE-2026-90054 [tcp: fix corruption of urgent data on multi-segment retransmit]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/ce2b807f42ed5e55567b8864ab72963f90779270 (7.3-rc1)
+CVE-2026-90053 [net/sched: sch_htb: limit htb_classify inner-class filter hops]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/729c4896ab829169f95915d65edd530325910b37 (7.3-rc1)
CVE-2026-XXXX [VSV00020]
- vinyl-cache <unfixed>
- varnish <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/703411d54fb09c532b45dd1147be575dc94b2e9d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/703411d54fb09c532b45dd1147be575dc94b2e9d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/0bff66e0/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list