[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 13:40:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2907e8ce by Salvatore Bonaccorso at 2026-09-25T14:36:17+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,232 @@
+CVE-2026-98150 [bpf: Fix BPF_F_CPU validation for sparse CPU IDs]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ed54bf564ac52699cf4def3d0c2125d493e756f9 (7.3-rc2)
+CVE-2026-98149 [bpf: Fix percpu map update indexing with sparse CPU IDs]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/75b0a6db4300e4c2c9e97a0848deaa7acfb42fb7 (7.3-rc2)
+CVE-2026-98146 [accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/b3709d354545e70388177500761f92d906c4dfd6 (7.3-rc2)
+CVE-2026-98145 [accel/amdxdna: reject a command chain that carries no commands]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ef6d27af71e1dc43181ec797a6aaa77c27c36786 (7.3-rc2)
+CVE-2026-98144 [accel/amdxdna: put the chained BO when its mapping fails]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/7e33ba3a1d48c2d20ed270dec9d2d08332585c8e (7.3-rc2)
+CVE-2026-98143 [accel: ethosu: Don't read the U65 rounding mode as a storage mode]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/db9deec5a345abc538d081fb221dc0b00a9695bd (7.3-rc2)
+CVE-2026-98141 [ntfs: propagate reparse index insertion failure]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/9692b1b4fc00cf89628bc43f71729ab21f14f8d3 (7.3-rc2)
+CVE-2026-98140 [ntfs: fix kmap_local leak in write_mft_record_nolock() error paths]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/cf06dcd572845723821b54a608fc2da995c3c8e2 (7.3-rc2)
+CVE-2026-98139 [ntfs: only count successfully cleared runs when freeing clusters]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/be9e89ccb8e52a3e4b67feeb03ebd8133091dc7e (7.3-rc2)
+CVE-2026-98138 [ntfs: do not mark the volume clean in sync_fs when errors were recorded]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/0e4c839905418d55bafe571a92533a1d1ac7b0a8 (7.3-rc2)
+CVE-2026-98137 [ntfs: treat any nonzero dio zero-range return as an error]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/607a9478833db656e7ceac8e9e382fa4acfde545 (7.3-rc2)
+CVE-2026-98136 [ntfs: bound $AttrDef table walk to the loaded table size]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c8504fc1245f5322af5fa5c325ab05f9cf792b87 (7.3-rc2)
+CVE-2026-98135 [ntfs: reject invalid sectors_per_cluster in the boot sector]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/323751a604e7533fa473874d999371592a614207 (7.3-rc2)
+CVE-2026-98133 [ntfs: leave HasEA flag untouched on setxattr failure]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ac727d86fb84bdc9626ba9c756c26767459f3083 (7.3-rc2)
+CVE-2026-98132 [bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/2f3536bff8823d3c5fdbbe15e17bfca696cc2b2e (7.3-rc2)
+CVE-2026-98120 [netfs: Fix subreq ref leak]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/3c30087e27598d9d359763e8be9bd3017fe08348 (7.3-rc3)
+CVE-2026-98117 [cachefiles: Fix potential UAF/KASAN warning]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a67632c8c2688d6e0091529bcefe54bc5ee80e9b (7.3-rc3)
+CVE-2026-98112 [ksmbd: fix listener task lifetime on netdev events]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/a506290f59e1c6ce9ac0a13158640bb8fee93471 (7.3-rc2)
+CVE-2026-98159 [wifi: mt76: mt7921: validate CLC firmware records]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/9417c5818a0146980c2608fda94c908e604eb033 (7.3-rc1)
+CVE-2026-98158 [ppp_async: drop the errored frame instead of resetting its headroom]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/8dc5d98a16fa23c00999aecf10018c9f69fa5bf4 (7.3-rc3)
+CVE-2026-98157 [EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/66cc9dec919dd63d8e4b3d386f7aed3ae684e645 (7.3-rc2)
+CVE-2026-98156 [drm/virtio: use the DMA API for resource backing on Xen]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/6a736d2f9d0c6e6217fe7532bc4c50ceca71db78 (7.3-rc2)
+CVE-2026-98155 [accel/qaic: Address potential out-of-bounds read in resp_worker()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ab243f74ab4084ca5c8dec608cb5b0deb27db067 (7.3-rc2)
+CVE-2026-98154 [nvme-rdma: fix -EIO cleanup order in queue_rq]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d61828199c6cb4b76d48403c77023cd4bb9d09fc (7.3-rc2)
+CVE-2026-98153 [nvme: fix racy access to FDP placement id array]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/56e1c6bbe4bb084d7ecf61698afdf70be23dd35f (7.3-rc2)
+CVE-2026-98152 [nvmet-rdma: fix queue leak when connect backlog is exceeded]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fb1ed67788e21832b614c23767a088c08cfdd2f2 (7.3-rc2)
+CVE-2026-98151 [bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/150aeba624e8b7cac51c39440d7e8e1fd11de9a0 (7.3-rc2)
+CVE-2026-98148 [drm/gud: validate GUD_ROTATION_0 is present in supported rotations]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/cb732d027aa18e1fcf9d2797f47d20b179ebc59c (7.3-rc2)
+CVE-2026-98147 [printk: Don't WARN on kthread_run failure.]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/72dd0ec09e7cc98ed58ddeac26575e5d1ab8a93d (7.3-rc3)
+CVE-2026-98142 [drm/cirrus-qemu: Validate BAR0 size during probe]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/92312d333bf700798f92f30406c721bce87506f3 (7.3-rc2)
+CVE-2026-98134 [bpf: check_cond_jmp_op(): properly infer if register is null]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d3ef6c097ba078e1f8c7239d76a0ce8b61e75095 (7.3-rc2)
+CVE-2026-98131 [net: stmmac: fix dma mapping leak in stmmac_tso_xmit()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a5d946466a95621fa2769720d59ea336003aa1a5 (7.3-rc2)
+CVE-2026-98130 [sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2188569e7e1b0bc3f3b557dc97ab7a02befc11c8 (7.3-rc2)
+CVE-2026-98129 [scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/dba9e2181ca5e875f98b8b9b4535cdaab87dcb0d (7.3-rc2)
+CVE-2026-98128 [scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/419d129f970aaa6567dbac366b0c93784bf9ec97 (7.3-rc2)
+CVE-2026-98127 [smb/client: validate new EOF for insert range]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/1519dc88c87f5346dae0464d7d6da1b6bf1f6e8e (7.3-rc2)
+CVE-2026-98126 [smb/client: validate new EOF for zero range]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/88972e35750792e717af287dc71f42a03b5cbce4 (7.3-rc2)
+CVE-2026-98125 [smb/client: fix stale page cache in insert/collapse range]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/01261a6fa48b62f5ead8e88aaca1e27cb9ab9032 (7.3-rc2)
+CVE-2026-98124 [smb/client: invalidate fscache for fallocate range operations]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/448ba0ae65ca61064183564d2983c9aa59bd6ba7 (7.3-rc2)
+CVE-2026-98123 [sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2cb0b0b1ed69430bf73740377ea0a1c44c50db63 (7.3-rc2)
+CVE-2026-98122 [vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/4aa61c88b4e292e10abdfd791334b8272108d68a (7.3-rc2)
+CVE-2026-98121 [watchdog: msc313e: Fix NULL pointer dereference in PM callbacks]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/e3eceb76515910746e6268c4e4ac1c07516ebd7b (7.3-rc3)
+CVE-2026-98119 [netfs: break unbuffered write when netfs_alloc_subrequest() fails]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/8fb45a934661419c04a44d4cfea1e0df7dcf2805 (7.3-rc3)
+CVE-2026-98118 [netfs: Fix readahead synchronisation issues by loading all folios upfront]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/fed0b33e6c584986ba70018ec9f9787a98216e64 (7.3-rc3)
+CVE-2026-98116 [ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/9b110a9dcecc59516c77cb3c0caf1f492f75df2d (7.3-rc2)
+CVE-2026-98115 [ksmbd: safely drain sessions during logoff]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/d12168084c8c1b6d883c8eca5853929ac5136a9e (7.3-rc2)
+CVE-2026-98114 [ksmbd: propagate DACL parsing errors]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c61dc7b1b4a3234b4aa3965502908a292238805c (7.3-rc2)
+CVE-2026-98113 [ksmbd: rate limit unmapped SID errors]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/feca5e70fc963b088377b20879e8cd8237c2fd7d (7.3-rc2)
+CVE-2026-98111 [Bluetooth: btintel: validate version TLV value lengths]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/a086c0892969bf8a0151b0f12bd14a68827c88b2 (7.3-rc2)
+CVE-2026-98110 [Bluetooth: btintel: bound firmware ID by TLV length]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/ac8aa9e0ec93a12a60230066f199f49c3b9aac3d (7.3-rc2)
+CVE-2026-98109 [Bluetooth: hci_core: Fix race condition during device registration]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/57938bbdb9bf7fd41cbd5cd509ec10c4b22bec18 (7.3-rc2)
+CVE-2026-98108 [Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/4ef05db5b08b176a551b4a6287372045998806b0 (7.3-rc2)
+CVE-2026-98107 [Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/56c2b5831d39dc84aad2573dc3e197af1a872a05 (7.3-rc2)
+CVE-2026-98106 [drm/pagemap: Prevent double migration of device pages]
+	- linux 7.2.7-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/c4126f1db36e6b2e1c79b0e30a8a2de91c568f4c (7.3-rc2)
+CVE-2026-98105 [net: ethernet: oa_tc6: Improve the error recovery]
+	- linux 7.2.7-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/172c974113bffe5723b80b1acac17593bb50513c (7.3-rc2)
+CVE-2026-98104 [net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f (7.3-rc2)
+CVE-2026-98103 [igmp: convert struct ip_sf_list to RCU]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/2987ee196c88dbde0463dc87d5fb209c684e34a2 (7.3-rc2)
+CVE-2026-98102 [ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/93b49239840b91313adbd77b8b52993eff2d08c1 (7.3-rc2)
+CVE-2026-98101 [ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()]
+	- linux 7.2.7-1
+	NOTE: https://git.kernel.org/linus/c073d1b070f171d206b19c98d71739a97f15b3f1 (7.3-rc2)
 CVE-2026-98093 [ASoC: fsl_micfil: balance mclk enable/disable]
 	- linux 7.2.7-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2907e8cec4469f50e0a8037448a5c2a00fe6824e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2907e8cec4469f50e0a8037448a5c2a00fe6824e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/e008113a/attachment.htm>


More information about the debian-security-tracker-commits mailing list