Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: d86fb1fb by Salvatore Bonaccorso at 2026-07-27T08:52:08+02:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,25 @@ +CVE-2026-64536 [staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop] + - linux 7.1.4-1 + [trixie] - linux 6.12.96-1 + NOTE: https://git.kernel.org/linus/3bf39f711ff27c64be8680a8938bcc5001982e81 (7.2-rc3) +CVE-2026-64535 [nvmet-tcp: Fix potential UAF when ddgst mismatch] + - linux 7.1.3-1 + NOTE: https://git.kernel.org/linus/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a (7.1-rc4) +CVE-2026-64534 [nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path] + - linux 7.1.3-1 + NOTE: https://git.kernel.org/linus/4606467a75cfc16721937272ed29462a750b60c8 (7.1-rc2) +CVE-2026-64533 [fs/ntfs3: validate lcns_follow in log_replay conversion] + - linux 7.1.5-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/6a4c53a2e26a865565bd6a460961e8d6fcb32329 (7.2-rc1) +CVE-2026-64532 [fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}] + - linux 7.1.5-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3e127829e57f5190f612412ece4541cb96d5ec7a (7.2-rc1) +CVE-2026-64531 [net: openvswitch: reject oversized nested action attrs] + - linux 7.1.5-1 + [bullseye] - linux <not-affected> (Vulnerable code not present) + NOTE: https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4) CVE-2026-49478 - golang-github-sigstore-fulcio 1.8.7-1 NOTE: https://github.com/sigstore/fulcio/pull/2354 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d86fb1fbe6a68354d0f41ec48cd4812287b81626 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d86fb1fbe6a68354d0f41ec48cd4812287b81626 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
