[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 13:32:33 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7631cdcb by Salvatore Bonaccorso at 2026-09-25T14:32:08+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,1081 @@
+CVE-2026-98093 [ASoC: fsl_micfil: balance mclk enable/disable]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d3dbccfe6afa7b9a6a7ed65cfaa76a47fa050a56 (7.3-rc3)
+CVE-2026-98065 [bpf: Reject key-less BTF for hash maps]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0895a0c0734703be5532f3883c42db95615fd98b (7.3-rc2)
+CVE-2026-98061 [bpf: Reject tail calls directly from callback frames]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/266aa4ad0b2e82397cd9045752c9bff03d98eddd (7.3-rc2)
+CVE-2026-98060 [bpf: Reject resilient lock operations in rbtree callbacks]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7b7b8b5960102566bd625ae829d1f330c5b5d104 (7.3-rc2)
+CVE-2026-98050 [mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2ac174dfcdde399fa95ba889541fb5e688d8bb35 (7.3-rc3)
+CVE-2026-98042 [bpf: Don't resurrect a scalar id dropped by collect_linked_regs()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/73a98f96811e2cb0f4210b1caa8cb322f92f2a2b (7.3-rc2)
+CVE-2026-98040 [bpf: Mark the zero register precise for a register-form NULL check]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6aed0134d3cda6382385a734ae0158eb7df6b142 (7.3-rc2)
+CVE-2026-98036 [bpf: Preserve special fields in recycled rhtab elements]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5df46ddcb7b36878c1b691e9057a0509042a2567 (7.3-rc2)
+CVE-2026-98035 [bpf: Cancel special fields when recycling rhtab elements]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/65cc95eba9e8b46312cac38c227473605a4b996a (7.3-rc2)
+CVE-2026-98005 [erofs: delimit inode_share cache key components]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/96bf9831fbf423b8104f7948cd8fe7007ecfb46c (7.3-rc3)
+CVE-2026-98002 [iommu/amd: Fix ineffective error check in nested domain allocation]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fa5c0827f0b7bac6d0a188f10118151769ae68fd (7.3-rc3)
+CVE-2026-98000 [hwmon: Fix potential UAF in pec_store]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/354ccc99b2dc8ba0cf6d4de34e520bcf6ecca5c2 (7.3-rc3)
+CVE-2026-97983 [vduse: return compat ioctl results directly]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/48a4ee65e677559776349128e6a81a6041986c99 (7.3-rc3)
+CVE-2026-97980 [s390/debug: Fix NULL pointer dereference in debug_set_level()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b1eb31d533cdfcae1011ed53850d52f36afe5774 (7.3-rc3)
+CVE-2026-97974 [ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cdca92eddc025fdb90071be97738f7d55a65f8dd (7.3-rc3)
+CVE-2026-97972 [net: macb: put the "mdio" child node reference on success]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/382a373d9ea7a6ac4de9c022385b6217f65ae3cc (7.3-rc3)
+CVE-2026-97971 [nstree: check listing permission before taking a namespace reference]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/56ea4e86832d8abe8930394473566c194d189f85 (7.3-rc3)
+CVE-2026-97956 [net: net_failover: Fix the deadlock in net_failover_slave_name_change()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/985a663bf00799c1daf1c5789efa6406958780c8 (7.3-rc3)
+CVE-2026-97955 [net: mana: restore the XDP program pointer when pre-allocation fails]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4c46beb807efcc93f5899ebe1f5958248eb296c6 (7.3-rc3)
+CVE-2026-97947 [x86/amd_node: Fix potential NULL pointer dereference]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/aefdbd574a362dcf7569bada6d72f64a006b9fb9 (7.3-rc3)
+CVE-2026-97946 [x86/amd_node: Fix PCI device reference counting in amd_smn_init()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/27600805e62f800bacf990354632eae4e487d34c (7.3-rc4)
+CVE-2026-97944 [x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5a5d26f2cfe13467166219f6bf58099326912ddb (7.3-rc4)
+CVE-2026-97943 [x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a1c7570cedd03372812a5b693732880867babbca (7.3-rc4)
+CVE-2026-97942 [x86/alternatives: Exclude text poking against change_page_attr()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1587d3394e254639cc36516256031334095e6ef3 (7.3-rc4)
+CVE-2026-97941 [mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4a724bcf5d703e18957397914d79156fa2cf1174 (7.3-rc3)
+CVE-2026-97937 [ftrace: fork: Initialize function graph state before copy_exec_state()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/08cacffeef8f64f1a222c93467ca84f24a46c953 (7.3-rc3)
+CVE-2026-97932 [tracing: Don't dereference trace_event_file in deferred trigger free]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bcfe2816e6ec46c3f4c58aa4264476665ddb3f69 (7.3-rc3)
+CVE-2026-97914 [accel: ethosu: Fix ethosu_job_open() return value]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b3c8d4672f7a8735e2884cefcd89286268e88b2e (7.3-rc3)
+CVE-2026-97913 [accel: ethosu: Ensure cmd stream ends with a stop op]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/eb3a41fd35e352fba387c4320a1fa0352f3e551c (7.3-rc3)
+CVE-2026-97912 [accel: ethosu: Ensure SRAM size is 0 on mapping failure]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f5376d7e0fb703876199d3b6f9f97e128fa2f8a4 (7.3-rc3)
+CVE-2026-97911 [accel: ethosu: Ensure SRAM region size matches job]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b39d680c9e0fb4d625f2916980977622e84248c (7.3-rc3)
+CVE-2026-97903 [exit: hold a reference to thread_pid across proc_flush_pid]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cdd812d0683dee14ead02c9eded568685e61b23f (7.3-rc3)
+CVE-2026-97621 [drm/rockchip: analogix_dp: fix unchecked bound endpoint name length]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/bc69439d983cc491cc86e01fafc1deb94e1bb85e (7.3-rc3)
+CVE-2026-97614 [net: dsa: tag_brcm: legacy FCS: request needed tailroom]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5be081b83abd3f17d908953b4bb77279f5a149e3 (7.3-rc3)
+CVE-2026-97610 [netfs: Fix uninitialized return value in netfs_unbuffered_write()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f18e8774f4d3137fa0a5fb8ffa83d59a719666d8 (7.3-rc3)
+CVE-2026-97593 [iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/20db6573301e66cd65ebf6c130b6563c69374d9d (7.3-rc3)
+CVE-2026-97591 [s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/330148371401de474b656eaf521861f12ec1a1ce (7.3-rc3)
+CVE-2026-97590 [s390/crypto: Fix missing scrub of temp buffers with PAES algorithm]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/19a218b46b2471d370c11fb52040f36ac8d05d23 (7.3-rc3)
+CVE-2026-97589 [s390/crypto: Fix wrong return code to engine in asynch callbacks]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ac1481320110b803ab9b79ab4d2ca11a74fc05f2 (7.3-rc3)
+CVE-2026-97588 [s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7a08507ea5b4d06ad8d269287913573f34467565 (7.3-rc3)
+CVE-2026-97586 [afs: Fix missing kunmap in afs_dir_search_bucket()]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/950ae84b5cc944fbe27d81806d0b76af765f779c (7.3-rc3)
+CVE-2026-97585 [afs: Fix double-unmap of directory block]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e3cfd3eb7d5be7787cc69530b423f788f14d084f (7.3-rc3)
+CVE-2026-97580 [media: rkvdec: bound HEVC tile loops and PPS id to the array capacity]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/81ad46bb33d8fd279aaa33af5296c648814c964b (7.3-rc3)
+CVE-2026-97570 [bnxt_en: Bound SW TPA IDs to prevent crashes]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c0aceaf65b70b3c000e70dd867f3a673015f24ca (7.3-rc3)
+CVE-2026-97569 [bnxt_en: Prevent queue stop with deferred completions]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/39b23c1c40e1f73d2b94a09282cc476af647e438 (7.3-rc3)
+CVE-2026-97553 [xfs: lock the healthmon when inserting unmount event]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7538ba528cfd6f176076186c1b1678fdca1c197b (7.3-rc3)
+CVE-2026-97550 [xfs: fix unit conversions in per_binval computation]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/05cff7c2b79f76c7cfe90613a60e16aaaa051ef7 (7.3-rc3)
+CVE-2026-97548 [xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/aa301322f72f82f26e4ba0826018d41388ab9896 (7.3-rc3)
+CVE-2026-97533 [x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d5d8b8662e6e5a565b47a0388640e88402f23274 (7.3-rc4)
+CVE-2026-97525 [x86/mm/pat: Allocate split page tables as kernel page tables]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9e4a3ec3411bb6bb59e3c1f29b75609f1e87aac4 (7.3-rc4)
+CVE-2026-98099 [ipv6: mcast: use rcu_assign_pointer() for __rcu list updates]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0c8f56c583c3250408367880c98e4d6fbc929315 (7.3-rc2)
+CVE-2026-98098 [tipc: fix NULL deref in tipc_named_node_up() on empty publication list]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b3b76e9f4f2476f1135b2ba7743a821db4a0df4b (7.3-rc2)
+CVE-2026-98097 [tipc: Dont send random pad bytes in RESET/ACTIVATE messages]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/81c600c26302a27852ed8b19c5f2f647ea3555c9 (7.3-rc2)
+CVE-2026-98096 [ipv6: sr: restore network header before routing and forwarding]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/975b5b067f525a1b1338c4a3bee1c46545801518 (7.3-rc2)
+CVE-2026-98095 [af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/73e594c19b4f815d8343461cec7074c4713bbde7 (7.3-rc2)
+CVE-2026-98094 [staging: fbtft: make dirty_lock IRQ-safe]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/f576944a59f31bcffff121117ebf452c5dd162b7 (7.3-rc2)
+CVE-2026-98092 [ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1b67e0d3b9691d7b6b74e18960ddd2be24f9dc9d (7.3-rc3)
+CVE-2026-98091 [btrfs: detach failed sprout device from transaction update list]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c93b3c43df561cd9f592cee20ae058b563f9e5b6 (7.3-rc2)
+CVE-2026-98090 [btrfs: restore active device pointers after failed sprout]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e0b54613aabeb8e9da597f23b90c6a03d0981986 (7.3-rc2)
+CVE-2026-98089 [bonding: alb: fix uninitialized transport header access in alb_determine_nd()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/70f3995830d3f1e79faa14eb0605914f778feca9 (7.3-rc2)
+CVE-2026-98088 [scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e0d26fe176a8db6ccad4ab38c5bab29391c1946b (7.3-rc2)
+CVE-2026-98087 [sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/dae5c0292080dd7b9c7d784268dcf443f1f3d15e (7.3-rc2)
+CVE-2026-98086 [ALSA: ump: do not touch legacy_rmidi before it exists]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/adeee7187694719890aaffdc14b7e89cfd736f1d (7.3-rc2)
+CVE-2026-98085 [bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/387b1baefbb776e3f48dc2261e77a49213f470f7 (7.3-rc2)
+CVE-2026-98084 [bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e3e4f66cc4b72333d0886ae2673c360248987889 (7.3-rc2)
+CVE-2026-98083 [btrfs: fix transaction use-after-free in raid stripe insertion]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a8813a923f9e43f788b357fb55c35f7f6ed6f98c (7.3-rc2)
+CVE-2026-98082 [btrfs: fix the possible bioc_list memory leak during error]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/afbe73778338e6d1ac8c4486fbdf33f0cc1f2624 (7.3-rc2)
+CVE-2026-98081 [btrfs: zoned: finish active block group cleanup if call_zone_finish() fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a18a6b93a2843b9d103d3456bbd4b3f90282a379 (7.3-rc2)
+CVE-2026-98080 [btrfs: do not force reloc root creation during qgroup_account_snapshot()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/cacf35832292997018837e484283f95a9301ebf5 (7.3-rc2)
+CVE-2026-98079 [btrfs: zstd: fix lost wakeup when waiting for a workspace]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2acb9f3d1cc8f65dc81ed55e238cbf8e5b60bff7 (7.3-rc2)
+CVE-2026-98078 [ipvs: fix reversed sequence option serialization]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b04578b74f2d3755548fe9e829e3b2a6c6f966a1 (7.3-rc3)
+CVE-2026-98077 [netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e8f8231824b5815f57ce62cba116e511b10196de (7.3-rc3)
+CVE-2026-98076 [tracing/probes: Fix use-after-free on field name/type of events with multiple probes]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/86b7a239ec6b14a7544200ede85474c6f5526049 (7.3-rc2)
+CVE-2026-98075 [bpf: reject BPF_PSEUDO_FUNC reference to the main program]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/374b2c5561db80fcdd7cdce44af37a49416f61c7 (7.3-rc2)
+CVE-2026-98074 [bonding: do not clear curr_active_slave prematurely when releasing all slaves]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/af602c7aa5fedc9be3043244017aef4f26c96b70 (7.3-rc2)
+CVE-2026-98073 [net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/debac3a20dec524a59625cf10fa2f18571127824 (7.3-rc2)
+CVE-2026-98072 [net/rds: use wq_has_sleeper() in release_in_xmit()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6d0c8b7073913011459cf968cbbadd341e166bc3 (7.3-rc2)
+CVE-2026-98071 [net/rds: clear cp_flags bits individually in rds_conn_path_reset()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/103c4b13c4f50322910078d1c02f29334a574122 (7.3-rc2)
+CVE-2026-98070 [net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/02c5f9dc2efd823e061954d564ce00bacd1bebeb (7.3-rc2)
+CVE-2026-98069 [net/rds: acquire the fastpath locks in rds_conn_shutdown()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/813f3582ac7ae9f60f917937d54660e0952d5f2d (7.3-rc2)
+CVE-2026-98068 [net/rds: don't let rds_conn_shutdown() consume a concurrent drop]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/260c6308fe2e19ad519389d44d582e292aecc3af (7.3-rc2)
+CVE-2026-98067 [erofs: disable LZ4 rolling decompression for now]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/82e664cf1219c459c33aae931b222cf951af9cb7 (7.3-rc3)
+CVE-2026-98066 [ALSA: caiaq: Fix potential double-free at error path]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/3b26ceef88c110f4d188387cffa0df78657be904 (7.3-rc2)
+CVE-2026-98064 [bpf: Fix NULL-ptr-deref when showing a void BTF type]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4ea508b9ebd78bce7f212166d2e2cba66b875f08 (7.3-rc2)
+CVE-2026-98063 [bpf: Fix NULL-ptr-deref in btf_var_show()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5403a383f52fc0905703b488f7c3db4b2447dc58 (7.3-rc2)
+CVE-2026-98062 [bpf: Mark signal tracepoint siginfo arguments as scalar]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/77515ab12e4983e6416f8c35039a3f0c0822ac70 (7.3-rc2)
+CVE-2026-98059 [bpf: Mark sched_process_wait argument as nullable]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a453d6e3b8e8e1a321c8744d6189d763af9287d0 (7.3-rc2)
+CVE-2026-98058 [bpf: Mark syscall helpers as sleepable]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d05524794240b52fdc3b6c1220dd05505715824d (7.3-rc2)
+CVE-2026-98057 [ring-buffer: Add checking nr_subbufs to persistent ring buffer validation]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6c001a62c34f13fe1c6a24304c289b387d9e697d (7.3-rc2)
+CVE-2026-98056 [nvme: remove stale namespaces by NSID range during scan]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4ed7f3d7d435bf5b63da2814dc9270f5ba896011 (7.3-rc2)
+CVE-2026-98055 [ASoC: Intel: avs: Clean up the bus when fetching ML caps fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/559ea14b7ae7c7562b48759fa545b64958f35b73 (7.3-rc3)
+CVE-2026-98054 [ASoC: Intel: avs: Fix unbalanced module reference count]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d4fa6f94b91137e329ea3f5b360e140b227bb696 (7.3-rc3)
+CVE-2026-98053 [ASoC: Intel: avs: Refactor and fix init_config access]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/681e91035dc794896a904852040837190e5041f5 (7.3-rc3)
+CVE-2026-98052 [net: bcmasp: clear txcb->last before writing each descriptor]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/18e5e0ec0e9282c897e2aa81a3e43ccaee03b003 (7.3-rc3)
+CVE-2026-98051 [net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0c5cf62e72d7a666ee4da757e122dc1600df1ecc (7.3-rc3)
+CVE-2026-98049 [bpf: zero extend the result of an arena 32-bit cmpxchg]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4814ed6406f3493bd554ad046da5f7fc04833571 (7.3-rc2)
+CVE-2026-98048 [bpf: don't rewrite bpf_fastcall patterns entered by a jump]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0b1c83dc3c4401cd7e846548f62e3caf3d06742e (7.3-rc2)
+CVE-2026-98047 [bpf: Check ancestor frames for rbtree callbacks]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/369f4ce734570bdfedaa4b5ca50e2a3f6a892728 (7.3-rc2)
+CVE-2026-98046 [bpf: Mark bpf_btf_find_by_name_kind() as sleepable]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/620614bf7672130c43b3cff375525a2202f61979 (7.3-rc2)
+CVE-2026-98045 [bpf: Mark faultable stack helpers as sleepable]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9d02927fdf4e930893c92e35fed01a2704496900 (7.3-rc2)
+CVE-2026-98044 [bpf: Reject legacy packet loads from callbacks]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e7d28823c662128caae63f14e16bd394916c139b (7.3-rc2)
+CVE-2026-98043 [bpf: Don't infer non-NULL from a pointer with an unbounded offset]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/67b529f521a6676cdfc78b91b0217d7eaa84216b (7.3-rc2)
+CVE-2026-98041 [bpf: Don't predict JMP32 pointer vs zero comparisons]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e51179a4e09846f8fd0f26a05068520de2b301bf (7.3-rc2)
+CVE-2026-98039 [bpf: Require MEM_PERCPU for percpu kptr stores]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/048029ba1c793f8cabc4ad5eea765da01903f8f1 (7.3-rc2)
+CVE-2026-98038 [bpf: Keep refcount_acquire nullable for borrowed RCU kptrs]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dc36739e5cc9f60485418a910b42bc95339218d2 (7.3-rc2)
+CVE-2026-98037 [bpf: Reject untrusted allocated-object pointers]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7441ee8276641bddaf1cba7bb75ef9c1458ceb3b (7.3-rc2)
+CVE-2026-98034 [bpf: Mark NULL kptr stores precise]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ecdc5043794c9184aa8e6c814603899479c46b35 (7.3-rc2)
+CVE-2026-98033 [bpf: Preserve inner map identity in callback frames]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b90c5d770dad910fb89e6c1b15052a8a1e8db752 (7.3-rc2)
+CVE-2026-98032 [tracing: Fix subbuf resize races with trace_pipe_raw readers]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/dae8dda341d2d9034a90d59e8a7d502e1263813f (7.3-rc2)
+CVE-2026-98031 [nexthop: Initialize extack in remove_nh_grp_entry()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5bd9e4e7cdaa03879e9b73b12ab52cceb1edd55b (7.3-rc3)
+CVE-2026-98030 [net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/cdb719f4b8596d9ccee2d56d204c2c4dce982f46 (7.3-rc3)
+CVE-2026-98029 [eth: nfp: bound the ntuple rule dump by the caller's buffer size]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f1986bf87b0709c95126fe196cf39e5b8c8453a1 (7.3-rc3)
+CVE-2026-98028 [eth: nfp: drop the replaced rule from the list when reprogramming fails]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/108bb2142e3a12c9ad625ad662973127a113ddc6 (7.3-rc3)
+CVE-2026-98027 [net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b1fffc273112e7284c5b705e186b43b5770cd3d5 (7.3-rc3)
+CVE-2026-98026 [net: bridge: mcast: properly convert mglist to rcu]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4b772869a1e5f9da5cef5b9c722ec0aa424ee0a0 (7.3-rc3)
+CVE-2026-98025 [net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5d50e90add8b4a978395e893e81954d19d58a7c5 (7.3-rc3)
+CVE-2026-98024 [s390/ism: folio_put() after error]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/907a56ab3eb8a58500a58daa76087f17bb2b6826 (7.3-rc3)
+CVE-2026-98023 [vxlan: reject dynamic fdb entries that reference a nexthop id]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/98fc57d167446b95b4e719815fe79edef93f8e7a (7.3-rc3)
+CVE-2026-98022 [net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/66ab4c59b74db7ab53a1c9083feaaede393a96a0 (7.3-rc3)
+CVE-2026-98021 [net: reject oversized tx_queue_len at netlink parse time]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1aa9e143bf51405665a793d4cc925e1c4f0c5922 (7.3-rc3)
+CVE-2026-98020 [pds_core: fix cmd_regs access racing BAR unmap on reset]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7980325b2f71e3f65c1323c39792e2455da6fab6 (7.3-rc3)
+CVE-2026-98019 [bpf: mark a NULL call argument precise]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1a3a10b030c96ea88868ccc060a16827c01eaa5a (7.3-rc2)
+CVE-2026-98018 [net: mctp: i3c: serialize probe with bus removal]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2b4707a149a55e8fa75c9ef32b359d60f470a566 (7.3-rc3)
+CVE-2026-98017 [net/sched: defer qdisc freeing after failed creation]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e6662f2100f8d33b0f4d0047c219efd6bba186ea (7.3-rc3)
+CVE-2026-98016 [net/mlx5e: Fix use-after-free race in sample_restore_put()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/af3aef0245abbab5e9f6302e7a7d6407187afb71 (7.3-rc3)
+CVE-2026-98015 [net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/7ee07f601f8f507c9faf25c68a49396ab8950596 (7.3-rc3)
+CVE-2026-98014 [net/mlx5: E-Switch, prevent mc_list repopulation during vport disable]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c0c6f4ba8a37688f7b4d4044898d88f0450d44c2 (7.3-rc3)
+CVE-2026-98013 [net/sched: fq_pie: clamp quantum in change path]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4864f58c53eb47257d55e01f47d4a9f355f7f970 (7.3-rc3)
+CVE-2026-98012 [net/sched: sfq: clamp quantum in change path]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/fb9f88a33c516ea5c0bcd9a22ca288b246b34567 (7.3-rc3)
+CVE-2026-98011 [net/sched: hhf: clamp quantum in change and init paths]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/eb56a495f59baf6cad5ed80e3ffb9078098b1346 (7.3-rc3)
+CVE-2026-98010 [net/sched: drr: clamp quantum in change class]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8382abec0f1568d0a5590d75a3df92f23fcf5196 (7.3-rc3)
+CVE-2026-98009 [net/sched: ets: clamp quantum in parse and fallback paths]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1c38487f46b243bfeefec0c0c86023a3904f2214 (7.3-rc3)
+CVE-2026-98008 [net: macb: fix NULL pointer dereference on unbind with fixed-link]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/38b6be101006d3e7af972999f45d4f1e8250587a (7.3-rc3)
+CVE-2026-98007 [bpf: Reject non-scalar bpf_loop iteration counts]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c3fd8e5fd100f122bad503bdc0e9277219533253 (7.3-rc2)
+CVE-2026-98006 [ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/402a9d6aab7ac787ab075adeb562c3db8b8f564b (7.3-rc3)
+CVE-2026-98004 [iommu/riscv: Serialize command queue publishing]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ca58afa40946acd252a50fa4d4a86f15847a3d7d (7.3-rc3)
+CVE-2026-98003 [iommu/amd: Do not reallocate GA log buffers on resume]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/00a7dd64888d6dd72110b40e2824a088cf7b7386 (7.3-rc3)
+CVE-2026-98001 [hwmon: (ltc4282) Make sure clk_init_data is fully initialized]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e317326d1755ea054b98e7a4833b929157461c35 (7.3-rc3)
+CVE-2026-97998 [netfilter: nfnetlink_log: cope with concurrent instance destruction]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/387d744fa7e499d2c3748a4e60e02ebb24e7fb16 (7.3-rc3)
+CVE-2026-97997 [virtio_ring: fix stale descriptor flags after a failed packed add]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/75d276e5bb68778b2916f98a2bc30f142ebadc64 (7.3-rc3)
+CVE-2026-97996 [virtio: fix use-after-free in unregister_virtio_device()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3f9a0fceb730f5107d52421ead5568eae25a0049 (7.3-rc3)
+CVE-2026-97995 [virtio_console: do not free control-out buffers on remove]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/894f98e73983f37354214a89a3a7fd35bf9e3072 (7.3-rc3)
+CVE-2026-97994 [vhost/vdpa: reject VRING_NUM larger than device max]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ccb1dc7c527f8c925925cf92afc76ae590dac311 (7.3-rc3)
+CVE-2026-97993 [vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e74a9fa50749b9940b4fb13199652325e08d3c4a (7.3-rc3)
+CVE-2026-97992 [vhost-vdpa: protect config_ctx from being freed under the config callback]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/62be4e3e5f5f947fbf765b914cebdc478f715d12 (7.3-rc3)
+CVE-2026-97991 [vdpa_sim_blk: reject out-of-range sector starts]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0a8693f00c408d85f086ad85d29e7030bf1e2055 (7.3-rc3)
+CVE-2026-97990 [vdpa_sim_net: check TX pull result before RX copy]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0d195797a80b77f2ec56718cd26d3ee65d0093e8 (7.3-rc3)
+CVE-2026-97989 [vduse: validate virtqueue alignment]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/fa2c25b4add57888acfa89e398389e267bff3dcf (7.3-rc3)
+CVE-2026-97988 [vhost: invalidate vring access on IOTLB transitions]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e4f4761879a230aa59e569102a6ab9851847d833 (7.3-rc3)
+CVE-2026-97987 [virtio_input: reset device if input_register_device() fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/81489b32a21c9360f8750d1fb600155d27452e19 (7.3-rc3)
+CVE-2026-97986 [virtio_input: stop callbacks before unregistering input device]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d7808b37da0a619cf1fa541c2384e783fecc2480 (7.3-rc3)
+CVE-2026-97985 [af_unix: Update last skb marker in manage_oob().]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/94fd4debd2e3a69cf93e766c8b328a810c228119 (7.3-rc3)
+CVE-2026-97984 [net: ipv6: Fix UDP length overflow with PMTU discover and big MTU]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0ae10b6be49b425827659b23bcce498f80eb7182 (7.3-rc3)
+CVE-2026-97982 [net: ethernet: cortina: Fix budget accounting]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a0de06d0da78a3db53de65dfd7452cc6d111f703 (7.3-rc3)
+CVE-2026-97981 [net: ethernet: cortina: Count dropped frames as NAPI work]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b856c552f556bc0341c1dbe0bf88e630fd1dc4b7 (7.3-rc3)
+CVE-2026-97979 [ice: add missing xa_destroy for sched_node_ids]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/53432c4c3e869076350aef319534431af8ba99c1 (7.3-rc3)
+CVE-2026-97978 [eth: ice: don't dereference pointers from TP_printk()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b8bf9bfda5f62e11444e483c2b4aaff90c5cfc6b (7.3-rc3)
+CVE-2026-97977 [Bluetooth: btusb: Fix UAF of btusb_data by rx_work]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1c12c3117639e78940959d956519c758c57d0849 (7.3-rc3)
+CVE-2026-97976 [Bluetooth: btintel_pcie: validate packet_len before skb_put_data]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6436e1b5331b1aebf905c13e0880a37032719b75 (7.3-rc3)
+CVE-2026-97975 [Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/9b851b09b392da68bd715601f10a5adb2d8d19b8 (7.3-rc3)
+CVE-2026-97973 [net: macb: destroy the phylink instance on the probe error path]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/7d059f390750152b9bd69df934198651b94fc26d (7.3-rc3)
+CVE-2026-97970 [watchdog: msc313e: Avoid division by zero]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/3c73a37f5e40972ce26d8eeb98e8b938d719b069 (7.3-rc3)
+CVE-2026-97969 [watchdog: msc313e: Fix clock leak and spurious timer in settimeout()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/3db30f315935c2fb0d95f46b7a593b5b4d3ec3d0 (7.3-rc3)
+CVE-2026-97968 [hwmon: (corsair-cpro) Create debugfs entries after hwmon registration]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/508baf1713f32f287bfb4f85d759403ec8ba35a3 (7.3-rc3)
+CVE-2026-97967 [hwmon: (corsair-cpro) Remove debugfs entries when probe fails]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4ee875c423c66c45d7ef7bbff403cd0e3971e0a2 (7.3-rc3)
+CVE-2026-97966 [octeontx2-pf: reset HTB scheduler topology before freeing queues]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ef39fca8508597fa565cf2be72a884a712fb98af (7.3-rc3)
+CVE-2026-97965 [vxlan: initialize _md in vxlan_xmit_one()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/be83178bfc44588f6e3adb827ed874c683193466 (7.3-rc3)
+CVE-2026-97964 [ppp_synctty: ensure a writeable skb header]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8aaeb56aff2a557a88f83ae866da2c91ad247e59 (7.3-rc3)
+CVE-2026-97963 [net: stmmac: initialize ptp_lock at probe time]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0338c68e22abd2ee509ec2e32508a50896618c32 (7.3-rc3)
+CVE-2026-97962 [net/mlx5e: Move representor vnic reporter to eswitch devlink port]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7f26a5e8040b4957ef4dbdfcde6cc7ba2db53937 (7.3-rc3)
+CVE-2026-97961 [perf/core: Allow list_del during perf_event_overflow()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/59e63416f5153e7d58652c616fbdcb7d5e01fff7 (7.3-rc3)
+CVE-2026-97960 [perf/x86/intel: Prevent drain_pebs() reentry]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c (7.3-rc3)
+CVE-2026-97959 [net/sched: cls_route: free emptied bucket on filter move]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1853f30cf5c84971f99788a76207c6f745380896 (7.3-rc3)
+CVE-2026-97958 [net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain().]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/dff39930ad5e53d202bfdfb14687d1d2fd753b4d (7.3-rc3)
+CVE-2026-97957 [net: hinic: fix mailbox segment buffer overflow]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5d4d985957434867bbe85e4fa5e638f3e48ad522 (7.3-rc3)
+CVE-2026-97954 [net/rds: fix tcp stream corruption with large pages]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2ac09b5353fe6858411fdc8c6efa60d832e20f13 (7.3-rc3)
+CVE-2026-97953 [net: stmmac: fix TX descriptor availability check for TSO traffic]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5e38d732ec67a5b1f9a56e6c73add480c4b6030a (7.3-rc3)
+CVE-2026-97952 [sunvdc: unmap LDC cookies when the descriptor send fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0c6da21fa35e03fc74f09895433ccd6d4a9c3530 (7.3-rc3)
+CVE-2026-97951 [scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d5869dae5080e976d4b03cc33eb7ceb527f242bf (7.3-rc2)
+CVE-2026-97950 [configfs: pin the symlink target's dirent instead of chasing ->ci_dentry]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a7c1290eef60711c10289c056ad32ed1f2b47b12 (7.3-rc3)
+CVE-2026-97949 [configfs: unhash the dentry before dropping the item in rmdir]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/f06c2d26d1999d37e93299db0ecead04ca7d0b9f (7.3-rc3)
+CVE-2026-97948 [powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c5e68706527968282e49de205cc2b935823cb88a (7.3-rc3)
+CVE-2026-97945 [x86/mm: Fix user-space data loss with MADV_FREE and THP]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f7491d7c81db0e7c304a7bd757a76d2fbeaff80e (7.3-rc4)
+CVE-2026-97940 [ipv6: fix fib6 walker UAF on seq stop]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/19b4ed644d68098cc62ab612727f40d30f43476c (7.3-rc3)
+CVE-2026-97939 [ipmr: account multicast table and route memory]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b7ee18725f2292ab554aa96a101ae42d45f008bd (7.3-rc3)
+CVE-2026-97938 [reboot: fix cad_pid use-after-free race]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5a88f78df753993469dab4d1831f8fb4256a9468 (7.3-rc3)
+CVE-2026-97936 [tracing: Fix memory corruption from the histogram stacktrace modifier]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a5e70ba87ca8ebc79b4e63de302d03b0625fe153 (7.3-rc3)
+CVE-2026-97935 [tracing: Set the trace clock before registering the histogram trigger]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6ede78d0563a2a3ae3e46f9c07cedb5d79645429 (7.3-rc3)
+CVE-2026-97934 [tracing: Fix memory corruption from a "STACKTRACE" histogram key]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7f711e62355bb3123a2ca2f97a2facbfebc678c6 (7.3-rc3)
+CVE-2026-97933 [tracing: Take trace_array reference when opening a tracer options file]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80 (7.3-rc3)
+CVE-2026-97931 [ALSA: us122l: Prevent write upgrades for read mappings]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/71c610aeb1770302ac9c9e0b9a4ecd37f1311928 (7.3-rc3)
+CVE-2026-97930 [ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/861111a14740e12c36d363e9830f8daa734279c9 (7.3-rc3)
+CVE-2026-97929 [ALSA: usbusx2y: validate URB actual_length in interrupt callback]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8f5ef203abda9dd36b2af473c7b737d544f807bd (7.3-rc3)
+CVE-2026-97928 [drm/amdgpu: skip the VMID 0 flush for VRAM]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/87ceb8cba73d0b3c4025ff42495bccd8164acaed (7.3-rc3)
+CVE-2026-97927 [ufs: create the root dentry after loading cylinder metadata]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/55a4c98abb9694b067c6a031d11501f06b6b523c (7.3-rc3)
+CVE-2026-97926 [ufs: validate cylinder group metadata before caching it]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c9d263be26806d388129fab8c6904bed197fc6af (7.3-rc3)
+CVE-2026-97925 [tick/broadcast: Plug clockevents replacement race]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/113a9796effe3376d2ec5aabcca1fef4fef4cd62 (7.3-rc3)
+CVE-2026-97924 [tracing/user_events: Don't destroy fields when event removal fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2deb753127d7b7035e893955c5e91875e767d1f8 (7.3-rc3)
+CVE-2026-97923 [tracing: Free histogram the var ref when its initialization fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/516001d53e6b2ea95a251ee2ef54a1a689a3fd58 (7.3-rc3)
+CVE-2026-97922 [tracing: Free histogram var refs regardless of how often they are referenced]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4bddcb346a6cf4615ca77f69a589623b877ca267 (7.3-rc3)
+CVE-2026-97921 [tracing: Free histogram the field rejected for a bad modifier]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/230234d12ce42ab04132a32c3a848f07a5d27a71 (7.3-rc3)
+CVE-2026-97920 [tracing: Keep the entry count when the histogram stats allocation fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/06f5634ec5584954177f9a22e36b3bfb398a971b (7.3-rc3)
+CVE-2026-97919 [tracing: Take the reference before publishing the named histogram trigger]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0fe23b8eaba0d3372c66b7b31204408da0715edc (7.3-rc3)
+CVE-2026-97918 [tracing: Undo the registration when enabling the histogram trigger fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/92383cef66791a0c63a2f27755cadbdb2fbf270b (7.3-rc3)
+CVE-2026-97917 [accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3837c3f29fbc3b8c12bebf5c62741e2befe3482a (7.3-rc3)
+CVE-2026-97916 [accel/ivpu: Validate firmware log buffer metadata]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0724afc55c77c36c7feb9a7264b02aa7593c5c2d (7.3-rc3)
+CVE-2026-97915 [accel/ivpu: Limit firmware log name prints to field size]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/95bf070f3225dc7175725438c916ad321d42fe45 (7.3-rc3)
+CVE-2026-97910 [ASoC: sprd: validate compress buffer sizes against fixed allocations]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/7a4ce92d150b9e7ecf1a710a34d8cdeb590d3751 (7.3-rc3)
+CVE-2026-97909 [ASoC: sti: initialize IRQ lock before requesting IRQ]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/04405aeef4f8d7bcac6dcb1947acafdb4420c2c3 (7.3-rc3)
+CVE-2026-97908 [Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/f5a427b16e45210dee656b0860728f3d496dee85 (7.3-rc3)
+CVE-2026-97907 [Bluetooth: btrtl: Don't leak return code when parsing firmware format v2]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/83e3e515fd261600ed8491fb0a8bcdfb115c904e (7.3-rc3)
+CVE-2026-97906 [bootconfig: Fix integer overflow in initrd size check]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/7812d6dab0698001e50e8c2f901e17da3eb6f429 (7.3-rc3)
+CVE-2026-97905 [cpufreq: zero-initialize policy cpumask before sysfs publication]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/54d37bcf2f497140b9207968557ddb484058e749 (7.3-rc3)
+CVE-2026-97904 [cpufreq: initialize policy rwsem before sysfs publication]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/3e5d1bf4bd687beb2cb4e32a07af695455925588 (7.3-rc3)
+CVE-2026-97902 [fs: don't return -EINVAL for successful nested thaw]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fe967191e5851ea79818c5fe4e781c3882139218 (7.3-rc3)
+CVE-2026-97901 [genetlink: pin family module during policy dump]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6a1094c34d176827b2b173e163dcc964a13af93f (7.3-rc3)
+CVE-2026-97900 [drm/drm_exec: fix up contended obj when num_objects is 0]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/159720704d9d652b64390c11fb971e15b0a78d23 (7.3-rc3)
+CVE-2026-97899 [drm/i915: Fix memory leak in query_perf_config_list()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/cbd3dafc2003db679ccd2f6c6a2551db79657049 (7.3-rc3)
+CVE-2026-97620 [drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f5fcf7e638b904397ec0f66d3ea6766ef0cfe25b (7.3-rc3)
+CVE-2026-97619 [io_uring/rw: end write accounting from ->ki_complete]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/796aa0547557e63338657ed1c487906f9fac4c73 (7.3-rc3)
+CVE-2026-97618 [io_uring/net: don't overconsume buffers when using MSG_TRUNC]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6028b543884f8735e057ec9eea4908cd61cab230 (7.3-rc3)
+CVE-2026-97617 [ring-buffer: Check resize_disabled before publishing the new subbuf order]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d860c67c051685abb0460b593b193f0f45f4fa92 (7.3-rc3)
+CVE-2026-97616 [net/sched: act_api: release all action references on NEWACTION failure]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/478eb5abb51931a152abab068f8a717b7ff480fd (7.3-rc3)
+CVE-2026-97615 [net: bridge: use option bits for CFM/MRP frame handlers]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/7a49e6b16f36b8e085521699adbca3e321b6dd0c (7.3-rc3)
+CVE-2026-97613 [net: mana: Reserve extra CQ slot for the fence completion CQE]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/80dd7e754b3aa9637a0758ad93fa209f9650ec48 (7.3-rc3)
+CVE-2026-97612 [net: mpls: clear inner_protocol when the last label is popped]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/78a86d75a70e1e227711c72865c59b1422d0a5ae (7.3-rc3)
+CVE-2026-97611 [net: openvswitch: fix use-after-free of the flow table mask array]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ba4ba11ed6eb8972c69070417fc27b48deb002e8 (7.3-rc3)
+CVE-2026-97609 [netfilter: cttimeout: prevent UAF during module unload]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/fec9b1de0d02de8dafa3cc344bcb91cf28660643 (7.3-rc3)
+CVE-2026-97608 [netfilter: nf_log: unregister loggers before per-net teardown]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2c018cc4842c33f0c732962e2ab58635e8ae5823 (7.3-rc3)
+CVE-2026-97607 [vdpa: ifcvf: Put device on unsupported feature error]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4d470be71196ca0ce302e6623454533dc31b465b (7.3-rc3)
+CVE-2026-97606 [fs: autofs: fix memory leak in autofs_fill_super()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5ab54837fce04a1c9923d0bfd3d5de51fdc768b3 (7.3-rc3)
+CVE-2026-97605 [erofs: preserve LZMA decoders on resize failure]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/617d0d8d199ba1790c94310fd75a22d01c97a8d6 (7.3-rc3)
+CVE-2026-97604 [fbdev: vfb: defer cleanup until the last reference]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a0a34a40ed299c9c7cff6af163a5b883ee9d6d73 (7.3-rc3)
+CVE-2026-97603 [idpf: disable DIM work before freeing q_vectors]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7dd4c829bac2916be98a3e34b41daaba7f42b4c4 (7.3-rc3)
+CVE-2026-97602 [inet: frags: invalidate queues before flushing them]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b824476c56a153934c67c9e0f873e1fd967743d6 (7.3-rc3)
+CVE-2026-97601 [ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/bf79662bc85e820ac3b846e2f347da29fbf6ac95 (7.3-rc3)
+CVE-2026-97600 [ieee802154: cc2520: fix FIFOP work use-after-free]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ff5891b266a7fc6a062710836be84f1cc19338b5 (7.3-rc3)
+CVE-2026-97599 [ieee802154: hwsim: serialize pib updates to fix double-free]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/979d5b8de8ed4e1f997aef12da5694b99be7b871 (7.3-rc3)
+CVE-2026-97598 [ipv4: fib: bound automatic table ID allocation]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/efdfb1e27a3328085b79540dfe781d537b576ea1 (7.3-rc3)
+CVE-2026-97597 [ipv6: flowlabel: cap duplicate leases per socket]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8d6cd188508513503805c156165de38e4e4a8615 (7.3-rc3)
+CVE-2026-97596 [ipvs: reject invalid states in connection template sync records]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/74cb39735b6cd0aff4b5584158f09376fd97aadf (7.3-rc3)
+CVE-2026-97595 [mac802154: fix use-after-free of sdata via queued RX frames]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2f37fba846c9fdff5fc15b6d93656057ccd13031 (7.3-rc3)
+CVE-2026-97594 [landlock: Fix use-after-free of the source's parent directory]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2c6dc792538260a8087ac5b22c31b3b8e47c85d6 (7.3-rc3)
+CVE-2026-97592 [s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8b7c3b6914f19caf648d05726a86af6326d3c2c6 (7.3-rc3)
+CVE-2026-97587 [perf: RISC-V: store available counter mask as bitmap]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6809da6e9c08ccc9a09cb0a48c61471679274aaa (7.3-rc3)
+CVE-2026-97584 [afs: Fix incorrect free in candidate cleanup in afs_lookup_server()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/044d596094af4b769fb8e1173dff0d08bd68db6c (7.3-rc3)
+CVE-2026-97583 [afs: Clear stale peer app data after address list changes]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ba0623fc19a424f4745394c499f9f28a8d88d397 (7.3-rc3)
+CVE-2026-97582 [hwmon: (gpio-fan) Fix use-after-free in alarm work]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a2471ed17b0e6ff7bfb6b2ea8e6e5b04c309d293 (7.3-rc3)
+CVE-2026-97581 [media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/06236b094c899c22c12ac5097935eb6719293de8 (7.3-rc3)
+CVE-2026-97579 [media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/37bef2170d4c88fc3d708eecf3ef0f4032bc1372 (7.3-rc3)
+CVE-2026-97578 [media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b84f6533a8ed2fd7b282fc7ab4b8efadc745a89c (7.3-rc3)
+CVE-2026-97577 [media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/367db8b23c26a913d76ed70457bbcd781c422b49 (7.3-rc3)
+CVE-2026-97576 [media: v4l2-ctrls: validate HEVC tile counts]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/dc694a9929f7cb9c88ef91e45eb982b7bbe5a477 (7.3-rc3)
+CVE-2026-97575 [media: v4l2-ctrls: validate AV1 tile counts]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/439058ced617fbb3febc017b9e93bb7387f309e0 (7.3-rc3)
+CVE-2026-97574 [bnxt_en: Don't free the live ring's TPA state on queue restart failure]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/5ce7f36c334d723954855ac769ede2fe0e8f89c8 (7.3-rc3)
+CVE-2026-97573 [bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/961e2a17c5e3559b3f8654d2daabdd25a42e770a (7.3-rc3)
+CVE-2026-97572 [bnxt_en: Propagate RX ring init failures in bnxt_init_nic()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8e6a850c0746bb4be167aedf1ee57469fcda09a9 (7.3-rc3)
+CVE-2026-97571 [bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b814dfbfeb0a68c9a52073f2caa05a2d5247a329 (7.3-rc3)
+CVE-2026-97568 [mptcp: syncookies: remember the request backup flag]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/b76c0e28b392620dfbaf92cdeedbf115820b44cb (7.3-rc3)
+CVE-2026-97567 [mptcp: prevent race between disconnect() and rtx]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/85c580b0d8590520ae00a15c29e9fb9c99427a3e (7.3-rc3)
+CVE-2026-97566 [mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2ac7d6e620764f1fc79eb4edd3610a7a661981ca (7.3-rc3)
+CVE-2026-97565 [smb: client: reject short READ responses in CIFSSMBRead()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e6142a8bfc230c7263eb8b0475249c958ce49367 (7.3-rc3)
+CVE-2026-97564 [smb: client: reject userspace cifs.idmap descriptions]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d9d7eeb0cea5b55b82888f443622fd8d4ee064f3 (7.3-rc3)
+CVE-2026-97563 [smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5be5bdda5863eacc964b609ba927764f253431b3 (7.3-rc3)
+CVE-2026-97562 [smb: client: pin DFS superblock in iterator callback]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d806d5a85dcbe2a0f181b2f0f9f61ddfbefa1818 (7.3-rc3)
+CVE-2026-97561 [smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/18a72975e9f35aadecc75b031f693f2d1f49308f (7.3-rc3)
+CVE-2026-97560 [smb: client: fix one-byte OOB read in smb2_parse_native_symlink()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cb26524ef4ac28fcfa554c0656e8dc412c38a8ff (7.3-rc3)
+CVE-2026-97559 [smb: client: fail DACL rewrite when the new DACL exceeds 64K]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d05045177a855386bca5e1909e08d06290e6e3b3 (7.3-rc3)
+CVE-2026-97558 [smb: client: fix cifsFileInfo reference leak in deferred close]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/5520e89a5a4f834bced64cf2ac927001cc513a40 (7.3-rc3)
+CVE-2026-97557 [smb: client: avoid leaking refcount in cifs_queue_oplock_break()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/9f2e63f1b2d5fc5b5423424902c091123e220e7e (7.3-rc3)
+CVE-2026-97556 [smb: client: avoid leaking refcount when cifs_sb_tlink() fails]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/23b26f4408ac3f35a482d2e5cf6fc865d4201b71 (7.3-rc3)
+CVE-2026-97555 [smb: client: fix heap overflow in DACL owner/group rewrite]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/0ee150794c75bcd0be0e24ff3394f433cbae18cc (7.3-rc3)
+CVE-2026-97554 [smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/da6e25842431982d5a53cf00d925b98c690f4467 (7.3-rc3)
+CVE-2026-97552 [xfs: initialise error in xfs_defer_finish_one()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/6176d21d7bd609632c5b7e87a3adb9be29ec1e72 (7.3-rc3)
+CVE-2026-97551 [xfs: initialise args->total for parent pointer updates]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8e4ebb6afaa34bd2e8ce52da231003d24111c2d6 (7.3-rc3)
+CVE-2026-97549 [xfs: fix under-reservation of blocks when repairing sf directories]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4d3c07591534517c633945c8d8e6526f10e3fabc (7.3-rc3)
+CVE-2026-97547 [xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a23eca88448e52eb1a81549862df7adce794fafb (7.3-rc3)
+CVE-2026-97546 [xfs: don't spin forever on zero-length dirents when salvaging them]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9f84792b40d0c96833341602144574bf0bd14a6a (7.3-rc3)
+CVE-2026-97545 [xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f1930bc578095409c2dcfca6e4e898b24f0f0de6 (7.3-rc3)
+CVE-2026-97544 [xfs: don't leak dqacct if rhashtable insertion fails]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2eac8d01d2c776fc26b0ac74aebdf91bc4490891 (7.3-rc3)
+CVE-2026-97543 [xfs: destroy seen inode bitmap when we fail to add a dirpath]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/1a441c6842da75c5b862cc1c9f7969d6a93b54b9 (7.3-rc3)
+CVE-2026-97542 [xfs: bail out on bitmap errors in xrep_agfl_fill]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/eaf580538eb1be3d162400d04c4b7dc4c627296b (7.3-rc3)
+CVE-2026-97541 [wifi: ath9k_htc: don't store usb_device_id]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/14d2ac442d660e112efc0ce87ad10085013ed2b1 (7.3-rc1)
+CVE-2026-97540 [net: usb: pegasus: don't rely on id table pointer arithmetic]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/ce8101c331956bbd3e20681331dfd22eb7c1c1ea (7.3-rc1)
+CVE-2026-97539 [usb: xusbatm: don't rely on id table pointer arithmetic]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/eb6cd6d3d8abeac5d7e8251b898067184afdad8a (7.3-rc1)
+CVE-2026-97538 [hwmon: (asus_rog_ryujin) Validate HID report lengths]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8042312e73c50de82634ce63eae7cf219464b481 (7.3-rc3)
+CVE-2026-97537 [scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/34a40e0dff940ac5eba494a69b553ea571e24873 (7.3-rc1)
+CVE-2026-97536 [scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/19788a55cab61d78e33e0914a5a31d27843e8a4a (7.3-rc1)
+CVE-2026-97535 [scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/878613ecb5a36db26859c4fd83daf9283a334fa2 (7.3-rc1)
+CVE-2026-97534 [f2fs: accurately adjust free_sections during free_segment_range]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8c963d1738fdca400082ff5f9d99e083de4f4e70 (7.3-rc1)
+CVE-2026-97532 [scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6d90f0feb929f6c0f3010f9af4747c7230b75993 (7.3-rc1)
+CVE-2026-97531 [scsi: qla2xxx: Skip vport under deletion in report ID acquisition]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/23582731afa35031c94fadb71a4f3b4afd094649 (7.3-rc1)
+CVE-2026-97530 [scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d7e3fa7d06bf7fcaac186d3c4d635caac166d36c (7.3-rc1)
+CVE-2026-97529 [scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4cf38dd9465736141263ebb63375868311a0ec81 (7.3-rc1)
+CVE-2026-97528 [scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/e46160a5d4fa59bf4d5f3412b6b5cb79edb967dd (7.3-rc1)
+CVE-2026-97527 [scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/76da0c43c63eb0496649e372ac64466364d0fe7d (7.3-rc1)
+CVE-2026-97526 [s390/pai: Support CPU hotplug for PMU PAI]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9ecc4d033879f7761f2df07e20cd2fbec00fd90b (7.3-rc3)
+CVE-2026-97524 [mptcp: avoid unneeded actions on subflow reset]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2b0f561f21b27c40c91ea4975268a06092bd7e9c (7.3-rc4)
+CVE-2026-97523 [mptcp: close race between scheduler and state change]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/42064de57fb83231fcc89663a94885f228a1ee53 (7.3-rc4)
+CVE-2026-97522 [mptcp: fix bad accounting in __mptcp_subflow_push_pending()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/f3ef03357396d4b147d8e76c75fb612c2f264ffc (7.3-rc4)
 CVE-2026-84711
 	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84709



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7631cdcb8796dc4f735db70370a8f123655175a1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7631cdcb8796dc4f735db70370a8f123655175a1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/17c7cbd8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list