[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 16:45:02 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
00bc0f30 by Salvatore Bonaccorso at 2026-09-24T17:44:34+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,32 @@
+CVE-2026-93233 [drm/nouveau/dmem: fix callocated underflow on large folio split]
+ - linux 7.2.6-1
+ [trixie] - linux <not-affected> (Vulnerable code not present)
+ [bookworm] - linux <not-affected> (Vulnerable code not present)
+ NOTE: https://git.kernel.org/linus/c2256c044a1df39c8aad4dd2d6f709b2533e2d7a (7.3-rc2)
+CVE-2026-93241 [memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/6b0d1083364fc8e7cc2f7d1f93ee3ee78f4d52f7 (7.3-rc1)
+CVE-2026-93240 [memcg: make the v1 soft limit knob inert]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a3417097fb107cea3358b19bcbb4eb655fd67f8c (7.3-rc2)
+CVE-2026-93239 [arm64: mm: Fix the lockless page-table walk in show_pte()]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/a77644d009dece1104b6fcc6e322b0e4503db0d6 (7.3-rc2)
+CVE-2026-93238 [s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7 (7.3-rc1)
+CVE-2026-93237 [LoongArch: Add DIRECT_MAP_PHYSMEM_END definition]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/2677f97a67fdbc62a82ce1faa67791f54451d36f (7.3-rc1)
+CVE-2026-93236 [media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/20aa934ace6917262ff579a73ec018d06a7bad1c (7.3-rc1)
+CVE-2026-93235 [f2fs: fix to zero post-EOF data when extending file size]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/5eced87b7d19dbc76ebdddaf322046f9ac582fcb (7.3-rc1)
+CVE-2026-93234 [drm/gud: validate TV mode names before creating enum property]
+ - linux 7.2.6-1
+ NOTE: https://git.kernel.org/linus/da1ea35fea67ad841f4ada28dd61b41be65e5437 (7.3-rc2)
CVE-2026-93232 [mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages]
- linux 7.2.6-1
[trixie] - linux <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/00bc0f30c02bdc29a05e9172a4e836111ab09440
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/00bc0f30c02bdc29a05e9172a4e836111ab09440
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/437a2105/attachment.htm>
More information about the debian-security-tracker-commits
mailing list