[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 18:34:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7e9511b9 by Salvatore Bonaccorso at 2026-09-25T19:33:58+02:00
Merge Linux CVEs from kernel-sec

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,46 @@
+CVE-2026-98162 [smb/server: fix tree connection leak in smb2_tree_connect()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/39f2032096715daae5f6fd0f587ca7a474b019df (7.3-rc1)
+CVE-2026-98161 [nvdimm: pmem: keep PREFLUSH before data writes]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/c644a2f8fef5618fcf453c591177700fd07dd024 (7.3-rc1)
+CVE-2026-98160 [staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/264676418b726baca7be49171e306b6aa05cceb0 (7.3-rc1)
+CVE-2026-100079 [usb: typec: ucsi: unregister debugfs entries on teardown]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/eed73a65ab609b79d53de88cccc34b36dfe753c4 (7.3-rc1)
+CVE-2026-100078 [wifi: iwlwifi: mei: pass correct argument to function]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/905f57aefde4f4092a411c8a55856182fb1c7598 (7.3-rc1)
+CVE-2026-100077 [drm/msm: Recover HW before retire hung submit]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/b303e1d52811de7d1bcf793560754d4df68d4a1c (7.3-rc1)
+CVE-2026-100076 [staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/41b8209376dffbd7b0b85c8bc4697d9166ac62ef (7.3-rc1)
+CVE-2026-100075 [RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/b38f98e176050850f41bb6415f3a71400056623e (7.3-rc1)
+CVE-2026-100074 [bpf: Mark bpf_refcount field as unique]
+	- linux 7.2.6-1
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/61e655391cb19c31f94ecd4354f624c81ce4cf75 (7.3-rc1)
+CVE-2026-100073 [ext4: fix transaction overflow during writeback]
+	- linux 7.2.6-1
+	[trixie] - linux <not-affected> (Vulnerable code not present)
+	[bookworm] - linux <not-affected> (Vulnerable code not present)
+	NOTE: https://git.kernel.org/linus/46e8e31771f4f1c5e1cdec37a889a6730e42e9f1 (7.3-rc1)
+CVE-2026-100072 [ACPI: platform: Use acpi_bus_get_primary_device()]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/a9ba4dd2f18bf3f439d9ef0d8f375f90360ba1bd (7.3-rc1)
+CVE-2026-100071 [net: hsr: free learned nodes on device setup failure]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/7f16289b91eb316f170a6bd22d32e6c632f6a5b6 (7.3-rc1)
+CVE-2026-100070 [netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet]
+	- linux 7.2.6-1
+	NOTE: https://git.kernel.org/linus/16aecbe3036f6097c26b51b12e4c1cf207769690 (7.3-rc1)
 CVE-2026-98150 [bpf: Fix BPF_F_CPU validation for sparse CPU IDs]
 	- linux 7.2.7-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e9511b9e5308a98e78c9e9bcb3427bee83ebe3b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e9511b9e5308a98e78c9e9bcb3427bee83ebe3b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/9f3c9d1b/attachment.htm>


More information about the debian-security-tracker-commits mailing list