[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 16:39:00 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ca5ee7f1 by Salvatore Bonaccorso at 2026-09-24T17:38:15+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,65 @@
+CVE-2026-93220 [sched_ext: Keep kick_sync waiting on the rq's own CPU]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/e0253dd04beb03e79477c5ef4768b11135687206 (7.3-rc1)
+CVE-2026-93218 [mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/ce579dcf730ce5ed8043a5eeea18a3e6706a97e5 (7.3-rc1)
+CVE-2026-93217 [mm/madvise: skip device-private PMDs in cold and pageout walks]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/d4b76d0b03cb49611312ecc4bcfb55ccdf0843e2 (7.3-rc1)
+CVE-2026-93221 [nfsd: convert nfsd_net boolean flags to unsigned long flags word]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/11a5fe42e1811f793e04ef885b639ea7668f439d (7.3-rc1)
+CVE-2026-93219 [clocksource/drivers/timer-sun4i: Advertise a real minimum delta]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/d21808328225ab8cee46885bf9a0dffcefbe630e (7.3-rc1)
+CVE-2026-93216 [mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/90f095b816e25c6a9e4446d299bac5007fdcb3df (7.3-rc1)
+CVE-2026-93215 [cdx: Fix double free when sysfs file creation fails]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/6f4acc3a3c300e174e3f586b97b04ed8f5948c36 (7.3-rc1)
+CVE-2026-93214 [usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/9dbf74f4022f80f7669d2b3c22c5deb46c1b5674 (7.3-rc1)
+CVE-2026-93213 [of: fix out-of-bounds read in of_alias_scan() stem parser]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f (7.3-rc1)
+CVE-2026-93212 [nfsd: guard nfsd_serv deref in nfsd_file_net_dispose]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/9f1ddfc8cb9076592401a611eb3a44d36186d014 (7.3-rc1)
+CVE-2026-93211 [nfsd: initialize DRC hash table before registering shrinker]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/b0c58934f5cc4f05b63ef6605dd10c1d0d489e88 (7.3-rc1)
+CVE-2026-93210 [smb: client: harden DFS cache against invalid target hints]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bf86c08123c6ab8c61cc0be1dad7540db93738ff (7.3-rc1)
+CVE-2026-93209 [Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb]
+ - linux 7.2.6-1
+ [bookworm] - linux 6.1.119-1
+ NOTE: https://git.kernel.org/linus/f5afdff569a09d1cb8cf19826199d024725576cb (7.3-rc1)
+CVE-2026-93208 [kasan: fix cache shrink race with CPU hotplug]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/8790303cbaac52a11dfed4aab261f8ea60682525 (7.3-rc1)
+CVE-2026-93207 [SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry]
+ - linux 7.2.6-1
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/11539e8fcce0b0af062ae5fecf7b3676c2f7aeed (7.3-rc1)
+CVE-2026-93206 [PCI/proc: Use file_ns_capable() when checking config space read access]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/f82f53e75eff382fc8f56b73279b54f7cf5a5c65 (7.3-rc1)
+CVE-2026-93205 [iommu/arm-smmu-v3: Manage teardown with devm]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2bd22a0d40503a65d243b011de146603c8ce1cbc (7.3-rc1)
CVE-2026-XXXX [grub serial-mmio secure boot bypass]
- grub2 2.14-4 (bug #1148741)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/13/5
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca5ee7f1f808a6d74412af6e448941963e07cd50
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca5ee7f1f808a6d74412af6e448941963e07cd50
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/25d41f61/attachment.htm>
More information about the debian-security-tracker-commits
mailing list