[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 24 18:08:37 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
31c45449 by Salvatore Bonaccorso at 2026-09-24T19:08:10+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,151 @@
+CVE-2026-93277 [RDMA/bnxt_re: Validate udata before executing commands]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d38c835925d4a3bfdf0a85ff2829ee90c709c561 (7.3-rc1)
+CVE-2026-93267 [RDMA/core: Fix potential use after free in uverbs_free_dmah()]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2696626a0be5877f445fb647c25ef43930c777e6 (7.3-rc1)
+CVE-2026-93266 [arm64: RSI: fix field-spanning write warning in attestation token init]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/221049874b6a78c7d87bc826581b0695cd338e2b (7.3-rc1)
+CVE-2026-93265 [PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6e5e6c2194b2acbded5b12ed80590d215b786d29 (7.3-rc1)
+CVE-2026-93263 [clk: eswin: Zero-initialize stack-allocated clk_init_data]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/011d8de504bc84402aabc1dda1cf0552fe9a5af2 (7.3-rc1)
+CVE-2026-93258 [ocfs2: do not use make_bad_inode() in ocfs2_read_inode_block_full()]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d48ace65322001b41bb5322442a21425ef4407d4 (7.3-rc1)
+CVE-2026-93257 [block: handle nogenerate/noverify properly in fs-integrity]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3bf9a21e7bccfd8c35b440efd114c61cc9838a41 (7.3-rc1)
+CVE-2026-93255 [btrfs: make sure EXTENT_BUFFER_READING is cleared under refs_lock]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/690c2accacb1aca91ab8186d15dee56da8723f31 (7.3-rc1)
+CVE-2026-93254 [arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/39aebe0e89469c2904e60b1e977e0d4dbf33326b (7.3-rc1)
+CVE-2026-93253 [sched/isolation: Defer freeing of cpumask memblock memory to initcall]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b58c749b8c5244e259a0230bc57b10b010dc545 (7.3-rc1)
+CVE-2026-93249 [spi: amlogic-spisg: Make sure clk_init_data is fully initialized]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b2702908ee23ef31bfcf241a2e07ace0eb76bd71 (7.3-rc1)
+CVE-2026-93246 [octeontx2-af: fix out-of-bounds read setting MSI-X irq affinity]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4d5df98369c5f45710b786499f8bd7ffc3196433 (7.3-rc1)
+CVE-2026-93283 [i3c: master: Fix device_register() error path]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/74be657d98a8d684c0475f3cbd450ef2a30ffc73 (7.3-rc1)
+CVE-2026-93282 [ksmbd: fix maximum allowed access checks]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/cc2f133e80eb2c4a04bfa77a2f207749fe2f516a (7.3-rc1)
+CVE-2026-93281 [wifi: rtw89: fix HE extended capability length check]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/2aba608a86e9b099c9af2ea70b620552dee2b628 (7.3-rc1)
+CVE-2026-93280 [greybus: audio: bound the topology section sizes against the fetched size]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/33d8c7b794d2a30637c9d3fcb478f1d3222bef1e (7.3-rc1)
+CVE-2026-93279 [staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/b9af44b0d20b2247c4eb0ea5cfca907d643eea50 (7.3-rc1)
+CVE-2026-93278 [staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/c0a9a8586a63fda49e61a6b83360feac2a60d898 (7.3-rc1)
+CVE-2026-93276 [phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/49c9b71b45081e5e5eeb507a2d6edb80d332dc59 (7.3-rc1)
+CVE-2026-93275 [perf/x86/intel/pt: Fix stop/start with no update]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/2e17bf3a469a41457a3bc31b1f8fd66b6ce94a6d (7.3-rc1)
+CVE-2026-93274 [pinctrl: bcm2835: Don't remove an unregistered GPIO chip]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/32711f77db0641e57fd96fdc013bf1286b9f2514 (7.3-rc1)
+CVE-2026-93273 [regulator: tps6594: Fix device node reference leaks in multiphase loop]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7fd28093b3effc4f92566466df364622830ec608 (7.3-rc1)
+CVE-2026-93272 [remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/3dbc90b9c22ea96e37bf55f6011e63b5123ec668 (7.3-rc1)
+CVE-2026-93271 [wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/12b09e478aa7459b7893a695ef77682202f2da83 (7.3-rc1)
+CVE-2026-93270 [bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7a0855e73757ee9cf25ba635a1c735018ecba742 (7.3-rc1)
+CVE-2026-93269 [ext4: fix circular lock dependency in ext4_ext_migrate]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/a897682793eba5de51ee6f3152760374afa629cf (7.3-rc1)
+CVE-2026-93268 [ext4: skip extra isize expansion during mount to prevent deadlock]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/7461c60b9c6a839b13ad4c3490681a0cf5aa0637 (7.3-rc1)
+CVE-2026-93264 [RDMA/efa: Fix PBL chunk length computation]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/229b42d7450c1cf96f45ec39ebb69211b06bc036 (7.3-rc1)
+CVE-2026-93262 [md/raid5-ppl: fix use-after-free in ppl_do_flush()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/371f7a1b392edc8b7cf449cc7713179b588f2d0e (7.3-rc1)
+CVE-2026-93261 [locking/lockdep: Fix NULL pointer dereference in __lock_set_class()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/7577e00b9ab506202b9f1a33de3cc8cc6413a4db (7.3-rc1)
+CVE-2026-93260 [powerpc/xive: propagate IPI init errors to prevent use-after-free]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/411a3c016e7a95f5fa105a0587e07d0647a77727 (7.3-rc1)
+CVE-2026-93259 [powerpc/irq: Fix missing r2 clobber in PCREL inline assembly]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/00be69070d91d2be978e752bb117a0a4db0e1281 (7.3-rc1)
+CVE-2026-93256 [arm64: hibernate: mask DAIF before restoring hibernated kernel]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/684bde100117931f4c51c644a95f42f2dab041bc (7.3-rc1)
+CVE-2026-93252 [ocfs2: fix circular locking dependency in ocfs2_init_acl()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/bd7c05fb4a4776dff5a87b19008d28458647d15d (7.3-rc1)
+CVE-2026-93251 [ACPI: bus: Introduce acpi_bus_get_primary_device()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/72530e1f72b0515a73fd88292254d04fecf03649 (7.3-rc1)
+CVE-2026-93250 [vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bc2dc66a6693a78f8c1e6ca2dbebd50f16e2c366 (7.3-rc1)
+CVE-2026-93248 [drm/xe: don't WARN on kernel job timeout when device already wedged]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/13087ad7817e6e5f210064518bfc4d6d58a9c2f3 (7.3-rc1)
+CVE-2026-93247 [Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/59eecbe2f2f38d8f3e1104bd11da97f9a2c58998 (7.3-rc1)
+CVE-2026-93245 [apparmor: policy_int make sure list heads are initialized before fail path]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/3daad923a8685adb66087e0d819559b7eb6ba975 (7.3-rc1)
 CVE-2026-93244 [drm/sysfb: simpledrm: Improve stride validation]
 	- linux 7.2.6-1
 	NOTE: https://git.kernel.org/linus/df6533f11688aa30be3bb883c7637f4ffdbb7cbd (7.3-rc1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c45449dd53f5b0dd638129bbb672e425e2ff99

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31c45449dd53f5b0dd638129bbb672e425e2ff99
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/0ac321cd/attachment.htm>


More information about the debian-security-tracker-commits mailing list