Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-yarn-classic/component-prefetch-yarn-classic Running clair-action on amd64 image manifest... 2026/08/15 03:07:43 INFO matchers created matcher.suse=https://pkg.go.dev/github.com/quay/claircore/suse matcher.alpine-matcher=https://pkg.go.dev/github.com/quay/claircore/alpine matcher.debian-matcher=https://pkg.go.dev/github.com/quay/claircore/debian matcher.ubuntu-matcher=https://pkg.go.dev/github.com/quay/claircore/ubuntu matcher.aws-matcher=https://pkg.go.dev/github.com/quay/claircore/aws matcher.python=https://pkg.go.dev/github.com/quay/claircore/python matcher.ruby-gem=https://pkg.go.dev/github.com/quay/claircore/ruby matcher.java-maven=https://pkg.go.dev/github.com/quay/claircore/java matcher.oracle=https://pkg.go.dev/github.com/quay/claircore/oracle matcher.rhel=https://pkg.go.dev/github.com/quay/claircore/rhel matcher.gobin=https://pkg.go.dev/github.com/quay/claircore/gobin matcher.photon=https://pkg.go.dev/github.com/quay/claircore/photon matcher.rhel-container-matcher=https://pkg.go.dev/github.com/quay/claircore/rhel/rhcc 2026/08/15 03:07:43 INFO vex factory configured base_url=https://security.access.redhat.com/data/csaf/v2/vex/ compressed_file_timeout=2m0s 2026/08/15 03:07:43 INFO libvuln initialized 2026/08/15 03:07:43 INFO registered configured scanners 2026/08/15 03:07:43 INFO constructing 2026/08/15 03:07:43 INFO index request start 2026/08/15 03:07:43 INFO starting scan 2026/08/15 03:07:43 INFO manifest to be scanned 2026/08/15 03:07:43 INFO layers fetch start 2026/08/15 03:07:53 INFO layers fetch success 2026/08/15 03:07:53 INFO layers fetch done 2026/08/15 03:07:53 INFO layers scan start 2026/08/15 03:07:53 WARN required labels not found in labels.json 2026/08/15 03:07:54 INFO layers scan done 2026/08/15 03:07:54 INFO starting index manifest 2026/08/15 03:07:54 INFO finishing scan 2026/08/15 03:07:54 INFO manifest successfully scanned 2026/08/15 03:07:54 INFO index request done { "manifest_hash": "sha256:9d32d450559588bcb1f842fbe5e630e24ace63142be8e03d405793b1e1587237", "packages": { "+6B10TyZ7Yw1Uati+EDFTg==": { "id": "+6B10TyZ7Yw1Uati+EDFTg==", "name": "libncursesw5-dev", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "+EvVUYESwvcEspjJuRUM8Q==": { "id": "+EvVUYESwvcEspjJuRUM8Q==", "name": "gpg-wks-client", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "+H4zAe65wQjw+4vudFFWQA==": { "id": "+H4zAe65wQjw+4vudFFWQA==", "name": "libxcb1", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "+h682k8DPZQDWsNWMpPCnA==": { "id": "+h682k8DPZQDWsNWMpPCnA==", "name": "libgmp10", "version": "2:6.2.1+dfsg1-1.1", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "2:6.2.1+dfsg1-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "+iLzjzcgN8yvafgaUEN6Mg==": { "id": "+iLzjzcgN8yvafgaUEN6Mg==", "name": "autoconf", "version": "2.71-3", "kind": "binary", "source": { "id": "", "name": "autoconf", "version": "2.71-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "/+Kyg0TsZIwaRl7+5J3rRg==": { "id": "/+Kyg0TsZIwaRl7+5J3rRg==", "name": "libsasl2-2", "version": "2.1.28+dfsg-10", "kind": "binary", "source": { "id": "", "name": "cyrus-sasl2", "version": "2.1.28+dfsg-10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "/1xbchBbkMyq0Ur9WaUTgg==": { "id": "/1xbchBbkMyq0Ur9WaUTgg==", "name": "sysvinit-utils", "version": "3.06-4", "kind": "binary", "source": { "id": "", "name": "sysvinit", "version": "3.06-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "/4BvI5P5ynGyNUU97zqdMw==": { "id": "/4BvI5P5ynGyNUU97zqdMw==", "name": "libkeyutils1", "version": "1.6.3-2", "kind": "binary", "source": { "id": "", "name": "keyutils", "version": "1.6.3-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "/nkMmPBG6SYwe3XCMMkFfg==": { "id": "/nkMmPBG6SYwe3XCMMkFfg==", "name": "libmpc3", "version": "1.3.1-1", "kind": "binary", "source": { "id": "", "name": "mpclib3", "version": "1.3.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "/rs/W+FOAL/4DwyA5fEcyQ==": { "id": "/rs/W+FOAL/4DwyA5fEcyQ==", "name": "libcap2", "version": "1:2.66-4+deb12u3+b1", "kind": "binary", "source": { "id": "", "name": "libcap2", "version": "1:2.66-4+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "03Bi06wwCZvhMScXOn+12g==": { "id": "03Bi06wwCZvhMScXOn+12g==", "name": "libxcb-shm0", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "0rQO8ev0gA2bMPyvfyRTSg==": { "id": "0rQO8ev0gA2bMPyvfyRTSg==", "name": "libmariadb-dev", "version": "1:10.11.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "mariadb", "version": "1:10.11.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "0zZmFEOjIMpFAeP+24iakA==": { "id": "0zZmFEOjIMpFAeP+24iakA==", "name": "perl-modules-5.36", "version": "5.36.0-7+deb12u3", "kind": "binary", "source": { "id": "", "name": "perl", "version": "5.36.0-7+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "138kks0ax5N2nNIEzmExjg==": { "id": "138kks0ax5N2nNIEzmExjg==", "name": "libnsl-dev", "version": "1.3.0-2", "kind": "binary", "source": { "id": "", "name": "libnsl", "version": "1.3.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "1BEuahkY5GQ7T8hAznQnJA==": { "id": "1BEuahkY5GQ7T8hAznQnJA==", "name": "media-types", "version": "10.0.0", "kind": "binary", "source": { "id": "", "name": "media-types", "version": "10.0.0", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "1MYT+bMAGBkKcm+bMIqb6Q==": { "id": "1MYT+bMAGBkKcm+bMIqb6Q==", "name": "libassuan0", "version": "2.5.5-5", "kind": "binary", "source": { "id": "", "name": "libassuan", "version": "2.5.5-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "1T4167CC3sXBfikeGTBamA==": { "id": "1T4167CC3sXBfikeGTBamA==", "name": "libdav1d6", "version": "1.0.0-2+deb12u1", "kind": "binary", "source": { "id": "", "name": "dav1d", "version": "1.0.0-2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "1d+ozfBeVKodpg99SYjl1A==": { "id": "1d+ozfBeVKodpg99SYjl1A==", "name": "libjbig0", "version": "2.1-6.1", "kind": "binary", "source": { "id": "", "name": "jbigkit", "version": "2.1-6.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "1ibbew6p8bvI8FxMYegw1g==": { "id": "1ibbew6p8bvI8FxMYegw1g==", "name": "libbz2-1.0", "version": "1.0.8-5+b1", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.8-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "1jsoelSNrhP+91EF5BRAZQ==": { "id": "1jsoelSNrhP+91EF5BRAZQ==", "name": "libaudit-common", "version": "1:3.0.9-1", "kind": "binary", "source": { "id": "", "name": "audit", "version": "1:3.0.9-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "2GdIFjp2v2PoJza2YjGYeA==": { "id": "2GdIFjp2v2PoJza2YjGYeA==", "name": "mercurial-common", "version": "6.3.2-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "mercurial", "version": "6.3.2-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "2M24H7TupgyXsQi8O+lCmw==": { "id": "2M24H7TupgyXsQi8O+lCmw==", "name": "subversion", "version": "1.14.2-4+deb12u1", "kind": "binary", "source": { "id": "", "name": "subversion", "version": "1.14.2-4+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "2ZcPfrj/S1OihNpEALoqBQ==": { "id": "2ZcPfrj/S1OihNpEALoqBQ==", "name": "imagemagick-6.q16", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "2ZjFWZInqL1yRVL3PtElzg==": { "id": "2ZjFWZInqL1yRVL3PtElzg==", "name": "libblkid-dev", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "2fLCAY2+SVCQ2VXaZQ3hqg==": { "id": "2fLCAY2+SVCQ2VXaZQ3hqg==", "name": "libgomp1", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "2j1W2lPmBANCzFxgA5vkow==": { "id": "2j1W2lPmBANCzFxgA5vkow==", "name": "libdpkg-perl", "version": "1.21.23", "kind": "binary", "source": { "id": "", "name": "dpkg", "version": "1.21.23", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "2q4gD1GZAkS/i3n3Sy+/DQ==": { "id": "2q4gD1GZAkS/i3n3Sy+/DQ==", "name": "libxslt1-dev", "version": "1.1.35-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "libxslt", "version": "1.1.35-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "30Y83yLPxjZH53BgMHRMgg==": { "id": "30Y83yLPxjZH53BgMHRMgg==", "name": "libaom3", "version": "3.6.0-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "aom", "version": "3.6.0-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "34WD1/tcvM7PC3MYaksE/A==": { "id": "34WD1/tcvM7PC3MYaksE/A==", "name": "libpcre2-posix3", "version": "10.42-1", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.42-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "36PkSUqF3oUYJxM3LL7ytg==": { "id": "36PkSUqF3oUYJxM3LL7ytg==", "name": "libkdb5-10", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "3GFMF+uXbATcLfbem/AI2A==": { "id": "3GFMF+uXbATcLfbem/AI2A==", "name": "librtmp1", "version": "2.4+20151223.gitfa8646d.1-2+b2", "kind": "binary", "source": { "id": "", "name": "rtmpdump", "version": "2.4+20151223.gitfa8646d.1-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "3S82cOcntf6/9zxs22JKWA==": { "id": "3S82cOcntf6/9zxs22JKWA==", "name": "libpcre2-8-0", "version": "10.42-1", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.42-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "3k4FPwKVTHyfyKjD8kMK+A==": { "id": "3k4FPwKVTHyfyKjD8kMK+A==", "name": "libapt-pkg6.0", "version": "2.6.1", "kind": "binary", "source": { "id": "", "name": "apt", "version": "2.6.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "45yJxXr/oZ39MkwKjVCtMw==": { "id": "45yJxXr/oZ39MkwKjVCtMw==", "name": "libmpfr6", "version": "4.2.0-1", "kind": "binary", "source": { "id": "", "name": "mpfr4", "version": "4.2.0-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "46hyRjmPCCIvx2yjneoXzQ==": { "id": "46hyRjmPCCIvx2yjneoXzQ==", "name": "g++", "version": "4:12.2.0-3", "kind": "binary", "source": { "id": "", "name": "gcc-defaults", "version": "1.203", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "4HvsO4LmB5qq71OYhAgtsw==": { "id": "4HvsO4LmB5qq71OYhAgtsw==", "name": "gpg-agent", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "4NCpmpKxo8GpWHW5UMZtDQ==": { "id": "4NCpmpKxo8GpWHW5UMZtDQ==", "name": "libx11-data", "version": "2:1.8.4-2+deb12u2", "kind": "binary", "source": { "id": "", "name": "libx11", "version": "2:1.8.4-2+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "4TrIugtbBqxqa6oPXOcZ9A==": { "id": "4TrIugtbBqxqa6oPXOcZ9A==", "name": "libapr1", "version": "1.7.2-3+deb12u1", "kind": "binary", "source": { "id": "", "name": "apr", "version": "1.7.2-3+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "4bhBgLYIRdRNvwRcgDDNIA==": { "id": "4bhBgLYIRdRNvwRcgDDNIA==", "name": "libgirepository-1.0-1", "version": "1.74.0-3", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.74.0-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "4eit2G6XEpf9131xbIDkiQ==": { "id": "4eit2G6XEpf9131xbIDkiQ==", "name": "fonts-dejavu-core", "version": "2.37-6", "kind": "binary", "source": { "id": "", "name": "fonts-dejavu", "version": "2.37-6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "4fCygkDtdC/0bxMKYOg9Rg==": { "id": "4fCygkDtdC/0bxMKYOg9Rg==", "name": "grep", "version": "3.8-5", "kind": "binary", "source": { "id": "", "name": "grep", "version": "3.8-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "4j0fN++xbxUCmc5aXfanEw==": { "id": "4j0fN++xbxUCmc5aXfanEw==", "name": "mariadb-common", "version": "1:10.11.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "mariadb", "version": "1:10.11.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "4uoDWqA6j1h67XvnWkb69Q==": { "id": "4uoDWqA6j1h67XvnWkb69Q==", "name": "gnupg-l10n", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "4xzOAwX8EAP1eOlXGJnUVQ==": { "id": "4xzOAwX8EAP1eOlXGJnUVQ==", "name": "libcairo2", "version": "1.16.0-7", "kind": "binary", "source": { "id": "", "name": "cairo", "version": "1.16.0-7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5//49B09LJAbC2XX9es0/Q==": { "id": "5//49B09LJAbC2XX9es0/Q==", "name": "libpsl5", "version": "0.21.2-1", "kind": "binary", "source": { "id": "", "name": "libpsl", "version": "0.21.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5LsAwCM1hSXSqHbcXxFSaQ==": { "id": "5LsAwCM1hSXSqHbcXxFSaQ==", "name": "libzstd1", "version": "1.5.4+dfsg2-5", "kind": "binary", "source": { "id": "", "name": "libzstd", "version": "1.5.4+dfsg2-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5dR7lWzzD+nj4jHczZv87g==": { "id": "5dR7lWzzD+nj4jHczZv87g==", "name": "libnettle8", "version": "3.8.1-2", "kind": "binary", "source": { "id": "", "name": "nettle", "version": "3.8.1-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5jj9c572EogqkPW6Ucwcag==": { "id": "5jj9c572EogqkPW6Ucwcag==", "name": "e2fsprogs", "version": "1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5uWQa9ljjSF0OokLG8is7A==": { "id": "5uWQa9ljjSF0OokLG8is7A==", "name": "libgcc-s1", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5wydsqQl0bNu0Far4Hwvlg==": { "id": "5wydsqQl0bNu0Far4Hwvlg==", "name": "libwmflite-0.2-7", "version": "0.2.12-5.1", "kind": "binary", "source": { "id": "", "name": "libwmf", "version": "0.2.12-5.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "5xli1ibcVetek1e+KZM6ow==": { "id": "5xli1ibcVetek1e+KZM6ow==", "name": "gzip", "version": "1.12-1", "kind": "binary", "source": { "id": "", "name": "gzip", "version": "1.12-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "60WVKLZwJNhOxCy+uvFphw==": { "id": "60WVKLZwJNhOxCy+uvFphw==", "name": "libyaml-0-2", "version": "0.2.5-1", "kind": "binary", "source": { "id": "", "name": "libyaml", "version": "0.2.5-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6ATWONUn9Z77FRku437S0A==": { "id": "6ATWONUn9Z77FRku437S0A==", "name": "libncurses-dev", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6EEIMKT/hWmOhDYuGd9fsQ==": { "id": "6EEIMKT/hWmOhDYuGd9fsQ==", "name": "xtrans-dev", "version": "1.4.0-1", "kind": "binary", "source": { "id": "", "name": "xtrans", "version": "1.4.0-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "6NlVgElnclw5vmTnQK9Kfw==": { "id": "6NlVgElnclw5vmTnQK9Kfw==", "name": "libzstd-dev", "version": "1.5.4+dfsg2-5", "kind": "binary", "source": { "id": "", "name": "libzstd", "version": "1.5.4+dfsg2-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6SJtgGhuLlRhbMpPiqkd3g==": { "id": "6SJtgGhuLlRhbMpPiqkd3g==", "name": "libgdk-pixbuf2.0-common", "version": "2.42.10+dfsg-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "gdk-pixbuf", "version": "2.42.10+dfsg-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "6T3N+jQPDlXgrfLG1fI1YQ==": { "id": "6T3N+jQPDlXgrfLG1fI1YQ==", "name": "libimath-dev", "version": "3.1.6-1", "kind": "binary", "source": { "id": "", "name": "imath", "version": "3.1.6-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6V73823qwtABE6sG2lbnnw==": { "id": "6V73823qwtABE6sG2lbnnw==", "name": "libxcb-render0-dev", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6Wc644zWglyAsbvhtOZ3dg==": { "id": "6Wc644zWglyAsbvhtOZ3dg==", "name": "libevent-dev", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "6jYszk7CIbKEpuqb5CQ2dA==": { "id": "6jYszk7CIbKEpuqb5CQ2dA==", "name": "libjpeg62-turbo", "version": "1:2.1.5-2", "kind": "binary", "source": { "id": "", "name": "libjpeg-turbo", "version": "1:2.1.5-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "74RbRvv2uTUZVyS/aUST+A==": { "id": "74RbRvv2uTUZVyS/aUST+A==", "name": "libncurses6", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "75SnQC+8AKaRBUB2VJtspw==": { "id": "75SnQC+8AKaRBUB2VJtspw==", "name": "libtirpc3", "version": "1.3.3+ds-1", "kind": "binary", "source": { "id": "", "name": "libtirpc", "version": "1.3.3+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "7I8pkw9XzeISk4juz4yhaA==": { "id": "7I8pkw9XzeISk4juz4yhaA==", "name": "libsepol-dev", "version": "3.4-2.1", "kind": "binary", "source": { "id": "", "name": "libsepol", "version": "3.4-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "7f5C30nClWQKp6ABE9Cr6g==": { "id": "7f5C30nClWQKp6ABE9Cr6g==", "name": "python3-distutils", "version": "3.11.2-3", "kind": "binary", "source": { "id": "", "name": "python3-stdlib-extensions", "version": "3.11.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "7jIzXM6Spac0GoVcshxV2Q==": { "id": "7jIzXM6Spac0GoVcshxV2Q==", "name": "libmagickcore-dev", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "7m9Wfd2N4nRasn5qfmA8DQ==": { "id": "7m9Wfd2N4nRasn5qfmA8DQ==", "name": "libwmf-dev", "version": "0.2.12-5.1", "kind": "binary", "source": { "id": "", "name": "libwmf", "version": "0.2.12-5.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "7pVJMzmeLLO4NXWj0YVBag==": { "id": "7pVJMzmeLLO4NXWj0YVBag==", "name": "libexpat1", "version": "2.5.0-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "expat", "version": "2.5.0-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "80qkhrcVZcBsMIrLNl9O9Q==": { "id": "80qkhrcVZcBsMIrLNl9O9Q==", "name": "libx11-6", "version": "2:1.8.4-2+deb12u2", "kind": "binary", "source": { "id": "", "name": "libx11", "version": "2:1.8.4-2+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "80rK+6RM4F9Hot2jSdUHAg==": { "id": "80rK+6RM4F9Hot2jSdUHAg==", "name": "binutils", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "8LWvv86uV3cw8wj3q3pMEA==": { "id": "8LWvv86uV3cw8wj3q3pMEA==", "name": "libmagickwand-6.q16-6", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "8cpRxcbI/vwUuKrU5hjaWw==": { "id": "8cpRxcbI/vwUuKrU5hjaWw==", "name": "libctf-nobfd0", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "8o+FZPqse3WD3r9kbW1vBQ==": { "id": "8o+FZPqse3WD3r9kbW1vBQ==", "name": "init-system-helpers", "version": "1.65.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "init-system-helpers", "version": "1.65.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "8zBqc6YLv7EX5QenNkOW/g==": { "id": "8zBqc6YLv7EX5QenNkOW/g==", "name": "apt", "version": "2.6.1", "kind": "binary", "source": { "id": "", "name": "apt", "version": "2.6.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "9C+D4ZDW4GoIg1zwhO7Imw==": { "id": "9C+D4ZDW4GoIg1zwhO7Imw==", "name": "liblqr-1-0", "version": "0.4.2-2.1", "kind": "binary", "source": { "id": "", "name": "liblqr", "version": "0.4.2-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "9N0r285o7XdVZky2fQCnLQ==": { "id": "9N0r285o7XdVZky2fQCnLQ==", "name": "liblerc4", "version": "4.0.0+ds-2", "kind": "binary", "source": { "id": "", "name": "lerc", "version": "4.0.0+ds-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "9UvQ/J5UURubT6sa1VdVyw==": { "id": "9UvQ/J5UURubT6sa1VdVyw==", "name": "libexif12", "version": "0.6.24-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "libexif", "version": "0.6.24-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "9WR568tmvkLmS+IEW2uG3Q==": { "id": "9WR568tmvkLmS+IEW2uG3Q==", "name": "fontconfig", "version": "2.14.1-4", "kind": "binary", "source": { "id": "", "name": "fontconfig", "version": "2.14.1-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "9s5TckcK6fsQxj1m2NeLGg==": { "id": "9s5TckcK6fsQxj1m2NeLGg==", "name": "libyaml-dev", "version": "0.2.5-1", "kind": "binary", "source": { "id": "", "name": "libyaml", "version": "0.2.5-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "A9S4GbGT4KbqDQ4Rk+9rjw==": { "id": "A9S4GbGT4KbqDQ4Rk+9rjw==", "name": "libacl1", "version": "2.3.1-3", "kind": "binary", "source": { "id": "", "name": "acl", "version": "2.3.1-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ADxcp+yqIg7//17igk2iWw==": { "id": "ADxcp+yqIg7//17igk2iWw==", "name": "liblcms2-2", "version": "2.14-2+deb12u1", "kind": "binary", "source": { "id": "", "name": "lcms2", "version": "2.14-2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "AEmJ/DcX9k+YTOaY1TPipw==": { "id": "AEmJ/DcX9k+YTOaY1TPipw==", "name": "libmagickwand-dev", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "AhInnwPSn3Bcv7iW4TN06A==": { "id": "AhInnwPSn3Bcv7iW4TN06A==", "name": "libwebp7", "version": "1.2.4-0.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "libwebp", "version": "1.2.4-0.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "AxDgJRPby1Bn5TyQqmbUVA==": { "id": "AxDgJRPby1Bn5TyQqmbUVA==", "name": "libpq-dev", "version": "15.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "postgresql-15", "version": "15.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "B1MLdrb97A3HO0mN23HVww==": { "id": "B1MLdrb97A3HO0mN23HVww==", "name": "python3-minimal", "version": "3.11.2-1+b1", "kind": "binary", "source": { "id": "", "name": "python3-defaults", "version": "3.11.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "B5DdwMEMymJ408z76zs2OA==": { "id": "B5DdwMEMymJ408z76zs2OA==", "name": "libglib2.0-dev", "version": "2.74.6-2+deb12u9", "kind": "binary", "source": { "id": "", "name": "glib2.0", "version": "2.74.6-2+deb12u9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "BRBqHmWAPbyliD6oY5fPZQ==": { "id": "BRBqHmWAPbyliD6oY5fPZQ==", "name": "libreadline-dev", "version": "8.2-1.3", "kind": "binary", "source": { "id": "", "name": "readline", "version": "8.2-1.3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "BaHdDBXo9vGpSxaSNpfxzQ==": { "id": "BaHdDBXo9vGpSxaSNpfxzQ==", "name": "libdeflate-dev", "version": "1.14-1", "kind": "binary", "source": { "id": "", "name": "libdeflate", "version": "1.14-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "BfdRzqdpSloHTsPV0bYqfQ==": { "id": "BfdRzqdpSloHTsPV0bYqfQ==", "name": "libatomic1", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "BlVTvBeWBIL5xG6a/M13Hg==": { "id": "BlVTvBeWBIL5xG6a/M13Hg==", "name": "liblzo2-2", "version": "2.10-2", "kind": "binary", "source": { "id": "", "name": "lzo2", "version": "2.10-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Btnm9wBBF+iO/PtfE/g4Uw==": { "id": "Btnm9wBBF+iO/PtfE/g4Uw==", "name": "libgprofng0", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "C1WOj2zBssIM43TekSCMGg==": { "id": "C1WOj2zBssIM43TekSCMGg==", "name": "libbrotli-dev", "version": "1.0.9-2+b6", "kind": "binary", "source": { "id": "", "name": "brotli", "version": "1.0.9-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "C3CbqpDjQWFfxEMRICv6tA==": { "id": "C3CbqpDjQWFfxEMRICv6tA==", "name": "tzdata", "version": "2026b-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "tzdata", "version": "2026b-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "C48XyIAaKniO5HPydCvKpg==": { "id": "C48XyIAaKniO5HPydCvKpg==", "name": "binutils-x86-64-linux-gnu", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "C5Hw0IeNICIIcRkshUzBng==": { "id": "C5Hw0IeNICIIcRkshUzBng==", "name": "libxau6", "version": "1:1.0.9-1", "kind": "binary", "source": { "id": "", "name": "libxau", "version": "1:1.0.9-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "C71NyBHK4UlqmXFWNE4I2Q==": { "id": "C71NyBHK4UlqmXFWNE4I2Q==", "name": "libice-dev", "version": "2:1.0.10-1", "kind": "binary", "source": { "id": "", "name": "libice", "version": "2:1.0.10-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "C8k9goj1GczZJ4keNY2UHQ==": { "id": "C8k9goj1GczZJ4keNY2UHQ==", "name": "libgpg-error0", "version": "1.46-1", "kind": "binary", "source": { "id": "", "name": "libgpg-error", "version": "1.46-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "CFG/JDkRv9ezCh1qEKQ8ug==": { "id": "CFG/JDkRv9ezCh1qEKQ8ug==", "name": "login", "version": "1:4.13+dfsg1-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "shadow", "version": "1:4.13+dfsg1-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "CT3G0GG1+aFkXHFGTSDi3A==": { "id": "CT3G0GG1+aFkXHFGTSDi3A==", "name": "m4", "version": "1.4.19-3", "kind": "binary", "source": { "id": "", "name": "m4", "version": "1.4.19-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "CmCZ256ji6DcGmXCpaluIQ==": { "id": "CmCZ256ji6DcGmXCpaluIQ==", "name": "libgdk-pixbuf-2.0-dev", "version": "2.42.10+dfsg-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "gdk-pixbuf", "version": "2.42.10+dfsg-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Crh7PcjcI6TuJynTs7Y4sQ==": { "id": "Crh7PcjcI6TuJynTs7Y4sQ==", "name": "libcairo-gobject2", "version": "1.16.0-7", "kind": "binary", "source": { "id": "", "name": "cairo", "version": "1.16.0-7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "D/Trx1uUSMxZ8dPrvnFCjA==": { "id": "D/Trx1uUSMxZ8dPrvnFCjA==", "name": "libfribidi0", "version": "1.0.8-2.1", "kind": "binary", "source": { "id": "", "name": "fribidi", "version": "1.0.8-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "D32BJsOkZunke8aQ5YzeMA==": { "id": "D32BJsOkZunke8aQ5YzeMA==", "name": "libgdbm-dev", "version": "1.23-3", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.23-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "D4CAttxDppQB4nUjxeAQYg==": { "id": "D4CAttxDppQB4nUjxeAQYg==", "name": "libxml2-dev", "version": "2.9.14+dfsg-1.3~deb12u6", "kind": "binary", "source": { "id": "", "name": "libxml2", "version": "2.9.14+dfsg-1.3~deb12u6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "D7pQ2iqeywkQv+e7IPd32g==": { "id": "D7pQ2iqeywkQv+e7IPd32g==", "name": "libtsan2", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DLENylM5mXuzVt1bbHQcdg==": { "id": "DLENylM5mXuzVt1bbHQcdg==", "name": "libwmf-0.2-7", "version": "0.2.12-5.1", "kind": "binary", "source": { "id": "", "name": "libwmf", "version": "0.2.12-5.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DMI7vu+hT7nBL5mdHloddg==": { "id": "DMI7vu+hT7nBL5mdHloddg==", "name": "procps", "version": "2:4.0.2-3", "kind": "binary", "source": { "id": "", "name": "procps", "version": "2:4.0.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DO2gYwj9yFnFCsYsp/BBVA==": { "id": "DO2gYwj9yFnFCsYsp/BBVA==", "name": "gpgv", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DQdtnFQaBdkM1bMve6ZgwQ==": { "id": "DQdtnFQaBdkM1bMve6ZgwQ==", "name": "libdb5.3-dev", "version": "5.3.28+dfsg2-1", "kind": "binary", "source": { "id": "", "name": "db5.3", "version": "5.3.28+dfsg2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DUfRr94DlcXwFiSA+XKESw==": { "id": "DUfRr94DlcXwFiSA+XKESw==", "name": "libpython3.11-stdlib", "version": "3.11.2-6+deb12u8", "kind": "binary", "source": { "id": "", "name": "python3.11", "version": "3.11.2-6+deb12u8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DX5vrXfJMAv8MvKCJYZehA==": { "id": "DX5vrXfJMAv8MvKCJYZehA==", "name": "hostname", "version": "3.23+nmu1", "kind": "binary", "source": { "id": "", "name": "hostname", "version": "3.23+nmu1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Dbw8fwJSQtnZOBPRtWZjAw==": { "id": "Dbw8fwJSQtnZOBPRtWZjAw==", "name": "g++-12", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DcSn3Y7HFbVbRH2l8vXSOw==": { "id": "DcSn3Y7HFbVbRH2l8vXSOw==", "name": "libmagickcore-6.q16-6-extra", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DdG2a7LFFvSXCrM63lYSQQ==": { "id": "DdG2a7LFFvSXCrM63lYSQQ==", "name": "libxslt1.1", "version": "1.1.35-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "libxslt", "version": "1.1.35-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DoeL4sQy46KMZZcZaGrPwA==": { "id": "DoeL4sQy46KMZZcZaGrPwA==", "name": "libc-bin", "version": "2.36-9+deb12u14", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.36-9+deb12u14", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "DpnNcNYKroLPe/ukW+XyqA==": { "id": "DpnNcNYKroLPe/ukW+XyqA==", "name": "libjansson4", "version": "2.14-2", "kind": "binary", "source": { "id": "", "name": "jansson", "version": "2.14-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Dr0qgUJ7DFtPHxF+bH4bdg==": { "id": "Dr0qgUJ7DFtPHxF+bH4bdg==", "name": "libpython3.11-minimal", "version": "3.11.2-6+deb12u8", "kind": "binary", "source": { "id": "", "name": "python3.11", "version": "3.11.2-6+deb12u8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "E1SCWpEriPaS0rZtcE9l3A==": { "id": "E1SCWpEriPaS0rZtcE9l3A==", "name": "mercurial", "version": "6.3.2-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "mercurial", "version": "6.3.2-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "EC+JU6AsEvpEEhY498jxOg==": { "id": "EC+JU6AsEvpEEhY498jxOg==", "name": "binutils-common", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ET151dfn2MZGHv3vzXEthQ==": { "id": "ET151dfn2MZGHv3vzXEthQ==", "name": "libmagickcore-6-headers", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "EoG2zpKSlJJwW+MSosZk9w==": { "id": "EoG2zpKSlJJwW+MSosZk9w==", "name": "libmariadb3", "version": "1:10.11.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "mariadb", "version": "1:10.11.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "EyNTk1gqN4KHi+AHyTGTsA==": { "id": "EyNTk1gqN4KHi+AHyTGTsA==", "name": "libc6", "version": "2.36-9+deb12u14", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.36-9+deb12u14", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "F6hFIFBLlsM5E0Jh5GMVew==": { "id": "F6hFIFBLlsM5E0Jh5GMVew==", "name": "liblcms2-dev", "version": "2.14-2+deb12u1", "kind": "binary", "source": { "id": "", "name": "lcms2", "version": "2.14-2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FCK/2by4dcPj2zSU0jBk7w==": { "id": "FCK/2by4dcPj2zSU0jBk7w==", "name": "libcap-ng0", "version": "0.8.3-1+b3", "kind": "binary", "source": { "id": "", "name": "libcap-ng", "version": "0.8.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FGLgg9hMQpl+MW2W94NfHA==": { "id": "FGLgg9hMQpl+MW2W94NfHA==", "name": "libbz2-dev", "version": "1.0.8-5+b1", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.8-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FR1lLXy1N/YqpoQMUrt9iw==": { "id": "FR1lLXy1N/YqpoQMUrt9iw==", "name": "libgmp-dev", "version": "2:6.2.1+dfsg1-1.1", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "2:6.2.1+dfsg1-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FTVHNcoQ+LhcUCcvhRsNKA==": { "id": "FTVHNcoQ+LhcUCcvhRsNKA==", "name": "libcrypt-dev", "version": "1:4.4.33-2", "kind": "binary", "source": { "id": "", "name": "libxcrypt", "version": "1:4.4.33-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FUhID3jFFxB1MwHm8UODUA==": { "id": "FUhID3jFFxB1MwHm8UODUA==", "name": "liblsan0", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "FfB0oKhOP9dQDp61Fjo6EA==": { "id": "FfB0oKhOP9dQDp61Fjo6EA==", "name": "libde265-0", "version": "1.0.11-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "libde265", "version": "1.0.11-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Ffr9t+FrG7UHpzTQia/UJA==": { "id": "Ffr9t+FrG7UHpzTQia/UJA==", "name": "debianutils", "version": "5.7-0.5~deb12u1", "kind": "binary", "source": { "id": "", "name": "debianutils", "version": "5.7-0.5~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "G0+fRlKRRZRSnY58y39BzA==": { "id": "G0+fRlKRRZRSnY58y39BzA==", "name": "libfontconfig1", "version": "2.14.1-4", "kind": "binary", "source": { "id": "", "name": "fontconfig", "version": "2.14.1-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "G1Vp9YU2liBtgeHfuXjSKA==": { "id": "G1Vp9YU2liBtgeHfuXjSKA==", "name": "libjpeg62-turbo-dev", "version": "1:2.1.5-2", "kind": "binary", "source": { "id": "", "name": "libjpeg-turbo", "version": "1:2.1.5-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "G4hHb/2sARVgwAB8zCN/8Q==": { "id": "G4hHb/2sARVgwAB8zCN/8Q==", "name": "pkgconf", "version": "1.8.1-1", "kind": "binary", "source": { "id": "", "name": "pkgconf", "version": "1.8.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "GZaXtjtG9UqJe33Ris8hvw==": { "id": "GZaXtjtG9UqJe33Ris8hvw==", "name": "libglib2.0-dev-bin", "version": "2.74.6-2+deb12u9", "kind": "binary", "source": { "id": "", "name": "glib2.0", "version": "2.74.6-2+deb12u9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Gq4SASJyeL2+pL7FgFSZfw==": { "id": "Gq4SASJyeL2+pL7FgFSZfw==", "name": "libmaxminddb-dev", "version": "1.7.1-1", "kind": "binary", "source": { "id": "", "name": "libmaxminddb", "version": "1.7.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "GrX0NC3DRB9appRe0ANbeQ==": { "id": "GrX0NC3DRB9appRe0ANbeQ==", "name": "gpg", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "GwYg1UGFzP9MDjj8Bzao7w==": { "id": "GwYg1UGFzP9MDjj8Bzao7w==", "name": "libdb-dev", "version": "5.3.2", "kind": "binary", "source": { "id": "", "name": "db-defaults", "version": "5.3.2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "GxIFrX03TO2H3bV6/l8Mgw==": { "id": "GxIFrX03TO2H3bV6/l8Mgw==", "name": "ncurses-base", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "H15dvVf6yrGTTQeCLbwg8w==": { "id": "H15dvVf6yrGTTQeCLbwg8w==", "name": "libasan8", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "H1jcx9ub/KyuVLut+nrRxQ==": { "id": "H1jcx9ub/KyuVLut+nrRxQ==", "name": "libelf1", "version": "0.188-2.1", "kind": "binary", "source": { "id": "", "name": "elfutils", "version": "0.188-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "H5JM5I9PWZdJLP6nda5pEQ==": { "id": "H5JM5I9PWZdJLP6nda5pEQ==", "name": "mysql-common", "version": "5.8+1.1.0", "kind": "binary", "source": { "id": "", "name": "mysql-defaults", "version": "1.1.0", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "HAbchZDXADggw0sECzOfoQ==": { "id": "HAbchZDXADggw0sECzOfoQ==", "name": "debian-archive-keyring", "version": "2023.3+deb12u2", "kind": "binary", "source": { "id": "", "name": "debian-archive-keyring", "version": "2023.3+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "HQv3we+HpzbjJVEgufFblw==": { "id": "HQv3we+HpzbjJVEgufFblw==", "name": "pkg-config", "version": "1.8.1-1", "kind": "binary", "source": { "id": "", "name": "pkgconf", "version": "1.8.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "HhdzR4wjQEAouKFVlc08JA==": { "id": "HhdzR4wjQEAouKFVlc08JA==", "name": "libpcre2-32-0", "version": "10.42-1", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.42-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "I1bAbBi99CgH1Fe4vQq8lA==": { "id": "I1bAbBi99CgH1Fe4vQq8lA==", "name": "libncursesw6", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "I5/CO7OYsT3D2w8k/V9jeA==": { "id": "I5/CO7OYsT3D2w8k/V9jeA==", "name": "libxcb-shm0-dev", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "IIgYYwpoulHCI9LIpdK3SA==": { "id": "IIgYYwpoulHCI9LIpdK3SA==", "name": "libcairo2-dev", "version": "1.16.0-7", "kind": "binary", "source": { "id": "", "name": "cairo", "version": "1.16.0-7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "IfM/G/gG/1hvKemCx2uliQ==": { "id": "IfM/G/gG/1hvKemCx2uliQ==", "name": "usr-is-merged", "version": "37~deb12u1", "kind": "binary", "source": { "id": "", "name": "usrmerge", "version": "37~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "IgM3Tu1xX41jkcHPcFVmNQ==": { "id": "IgM3Tu1xX41jkcHPcFVmNQ==", "name": "libxext-dev", "version": "2:1.3.4-1+b1", "kind": "binary", "source": { "id": "", "name": "libxext", "version": "2:1.3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "IxIuQ+IDxSN2ss/kdg/dxA==": { "id": "IxIuQ+IDxSN2ss/kdg/dxA==", "name": "libdjvulibre-dev", "version": "3.5.28-2.2~deb12u1", "kind": "binary", "source": { "id": "", "name": "djvulibre", "version": "3.5.28-2.2~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "J+dxZrjQP+fIW/oF0opOcQ==": { "id": "J+dxZrjQP+fIW/oF0opOcQ==", "name": "libpcre2-16-0", "version": "10.42-1", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.42-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "J1M13jv06LUgBQFe/2hBhQ==": { "id": "J1M13jv06LUgBQFe/2hBhQ==", "name": "libglib2.0-bin", "version": "2.74.6-2+deb12u9", "kind": "binary", "source": { "id": "", "name": "glib2.0", "version": "2.74.6-2+deb12u9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "JL3p4IPiugYqmqbhcEI4Qg==": { "id": "JL3p4IPiugYqmqbhcEI4Qg==", "name": "libtool", "version": "2.4.7-7~deb12u1", "kind": "binary", "source": { "id": "", "name": "libtool", "version": "2.4.7-7~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "JSIFkKzhU9FvkmcYKQhwAA==": { "id": "JSIFkKzhU9FvkmcYKQhwAA==", "name": "libkrb5-3", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "JSmVKr1KluQ/VM/0yAWB8g==": { "id": "JSmVKr1KluQ/VM/0yAWB8g==", "name": "patch", "version": "2.7.6-7", "kind": "binary", "source": { "id": "", "name": "patch", "version": "2.7.6-7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "JwsgRUBDkHrNKaGcAJZ/rQ==": { "id": "JwsgRUBDkHrNKaGcAJZ/rQ==", "name": "libpam-modules-bin", "version": "1.5.2-6+deb12u2", "kind": "binary", "source": { "id": "", "name": "pam", "version": "1.5.2-6+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "JyXX6aacgQ9R5u7F789q9w==": { "id": "JyXX6aacgQ9R5u7F789q9w==", "name": "libuuid1", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "JywcP/qyzW2E6sHDgBtGgQ==": { "id": "JywcP/qyzW2E6sHDgBtGgQ==", "name": "libsqlite3-dev", "version": "3.40.1-2+deb12u2", "kind": "binary", "source": { "id": "", "name": "sqlite3", "version": "3.40.1-2+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "K5LO+DczsLnXcUymG8Ov4Q==": { "id": "K5LO+DczsLnXcUymG8Ov4Q==", "name": "libcc1-0", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "KHFQPWvdLygTz81nClfvbg==": { "id": "KHFQPWvdLygTz81nClfvbg==", "name": "libisl23", "version": "0.25-1.1", "kind": "binary", "source": { "id": "", "name": "isl", "version": "0.25-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "KRveFNaAnbaL3OL2dfsnmw==": { "id": "KRveFNaAnbaL3OL2dfsnmw==", "name": "libice6", "version": "2:1.0.10-1", "kind": "binary", "source": { "id": "", "name": "libice", "version": "2:1.0.10-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "KW/XvnvOR1sqrB5iyXYx1A==": { "id": "KW/XvnvOR1sqrB5iyXYx1A==", "name": "gir1.2-freedesktop", "version": "1.74.0-3", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.74.0-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Kdos9fuXp7Tdirl5OEPk0A==": { "id": "Kdos9fuXp7Tdirl5OEPk0A==", "name": "libcairo-script-interpreter2", "version": "1.16.0-7", "kind": "binary", "source": { "id": "", "name": "cairo", "version": "1.16.0-7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Kok6pjCr2iPr0BdF5PzCLA==": { "id": "Kok6pjCr2iPr0BdF5PzCLA==", "name": "libxt6", "version": "1:1.2.1-1.1", "kind": "binary", "source": { "id": "", "name": "libxt", "version": "1:1.2.1-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Ku5epPEPwJZIjh+l6VcECQ==": { "id": "Ku5epPEPwJZIjh+l6VcECQ==", "name": "rpcsvc-proto", "version": "1.4.3-1", "kind": "binary", "source": { "id": "", "name": "rpcsvc-proto", "version": "1.4.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "L1BPNHEXKJg2qshBU/0DVg==": { "id": "L1BPNHEXKJg2qshBU/0DVg==", "name": "shared-mime-info", "version": "2.2-1", "kind": "binary", "source": { "id": "", "name": "shared-mime-info", "version": "2.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "L4m+pCjjwdEngLX0mu57Nw==": { "id": "L4m+pCjjwdEngLX0mu57Nw==", "name": "libdatrie1", "version": "0.2.13-2+b1", "kind": "binary", "source": { "id": "", "name": "libdatrie", "version": "0.2.13-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "L8JIZ/GZyKE8KVi4qkx8Jw==": { "id": "L8JIZ/GZyKE8KVi4qkx8Jw==", "name": "gcc", "version": "4:12.2.0-3", "kind": "binary", "source": { "id": "", "name": "gcc-defaults", "version": "1.203", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "LC/APWT5szmLAgZmxYTyQg==": { "id": "LC/APWT5szmLAgZmxYTyQg==", "name": "libfreetype-dev", "version": "2.12.1+dfsg-5+deb12u4", "kind": "binary", "source": { "id": "", "name": "freetype", "version": "2.12.1+dfsg-5+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "LIR5D4Dte5MOrnhvpHsVrQ==": { "id": "LIR5D4Dte5MOrnhvpHsVrQ==", "name": "libpng16-16", "version": "1.6.39-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "libpng1.6", "version": "1.6.39-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "LK5Y5pt6gg2teLo4lyUl5Q==": { "id": "LK5Y5pt6gg2teLo4lyUl5Q==", "name": "libevent-core-2.1-7", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "LSzaEcRtEcwSgtd7CLRn1A==": { "id": "LSzaEcRtEcwSgtd7CLRn1A==", "name": "libthai0", "version": "0.1.29-1", "kind": "binary", "source": { "id": "", "name": "libthai", "version": "0.1.29-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "LoENU9wMD2M0RgtDzEVVrQ==": { "id": "LoENU9wMD2M0RgtDzEVVrQ==", "name": "libsvn1", "version": "1.14.2-4+deb12u1", "kind": "binary", "source": { "id": "", "name": "subversion", "version": "1.14.2-4+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "M2yshyCx4J0OAFSMphgrFw==": { "id": "M2yshyCx4J0OAFSMphgrFw==", "name": "libpixman-1-0", "version": "0.42.2-1", "kind": "binary", "source": { "id": "", "name": "pixman", "version": "0.42.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MJc99fNviurhcvfrwqhFnw==": { "id": "MJc99fNviurhcvfrwqhFnw==", "name": "libgcrypt20", "version": "1.10.1-3+deb12u1", "kind": "binary", "source": { "id": "", "name": "libgcrypt20", "version": "1.10.1-3+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MK+wvMZG5H9N57m0tlxOBQ==": { "id": "MK+wvMZG5H9N57m0tlxOBQ==", "name": "tar", "version": "1.34+dfsg-1.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "tar", "version": "1.34+dfsg-1.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MKH6OlgsSoSX5b3bX6J9iQ==": { "id": "MKH6OlgsSoSX5b3bX6J9iQ==", "name": "libdb5.3", "version": "5.3.28+dfsg2-1", "kind": "binary", "source": { "id": "", "name": "db5.3", "version": "5.3.28+dfsg2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MXjHhG8IwQ7T8QqaXIL6BA==": { "id": "MXjHhG8IwQ7T8QqaXIL6BA==", "name": "bash", "version": "5.2.15-2+b13", "kind": "binary", "source": { "id": "", "name": "bash", "version": "5.2.15-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MbThVdB9Kwth+Y7uHVZ7aw==": { "id": "MbThVdB9Kwth+Y7uHVZ7aw==", "name": "curl", "version": "7.88.1-10+deb12u15", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.88.1-10+deb12u15", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MtXElwRG9C/XNTt79l1CoQ==": { "id": "MtXElwRG9C/XNTt79l1CoQ==", "name": "sed", "version": "4.9-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "sed", "version": "4.9-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "MuoTj+JInnKZmAOZidC2+Q==": { "id": "MuoTj+JInnKZmAOZidC2+Q==", "name": "libxrender1", "version": "1:0.9.10-1.1", "kind": "binary", "source": { "id": "", "name": "libxrender", "version": "1:0.9.10-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Mw3Qz3FPdmU90ekkNVtotw==": { "id": "Mw3Qz3FPdmU90ekkNVtotw==", "name": "fontconfig-config", "version": "2.14.1-4", "kind": "binary", "source": { "id": "", "name": "fontconfig", "version": "2.14.1-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "NJT+hpryRcorOQzKPH0mFA==": { "id": "NJT+hpryRcorOQzKPH0mFA==", "name": "libgmpxx4ldbl", "version": "2:6.2.1+dfsg1-1.1", "kind": "binary", "source": { "id": "", "name": "gmp", "version": "2:6.2.1+dfsg1-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "NM2r479xc6Vy7ZfeePrYRg==": { "id": "NM2r479xc6Vy7ZfeePrYRg==", "name": "libkadm5clnt-mit12", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Nd5ksUhotJjJPRXnhgHx7g==": { "id": "Nd5ksUhotJjJPRXnhgHx7g==", "name": "libnpth0", "version": "1.6-3", "kind": "binary", "source": { "id": "", "name": "npth", "version": "1.6-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "NnEYV8lKPl93vYgryCkEwQ==": { "id": "NnEYV8lKPl93vYgryCkEwQ==", "name": "libpng-dev", "version": "1.6.39-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "libpng1.6", "version": "1.6.39-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Nr51nSGhXANVx6//HdGhXg==": { "id": "Nr51nSGhXANVx6//HdGhXg==", "name": "libaprutil1", "version": "1.6.3-1", "kind": "binary", "source": { "id": "", "name": "apr-util", "version": "1.6.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "O1IBSbu57cJrxyull5RDow==": { "id": "O1IBSbu57cJrxyull5RDow==", "name": "gir1.2-rsvg-2.0", "version": "2.54.7+dfsg-1~deb12u1", "kind": "binary", "source": { "id": "", "name": "librsvg", "version": "2.54.7+dfsg-1~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "O66ab0mg2AGYJRzvYRXyJw==": { "id": "O66ab0mg2AGYJRzvYRXyJw==", "name": "libdeflate0", "version": "1.14-1", "kind": "binary", "source": { "id": "", "name": "libdeflate", "version": "1.14-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "OPa+O2qJ8bwSNOa/i8UZrg==": { "id": "OPa+O2qJ8bwSNOa/i8UZrg==", "name": "libmagickcore-6.q16-6", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "OUGiefTyVQSIR5zV3J7jrw==": { "id": "OUGiefTyVQSIR5zV3J7jrw==", "name": "libxdmcp6", "version": "1:1.1.2-3", "kind": "binary", "source": { "id": "", "name": "libxdmcp", "version": "1:1.1.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "OmtFkla3zEOgSVB264/6FQ==": { "id": "OmtFkla3zEOgSVB264/6FQ==", "name": "libhogweed6", "version": "3.8.1-2", "kind": "binary", "source": { "id": "", "name": "nettle", "version": "3.8.1-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "OnEFy9GimJqtid0VmTRXbg==": { "id": "OnEFy9GimJqtid0VmTRXbg==", "name": "libevent-pthreads-2.1-7", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "P6kIETtDNA9xKWuxdLqDZg==": { "id": "P6kIETtDNA9xKWuxdLqDZg==", "name": "libffi8", "version": "3.4.4-1", "kind": "binary", "source": { "id": "", "name": "libffi", "version": "3.4.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "P9QnQZyS5ZoKO5leln0hMg==": { "id": "P9QnQZyS5ZoKO5leln0hMg==", "name": "python3", "version": "3.11.2-1+b1", "kind": "binary", "source": { "id": "", "name": "python3-defaults", "version": "3.11.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "PPjVsVksOg1xBjerPFAZbA==": { "id": "PPjVsVksOg1xBjerPFAZbA==", "name": "libgdk-pixbuf-2.0-0", "version": "2.42.10+dfsg-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "gdk-pixbuf", "version": "2.42.10+dfsg-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "PTPT9COe35b5PMqNzUG1Jg==": { "id": "PTPT9COe35b5PMqNzUG1Jg==", "name": "comerr-dev", "version": "2.1-1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "PVKi3k0lvwaf877Vg/Hf+Q==": { "id": "PVKi3k0lvwaf877Vg/Hf+Q==", "name": "adduser", "version": "3.134", "kind": "binary", "source": { "id": "", "name": "adduser", "version": "3.134", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "PVYbPIfqCsqfnehuqa5Yzw==": { "id": "PVYbPIfqCsqfnehuqa5Yzw==", "name": "libsmartcols1", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "PYGOW+lwjkJCppSeNofPwA==": { "id": "PYGOW+lwjkJCppSeNofPwA==", "name": "libwebpmux3", "version": "1.2.4-0.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "libwebp", "version": "1.2.4-0.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Pe0LNCf/FarOFJF3JTE7Lw==": { "id": "Pe0LNCf/FarOFJF3JTE7Lw==", "name": "file", "version": "1:5.44-3", "kind": "binary", "source": { "id": "", "name": "file", "version": "1:5.44-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "PjtfT38VjsInzOfwCofi8w==": { "id": "PjtfT38VjsInzOfwCofi8w==", "name": "xorg-sgml-doctools", "version": "1:1.11-1.1", "kind": "binary", "source": { "id": "", "name": "xorg-sgml-doctools", "version": "1:1.11-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "Q5UNFAAmvKoOzO5GwPt4eQ==": { "id": "Q5UNFAAmvKoOzO5GwPt4eQ==", "name": "libpcre2-dev", "version": "10.42-1", "kind": "binary", "source": { "id": "", "name": "pcre2", "version": "10.42-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "QNQML/EdNKRr8feN6gNQ7Q==": { "id": "QNQML/EdNKRr8feN6gNQ7Q==", "name": "libbinutils", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "QNXfg7x0fKp3nkVykQPVdg==": { "id": "QNXfg7x0fKp3nkVykQPVdg==", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "QiE70L4UggeCJp5Ei3ScLg==": { "id": "QiE70L4UggeCJp5Ei3ScLg==", "name": "gpg-wks-server", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Qj5vih+YB0oqxjBJX47HcQ==": { "id": "Qj5vih+YB0oqxjBJX47HcQ==", "name": "libcurl4-openssl-dev", "version": "7.88.1-10+deb12u15", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.88.1-10+deb12u15", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "QunivO3Btr+12V40Q7zvOA==": { "id": "QunivO3Btr+12V40Q7zvOA==", "name": "liblzma5", "version": "5.4.1-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "xz-utils", "version": "5.4.1-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "R+TifLmNsnKmWod+U5H3dw==": { "id": "R+TifLmNsnKmWod+U5H3dw==", "name": "libpthread-stubs0-dev", "version": "0.4-1", "kind": "binary", "source": { "id": "", "name": "libpthread-stubs", "version": "0.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "RVCbg6a7ro741dC4GIWUhw==": { "id": "RVCbg6a7ro741dC4GIWUhw==", "name": "readline-common", "version": "8.2-1.3", "kind": "binary", "source": { "id": "", "name": "readline", "version": "8.2-1.3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "Rm6aYlmrhSHTgUrwIkrtXQ==": { "id": "Rm6aYlmrhSHTgUrwIkrtXQ==", "name": "libltdl7", "version": "2.4.7-7~deb12u1", "kind": "binary", "source": { "id": "", "name": "libtool", "version": "2.4.7-7~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Rn8Y2sWVEJp/cwRTbBXU4g==": { "id": "Rn8Y2sWVEJp/cwRTbBXU4g==", "name": "libsemanage-common", "version": "3.4-1", "kind": "binary", "source": { "id": "", "name": "libsemanage", "version": "3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "RrvOhWF4pNgkD1EzBzqhHw==": { "id": "RrvOhWF4pNgkD1EzBzqhHw==", "name": "libjbig-dev", "version": "2.1-6.1", "kind": "binary", "source": { "id": "", "name": "jbigkit", "version": "2.1-6.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "RvZnrgr9AoeYG/LgkEW41w==": { "id": "RvZnrgr9AoeYG/LgkEW41w==", "name": "liblzma-dev", "version": "5.4.1-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "xz-utils", "version": "5.4.1-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "SKBqRjphRN4tmZGXSGijng==": { "id": "SKBqRjphRN4tmZGXSGijng==", "name": "sq", "version": "0.27.0-2+b1", "kind": "binary", "source": { "id": "", "name": "rust-sequoia-sq", "version": "0.27.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "SNUPzPRR4049keiaYnwZRg==": { "id": "SNUPzPRR4049keiaYnwZRg==", "name": "libksba8", "version": "1.6.3-2", "kind": "binary", "source": { "id": "", "name": "libksba", "version": "1.6.3-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "SdY6vnz+BkS661rpTNZj9Q==": { "id": "SdY6vnz+BkS661rpTNZj9Q==", "name": "coreutils", "version": "9.1-1", "kind": "binary", "source": { "id": "", "name": "coreutils", "version": "9.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Sqf4aZ2zleKl0J9AxLdThA==": { "id": "Sqf4aZ2zleKl0J9AxLdThA==", "name": "cpp-12", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "SvuwU4tnJtOpkXPvd+HGUw==": { "id": "SvuwU4tnJtOpkXPvd+HGUw==", "name": "libicu-dev", "version": "72.1-3+deb12u1", "kind": "binary", "source": { "id": "", "name": "icu", "version": "72.1-3+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "TJn6Tj11pQiEiMhC9dLTLw==": { "id": "TJn6Tj11pQiEiMhC9dLTLw==", "name": "libsasl2-modules-db", "version": "2.1.28+dfsg-10", "kind": "binary", "source": { "id": "", "name": "cyrus-sasl2", "version": "2.1.28+dfsg-10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "TSIllJtHNmWZGqpbQMvKDQ==": { "id": "TSIllJtHNmWZGqpbQMvKDQ==", "name": "git", "version": "1:2.39.5-0+deb12u3", "kind": "binary", "source": { "id": "", "name": "git", "version": "1:2.39.5-0+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "TVoY0Z/LyrK88/UqwT1iKQ==": { "id": "TVoY0Z/LyrK88/UqwT1iKQ==", "name": "python3.11", "version": "3.11.2-6+deb12u8", "kind": "binary", "source": { "id": "", "name": "python3.11", "version": "3.11.2-6+deb12u8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "TwB4+3YtKvcmJqfVl3VNfQ==": { "id": "TwB4+3YtKvcmJqfVl3VNfQ==", "name": "libaudit1", "version": "1:3.0.9-1", "kind": "binary", "source": { "id": "", "name": "audit", "version": "1:3.0.9-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "UEgUESKyO8ANGmbG9eyDcQ==": { "id": "UEgUESKyO8ANGmbG9eyDcQ==", "name": "libwebp-dev", "version": "1.2.4-0.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "libwebp", "version": "1.2.4-0.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "UGdCvwdFwDgVlrc4KyAStg==": { "id": "UGdCvwdFwDgVlrc4KyAStg==", "name": "openssl", "version": "3.0.20-1~deb12u2", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "3.0.20-1~deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "UaVF3pH6oV2FHpAzXp1raw==": { "id": "UaVF3pH6oV2FHpAzXp1raw==", "name": "libevent-extra-2.1-7", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "UgKTqEFEym2yE14Xm7MjZQ==": { "id": "UgKTqEFEym2yE14Xm7MjZQ==", "name": "libgraphite2-3", "version": "1.3.14-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "graphite2", "version": "1.3.14-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "UjugzpaTnXWKhG4OAkEZpw==": { "id": "UjugzpaTnXWKhG4OAkEZpw==", "name": "libpam-runtime", "version": "1.5.2-6+deb12u2", "kind": "binary", "source": { "id": "", "name": "pam", "version": "1.5.2-6+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "Vb9RpGB0uEvlFvfuUopE+Q==": { "id": "Vb9RpGB0uEvlFvfuUopE+Q==", "name": "libtiff6", "version": "4.5.0-6+deb12u4", "kind": "binary", "source": { "id": "", "name": "tiff", "version": "4.5.0-6+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Vq6qRMnL8ZtI/FTotk7z9w==": { "id": "Vq6qRMnL8ZtI/FTotk7z9w==", "name": "xz-utils", "version": "5.4.1-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "xz-utils", "version": "5.4.1-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "WH0tX6ZQDstQQf37sHDxgA==": { "id": "WH0tX6ZQDstQQf37sHDxgA==", "name": "libgssapi-krb5-2", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "WnY97W2M4cMYcgodtwdeug==": { "id": "WnY97W2M4cMYcgodtwdeug==", "name": "libcrypt1", "version": "1:4.4.33-2", "kind": "binary", "source": { "id": "", "name": "libxcrypt", "version": "1:4.4.33-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Wr9/hCEIMcG8tvcDvngj7g==": { "id": "Wr9/hCEIMcG8tvcDvngj7g==", "name": "libpango-1.0-0", "version": "1.50.12+ds-1", "kind": "binary", "source": { "id": "", "name": "pango1.0", "version": "1.50.12+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "X/R7rdEojRYgcmiRFcNgow==": { "id": "X/R7rdEojRYgcmiRFcNgow==", "name": "libimath-3-1-29", "version": "3.1.6-1", "kind": "binary", "source": { "id": "", "name": "imath", "version": "3.1.6-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "X1WjUMTLpPJaqCK06wnQtQ==": { "id": "X1WjUMTLpPJaqCK06wnQtQ==", "name": "findutils", "version": "4.9.0-4", "kind": "binary", "source": { "id": "", "name": "findutils", "version": "4.9.0-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "X3q1EDF8zyUvx2mfTW4asA==": { "id": "X3q1EDF8zyUvx2mfTW4asA==", "name": "libidn2-0", "version": "2.3.3-1+b1", "kind": "binary", "source": { "id": "", "name": "libidn2", "version": "2.3.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "XEWu7z0CgmagC+WX60/Fhw==": { "id": "XEWu7z0CgmagC+WX60/Fhw==", "name": "debconf", "version": "1.5.82", "kind": "binary", "source": { "id": "", "name": "debconf", "version": "1.5.82", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "XRk1dINrYyWFrO0TPT5vSQ==": { "id": "XRk1dINrYyWFrO0TPT5vSQ==", "name": "libx11-dev", "version": "2:1.8.4-2+deb12u2", "kind": "binary", "source": { "id": "", "name": "libx11", "version": "2:1.8.4-2+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "XUoS/2ycdVjHeXgE8Lrk9g==": { "id": "XUoS/2ycdVjHeXgE8Lrk9g==", "name": "python3-lib2to3", "version": "3.11.2-3", "kind": "binary", "source": { "id": "", "name": "python3-stdlib-extensions", "version": "3.11.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "XYVajzAF62/3canSa7aN3w==": { "id": "XYVajzAF62/3canSa7aN3w==", "name": "libcbor0.8", "version": "0.8.0-2+b1", "kind": "binary", "source": { "id": "", "name": "libcbor", "version": "0.8.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "XkcBMYJ7ffi3rubZkBKcEw==": { "id": "XkcBMYJ7ffi3rubZkBKcEw==", "name": "libfontconfig-dev", "version": "2.14.1-4", "kind": "binary", "source": { "id": "", "name": "fontconfig", "version": "2.14.1-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YLnDZQFr2jPrZgUlu5KKAg==": { "id": "YLnDZQFr2jPrZgUlu5KKAg==", "name": "libkrb5support0", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YPTdPMRgbDdBBetyCawKmw==": { "id": "YPTdPMRgbDdBBetyCawKmw==", "name": "libss2", "version": "1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YQfQT1wRk+YJhnXfvhY46w==": { "id": "YQfQT1wRk+YJhnXfvhY46w==", "name": "perl", "version": "5.36.0-7+deb12u3", "kind": "binary", "source": { "id": "", "name": "perl", "version": "5.36.0-7+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YR/r5vxq5Kq88OnLa984Eg==": { "id": "YR/r5vxq5Kq88OnLa984Eg==", "name": "linux-libc-dev", "version": "6.1.180-1", "kind": "binary", "source": { "id": "", "name": "linux", "version": "6.1.180-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YVC1tKdseGyjyPlBWGWXsg==": { "id": "YVC1tKdseGyjyPlBWGWXsg==", "name": "libxcb1-dev", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "YnPSos1SroYgrNVto6+i2w==": { "id": "YnPSos1SroYgrNVto6+i2w==", "name": "libharfbuzz0b", "version": "6.0.0+dfsg-3", "kind": "binary", "source": { "id": "", "name": "harfbuzz", "version": "6.0.0+dfsg-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Ytx7KD+lxlaFvaInJa6yPg==": { "id": "Ytx7KD+lxlaFvaInJa6yPg==", "name": "logsave", "version": "1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Z31z4+OLZbTfgacr2IF35Q==": { "id": "Z31z4+OLZbTfgacr2IF35Q==", "name": "ucf", "version": "3.0043+nmu1+deb12u1", "kind": "binary", "source": { "id": "", "name": "ucf", "version": "3.0043+nmu1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "Z4PEfJvMbj4dqTXnsp95Aw==": { "id": "Z4PEfJvMbj4dqTXnsp95Aw==", "name": "imagemagick-6-common", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "ZTVtM/3ZWA9Gl2UwxERsuA==": { "id": "ZTVtM/3ZWA9Gl2UwxERsuA==", "name": "libpq5", "version": "15.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "postgresql-15", "version": "15.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "Zc22Q3iFIPZ+epg2FdgpvA==": { "id": "Zc22Q3iFIPZ+epg2FdgpvA==", "name": "gnupg", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "ZfVnnJy7oaL9gSdtJaq2cQ==": { "id": "ZfVnnJy7oaL9gSdtJaq2cQ==", "name": "gnupg-utils", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ZnzG2AHpIfwDtaj3GRZrrw==": { "id": "ZnzG2AHpIfwDtaj3GRZrrw==", "name": "sensible-utils", "version": "0.0.17+nmu1", "kind": "binary", "source": { "id": "", "name": "sensible-utils", "version": "0.0.17+nmu1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "ZrenMRS4ooimSw7HXEAolA==": { "id": "ZrenMRS4ooimSw7HXEAolA==", "name": "libmount1", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ZshnlexyascwPM2O9elYkQ==": { "id": "ZshnlexyascwPM2O9elYkQ==", "name": "libsm-dev", "version": "2:1.2.3-1", "kind": "binary", "source": { "id": "", "name": "libsm", "version": "2:1.2.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "a7ySLyg5kySmKUmKI87EKQ==": { "id": "a7ySLyg5kySmKUmKI87EKQ==", "name": "gir1.2-glib-2.0", "version": "1.74.0-3", "kind": "binary", "source": { "id": "", "name": "gobject-introspection", "version": "1.74.0-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "aEtzpfwMbCldfN1nMySS/Q==": { "id": "aEtzpfwMbCldfN1nMySS/Q==", "name": "libtiff-dev", "version": "4.5.0-6+deb12u4", "kind": "binary", "source": { "id": "", "name": "tiff", "version": "4.5.0-6+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "aLjZ2cat4dKFZXAvWmHWmA==": { "id": "aLjZ2cat4dKFZXAvWmHWmA==", "name": "x11proto-dev", "version": "2022.1-1", "kind": "binary", "source": { "id": "", "name": "xorgproto", "version": "2022.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "aN1Jp7DF2Q77pDWX5eLS7Q==": { "id": "aN1Jp7DF2Q77pDWX5eLS7Q==", "name": "libsemanage2", "version": "3.4-1+b5", "kind": "binary", "source": { "id": "", "name": "libsemanage", "version": "3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "aZVh1+7qlPGF1Mzt+c+CWw==": { "id": "aZVh1+7qlPGF1Mzt+c+CWw==", "name": "zlib1g-dev", "version": "1:1.2.13.dfsg-1", "kind": "binary", "source": { "id": "", "name": "zlib", "version": "1:1.2.13.dfsg-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "actKaDb3xYrYFwmm8ud9yA==": { "id": "actKaDb3xYrYFwmm8ud9yA==", "name": "zlib1g", "version": "1:1.2.13.dfsg-1", "kind": "binary", "source": { "id": "", "name": "zlib", "version": "1:1.2.13.dfsg-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "aeGWMCgnauz71afUV6KWIg==": { "id": "aeGWMCgnauz71afUV6KWIg==", "name": "mount", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "auDAxNEJu9eRfZtk79PicA==": { "id": "auDAxNEJu9eRfZtk79PicA==", "name": "libnuma1", "version": "2.0.16-1", "kind": "binary", "source": { "id": "", "name": "numactl", "version": "2.0.16-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "b9QJEyrIJkdG8LUQ9Efa5Q==": { "id": "b9QJEyrIJkdG8LUQ9Efa5Q==", "name": "libwebpdemux2", "version": "1.2.4-0.2+deb12u1", "kind": "binary", "source": { "id": "", "name": "libwebp", "version": "1.2.4-0.2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "bRgs7+GRebE8GepCiTgVUg==": { "id": "bRgs7+GRebE8GepCiTgVUg==", "name": "libsystemd0", "version": "252.39-1~deb12u2", "kind": "binary", "source": { "id": "", "name": "systemd", "version": "252.39-1~deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "bh8ssVhS9Y+kH8SHn/gSBw==": { "id": "bh8ssVhS9Y+kH8SHn/gSBw==", "name": "libpam-modules", "version": "1.5.2-6+deb12u2", "kind": "binary", "source": { "id": "", "name": "pam", "version": "1.5.2-6+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "bqiN2A8K3nPnvjFFN5DSug==": { "id": "bqiN2A8K3nPnvjFFN5DSug==", "name": "libmaxminddb0", "version": "1.7.1-1", "kind": "binary", "source": { "id": "", "name": "libmaxminddb", "version": "1.7.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "c5tjU1eTINvwTj7oRd+r4w==": { "id": "c5tjU1eTINvwTj7oRd+r4w==", "name": "libkadm5srv-mit12", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "cKuouhxzNwqPCwYlA0+RvA==": { "id": "cKuouhxzNwqPCwYlA0+RvA==", "name": "libmagickcore-6-arch-config", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "cUipGVe8goaGwm2aT3+3Lw==": { "id": "cUipGVe8goaGwm2aT3+3Lw==", "name": "libpangoft2-1.0-0", "version": "1.50.12+ds-1", "kind": "binary", "source": { "id": "", "name": "pango1.0", "version": "1.50.12+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "cdMtaom6+kBauoZ8sh47yQ==": { "id": "cdMtaom6+kBauoZ8sh47yQ==", "name": "dirmngr", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "cjiQfFpqlL6r2yX1yzvy2g==": { "id": "cjiQfFpqlL6r2yX1yzvy2g==", "name": "libncurses5-dev", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "cu//fzDqaCGg4IckBdBb/Q==": { "id": "cu//fzDqaCGg4IckBdBb/Q==", "name": "libfftw3-double3", "version": "3.3.10-1", "kind": "binary", "source": { "id": "", "name": "fftw3", "version": "3.3.10-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "d5gn36upXf4qnQ9Za5ikaA==": { "id": "d5gn36upXf4qnQ9Za5ikaA==", "name": "libfreetype6", "version": "2.12.1+dfsg-5+deb12u4", "kind": "binary", "source": { "id": "", "name": "freetype", "version": "2.12.1+dfsg-5+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "dQV6llj0RdZXO5w4gns9/g==": { "id": "dQV6llj0RdZXO5w4gns9/g==", "name": "liblqr-1-0-dev", "version": "0.4.2-2.1", "kind": "binary", "source": { "id": "", "name": "liblqr", "version": "0.4.2-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "dmSlsRqKvEhuqJKLlZl0Ng==": { "id": "dmSlsRqKvEhuqJKLlZl0Ng==", "name": "librsvg2-2", "version": "2.54.7+dfsg-1~deb12u1", "kind": "binary", "source": { "id": "", "name": "librsvg", "version": "2.54.7+dfsg-1~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "doTtw5XfITX5mpS5AWcHgg==": { "id": "doTtw5XfITX5mpS5AWcHgg==", "name": "libtiffxx6", "version": "4.5.0-6+deb12u4", "kind": "binary", "source": { "id": "", "name": "tiff", "version": "4.5.0-6+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "dxnmYyzrNAzDZvX4HJ02IQ==": { "id": "dxnmYyzrNAzDZvX4HJ02IQ==", "name": "libtirpc-dev", "version": "1.3.3+ds-1", "kind": "binary", "source": { "id": "", "name": "libtirpc", "version": "1.3.3+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "e5xJm0VsLY9aC2eBzS/hRg==": { "id": "e5xJm0VsLY9aC2eBzS/hRg==", "name": "libunistring2", "version": "1.0-2", "kind": "binary", "source": { "id": "", "name": "libunistring", "version": "1.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "e62g+eBZRfYBs6yG5WT/QA==": { "id": "e62g+eBZRfYBs6yG5WT/QA==", "name": "libcurl4", "version": "7.88.1-10+deb12u15", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.88.1-10+deb12u15", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "eIk+qkkRXA+xGo/1q5dw9A==": { "id": "eIk+qkkRXA+xGo/1q5dw9A==", "name": "libedit2", "version": "3.1-20221030-2", "kind": "binary", "source": { "id": "", "name": "libedit", "version": "3.1-20221030-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "eV7DKdUD9pVAnDtfbcVAEw==": { "id": "eV7DKdUD9pVAnDtfbcVAEw==", "name": "libbsd0", "version": "0.11.7-2", "kind": "binary", "source": { "id": "", "name": "libbsd", "version": "0.11.7-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "eZNFlnEXjKUCdUf65UDWyQ==": { "id": "eZNFlnEXjKUCdUf65UDWyQ==", "name": "libevent-2.1-7", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "eZksHyCeAZGfeU9bFOEVpg==": { "id": "eZksHyCeAZGfeU9bFOEVpg==", "name": "libsepol2", "version": "3.4-2.1", "kind": "binary", "source": { "id": "", "name": "libsepol", "version": "3.4-2.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "eb3MoYEkG53wzbp2nH2s+w==": { "id": "eb3MoYEkG53wzbp2nH2s+w==", "name": "libdjvulibre-text", "version": "3.5.28-2.2~deb12u1", "kind": "binary", "source": { "id": "", "name": "djvulibre", "version": "3.5.28-2.2~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "etBHHpaJIkAd+r+FzrnQYQ==": { "id": "etBHHpaJIkAd+r+FzrnQYQ==", "name": "libssh2-1", "version": "1.10.0-3+b1", "kind": "binary", "source": { "id": "", "name": "libssh2", "version": "1.10.0-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "f10UoKkRE6Jo0iYAIvrZVg==": { "id": "f10UoKkRE6Jo0iYAIvrZVg==", "name": "base-files", "version": "12.4+deb12u15", "kind": "binary", "source": { "id": "", "name": "base-files", "version": "12.4+deb12u15", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "fCqlJ47aDkcKyofpeMLozg==": { "id": "fCqlJ47aDkcKyofpeMLozg==", "name": "libxau-dev", "version": "1:1.0.9-1", "kind": "binary", "source": { "id": "", "name": "libxau", "version": "1:1.0.9-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "fNp2jCSWjymcyaSrauohUQ==": { "id": "fNp2jCSWjymcyaSrauohUQ==", "name": "libitm1", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "fXX1mg9IUP1aOVFN1izlsA==": { "id": "fXX1mg9IUP1aOVFN1izlsA==", "name": "libopenjp2-7-dev", "version": "2.5.0-2+deb12u3", "kind": "binary", "source": { "id": "", "name": "openjpeg2", "version": "2.5.0-2+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "fjmjfd8Z1obPxEblTqtW3A==": { "id": "fjmjfd8Z1obPxEblTqtW3A==", "name": "libcurl3-gnutls", "version": "7.88.1-10+deb12u15", "kind": "binary", "source": { "id": "", "name": "curl", "version": "7.88.1-10+deb12u15", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "fp2OvnA1/4UxQXzbyvpRFQ==": { "id": "fp2OvnA1/4UxQXzbyvpRFQ==", "name": "libmagic-mgc", "version": "1:5.44-3", "kind": "binary", "source": { "id": "", "name": "file", "version": "1:5.44-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "g4NDzTQtw6KVo/DkE5yxgA==": { "id": "g4NDzTQtw6KVo/DkE5yxgA==", "name": "libc6-dev", "version": "2.36-9+deb12u14", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.36-9+deb12u14", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gGBj281ejrz/q2buI9WLLQ==": { "id": "gGBj281ejrz/q2buI9WLLQ==", "name": "libexif-dev", "version": "0.6.24-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "libexif", "version": "0.6.24-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gPUUPwC35o/YYWvMKRT3jQ==": { "id": "gPUUPwC35o/YYWvMKRT3jQ==", "name": "libp11-kit0", "version": "0.24.1-2", "kind": "binary", "source": { "id": "", "name": "p11-kit", "version": "0.24.1-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gQ6Px92HfjNtE1SIyFrTNw==": { "id": "gQ6Px92HfjNtE1SIyFrTNw==", "name": "libssl3", "version": "3.0.20-1~deb12u2", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "3.0.20-1~deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gRa0ZxPS51x6lznq+sdgfQ==": { "id": "gRa0ZxPS51x6lznq+sdgfQ==", "name": "autotools-dev", "version": "20220109.1", "kind": "binary", "source": { "id": "", "name": "autotools-dev", "version": "20220109.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "gTvrCykxbI1a3Gcl7E0P9Q==": { "id": "gTvrCykxbI1a3Gcl7E0P9Q==", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gl0OhjS0CgURY1GbKaA3Pg==": { "id": "gl0OhjS0CgURY1GbKaA3Pg==", "name": "libxxhash0", "version": "0.8.1-1", "kind": "binary", "source": { "id": "", "name": "xxhash", "version": "0.8.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "gymN3jPkoNdHmf8ZwEcYOA==": { "id": "gymN3jPkoNdHmf8ZwEcYOA==", "name": "dpkg-dev", "version": "1.21.23", "kind": "binary", "source": { "id": "", "name": "dpkg", "version": "1.21.23", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "hVfx408wtJy5zIeh3kwCqA==": { "id": "hVfx408wtJy5zIeh3kwCqA==", "name": "libutf8proc2", "version": "2.8.0-1", "kind": "binary", "source": { "id": "", "name": "utf8proc", "version": "2.8.0-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "iLiEn2koQeeimUI4OL8oGg==": { "id": "iLiEn2koQeeimUI4OL8oGg==", "name": "libgcc-12-dev", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "irT5nUZrGIIxlJv2pGpz2g==": { "id": "irT5nUZrGIIxlJv2pGpz2g==", "name": "dash", "version": "0.5.12-2", "kind": "binary", "source": { "id": "", "name": "dash", "version": "0.5.12-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "iwRi5YipcVuzlYupn5b+jg==": { "id": "iwRi5YipcVuzlYupn5b+jg==", "name": "libproc2-0", "version": "2:4.0.2-3", "kind": "binary", "source": { "id": "", "name": "procps", "version": "2:4.0.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "jJUMqmMNIdKKAQELQiVgZg==": { "id": "jJUMqmMNIdKKAQELQiVgZg==", "name": "libext2fs2", "version": "1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "jQVZQyvj/JpZn3nTjwL2PQ==": { "id": "jQVZQyvj/JpZn3nTjwL2PQ==", "name": "ca-certificates", "version": "20230311+deb12u1", "kind": "binary", "source": { "id": "", "name": "ca-certificates", "version": "20230311+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "jTg7U1tuUYtTikyJ6pCuGw==": { "id": "jTg7U1tuUYtTikyJ6pCuGw==", "name": "librsvg2-common", "version": "2.54.7+dfsg-1~deb12u1", "kind": "binary", "source": { "id": "", "name": "librsvg", "version": "2.54.7+dfsg-1~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "jgvkVKXQP/jGryvrRC8CjA==": { "id": "jgvkVKXQP/jGryvrRC8CjA==", "name": "libltdl-dev", "version": "2.4.7-7~deb12u1", "kind": "binary", "source": { "id": "", "name": "libtool", "version": "2.4.7-7~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "jkScyosTpCbpojjNpLe9lA==": { "id": "jkScyosTpCbpojjNpLe9lA==", "name": "libicu72", "version": "72.1-3+deb12u1", "kind": "binary", "source": { "id": "", "name": "icu", "version": "72.1-3+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "jw79kfCnmk5tgnxiuoD7dQ==": { "id": "jw79kfCnmk5tgnxiuoD7dQ==", "name": "mawk", "version": "1.3.4.20200120-3.1", "kind": "binary", "source": { "id": "", "name": "mawk", "version": "1.3.4.20200120-3.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "k0OfjdCQeCK/OovAA207Pg==": { "id": "k0OfjdCQeCK/OovAA207Pg==", "name": "passwd", "version": "1:4.13+dfsg1-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "shadow", "version": "1:4.13+dfsg1-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "kFXNoZ7znmAHcjIm9e1ZjQ==": { "id": "kFXNoZ7znmAHcjIm9e1ZjQ==", "name": "libheif1", "version": "1.15.1-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "libheif", "version": "1.15.1-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "kSEV+mUKUgo2G6fUzNc4Xw==": { "id": "kSEV+mUKUgo2G6fUzNc4Xw==", "name": "libldap-2.5-0", "version": "2.5.13+dfsg-5", "kind": "binary", "source": { "id": "", "name": "openldap", "version": "2.5.13+dfsg-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "knCuFHAKZKhlQzlL5X/4GA==": { "id": "knCuFHAKZKhlQzlL5X/4GA==", "name": "krb5-multidev", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "kodNZRS/kOF0CC46/w5OKQ==": { "id": "kodNZRS/kOF0CC46/w5OKQ==", "name": "libdebconfclient0", "version": "0.270", "kind": "binary", "source": { "id": "", "name": "cdebconf", "version": "0.270", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "kuFVsliIpJiDywtMew9a2Q==": { "id": "kuFVsliIpJiDywtMew9a2Q==", "name": "util-linux-extra", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "l+d8apBfkzYeHMLDsiDPfA==": { "id": "l+d8apBfkzYeHMLDsiDPfA==", "name": "bsdutils", "version": "1:2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "l1HDVI4ShrVXDfyI4V7kuw==": { "id": "l1HDVI4ShrVXDfyI4V7kuw==", "name": "libjpeg-dev", "version": "1:2.1.5-2", "kind": "binary", "source": { "id": "", "name": "libjpeg-turbo", "version": "1:2.1.5-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "lSvWkavUDMv8SqOHTq017g==": { "id": "lSvWkavUDMv8SqOHTq017g==", "name": "libk5crypto3", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ldxG14V6EBIxhDObD0C6XA==": { "id": "ldxG14V6EBIxhDObD0C6XA==", "name": "libkrb5-dev", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "lnKrfDFZYbpH3rjpRabl0g==": { "id": "lnKrfDFZYbpH3rjpRabl0g==", "name": "diffutils", "version": "1:3.8-4", "kind": "binary", "source": { "id": "", "name": "diffutils", "version": "1:3.8-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "m4X0sD8xf1gD4Z26V7ni2g==": { "id": "m4X0sD8xf1gD4Z26V7ni2g==", "name": "libmariadb-dev-compat", "version": "1:10.11.18-0+deb12u1", "kind": "binary", "source": { "id": "", "name": "mariadb", "version": "1:10.11.18-0+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "mI3yVFki3HI9pwU56Jym9Q==": { "id": "mI3yVFki3HI9pwU56Jym9Q==", "name": "x11proto-core-dev", "version": "2022.1-1", "kind": "binary", "source": { "id": "", "name": "xorgproto", "version": "2022.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "mKooU+H4DkWGjPk/O6MngQ==": { "id": "mKooU+H4DkWGjPk/O6MngQ==", "name": "libthai-data", "version": "0.1.29-1", "kind": "binary", "source": { "id": "", "name": "libthai", "version": "0.1.29-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "mWPGBAGgpAZ6v4RXC0mAXg==": { "id": "mWPGBAGgpAZ6v4RXC0mAXg==", "name": "libstdc++6", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "mbDygfWRp5m6a6Cz6HCilQ==": { "id": "mbDygfWRp5m6a6Cz6HCilQ==", "name": "libmd0", "version": "1.0.4-2", "kind": "binary", "source": { "id": "", "name": "libmd", "version": "1.0.4-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "munkvrAt8cZg1PdJDw+QAg==": { "id": "munkvrAt8cZg1PdJDw+QAg==", "name": "gir1.2-gdkpixbuf-2.0", "version": "2.42.10+dfsg-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "gdk-pixbuf", "version": "2.42.10+dfsg-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "n+AtxKIZ8VkeMUWxT4sCNw==": { "id": "n+AtxKIZ8VkeMUWxT4sCNw==", "name": "make", "version": "4.3-4.1", "kind": "binary", "source": { "id": "", "name": "make-dfsg", "version": "4.3-4.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "n+UCrXJ4CQvpUTP5YUfOFA==": { "id": "n+UCrXJ4CQvpUTP5YUfOFA==", "name": "libfreetype6-dev", "version": "2.12.1+dfsg-5+deb12u4", "kind": "binary", "source": { "id": "", "name": "freetype", "version": "2.12.1+dfsg-5+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "n2nnX6bHVed4z2/S7PHApQ==": { "id": "n2nnX6bHVed4z2/S7PHApQ==", "name": "libx265-199", "version": "3.5-2+b1", "kind": "binary", "source": { "id": "", "name": "x265", "version": "3.5-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "nLtBe1D/LMWpe8qyvoTEQg==": { "id": "nLtBe1D/LMWpe8qyvoTEQg==", "name": "libssl-dev", "version": "3.0.20-1~deb12u2", "kind": "binary", "source": { "id": "", "name": "openssl", "version": "3.0.20-1~deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "nfBx6td713hSJbdgrWWi7g==": { "id": "nfBx6td713hSJbdgrWWi7g==", "name": "libmagickwand-6.q16-dev", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "nglbwzrSsCpYknoI/PYm4w==": { "id": "nglbwzrSsCpYknoI/PYm4w==", "name": "pkgconf-bin", "version": "1.8.1-1", "kind": "binary", "source": { "id": "", "name": "pkgconf", "version": "1.8.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "nmKloy3CkYM0SIICJVg+lg==": { "id": "nmKloy3CkYM0SIICJVg+lg==", "name": "perl-base", "version": "5.36.0-7+deb12u3", "kind": "binary", "source": { "id": "", "name": "perl", "version": "5.36.0-7+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "nsXhakxka4aH9ndfG/DcZw==": { "id": "nsXhakxka4aH9ndfG/DcZw==", "name": "libctf0", "version": "2.40-2", "kind": "binary", "source": { "id": "", "name": "binutils", "version": "2.40-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "o/zohiVcmyo2pnjEk/WU6w==": { "id": "o/zohiVcmyo2pnjEk/WU6w==", "name": "automake", "version": "1:1.16.5-1.3", "kind": "binary", "source": { "id": "", "name": "automake-1.16", "version": "1:1.16.5-1.3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "oGeYh+clinYKyrkBhPoJQQ==": { "id": "oGeYh+clinYKyrkBhPoJQQ==", "name": "netbase", "version": "6.4", "kind": "binary", "source": { "id": "", "name": "netbase", "version": "6.4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "oJVJhm4h5O0CE9d/wGyW6w==": { "id": "oJVJhm4h5O0CE9d/wGyW6w==", "name": "ncurses-bin", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "oPBeJDH0EGBiFmMn2Hcv+A==": { "id": "oPBeJDH0EGBiFmMn2Hcv+A==", "name": "libxdmcp-dev", "version": "1:1.1.2-3", "kind": "binary", "source": { "id": "", "name": "libxdmcp", "version": "1:1.1.2-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "oVNzYxanlnKcVn1aOfjY0g==": { "id": "oVNzYxanlnKcVn1aOfjY0g==", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "oZB7NQXsGwhpn+1reikgKg==": { "id": "oZB7NQXsGwhpn+1reikgKg==", "name": "libgdk-pixbuf2.0-bin", "version": "2.42.10+dfsg-1+deb12u4", "kind": "binary", "source": { "id": "", "name": "gdk-pixbuf", "version": "2.42.10+dfsg-1+deb12u4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "oa2Klvjpg54cEHv2U+uMyg==": { "id": "oa2Klvjpg54cEHv2U+uMyg==", "name": "libpam0g", "version": "1.5.2-6+deb12u2", "kind": "binary", "source": { "id": "", "name": "pam", "version": "1.5.2-6+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ora7tN8FbXFI/08Oc6SVYQ==": { "id": "ora7tN8FbXFI/08Oc6SVYQ==", "name": "libselinux1-dev", "version": "3.4-1+b6", "kind": "binary", "source": { "id": "", "name": "libselinux", "version": "3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ow72bVQfBucqWn9Lpanhfw==": { "id": "ow72bVQfBucqWn9Lpanhfw==", "name": "libglib2.0-0", "version": "2.74.6-2+deb12u9", "kind": "binary", "source": { "id": "", "name": "glib2.0", "version": "2.74.6-2+deb12u9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pB8Ci86kQABf1+zQMekbbA==": { "id": "pB8Ci86kQABf1+zQMekbbA==", "name": "libsm6", "version": "2:1.2.3-1", "kind": "binary", "source": { "id": "", "name": "libsm", "version": "2:1.2.3-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pLcYsdHNKtQ11g/IKKVTng==": { "id": "pLcYsdHNKtQ11g/IKKVTng==", "name": "x11-common", "version": "1:7.7+23", "kind": "binary", "source": { "id": "", "name": "xorg", "version": "1:7.7+23", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "pT6NFp7xMNXzlWEMxC6XXA==": { "id": "pT6NFp7xMNXzlWEMxC6XXA==", "name": "libgdbm-compat4", "version": "1.23-3", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.23-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pbeJdaGLL/qpemruqH9rXg==": { "id": "pbeJdaGLL/qpemruqH9rXg==", "name": "gpgsm", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pfF+qwLjBmQwroRuGF5i9Q==": { "id": "pfF+qwLjBmQwroRuGF5i9Q==", "name": "libmagickcore-6.q16-dev", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pqXSQwt50vUG+o+dld9Maw==": { "id": "pqXSQwt50vUG+o+dld9Maw==", "name": "libgnutls30", "version": "3.7.9-2+deb12u7", "kind": "binary", "source": { "id": "", "name": "gnutls28", "version": "3.7.9-2+deb12u7", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "pzWPbMb0u08oeR+ebbcTtA==": { "id": "pzWPbMb0u08oeR+ebbcTtA==", "name": "libopenexr-dev", "version": "3.1.5-5", "kind": "binary", "source": { "id": "", "name": "openexr", "version": "3.1.5-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "q+wUXVJsEBDZFFv6fL5rjQ==": { "id": "q+wUXVJsEBDZFFv6fL5rjQ==", "name": "libpkgconf3", "version": "1.8.1-1", "kind": "binary", "source": { "id": "", "name": "pkgconf", "version": "1.8.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "qRujymkc3h1g3NGrFG5S4w==": { "id": "qRujymkc3h1g3NGrFG5S4w==", "name": "libxrender-dev", "version": "1:0.9.10-1.1", "kind": "binary", "source": { "id": "", "name": "libxrender", "version": "1:0.9.10-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "qljM0gjNc4JfErPeE+a4Mg==": { "id": "qljM0gjNc4JfErPeE+a4Mg==", "name": "openssh-client", "version": "1:9.2p1-2+deb12u10", "kind": "binary", "source": { "id": "", "name": "openssh", "version": "1:9.2p1-2+deb12u10", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "qq0mSZMgqtY1jW7K5EzEKw==": { "id": "qq0mSZMgqtY1jW7K5EzEKw==", "name": "libffi-dev", "version": "3.4.4-1", "kind": "binary", "source": { "id": "", "name": "libffi", "version": "3.4.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "qvtCTIsiRY8AFQ+wciQxjA==": { "id": "qvtCTIsiRY8AFQ+wciQxjA==", "name": "libstdc++-12-dev", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "r/gSRbuNjGeJm0J62Z57YQ==": { "id": "r/gSRbuNjGeJm0J62Z57YQ==", "name": "base-passwd", "version": "3.6.1", "kind": "binary", "source": { "id": "", "name": "base-passwd", "version": "3.6.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "rXBH8p7w0o7P+QqmKYI5cw==": { "id": "rXBH8p7w0o7P+QqmKYI5cw==", "name": "libopenexr-3-1-30", "version": "3.1.5-5", "kind": "binary", "source": { "id": "", "name": "openexr", "version": "3.1.5-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "rkyfCtkobwjj2Asc5nC2cA==": { "id": "rkyfCtkobwjj2Asc5nC2cA==", "name": "libudev1", "version": "252.39-1~deb12u2", "kind": "binary", "source": { "id": "", "name": "systemd", "version": "252.39-1~deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "rw8kHjHMNde/LbCq691EpQ==": { "id": "rw8kHjHMNde/LbCq691EpQ==", "name": "libpython3-stdlib", "version": "3.11.2-1+b1", "kind": "binary", "source": { "id": "", "name": "python3-defaults", "version": "3.11.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "s04lFaf8GISBWleGLKMYSg==": { "id": "s04lFaf8GISBWleGLKMYSg==", "name": "libsqlite3-0", "version": "3.40.1-2+deb12u2", "kind": "binary", "source": { "id": "", "name": "sqlite3", "version": "3.40.1-2+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "s0EZjv2nVvc8F2tzbZWnLg==": { "id": "s0EZjv2nVvc8F2tzbZWnLg==", "name": "libtasn1-6", "version": "4.19.0-2+deb12u1", "kind": "binary", "source": { "id": "", "name": "libtasn1-6", "version": "4.19.0-2+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "s3tOAOa/dusIyn91E3m9dQ==": { "id": "s3tOAOa/dusIyn91E3m9dQ==", "name": "libmagickwand-6-headers", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "binary", "source": { "id": "", "name": "imagemagick", "version": "8:6.9.11.60+dfsg-1.6+deb12u13", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "sORKOW7QN24djh240ax6Zg==": { "id": "sORKOW7QN24djh240ax6Zg==", "name": "icu-devtools", "version": "72.1-3+deb12u1", "kind": "binary", "source": { "id": "", "name": "icu", "version": "72.1-3+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "sQW39ax4RcAjxzY96dfosA==": { "id": "sQW39ax4RcAjxzY96dfosA==", "name": "libpangocairo-1.0-0", "version": "1.50.12+ds-1", "kind": "binary", "source": { "id": "", "name": "pango1.0", "version": "1.50.12+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "saTNJ4JLYjq2syxwkWSJ3w==": { "id": "saTNJ4JLYjq2syxwkWSJ3w==", "name": "python3.11-minimal", "version": "3.11.2-6+deb12u8", "kind": "binary", "source": { "id": "", "name": "python3.11", "version": "3.11.2-6+deb12u8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "sctPw/Cjix61rafbjj3Byg==": { "id": "sctPw/Cjix61rafbjj3Byg==", "name": "libserf-1-1", "version": "1.3.9-11", "kind": "binary", "source": { "id": "", "name": "serf", "version": "1.3.9-11", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "sfIougYRV8YRw5jl5oezkg==": { "id": "sfIougYRV8YRw5jl5oezkg==", "name": "librsvg2-dev", "version": "2.54.7+dfsg-1~deb12u1", "kind": "binary", "source": { "id": "", "name": "librsvg", "version": "2.54.7+dfsg-1~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "spwT18Eh7R672S2SX3nVOw==": { "id": "spwT18Eh7R672S2SX3nVOw==", "name": "liblerc-dev", "version": "4.0.0+ds-2", "kind": "binary", "source": { "id": "", "name": "lerc", "version": "4.0.0+ds-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "t3YU8qENudZWutw34Irysw==": { "id": "t3YU8qENudZWutw34Irysw==", "name": "hicolor-icon-theme", "version": "0.17-2", "kind": "binary", "source": { "id": "", "name": "hicolor-icon-theme", "version": "0.17-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "t86og0L00GStZ//a2urDmA==": { "id": "t86og0L00GStZ//a2urDmA==", "name": "libgdbm6", "version": "1.23-3", "kind": "binary", "source": { "id": "", "name": "gdbm", "version": "1.23-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "tNsAQRt9mzvTR/AkUSKmMw==": { "id": "tNsAQRt9mzvTR/AkUSKmMw==", "name": "libmagic1", "version": "1:5.44-3", "kind": "binary", "source": { "id": "", "name": "file", "version": "1:5.44-3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "tR8RKPSydOIs4d7KfihmaA==": { "id": "tR8RKPSydOIs4d7KfihmaA==", "name": "libglib2.0-data", "version": "2.74.6-2+deb12u9", "kind": "binary", "source": { "id": "", "name": "glib2.0", "version": "2.74.6-2+deb12u9", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "tXHETcPCqvJ02XXdcsXBCQ==": { "id": "tXHETcPCqvJ02XXdcsXBCQ==", "name": "libbrotli1", "version": "1.0.9-2+b6", "kind": "binary", "source": { "id": "", "name": "brotli", "version": "1.0.9-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "thfp8azY5po/jEHc88Id8Q==": { "id": "thfp8azY5po/jEHc88Id8Q==", "name": "libxext6", "version": "2:1.3.4-1+b1", "kind": "binary", "source": { "id": "", "name": "libxext", "version": "2:1.3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uHzr3rw094EOhdtD+MEZng==": { "id": "uHzr3rw094EOhdtD+MEZng==", "name": "libseccomp2", "version": "2.5.4-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "libseccomp", "version": "2.5.4-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uQdwRFO1nRMrmWEaKcAG8A==": { "id": "uQdwRFO1nRMrmWEaKcAG8A==", "name": "libxt-dev", "version": "1:1.2.1-1.1", "kind": "binary", "source": { "id": "", "name": "libxt", "version": "1:1.2.1-1.1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uRTnOnkqvYmKFWfBE8eF6Q==": { "id": "uRTnOnkqvYmKFWfBE8eF6Q==", "name": "cpp", "version": "4:12.2.0-3", "kind": "binary", "source": { "id": "", "name": "gcc-defaults", "version": "1.203", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uZRVQPPNGjtjKkLQKoY9Cw==": { "id": "uZRVQPPNGjtjKkLQKoY9Cw==", "name": "libc-dev-bin", "version": "2.36-9+deb12u14", "kind": "binary", "source": { "id": "", "name": "glibc", "version": "2.36-9+deb12u14", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uo2N4y3o0YlwTXR15IlWpQ==": { "id": "uo2N4y3o0YlwTXR15IlWpQ==", "name": "libevent-openssl-2.1-7", "version": "2.1.12-stable-8", "kind": "binary", "source": { "id": "", "name": "libevent", "version": "2.1.12-stable-8", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uotq0WJi2CaJg4+oE5qZFw==": { "id": "uotq0WJi2CaJg4+oE5qZFw==", "name": "libpixman-1-dev", "version": "0.42.2-1", "kind": "binary", "source": { "id": "", "name": "pixman", "version": "0.42.2-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "uyyQsF78T1CHrA0TO3N6tA==": { "id": "uyyQsF78T1CHrA0TO3N6tA==", "name": "libtinfo6", "version": "6.4-4", "kind": "binary", "source": { "id": "", "name": "ncurses", "version": "6.4-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "vnAoEPoqD8sCFdu/1HyFTg==": { "id": "vnAoEPoqD8sCFdu/1HyFTg==", "name": "libblkid1", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "vrwg5TC0wZPqmwcGBbnmpA==": { "id": "vrwg5TC0wZPqmwcGBbnmpA==", "name": "unzip", "version": "6.0-28", "kind": "binary", "source": { "id": "", "name": "unzip", "version": "6.0-28", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "wNKNI+lzZqD8WQpcAM3nlg==": { "id": "wNKNI+lzZqD8WQpcAM3nlg==", "name": "libquadmath0", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "wlUScb5LLgsHluTsMm3QGw==": { "id": "wlUScb5LLgsHluTsMm3QGw==", "name": "libopenjp2-7", "version": "2.5.0-2+deb12u3", "kind": "binary", "source": { "id": "", "name": "openjpeg2", "version": "2.5.0-2+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xC7THxKHU8rJGN7KeDkIyw==": { "id": "xC7THxKHU8rJGN7KeDkIyw==", "name": "pinentry-curses", "version": "1.2.1-1", "kind": "binary", "source": { "id": "", "name": "pinentry", "version": "1.2.1-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xOYvqnnLEnYNo3LYgrwOMg==": { "id": "xOYvqnnLEnYNo3LYgrwOMg==", "name": "gpgconf", "version": "2.2.40-1.1+deb12u2", "kind": "binary", "source": { "id": "", "name": "gnupg2", "version": "2.2.40-1.1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xOybpUB1yOVytErftRFyQQ==": { "id": "xOybpUB1yOVytErftRFyQQ==", "name": "libexpat1-dev", "version": "2.5.0-1+deb12u2", "kind": "binary", "source": { "id": "", "name": "expat", "version": "2.5.0-1+deb12u2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xWxpCGgNMpM0HCjlM4FkDg==": { "id": "xWxpCGgNMpM0HCjlM4FkDg==", "name": "libdjvulibre21", "version": "3.5.28-2.2~deb12u1", "kind": "binary", "source": { "id": "", "name": "djvulibre", "version": "3.5.28-2.2~deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xg3BDNqhQCocTz7Sp0BLZg==": { "id": "xg3BDNqhQCocTz7Sp0BLZg==", "name": "liberror-perl", "version": "0.17029-2", "kind": "binary", "source": { "id": "", "name": "liberror-perl", "version": "0.17029-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "xkYVRT04r3WxTy3oo/fXzQ==": { "id": "xkYVRT04r3WxTy3oo/fXzQ==", "name": "libgssrpc4", "version": "1.20.1-2+deb12u5", "kind": "binary", "source": { "id": "", "name": "krb5", "version": "1.20.1-2+deb12u5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xn3p89bkGlD/HFM/zmmZTQ==": { "id": "xn3p89bkGlD/HFM/zmmZTQ==", "name": "libubsan1", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xoTk41jWTPy1kr9JyPZ/HQ==": { "id": "xoTk41jWTPy1kr9JyPZ/HQ==", "name": "default-libmysqlclient-dev", "version": "1.1.0", "kind": "binary", "source": { "id": "", "name": "mysql-defaults", "version": "1.1.0", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "xvFdzctIUU+pgbZNN5yUYQ==": { "id": "xvFdzctIUU+pgbZNN5yUYQ==", "name": "wget", "version": "1.21.3-1+deb12u1", "kind": "binary", "source": { "id": "", "name": "wget", "version": "1.21.3-1+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "y7fV0ey1tXsmdYkL7TASCw==": { "id": "y7fV0ey1tXsmdYkL7TASCw==", "name": "libmount-dev", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "yDNUD3wG3wsxr/KwdyEmpA==": { "id": "yDNUD3wG3wsxr/KwdyEmpA==", "name": "libperl5.36", "version": "5.36.0-7+deb12u3", "kind": "binary", "source": { "id": "", "name": "perl", "version": "5.36.0-7+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "yKlKN1Y5OU0/iEuHPCOKlw==": { "id": "yKlKN1Y5OU0/iEuHPCOKlw==", "name": "libattr1", "version": "1:2.5.1-4", "kind": "binary", "source": { "id": "", "name": "attr", "version": "1:2.5.1-4", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "yM8jkmzlfWw9NHaIMH+aVA==": { "id": "yM8jkmzlfWw9NHaIMH+aVA==", "name": "liblz4-1", "version": "1.9.4-1", "kind": "binary", "source": { "id": "", "name": "lz4", "version": "1.9.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "yldOrO/JCuMra2G/2eq3Kw==": { "id": "yldOrO/JCuMra2G/2eq3Kw==", "name": "libreadline8", "version": "8.2-1.3", "kind": "binary", "source": { "id": "", "name": "readline", "version": "8.2-1.3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "ypha8g8Z4b071lSnccTVsQ==": { "id": "ypha8g8Z4b071lSnccTVsQ==", "name": "libxml2", "version": "2.9.14+dfsg-1.3~deb12u6", "kind": "binary", "source": { "id": "", "name": "libxml2", "version": "2.9.14+dfsg-1.3~deb12u6", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "yuHBMNVMQn8orbdaXBHz+w==": { "id": "yuHBMNVMQn8orbdaXBHz+w==", "name": "libxcb-render0", "version": "1.15-1", "kind": "binary", "source": { "id": "", "name": "libxcb", "version": "1.15-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "z3pzHZFRSYY1FGGY1OapeA==": { "id": "z3pzHZFRSYY1FGGY1OapeA==", "name": "libnghttp2-14", "version": "1.52.0-1+deb12u3", "kind": "binary", "source": { "id": "", "name": "nghttp2", "version": "1.52.0-1+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "z9brFT3oatEhdWlqGP4JDA==": { "id": "z9brFT3oatEhdWlqGP4JDA==", "name": "libselinux1", "version": "3.4-1+b6", "kind": "binary", "source": { "id": "", "name": "libselinux", "version": "3.4-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zBPaU1mMhx5jfMwCeUFl1w==": { "id": "zBPaU1mMhx5jfMwCeUFl1w==", "name": "uuid-dev", "version": "2.38.1-5+deb12u3", "kind": "binary", "source": { "id": "", "name": "util-linux", "version": "2.38.1-5+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zNTjhiZ8YqhvVViYkwqiSA==": { "id": "zNTjhiZ8YqhvVViYkwqiSA==", "name": "libtirpc-common", "version": "1.3.3+ds-1", "kind": "binary", "source": { "id": "", "name": "libtirpc", "version": "1.3.3+ds-1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "zR2+STDpAW0F4Hx0xZtBkg==": { "id": "zR2+STDpAW0F4Hx0xZtBkg==", "name": "libfido2-1", "version": "1.12.0-2+b1", "kind": "binary", "source": { "id": "", "name": "libfido2", "version": "1.12.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zRv/Q67g6qJWTz0qqj4+BA==": { "id": "zRv/Q67g6qJWTz0qqj4+BA==", "name": "libnsl2", "version": "1.3.0-2", "kind": "binary", "source": { "id": "", "name": "libnsl", "version": "1.3.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zS2GG5MD4wD3w6JwVU9pkA==": { "id": "zS2GG5MD4wD3w6JwVU9pkA==", "name": "git-man", "version": "1:2.39.5-0+deb12u3", "kind": "binary", "source": { "id": "", "name": "git", "version": "1:2.39.5-0+deb12u3", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "all", "cpe": "", "detector": null }, "zWUG57dHDYwGuXZm1eK4AA==": { "id": "zWUG57dHDYwGuXZm1eK4AA==", "name": "dpkg", "version": "1.21.23", "kind": "binary", "source": { "id": "", "name": "dpkg", "version": "1.21.23", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zgvSJIUhIFalYguys+yFgA==": { "id": "zgvSJIUhIFalYguys+yFgA==", "name": "bzip2", "version": "1.0.8-5+b1", "kind": "binary", "source": { "id": "", "name": "bzip2", "version": "1.0.8-5", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zqLyzwReG4IwDY3R9vbbCQ==": { "id": "zqLyzwReG4IwDY3R9vbbCQ==", "name": "libcom-err2", "version": "1.47.0-2+b2", "kind": "binary", "source": { "id": "", "name": "e2fsprogs", "version": "1.47.0-2", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null }, "zwCQDqDNfLrjHOe2yydsXQ==": { "id": "zwCQDqDNfLrjHOe2yydsXQ==", "name": "gcc-12-base", "version": "12.2.0-14+deb12u1", "kind": "binary", "source": { "id": "", "name": "gcc-12", "version": "12.2.0-14+deb12u1", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "normalized_version": "", "arch": "amd64", "cpe": "", "detector": null } }, "distributions": { "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd": { "id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" } }, "repository": {}, "environments": { "+6B10TyZ7Yw1Uati+EDFTg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "+EvVUYESwvcEspjJuRUM8Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "+H4zAe65wQjw+4vudFFWQA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "+h682k8DPZQDWsNWMpPCnA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "+iLzjzcgN8yvafgaUEN6Mg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "/+Kyg0TsZIwaRl7+5J3rRg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "/1xbchBbkMyq0Ur9WaUTgg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "/4BvI5P5ynGyNUU97zqdMw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "/nkMmPBG6SYwe3XCMMkFfg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "/rs/W+FOAL/4DwyA5fEcyQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "03Bi06wwCZvhMScXOn+12g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "0rQO8ev0gA2bMPyvfyRTSg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "0zZmFEOjIMpFAeP+24iakA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "138kks0ax5N2nNIEzmExjg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1BEuahkY5GQ7T8hAznQnJA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1MYT+bMAGBkKcm+bMIqb6Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1T4167CC3sXBfikeGTBamA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1d+ozfBeVKodpg99SYjl1A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1ibbew6p8bvI8FxMYegw1g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "1jsoelSNrhP+91EF5BRAZQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2GdIFjp2v2PoJza2YjGYeA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2M24H7TupgyXsQi8O+lCmw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2ZcPfrj/S1OihNpEALoqBQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2ZjFWZInqL1yRVL3PtElzg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2fLCAY2+SVCQ2VXaZQ3hqg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2j1W2lPmBANCzFxgA5vkow==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "2q4gD1GZAkS/i3n3Sy+/DQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "30Y83yLPxjZH53BgMHRMgg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "34WD1/tcvM7PC3MYaksE/A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "36PkSUqF3oUYJxM3LL7ytg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "3GFMF+uXbATcLfbem/AI2A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "3S82cOcntf6/9zxs22JKWA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "3k4FPwKVTHyfyKjD8kMK+A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "45yJxXr/oZ39MkwKjVCtMw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "46hyRjmPCCIvx2yjneoXzQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4HvsO4LmB5qq71OYhAgtsw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4NCpmpKxo8GpWHW5UMZtDQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4TrIugtbBqxqa6oPXOcZ9A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4bhBgLYIRdRNvwRcgDDNIA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4eit2G6XEpf9131xbIDkiQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4fCygkDtdC/0bxMKYOg9Rg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4j0fN++xbxUCmc5aXfanEw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4uoDWqA6j1h67XvnWkb69Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "4xzOAwX8EAP1eOlXGJnUVQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5//49B09LJAbC2XX9es0/Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5LsAwCM1hSXSqHbcXxFSaQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5dR7lWzzD+nj4jHczZv87g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5jj9c572EogqkPW6Ucwcag==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5uWQa9ljjSF0OokLG8is7A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5wydsqQl0bNu0Far4Hwvlg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "5xli1ibcVetek1e+KZM6ow==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "60WVKLZwJNhOxCy+uvFphw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6ATWONUn9Z77FRku437S0A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6EEIMKT/hWmOhDYuGd9fsQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6NlVgElnclw5vmTnQK9Kfw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6SJtgGhuLlRhbMpPiqkd3g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6T3N+jQPDlXgrfLG1fI1YQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6V73823qwtABE6sG2lbnnw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6Wc644zWglyAsbvhtOZ3dg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "6jYszk7CIbKEpuqb5CQ2dA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "74RbRvv2uTUZVyS/aUST+A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "75SnQC+8AKaRBUB2VJtspw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "7I8pkw9XzeISk4juz4yhaA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "7f5C30nClWQKp6ABE9Cr6g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "7jIzXM6Spac0GoVcshxV2Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "7m9Wfd2N4nRasn5qfmA8DQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "7pVJMzmeLLO4NXWj0YVBag==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "80qkhrcVZcBsMIrLNl9O9Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "80rK+6RM4F9Hot2jSdUHAg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "8LWvv86uV3cw8wj3q3pMEA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "8cpRxcbI/vwUuKrU5hjaWw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "8o+FZPqse3WD3r9kbW1vBQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "8zBqc6YLv7EX5QenNkOW/g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "9C+D4ZDW4GoIg1zwhO7Imw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "9N0r285o7XdVZky2fQCnLQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "9UvQ/J5UURubT6sa1VdVyw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "9WR568tmvkLmS+IEW2uG3Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "9s5TckcK6fsQxj1m2NeLGg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "A9S4GbGT4KbqDQ4Rk+9rjw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ADxcp+yqIg7//17igk2iWw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "AEmJ/DcX9k+YTOaY1TPipw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "AhInnwPSn3Bcv7iW4TN06A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "AxDgJRPby1Bn5TyQqmbUVA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "B1MLdrb97A3HO0mN23HVww==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "B5DdwMEMymJ408z76zs2OA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "BRBqHmWAPbyliD6oY5fPZQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "BaHdDBXo9vGpSxaSNpfxzQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "BfdRzqdpSloHTsPV0bYqfQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "BlVTvBeWBIL5xG6a/M13Hg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Btnm9wBBF+iO/PtfE/g4Uw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C1WOj2zBssIM43TekSCMGg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C3CbqpDjQWFfxEMRICv6tA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C48XyIAaKniO5HPydCvKpg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C5Hw0IeNICIIcRkshUzBng==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C71NyBHK4UlqmXFWNE4I2Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "C8k9goj1GczZJ4keNY2UHQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "CFG/JDkRv9ezCh1qEKQ8ug==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "CT3G0GG1+aFkXHFGTSDi3A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "CmCZ256ji6DcGmXCpaluIQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Crh7PcjcI6TuJynTs7Y4sQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "D/Trx1uUSMxZ8dPrvnFCjA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "D32BJsOkZunke8aQ5YzeMA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "D4CAttxDppQB4nUjxeAQYg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "D7pQ2iqeywkQv+e7IPd32g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DLENylM5mXuzVt1bbHQcdg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DMI7vu+hT7nBL5mdHloddg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DO2gYwj9yFnFCsYsp/BBVA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DQdtnFQaBdkM1bMve6ZgwQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DUfRr94DlcXwFiSA+XKESw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DX5vrXfJMAv8MvKCJYZehA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Dbw8fwJSQtnZOBPRtWZjAw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DcSn3Y7HFbVbRH2l8vXSOw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DdG2a7LFFvSXCrM63lYSQQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DoeL4sQy46KMZZcZaGrPwA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "DpnNcNYKroLPe/ukW+XyqA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Dr0qgUJ7DFtPHxF+bH4bdg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "E1SCWpEriPaS0rZtcE9l3A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "EC+JU6AsEvpEEhY498jxOg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ET151dfn2MZGHv3vzXEthQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "EoG2zpKSlJJwW+MSosZk9w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "EyNTk1gqN4KHi+AHyTGTsA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "F6hFIFBLlsM5E0Jh5GMVew==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FCK/2by4dcPj2zSU0jBk7w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FGLgg9hMQpl+MW2W94NfHA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FR1lLXy1N/YqpoQMUrt9iw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FTVHNcoQ+LhcUCcvhRsNKA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FUhID3jFFxB1MwHm8UODUA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "FfB0oKhOP9dQDp61Fjo6EA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Ffr9t+FrG7UHpzTQia/UJA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "G0+fRlKRRZRSnY58y39BzA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "G1Vp9YU2liBtgeHfuXjSKA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "G4hHb/2sARVgwAB8zCN/8Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "GZaXtjtG9UqJe33Ris8hvw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Gq4SASJyeL2+pL7FgFSZfw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "GrX0NC3DRB9appRe0ANbeQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "GwYg1UGFzP9MDjj8Bzao7w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "GxIFrX03TO2H3bV6/l8Mgw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "H15dvVf6yrGTTQeCLbwg8w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "H1jcx9ub/KyuVLut+nrRxQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "H5JM5I9PWZdJLP6nda5pEQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "HAbchZDXADggw0sECzOfoQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "HQv3we+HpzbjJVEgufFblw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "HhdzR4wjQEAouKFVlc08JA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "I1bAbBi99CgH1Fe4vQq8lA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "I5/CO7OYsT3D2w8k/V9jeA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "IIgYYwpoulHCI9LIpdK3SA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "IfM/G/gG/1hvKemCx2uliQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "IgM3Tu1xX41jkcHPcFVmNQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "IxIuQ+IDxSN2ss/kdg/dxA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "J+dxZrjQP+fIW/oF0opOcQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "J1M13jv06LUgBQFe/2hBhQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JL3p4IPiugYqmqbhcEI4Qg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JSIFkKzhU9FvkmcYKQhwAA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JSmVKr1KluQ/VM/0yAWB8g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JwsgRUBDkHrNKaGcAJZ/rQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JyXX6aacgQ9R5u7F789q9w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "JywcP/qyzW2E6sHDgBtGgQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "K5LO+DczsLnXcUymG8Ov4Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "KHFQPWvdLygTz81nClfvbg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "KRveFNaAnbaL3OL2dfsnmw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "KW/XvnvOR1sqrB5iyXYx1A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Kdos9fuXp7Tdirl5OEPk0A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Kok6pjCr2iPr0BdF5PzCLA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Ku5epPEPwJZIjh+l6VcECQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "L1BPNHEXKJg2qshBU/0DVg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "L4m+pCjjwdEngLX0mu57Nw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "L8JIZ/GZyKE8KVi4qkx8Jw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "LC/APWT5szmLAgZmxYTyQg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "LIR5D4Dte5MOrnhvpHsVrQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "LK5Y5pt6gg2teLo4lyUl5Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "LSzaEcRtEcwSgtd7CLRn1A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "LoENU9wMD2M0RgtDzEVVrQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "M2yshyCx4J0OAFSMphgrFw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MJc99fNviurhcvfrwqhFnw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MK+wvMZG5H9N57m0tlxOBQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MKH6OlgsSoSX5b3bX6J9iQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MXjHhG8IwQ7T8QqaXIL6BA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MbThVdB9Kwth+Y7uHVZ7aw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MtXElwRG9C/XNTt79l1CoQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "MuoTj+JInnKZmAOZidC2+Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Mw3Qz3FPdmU90ekkNVtotw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "NJT+hpryRcorOQzKPH0mFA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "NM2r479xc6Vy7ZfeePrYRg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Nd5ksUhotJjJPRXnhgHx7g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "NnEYV8lKPl93vYgryCkEwQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Nr51nSGhXANVx6//HdGhXg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "O1IBSbu57cJrxyull5RDow==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "O66ab0mg2AGYJRzvYRXyJw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "OPa+O2qJ8bwSNOa/i8UZrg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "OUGiefTyVQSIR5zV3J7jrw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "OmtFkla3zEOgSVB264/6FQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "OnEFy9GimJqtid0VmTRXbg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "P6kIETtDNA9xKWuxdLqDZg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "P9QnQZyS5ZoKO5leln0hMg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PPjVsVksOg1xBjerPFAZbA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PTPT9COe35b5PMqNzUG1Jg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PVKi3k0lvwaf877Vg/Hf+Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PVYbPIfqCsqfnehuqa5Yzw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PYGOW+lwjkJCppSeNofPwA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Pe0LNCf/FarOFJF3JTE7Lw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "PjtfT38VjsInzOfwCofi8w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Q5UNFAAmvKoOzO5GwPt4eQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "QNQML/EdNKRr8feN6gNQ7Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "QNXfg7x0fKp3nkVykQPVdg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "QiE70L4UggeCJp5Ei3ScLg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Qj5vih+YB0oqxjBJX47HcQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "QunivO3Btr+12V40Q7zvOA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "R+TifLmNsnKmWod+U5H3dw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "RVCbg6a7ro741dC4GIWUhw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Rm6aYlmrhSHTgUrwIkrtXQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Rn8Y2sWVEJp/cwRTbBXU4g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "RrvOhWF4pNgkD1EzBzqhHw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "RvZnrgr9AoeYG/LgkEW41w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "SKBqRjphRN4tmZGXSGijng==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "SNUPzPRR4049keiaYnwZRg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "SdY6vnz+BkS661rpTNZj9Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Sqf4aZ2zleKl0J9AxLdThA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "SvuwU4tnJtOpkXPvd+HGUw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "TJn6Tj11pQiEiMhC9dLTLw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "TSIllJtHNmWZGqpbQMvKDQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "TVoY0Z/LyrK88/UqwT1iKQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "TwB4+3YtKvcmJqfVl3VNfQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "UEgUESKyO8ANGmbG9eyDcQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "UGdCvwdFwDgVlrc4KyAStg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "UaVF3pH6oV2FHpAzXp1raw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "UgKTqEFEym2yE14Xm7MjZQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "UjugzpaTnXWKhG4OAkEZpw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Vb9RpGB0uEvlFvfuUopE+Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Vq6qRMnL8ZtI/FTotk7z9w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "WH0tX6ZQDstQQf37sHDxgA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "WnY97W2M4cMYcgodtwdeug==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Wr9/hCEIMcG8tvcDvngj7g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "X/R7rdEojRYgcmiRFcNgow==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "X1WjUMTLpPJaqCK06wnQtQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "X3q1EDF8zyUvx2mfTW4asA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "XEWu7z0CgmagC+WX60/Fhw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "XRk1dINrYyWFrO0TPT5vSQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "XUoS/2ycdVjHeXgE8Lrk9g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "XYVajzAF62/3canSa7aN3w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "XkcBMYJ7ffi3rubZkBKcEw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YLnDZQFr2jPrZgUlu5KKAg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YPTdPMRgbDdBBetyCawKmw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YQfQT1wRk+YJhnXfvhY46w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YR/r5vxq5Kq88OnLa984Eg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YVC1tKdseGyjyPlBWGWXsg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "YnPSos1SroYgrNVto6+i2w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Ytx7KD+lxlaFvaInJa6yPg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Z31z4+OLZbTfgacr2IF35Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Z4PEfJvMbj4dqTXnsp95Aw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ZTVtM/3ZWA9Gl2UwxERsuA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "Zc22Q3iFIPZ+epg2FdgpvA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ZfVnnJy7oaL9gSdtJaq2cQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ZnzG2AHpIfwDtaj3GRZrrw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ZrenMRS4ooimSw7HXEAolA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ZshnlexyascwPM2O9elYkQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "a7ySLyg5kySmKUmKI87EKQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "aEtzpfwMbCldfN1nMySS/Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "aLjZ2cat4dKFZXAvWmHWmA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "aN1Jp7DF2Q77pDWX5eLS7Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "aZVh1+7qlPGF1Mzt+c+CWw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "actKaDb3xYrYFwmm8ud9yA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "aeGWMCgnauz71afUV6KWIg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "auDAxNEJu9eRfZtk79PicA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "b9QJEyrIJkdG8LUQ9Efa5Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "bRgs7+GRebE8GepCiTgVUg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "bh8ssVhS9Y+kH8SHn/gSBw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "bqiN2A8K3nPnvjFFN5DSug==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "c5tjU1eTINvwTj7oRd+r4w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "cKuouhxzNwqPCwYlA0+RvA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "cUipGVe8goaGwm2aT3+3Lw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "cdMtaom6+kBauoZ8sh47yQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "cjiQfFpqlL6r2yX1yzvy2g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "cu//fzDqaCGg4IckBdBb/Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "d5gn36upXf4qnQ9Za5ikaA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "dQV6llj0RdZXO5w4gns9/g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "dmSlsRqKvEhuqJKLlZl0Ng==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "doTtw5XfITX5mpS5AWcHgg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "dxnmYyzrNAzDZvX4HJ02IQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "e5xJm0VsLY9aC2eBzS/hRg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "e62g+eBZRfYBs6yG5WT/QA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "eIk+qkkRXA+xGo/1q5dw9A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "eV7DKdUD9pVAnDtfbcVAEw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "eZNFlnEXjKUCdUf65UDWyQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "eZksHyCeAZGfeU9bFOEVpg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "eb3MoYEkG53wzbp2nH2s+w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "etBHHpaJIkAd+r+FzrnQYQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "f10UoKkRE6Jo0iYAIvrZVg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "fCqlJ47aDkcKyofpeMLozg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "fNp2jCSWjymcyaSrauohUQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "fXX1mg9IUP1aOVFN1izlsA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "fjmjfd8Z1obPxEblTqtW3A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "fp2OvnA1/4UxQXzbyvpRFQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "g4NDzTQtw6KVo/DkE5yxgA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gGBj281ejrz/q2buI9WLLQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gPUUPwC35o/YYWvMKRT3jQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gQ6Px92HfjNtE1SIyFrTNw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gRa0ZxPS51x6lznq+sdgfQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gTvrCykxbI1a3Gcl7E0P9Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gl0OhjS0CgURY1GbKaA3Pg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "gymN3jPkoNdHmf8ZwEcYOA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "hVfx408wtJy5zIeh3kwCqA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "iLiEn2koQeeimUI4OL8oGg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "irT5nUZrGIIxlJv2pGpz2g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "iwRi5YipcVuzlYupn5b+jg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jJUMqmMNIdKKAQELQiVgZg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jQVZQyvj/JpZn3nTjwL2PQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jTg7U1tuUYtTikyJ6pCuGw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jgvkVKXQP/jGryvrRC8CjA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jkScyosTpCbpojjNpLe9lA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "jw79kfCnmk5tgnxiuoD7dQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "k0OfjdCQeCK/OovAA207Pg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "kFXNoZ7znmAHcjIm9e1ZjQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "kSEV+mUKUgo2G6fUzNc4Xw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "knCuFHAKZKhlQzlL5X/4GA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "kodNZRS/kOF0CC46/w5OKQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "kuFVsliIpJiDywtMew9a2Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "l+d8apBfkzYeHMLDsiDPfA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "l1HDVI4ShrVXDfyI4V7kuw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "lSvWkavUDMv8SqOHTq017g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ldxG14V6EBIxhDObD0C6XA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "lnKrfDFZYbpH3rjpRabl0g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "m4X0sD8xf1gD4Z26V7ni2g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "mI3yVFki3HI9pwU56Jym9Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "mKooU+H4DkWGjPk/O6MngQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "mWPGBAGgpAZ6v4RXC0mAXg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "mbDygfWRp5m6a6Cz6HCilQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "munkvrAt8cZg1PdJDw+QAg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "n+AtxKIZ8VkeMUWxT4sCNw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "n+UCrXJ4CQvpUTP5YUfOFA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "n2nnX6bHVed4z2/S7PHApQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "nLtBe1D/LMWpe8qyvoTEQg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "nfBx6td713hSJbdgrWWi7g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "nglbwzrSsCpYknoI/PYm4w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "nmKloy3CkYM0SIICJVg+lg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "nsXhakxka4aH9ndfG/DcZw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "o/zohiVcmyo2pnjEk/WU6w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oGeYh+clinYKyrkBhPoJQQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oJVJhm4h5O0CE9d/wGyW6w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oPBeJDH0EGBiFmMn2Hcv+A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oVNzYxanlnKcVn1aOfjY0g==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oZB7NQXsGwhpn+1reikgKg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "oa2Klvjpg54cEHv2U+uMyg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ora7tN8FbXFI/08Oc6SVYQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ow72bVQfBucqWn9Lpanhfw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pB8Ci86kQABf1+zQMekbbA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pLcYsdHNKtQ11g/IKKVTng==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pT6NFp7xMNXzlWEMxC6XXA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pbeJdaGLL/qpemruqH9rXg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pfF+qwLjBmQwroRuGF5i9Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pqXSQwt50vUG+o+dld9Maw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "pzWPbMb0u08oeR+ebbcTtA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "q+wUXVJsEBDZFFv6fL5rjQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "qRujymkc3h1g3NGrFG5S4w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "qljM0gjNc4JfErPeE+a4Mg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "qq0mSZMgqtY1jW7K5EzEKw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "qvtCTIsiRY8AFQ+wciQxjA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "r/gSRbuNjGeJm0J62Z57YQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "rXBH8p7w0o7P+QqmKYI5cw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "rkyfCtkobwjj2Asc5nC2cA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "rw8kHjHMNde/LbCq691EpQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "s04lFaf8GISBWleGLKMYSg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "s0EZjv2nVvc8F2tzbZWnLg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "s3tOAOa/dusIyn91E3m9dQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "sORKOW7QN24djh240ax6Zg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "sQW39ax4RcAjxzY96dfosA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "saTNJ4JLYjq2syxwkWSJ3w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "sctPw/Cjix61rafbjj3Byg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "sfIougYRV8YRw5jl5oezkg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "spwT18Eh7R672S2SX3nVOw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "t3YU8qENudZWutw34Irysw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "t86og0L00GStZ//a2urDmA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "tNsAQRt9mzvTR/AkUSKmMw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "tR8RKPSydOIs4d7KfihmaA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "tXHETcPCqvJ02XXdcsXBCQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "thfp8azY5po/jEHc88Id8Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uHzr3rw094EOhdtD+MEZng==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uQdwRFO1nRMrmWEaKcAG8A==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uRTnOnkqvYmKFWfBE8eF6Q==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uZRVQPPNGjtjKkLQKoY9Cw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uo2N4y3o0YlwTXR15IlWpQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uotq0WJi2CaJg4+oE5qZFw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "uyyQsF78T1CHrA0TO3N6tA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "vnAoEPoqD8sCFdu/1HyFTg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "vrwg5TC0wZPqmwcGBbnmpA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "wNKNI+lzZqD8WQpcAM3nlg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "wlUScb5LLgsHluTsMm3QGw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xC7THxKHU8rJGN7KeDkIyw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xOYvqnnLEnYNo3LYgrwOMg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xOybpUB1yOVytErftRFyQQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xWxpCGgNMpM0HCjlM4FkDg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xg3BDNqhQCocTz7Sp0BLZg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xkYVRT04r3WxTy3oo/fXzQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xn3p89bkGlD/HFM/zmmZTQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xoTk41jWTPy1kr9JyPZ/HQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "xvFdzctIUU+pgbZNN5yUYQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "y7fV0ey1tXsmdYkL7TASCw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "yDNUD3wG3wsxr/KwdyEmpA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "yKlKN1Y5OU0/iEuHPCOKlw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "yM8jkmzlfWw9NHaIMH+aVA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "yldOrO/JCuMra2G/2eq3Kw==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "ypha8g8Z4b071lSnccTVsQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "yuHBMNVMQn8orbdaXBHz+w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "z3pzHZFRSYY1FGGY1OapeA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:34cc1ee43d5a1562153c14fda91fe7a666ac301641b5abcf83269eb9d2a42dd4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "z9brFT3oatEhdWlqGP4JDA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zBPaU1mMhx5jfMwCeUFl1w==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zNTjhiZ8YqhvVViYkwqiSA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zR2+STDpAW0F4Hx0xZtBkg==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zRv/Q67g6qJWTz0qqj4+BA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zS2GG5MD4wD3w6JwVU9pkA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:5834885656326e9535f99afcd80c931953d70988d521c845d3558567eaf8d99d", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zWUG57dHDYwGuXZm1eK4AA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zgvSJIUhIFalYguys+yFgA==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:1977cc4ef49c19dd72472d65c2be25c5b94dab26139d0b1a999c14b1bf5a6045", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zqLyzwReG4IwDY3R9vbbCQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ], "zwCQDqDNfLrjHOe2yydsXQ==": [ { "package_db": "var/lib/dpkg/status", "introduced_in": "sha256:0c228a0a713e36014dcc63417a815531e2f9395e030fc7b877085b1a11982fe4", "distribution_id": "cbeb444b-c3c2-4cc9-8834-4ef77feda9dd", "repository_ids": null } ] }, "vulnerabilities": { "++HdLGarq5GIso93i+MxpA==": { "id": "++HdLGarq5GIso93i+MxpA==", "updater": "debian/updater", "name": "CVE-2023-52771", "description": "In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix delete_endpoint() vs parent unregistration race The CXL subsystem, at cxl_mem -\u003eprobe() time, establishes a lineage of ports (struct cxl_port objects) between an endpoint and the root of a CXL topology. Each port including the endpoint port is attached to the cxl_port driver. Given that setup, it follows that when either any port in that lineage goes through a cxl_port -\u003eremove() event, or the memdev goes through a cxl_mem -\u003eremove() event. The hierarchy below the removed port, or the entire hierarchy if the memdev is removed needs to come down. The delete_endpoint() callback is careful to check whether it is being called to tear down the hierarchy, or if it is only being called to teardown the memdev because an ancestor port is going through -\u003eremove(). That care needs to take the device_lock() of the endpoint's parent. Which requires 2 bugs to be fixed: 1/ A reference on the parent is needed to prevent use-after-free scenarios like this signature: BUG: spinlock bad magic on CPU#0, kworker/u56:0/11 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc38 05/24/2023 Workqueue: cxl_port detach_memdev [cxl_core] RIP: 0010:spin_bug+0x65/0xa0 Call Trace: do_raw_spin_lock+0x69/0xa0 __mutex_lock+0x695/0xb80 delete_endpoint+0xad/0x150 [cxl_core] devres_release_all+0xb8/0x110 device_unbind_cleanup+0xe/0x70 device_release_driver_internal+0x1d2/0x210 detach_memdev+0x15/0x20 [cxl_core] process_one_work+0x1e3/0x4c0 worker_thread+0x1dd/0x3d0 2/ In the case of RCH topologies, the parent device that needs to be locked is not always @port-\u003edev as returned by cxl_mem_find_port(), use endpoint-\u003edev.parent instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52771", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+/SIYxDzhjXzas1XPY8Vww==": { "id": "+/SIYxDzhjXzas1XPY8Vww==", "updater": "debian/updater", "name": "CVE-2026-53910", "description": "diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815  NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53910", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "diffutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+0bRxY6TjQIuqDlOK+2izQ==": { "id": "+0bRxY6TjQIuqDlOK+2izQ==", "updater": "debian/updater", "name": "CVE-2016-8660", "description": "The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a \"page lock order bug in the XFS seek hole/data implementation.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-8660", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+41xmPLBp+GMWuqOpfmZWw==": { "id": "+41xmPLBp+GMWuqOpfmZWw==", "updater": "debian/updater", "name": "CVE-2025-39961", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table implementation supports dynamic page table levels (up to 6 levels), starting with a 3-level configuration that expands based on IOVA address. The kernel maintains a root pointer and current page table level to enable proper page table walks in alloc_pte()/fetch_pte() operations. The IOMMU IOVA allocator initially starts with 32-bit address and onces its exhuasted it switches to 64-bit address (max address is determined based on IOMMU and device DMA capability). To support larger IOVA, AMD IOMMU driver increases page table level. But in unmap path (iommu_v1_unmap_pages()), fetch_pte() reads pgtable-\u003e[root/mode] without lock. So its possible that in exteme corner case, when increase_address_space() is updating pgtable-\u003e[root/mode], fetch_pte() reads wrong page table level (pgtable-\u003emode). It does compare the value with level encoded in page table and returns NULL. This will result is iommu_unmap ops to fail and upper layer may retry/log WARN_ON. CPU 0 CPU 1 ------ ------ map pages unmap pages alloc_pte() -\u003e increase_address_space() iommu_v1_unmap_pages() -\u003e fetch_pte() pgtable-\u003eroot = pte (new root value) READ pgtable-\u003e[mode/root] \t\t\t\t\t Reads new root, old mode Updates mode (pgtable-\u003emode += 1) Since Page table level updates are infrequent and already synchronized with a spinlock, implement seqcount to enable lock-free read operations on the read path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+42NZLTTWEuGunTe6H5VAQ==": { "id": "+42NZLTTWEuGunTe6H5VAQ==", "updater": "debian/updater", "name": "CVE-2026-13221", "description": "Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-13221", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+5KO877diVdGAzL6goK/SQ==": { "id": "+5KO877diVdGAzL6goK/SQ==", "updater": "debian/updater", "name": "CVE-2024-53219", "description": "In the Linux kernel, the following vulnerability has been resolved: virtiofs: use pages instead of pointer for kernel direct IO When trying to insert a 10MB kernel module kept in a virtio-fs with cache disabled, the following warning was reported: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 404 at mm/page_alloc.c:4551 ...... Modules linked in: CPU: 1 PID: 404 Comm: insmod Not tainted 6.9.0-rc5+ #123 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ...... RIP: 0010:__alloc_pages+0x2bf/0x380 ...... Call Trace: \u003cTASK\u003e ? __warn+0x8e/0x150 ? __alloc_pages+0x2bf/0x380 __kmalloc_large_node+0x86/0x160 __kmalloc+0x33c/0x480 virtio_fs_enqueue_req+0x240/0x6d0 virtio_fs_wake_pending_and_unlock+0x7f/0x190 queue_request_and_unlock+0x55/0x60 fuse_simple_request+0x152/0x2b0 fuse_direct_io+0x5d2/0x8c0 fuse_file_read_iter+0x121/0x160 __kernel_read+0x151/0x2d0 kernel_read+0x45/0x50 kernel_read_file+0x1a9/0x2a0 init_module_from_file+0x6a/0xe0 idempotent_init_module+0x175/0x230 __x64_sys_finit_module+0x5d/0xb0 x64_sys_call+0x1c3/0x9e0 do_syscall_64+0x3d/0xc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 ...... \u003c/TASK\u003e ---[ end trace 0000000000000000 ]--- The warning is triggered as follows: 1) syscall finit_module() handles the module insertion and it invokes kernel_read_file() to read the content of the module first. 2) kernel_read_file() allocates a 10MB buffer by using vmalloc() and passes it to kernel_read(). kernel_read() constructs a kvec iter by using iov_iter_kvec() and passes it to fuse_file_read_iter(). 3) virtio-fs disables the cache, so fuse_file_read_iter() invokes fuse_direct_io(). As for now, the maximal read size for kvec iter is only limited by fc-\u003emax_read. For virtio-fs, max_read is UINT_MAX, so fuse_direct_io() doesn't split the 10MB buffer. It saves the address and the size of the 10MB-sized buffer in out_args[0] of a fuse request and passes the fuse request to virtio_fs_wake_pending_and_unlock(). 4) virtio_fs_wake_pending_and_unlock() uses virtio_fs_enqueue_req() to queue the request. Because virtiofs need DMA-able address, so virtio_fs_enqueue_req() uses kmalloc() to allocate a bounce buffer for all fuse args, copies these args into the bounce buffer and passed the physical address of the bounce buffer to virtiofsd. The total length of these fuse args for the passed fuse request is about 10MB, so copy_args_to_argbuf() invokes kmalloc() with a 10MB size parameter and it triggers the warning in __alloc_pages(): \tif (WARN_ON_ONCE_GFP(order \u003e MAX_PAGE_ORDER, gfp)) \t\treturn NULL; 5) virtio_fs_enqueue_req() will retry the memory allocation in a kworker, but it won't help, because kmalloc() will always return NULL due to the abnormal size and finit_module() will hang forever. A feasible solution is to limit the value of max_read for virtio-fs, so the length passed to kmalloc() will be limited. However it will affect the maximal read size for normal read. And for virtio-fs write initiated from kernel, it has the similar problem but now there is no way to limit fc-\u003emax_write in kernel. So instead of limiting both the values of max_read and max_write in kernel, introducing use_pages_for_kvec_io in fuse_conn and setting it as true in virtiofs. When use_pages_for_kvec_io is enabled, fuse will use pages instead of pointer to pass the KVEC_IO data. After switching to pages for KVEC_IO data, these pages will be used for DMA through virtio-fs. If these pages are backed by vmalloc(), {flush|invalidate}_kernel_vmap_range() are necessary to flush or invalidate the cache before the DMA operation. So add two new fields in fuse_args_pages to record the base address of vmalloc area and the condition indicating whether invalidation is needed. Perform the flush in fuse_get_user_pages() for write operations and the invalidation in fuse_release_user_pages() for read operations. It may seem necessary to introduce another fie ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53219", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+CL+shtoxDkUb+xwSTpgsg==": { "id": "+CL+shtoxDkUb+xwSTpgsg==", "updater": "debian/updater", "name": "CVE-2019-1010025", "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-1010025", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+Dpp4Bh7n/kRZxDGgTot4g==": { "id": "+Dpp4Bh7n/kRZxDGgTot4g==", "updater": "debian/updater", "name": "CVE-2025-21892", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix the recovery flow of the UMR QP This patch addresses an issue in the recovery flow of the UMR QP, ensuring tasks do not get stuck, as highlighted by the call trace [1]. During recovery, before transitioning the QP to the RESET state, the software must wait for all outstanding WRs to complete. Failing to do so can cause the firmware to skip sending some flushed CQEs with errors and simply discard them upon the RESET, as per the IB specification. This race condition can result in lost CQEs and tasks becoming stuck. To resolve this, the patch sends a final WR which serves only as a barrier before moving the QP state to RESET. Once a CQE is received for that final WR, it guarantees that no outstanding WRs remain, making it safe to transition the QP to RESET and subsequently back to RTS, restoring proper functionality. Note: For the barrier WR, we simply reuse the failed and ready WR. Since the QP is in an error state, it will only receive IB_WC_WR_FLUSH_ERR. However, as it serves only as a barrier we don't care about its status. [1] INFO: task rdma_resource_l:1922 blocked for more than 120 seconds. Tainted: G W 6.12.0-rc7+ #1626 \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:rdma_resource_l state:D stack:0 pid:1922 tgid:1922 ppid:1369 flags:0x00004004 Call Trace: \u003cTASK\u003e __schedule+0x420/0xd30 schedule+0x47/0x130 schedule_timeout+0x280/0x300 ? mark_held_locks+0x48/0x80 ? lockdep_hardirqs_on_prepare+0xe5/0x1a0 wait_for_completion+0x75/0x130 mlx5r_umr_post_send_wait+0x3c2/0x5b0 [mlx5_ib] ? __pfx_mlx5r_umr_done+0x10/0x10 [mlx5_ib] mlx5r_umr_revoke_mr+0x93/0xc0 [mlx5_ib] __mlx5_ib_dereg_mr+0x299/0x520 [mlx5_ib] ? _raw_spin_unlock_irq+0x24/0x40 ? wait_for_completion+0xfe/0x130 ? rdma_restrack_put+0x63/0xe0 [ib_core] ib_dereg_mr_user+0x5f/0x120 [ib_core] ? lock_release+0xc6/0x280 destroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs] uverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs] uobj_destroy+0x3f/0x70 [ib_uverbs] ib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs] ? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs] ? __lock_acquire+0x64e/0x2080 ? mark_held_locks+0x48/0x80 ? find_held_lock+0x2d/0xa0 ? lock_acquire+0xc1/0x2f0 ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] ? __fget_files+0xc3/0x1b0 ib_uverbs_ioctl+0xe7/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] __x64_sys_ioctl+0x1b0/0xa70 do_syscall_64+0x6b/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f99c918b17b RSP: 002b:00007ffc766d0468 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ffc766d0578 RCX: 00007f99c918b17b RDX: 00007ffc766d0560 RSI: 00000000c0181b01 RDI: 0000000000000003 RBP: 00007ffc766d0540 R08: 00007f99c8f99010 R09: 000000000000bd7e R10: 00007f99c94c1c70 R11: 0000000000000246 R12: 00007ffc766d0530 R13: 000000000000001c R14: 0000000040246a80 R15: 0000000000000000 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21892", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+FjM0LpqQllzdfIgyzd3kw==": { "id": "+FjM0LpqQllzdfIgyzd3kw==", "updater": "debian/updater", "name": "CVE-2025-38582", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix double destruction of rsv_qp rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() call into hns_roce_v2_init(). list_del corruption, ffff589732eb9b50-\u003enext is LIST_POISON1 (dead000000000100) WARNING: CPU: 8 PID: 1047115 at lib/list_debug.c:53 __list_del_entry_valid+0x148/0x240 ... Call trace: __list_del_entry_valid+0x148/0x240 hns_roce_qp_remove+0x4c/0x3f0 [hns_roce_hw_v2] hns_roce_v2_destroy_qp_common+0x1dc/0x5f4 [hns_roce_hw_v2] hns_roce_v2_destroy_qp+0x22c/0x46c [hns_roce_hw_v2] free_mr_exit+0x6c/0x120 [hns_roce_hw_v2] hns_roce_v2_exit+0x170/0x200 [hns_roce_hw_v2] hns_roce_exit+0x118/0x350 [hns_roce_hw_v2] __hns_roce_hw_v2_init_instance+0x1c8/0x304 [hns_roce_hw_v2] hns_roce_hw_v2_reset_notify_init+0x170/0x21c [hns_roce_hw_v2] hns_roce_hw_v2_reset_notify+0x6c/0x190 [hns_roce_hw_v2] hclge_notify_roce_client+0x6c/0x160 [hclge] hclge_reset_rebuild+0x150/0x5c0 [hclge] hclge_reset+0x10c/0x140 [hclge] hclge_reset_subtask+0x80/0x104 [hclge] hclge_reset_service_task+0x168/0x3ac [hclge] hclge_service_task+0x50/0x100 [hclge] process_one_work+0x250/0x9a0 worker_thread+0x324/0x990 kthread+0x190/0x210 ret_from_fork+0x10/0x18", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38582", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+FpneGJ45rNW63+Qsdw/ZQ==": { "id": "+FpneGJ45rNW63+Qsdw/ZQ==", "updater": "debian/updater", "name": "CVE-2026-68399", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in sock clone early bailouts Similar to recent commit 9b51a6155d14 (\"bpf,fork: wipe -\u003ebpf_storage before bailouts that access it\"), sk_clone() performs an initial shallow copy of the socket field -\u003esk_bpf_storage via sock_copy() for the cloned socket newsk. If sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior to calling bpf_sk_storage_clone(), newsk-\u003esk_bpf_storage still points to the parent socket's BPF local storage. When newsk is subsequently freed via sk_free(), the deallocation path (__sk_destruct() -\u003e bpf_sk_storage_free()) destroys the parent socket's BPF local storage, leading to a use-after-free (UAF) on the parent socket. Fix this by resetting newsk-\u003esk_bpf_storage to NULL immediately after sock_copy() in sk_clone(), and remove the now redundant initialization from bpf_sk_storage_clone().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68399", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+GZxNvAM2u9WlBgow5l1kQ==": { "id": "+GZxNvAM2u9WlBgow5l1kQ==", "updater": "debian/updater", "name": "CVE-2026-31771", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into validated event handlers hci_store_wake_reason() is called from hci_event_packet() immediately after stripping the HCI event header but before hci_event_func() enforces the per-event minimum payload length from hci_ev_table. This means a short HCI event frame can reach bacpy() before any bounds check runs. Rather than duplicating skb parsing and per-event length checks inside hci_store_wake_reason(), move wake-address storage into the individual event handlers after their existing event-length validation has succeeded. Convert hci_store_wake_reason() into a small helper that only stores an already-validated bdaddr while the caller holds hci_dev_lock(). Use the same helper after hci_event_func() with a NULL address to preserve the existing unexpected-wake fallback semantics when no validated event handler records a wake address. Annotate the helper with __must_hold(\u0026hdev-\u003elock) and add lockdep_assert_held(\u0026hdev-\u003elock) so future call paths keep the lock contract explicit. Call the helper from hci_conn_request_evt(), hci_conn_complete_evt(), hci_sync_conn_complete_evt(), le_conn_complete_evt(), hci_le_adv_report_evt(), hci_le_ext_adv_report_evt(), hci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and hci_le_past_received_evt().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31771", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+H/bIsJx0MWpkf9xibMEhA==": { "id": "+H/bIsJx0MWpkf9xibMEhA==", "updater": "debian/updater", "name": "CVE-2024-56611", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM We currently assume that there is at least one VMA in a MM, which isn't true. So we might end up having find_vma() return NULL, to then de-reference NULL. So properly handle find_vma() returning NULL. This fixes the report: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024 RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline] RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194 Code: ... RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000 RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044 RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1 R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003 R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8 FS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: \u003cTASK\u003e kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709 __do_sys_migrate_pages mm/mempolicy.c:1727 [inline] __se_sys_migrate_pages mm/mempolicy.c:1723 [inline] __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f [akpm@linux-foundation.org: add unlikely()]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56611", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+JVQA1F7TvkyaqDQnXuBMg==": { "id": "+JVQA1F7TvkyaqDQnXuBMg==", "updater": "debian/updater", "name": "CVE-2026-32327", "description": "A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32327", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "apr-util", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+LRjWXj/kMRxvO5AwDDNng==": { "id": "+LRjWXj/kMRxvO5AwDDNng==", "updater": "debian/updater", "name": "CVE-2022-45884", "description": "An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-45884", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+MC1LzBYIrxJU1ofAGLHLw==": { "id": "+MC1LzBYIrxJU1ofAGLHLw==", "updater": "debian/updater", "name": "CVE-2024-46727", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update [Why] Coverity reports NULL_RETURN warning. [How] Add otg_master NULL check.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46727", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+NN/IoxjMxchzwn/MMxhPQ==": { "id": "+NN/IoxjMxchzwn/MMxhPQ==", "updater": "debian/updater", "name": "CVE-2021-32256", "description": "An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-32256", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+PJ4bIlZWFeM+AWYRfXeKg==": { "id": "+PJ4bIlZWFeM+AWYRfXeKg==", "updater": "debian/updater", "name": "CVE-2026-68085", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is pending and blocks queueing it again. Currently this bit is not cleared when canceling the work in hci_uart_close(), which blocks future writes when device is reopened later if write_work was pending. Fix by clearing HCI_UART_SENDING when canceling the work. Also make clearing of tx_skb safe by using disable_work_sync + enable_work instead of just cancel_work_sync. hci_uart_flush() purges the proto tx queue so we can cancel the pending write_work there, instead of doing it just in hci_uart_close(). Re-enable and possibly requeue the work after queue flush.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68085", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+Plw2tabjfOcVdKKZpp6kQ==": { "id": "+Plw2tabjfOcVdKKZpp6kQ==", "updater": "debian/updater", "name": "CVE-2025-38449", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/gem: Acquire references on GEM handles for framebuffers A GEM handle can be released while the GEM buffer object is attached to a DRM framebuffer. This leads to the release of the dma-buf backing the buffer object, if any. [1] Trying to use the framebuffer in further mode-setting operations leads to a segmentation fault. Most easily happens with driver that use shadow planes for vmap-ing the dma-buf during a page flip. An example is shown below. [ 156.791968] ------------[ cut here ]------------ [ 156.796830] WARNING: CPU: 2 PID: 2255 at drivers/dma-buf/dma-buf.c:1527 dma_buf_vmap+0x224/0x430 [...] [ 156.942028] RIP: 0010:dma_buf_vmap+0x224/0x430 [ 157.043420] Call Trace: [ 157.045898] \u003cTASK\u003e [ 157.048030] ? show_trace_log_lvl+0x1af/0x2c0 [ 157.052436] ? show_trace_log_lvl+0x1af/0x2c0 [ 157.056836] ? show_trace_log_lvl+0x1af/0x2c0 [ 157.061253] ? drm_gem_shmem_vmap+0x74/0x710 [ 157.065567] ? dma_buf_vmap+0x224/0x430 [ 157.069446] ? __warn.cold+0x58/0xe4 [ 157.073061] ? dma_buf_vmap+0x224/0x430 [ 157.077111] ? report_bug+0x1dd/0x390 [ 157.080842] ? handle_bug+0x5e/0xa0 [ 157.084389] ? exc_invalid_op+0x14/0x50 [ 157.088291] ? asm_exc_invalid_op+0x16/0x20 [ 157.092548] ? dma_buf_vmap+0x224/0x430 [ 157.096663] ? dma_resv_get_singleton+0x6d/0x230 [ 157.101341] ? __pfx_dma_buf_vmap+0x10/0x10 [ 157.105588] ? __pfx_dma_resv_get_singleton+0x10/0x10 [ 157.110697] drm_gem_shmem_vmap+0x74/0x710 [ 157.114866] drm_gem_vmap+0xa9/0x1b0 [ 157.118763] drm_gem_vmap_unlocked+0x46/0xa0 [ 157.123086] drm_gem_fb_vmap+0xab/0x300 [ 157.126979] drm_atomic_helper_prepare_planes.part.0+0x487/0xb10 [ 157.133032] ? lockdep_init_map_type+0x19d/0x880 [ 157.137701] drm_atomic_helper_commit+0x13d/0x2e0 [ 157.142671] ? drm_atomic_nonblocking_commit+0xa0/0x180 [ 157.147988] drm_mode_atomic_ioctl+0x766/0xe40 [...] [ 157.346424] ---[ end trace 0000000000000000 ]--- Acquiring GEM handles for the framebuffer's GEM buffer objects prevents this from happening. The framebuffer's cleanup later puts the handle references. Commit 1a148af06000 (\"drm/gem-shmem: Use dma_buf from GEM object instance\") triggers the segmentation fault easily by using the dma-buf field more widely. The underlying issue with reference counting has been present before. v2: - acquire the handle instead of the BO (Christian) - fix comment style (Christian) - drop the Fixes tag (Christian) - rename err_ gotos - add missing Link tag", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38449", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+REan4BC4v//j+uT3WPbNQ==": { "id": "+REan4BC4v//j+uT3WPbNQ==", "updater": "debian/updater", "name": "CVE-2024-38564", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE bpf_prog_attach uses attach_type_to_prog_type to enforce proper attach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses bpf_prog_get and relies on bpf_prog_attach_check_attach_type to properly verify prog_type \u003c\u003e attach_type association. Add missing attach_type enforcement for the link_create case. Otherwise, it's currently possible to attach cgroup_skb prog types to other cgroup hooks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38564", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+SXw0I//F1BclxmXEGpShg==": { "id": "+SXw0I//F1BclxmXEGpShg==", "updater": "debian/updater", "name": "CVE-2026-64543", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() frees b-\u003edisc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b-\u003edisc in RX softirq under rcu_read_lock() (tipc_udp_recv -\u003e tipc_rcv -\u003e tipc_disc_rcv). L2 bearers are safe thanks to the synchronize_net() in tipc_disable_l2_media(), but the UDP bearer defers that call to the cleanup_bearer() workqueue, so the discoverer is freed with no grace period: BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149) Read of size 8 at addr ffff88802348b728 by task poc_tipc/184 \u003cIRQ\u003e tipc_disc_rcv (net/tipc/discover.c:149) tipc_rcv (net/tipc/node.c:2126) tipc_udp_recv (net/tipc/udp_media.c:391) udp_rcv (net/ipv4/udp.c:2643) ip_local_deliver_finish (net/ipv4/ip_input.c:241) \u003c/IRQ\u003e Freed by task 181: kfree (mm/slub.c:6565) bearer_disable (net/tipc/bearer.c:418) tipc_nl_bearer_disable (net/tipc/bearer.c:1001) The bearer is freed with kfree_rcu(); free the discoverer the same way. Add an rcu_head to struct tipc_discoverer and free it and its skb from an RCU callback. Because the RCU callback (tipc_disc_free_rcu) lives in module text, a call_rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu_barrier() to tipc_exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away. Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64543", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+SomP1jA3ScGJcfWiUw9WA==": { "id": "+SomP1jA3ScGJcfWiUw9WA==", "updater": "debian/updater", "name": "CVE-2024-41935", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to shrink read extent node in batches We use rwlock to protect core structure data of extent tree during its shrink, however, if there is a huge number of extent nodes in extent tree, during shrink of extent tree, it may hold rwlock for a very long time, which may trigger kernel hang issue. This patch fixes to shrink read extent node in batches, so that, critical region of the rwlock can be shrunk to avoid its extreme long time hold.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41935", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+WCO1HEUKIIM9snGdGBm2A==": { "id": "+WCO1HEUKIIM9snGdGBm2A==", "updater": "debian/updater", "name": "CVE-2026-23265", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in {read,write}_end_io -----------[ cut here ]------------ kernel BUG at fs/f2fs/data.c:358! Call Trace: \u003cIRQ\u003e blk_update_request+0x5eb/0xe70 block/blk-mq.c:987 blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1149 blk_complete_reqs block/blk-mq.c:1224 [inline] blk_done_softirq+0x107/0x160 block/blk-mq.c:1229 handle_softirqs+0x283/0x870 kernel/softirq.c:579 __do_softirq kernel/softirq.c:613 [inline] invoke_softirq kernel/softirq.c:453 [inline] __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680 irq_exit_rcu+0x9/0x30 kernel/softirq.c:696 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050 \u003c/IRQ\u003e In f2fs_write_end_io(), it detects there is inconsistency in between node page index (nid) and footer.nid of node page. If footer of node page is corrupted in fuzzed image, then we load corrupted node page w/ async method, e.g. f2fs_ra_node_pages() or f2fs_ra_node_page(), in where we won't do sanity check on node footer, once node page becomes dirty, we will encounter this bug after node page writeback.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23265", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+ZsvZzBtKkBP0sJejGpg/Q==": { "id": "+ZsvZzBtKkBP0sJejGpg/Q==", "updater": "debian/updater", "name": "CVE-2025-39901", "description": "In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c290814c (\"i40e: debugfs interface\"). Both of these debugfs files provide a read handler which is mostly useless, and which is implemented with questionable logic. They both use a static 256 byte buffer which is initialized to the empty string. In the case of the 'command' file this buffer is literally never used and simply wastes space. In the case of the 'netdev_ops' file, the last command written is saved here. On read, the files contents are presented as the name of the device followed by a colon and then the contents of their respective static buffer. For 'command' this will always be \"\u003cdevice\u003e: \". For 'netdev_ops', this will be \"\u003cdevice\u003e: \u003clast command written\u003e\". But note the buffer is shared between all devices operated by this module. At best, it is mostly meaningless information, and at worse it could be accessed simultaneously as there doesn't appear to be any locking mechanism. We have also recently received multiple reports for both read functions about their use of snprintf and potential overflow that could result in reading arbitrary kernel memory. For the 'command' file, this is definitely impossible, since the static buffer is always zero and never written to. For the 'netdev_ops' file, it does appear to be possible, if the user carefully crafts the command input, it will be copied into the buffer, which could be large enough to cause snprintf to truncate, which then causes the copy_to_user to read beyond the length of the buffer allocated by kzalloc. A minimal fix would be to replace snprintf() with scnprintf() which would cap the return to the number of bytes written, preventing an overflow. A more involved fix would be to drop the mostly useless static buffers, saving 512 bytes and modifying the read functions to stop needing those as input. Instead, lets just completely drop the read access to these files. These are debug interfaces exposed as part of debugfs, and I don't believe that dropping read access will break any script, as the provided output is pretty useless. You can find the netdev name through other more standard interfaces, and the 'netdev_ops' interface can easily result in garbage if you issue simultaneous writes to multiple devices at once. In order to properly remove the i40e_dbg_netdev_ops_buf, we need to refactor its write function to avoid using the static buffer. Instead, use the same logic as the i40e_dbg_command_write, with an allocated buffer. Update the code to use this instead of the static buffer, and ensure we free the buffer on exit. This fixes simultaneous writes to 'netdev_ops' on multiple devices, and allows us to remove the now unused static buffer along with removing the read access.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39901", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+aYX/oRvHl/0BC/uiR5NVA==": { "id": "+aYX/oRvHl/0BC/uiR5NVA==", "updater": "debian/updater", "name": "CVE-2024-56433", "description": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56433", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "shadow", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+f6yn1AEEkdjdgoOCMF2Tg==": { "id": "+f6yn1AEEkdjdgoOCMF2Tg==", "updater": "debian/updater", "name": "CVE-2026-31531", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() When querying a nexthop object via RTM_GETNEXTHOP, the kernel currently allocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for single nexthops and small Equal-Cost Multi-Path groups, this fixed allocation fails for large nexthop groups like 512 nexthops. This results in the following warning splat: WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608 [...] RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395) [...] Call Trace: \u003cTASK\u003e rtnetlink_rcv_msg (net/core/rtnetlink.c:6989) netlink_rcv_skb (net/netlink/af_netlink.c:2550) netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) ____sys_sendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585) ___sys_sendmsg (net/socket.c:2641) __sys_sendmsg (net/socket.c:2671) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) \u003c/TASK\u003e Fix this by allocating the size dynamically using nh_nlmsg_size() and using nlmsg_new(), this is consistent with nexthop_notify() behavior. In addition, adjust nh_nlmsg_size_grp() so it calculates the size needed based on flags passed. While at it, also add the size of NHA_FDB for nexthop group size calculation as it was missing too. This cannot be reproduced via iproute2 as the group size is currently limited and the command fails as follows: addattr_l ERROR: message exceeded bound of 1048", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31531", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+iI+0a0H7BIpaX/3sqTeqg==": { "id": "+iI+0a0H7BIpaX/3sqTeqg==", "updater": "debian/updater", "name": "CVE-2026-64562", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR. The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely freed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64562", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+iuUv0opvq3bo9n8yHMW+g==": { "id": "+iuUv0opvq3bo9n8yHMW+g==", "updater": "debian/updater", "name": "CVE-2023-53851", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: Drop aux devices together with DP controller Using devres to depopulate the aux bus made sure that upon a probe deferral the EDP panel device would be destroyed and recreated upon next attempt. But the struct device which the devres is tied to is the DPUs (drm_dev-\u003edev), which may be happen after the DP controller is torn down. Indications of this can be seen in the commonly seen EDID-hexdump full of zeros in the log, or the occasional/rare KASAN fault where the panel's attempt to read the EDID information causes a use after free on DP resources. It's tempting to move the devres to the DP controller's struct device, but the resources used by the device(s) on the aux bus are explicitly torn down in the error path. The KASAN-reported use-after-free also remains, as the DP aux \"module\" explicitly frees its devres-allocated memory in this code path. As such, explicitly depopulate the aux bus in the error path, and in the component unbind path, to avoid these issues. Patchwork: https://patchwork.freedesktop.org/patch/542163/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53851", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+jA2qUkOg/IukdQQNgzQEg==": { "id": "+jA2qUkOg/IukdQQNgzQEg==", "updater": "debian/updater", "name": "CVE-2020-15778", "description": "scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-15778", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+pBS1yXkx77P7vOf8YUZWQ==": { "id": "+pBS1yXkx77P7vOf8YUZWQ==", "updater": "debian/updater", "name": "CVE-2023-52653", "description": "In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix a memleak in gss_import_v2_context The ctx-\u003emech_used.data allocated by kmemdup is not freed in neither gss_import_v2_context nor it only caller gss_krb5_import_sec_context, which frees ctx on error. Thus, this patch reform the last call of gss_import_v2_context to the gss_krb5_import_ctx_v2, preventing the memleak while keepping the return formation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52653", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+uZXDdia4w8YnGrVMyzOtg==": { "id": "+uZXDdia4w8YnGrVMyzOtg==", "updater": "debian/updater", "name": "CVE-2026-68312", "description": "In the Linux kernel, the following vulnerability has been resolved: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths In cifs_close_deferred_file(), cifs_close_all_deferred_files(), and cifs_close_deferred_file_under_dentry(), when a pending deferred close is cancelled via cancel_delayed_work(), the subsequent kmalloc_obj() to add the file to the local processing list may fail under memory pressure. The loop breaks immediately, but the cancelled work is no longer pending (it would have called _cifsFileInfo_put()), and the cfile is never added to file_head for processing. The cifsFileInfo reference and the open server handle both leak. Fix by saving the cfile that failed allocation in a local variable, breaking as before, and calling _cifsFileInfo_put() on it after releasing the lock. Any files later in the iteration are unaffected since their deferred work is still pending and will fire normally.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68312", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "+w9hzA4OIRZ7YkoQQCaOOQ==": { "id": "+w9hzA4OIRZ7YkoQQCaOOQ==", "updater": "debian/updater", "name": "CVE-2025-21955", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not finished yet and to not release the connection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21955", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/1k9RtYbBTAP1KTpcUZZbg==": { "id": "/1k9RtYbBTAP1KTpcUZZbg==", "updater": "debian/updater", "name": "CVE-2026-68215", "description": "In the Linux kernel, the following vulnerability has been resolved: media: radio-si476x: Unregister v4l2_device on probe failure si476x_radio_probe() registers radio-\u003ev4l2dev before allocating the V4L2 controls and before registering the video device. If any of those later steps fails, probe returns through the exit label after freeing only the control handler. A failed probe does not call si476x_radio_remove(), so the v4l2_device_unregister() there is not reached. This leaves the parent device reference taken by v4l2_device_register() behind on the error path. Unregister the V4L2 device in the probe error path after freeing the controls.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68215", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/47FUb26z0KiPP0KvwhAsA==": { "id": "/47FUb26z0KiPP0KvwhAsA==", "updater": "debian/updater", "name": "CVE-2026-64563", "description": "In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter-\u003ep on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter-\u003ewalker.tbl is valid, it re-validates iter-\u003ep against the table and sets iter-\u003ep = NULL if the object is gone. When iter-\u003ewalker.tbl is NULL (table was freed during resize), it resets slot and skip but forgets to clear iter-\u003ep. rhashtable_walk_next() then dereferences the stale iter-\u003ep, reading freed memory. This is a use-after-free. Any caller that does multi-fragment rhashtable walks across walk_stop/walk_start boundaries is affected. Concrete cases include netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC (tipc_nl_sk_walk in net/tipc/socket.c). Crash stack (netlink_diag): BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0 Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080) Call Trace: rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016) __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122) netlink_diag_dump+0xc2/0x240 netlink_dump+0x5bc/0x1270 netlink_recvmsg+0x7a3/0x980 sock_recvmsg+0x1bc/0x200 __sys_recvfrom+0x1d4/0x2c0", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64563", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/4AjAEsHRRa43cZAeshWvA==": { "id": "/4AjAEsHRRa43cZAeshWvA==", "updater": "debian/updater", "name": "CVE-2025-21927", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a packet with an invalid header length (e.g. 255), causing nvme_tcp_verify_hdgst() to access memory outside the allocated area and cause memory corruptions by overwriting it with the calculated digest. Fix this by rejecting packets with an unexpected header length.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21927", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/6uQNJy+iHLVC38D5Bhy9Q==": { "id": "/6uQNJy+iHLVC38D5Bhy9Q==", "updater": "debian/updater", "name": "CVE-2024-57888", "description": "In the Linux kernel, the following vulnerability has been resolved: workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker After commit 746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\") amdgpu started seeing the following warning: [ ] workqueue: WQ_MEM_RECLAIM sdma0:drm_sched_run_job_work [gpu_sched] is flushing !WQ_MEM_RECLAIM events:amdgpu_device_delay_enable_gfx_off [amdgpu] ... [ ] Workqueue: sdma0 drm_sched_run_job_work [gpu_sched] ... [ ] Call Trace: [ ] \u003cTASK\u003e ... [ ] ? check_flush_dependency+0xf5/0x110 ... [ ] cancel_delayed_work_sync+0x6e/0x80 [ ] amdgpu_gfx_off_ctrl+0xab/0x140 [amdgpu] [ ] amdgpu_ring_alloc+0x40/0x50 [amdgpu] [ ] amdgpu_ib_schedule+0xf4/0x810 [amdgpu] [ ] ? drm_sched_run_job_work+0x22c/0x430 [gpu_sched] [ ] amdgpu_job_run+0xaa/0x1f0 [amdgpu] [ ] drm_sched_run_job_work+0x257/0x430 [gpu_sched] [ ] process_one_work+0x217/0x720 ... [ ] \u003c/TASK\u003e The intent of the verifcation done in check_flush_depedency is to ensure forward progress during memory reclaim, by flagging cases when either a memory reclaim process, or a memory reclaim work item is flushed from a context not marked as memory reclaim safe. This is correct when flushing, but when called from the cancel(_delayed)_work_sync() paths it is a false positive because work is either already running, or will not be running at all. Therefore cancelling it is safe and we can relax the warning criteria by letting the helper know of the calling context. References: 746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\")", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57888", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/72eyAw69+s+htVKV47W+A==": { "id": "/72eyAw69+s+htVKV47W+A==", "updater": "debian/updater", "name": "CVE-2023-53394", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix crash on regular rq reactivation When the regular rq is reactivated after the XSK socket is closed it could be reading stale cqes which eventually corrupts the rq. This leads to no more traffic being received on the regular rq and a crash on the next close or deactivation of the rq. Kal Cuttler Conely reported this issue as a crash on the release path when the xdpsock sample program is stopped (killed) and restarted in sequence while traffic is running. This patch flushes all cqes when during the rq flush. The cqe flushing is done in the reset state of the rq. mlx5e_rq_to_ready code is moved into the flush function to allow for this.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53394", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/7VBddfR6qwo6S8sjY5kGA==": { "id": "/7VBddfR6qwo6S8sjY5kGA==", "updater": "debian/updater", "name": "CVE-2022-1247", "description": "An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh-\u003euse to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and “use” are zero.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-1247", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/93Mw1QUwTLm8a7eq9zPEw==": { "id": "/93Mw1QUwTLm8a7eq9zPEw==", "updater": "debian/updater", "name": "CVE-2010-4651", "description": "Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2010-4651", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/HEhjSedxSIiGuLqKxMtww==": { "id": "/HEhjSedxSIiGuLqKxMtww==", "updater": "debian/updater", "name": "CVE-2022-3219", "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-3219", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/LPnqt/sacv88+z/V9sCnw==": { "id": "/LPnqt/sacv88+z/V9sCnw==", "updater": "debian/updater", "name": "CVE-2026-46054", "description": "In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the \"user\" file) and the mounter's credentials are sufficient to access the lower level file (the \"backing\" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46054", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/NbVFv0WYTS4IOv3EHzDgA==": { "id": "/NbVFv0WYTS4IOv3EHzDgA==", "updater": "debian/updater", "name": "CVE-2020-15719", "description": "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-15719", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/R+oZfF3C0jFiu9Vh76ooA==": { "id": "/R+oZfF3C0jFiu9Vh76ooA==", "updater": "debian/updater", "name": "CVE-2026-23346", "description": "In the Linux kernel, the following vulnerability has been resolved: arm64: io: Extract user memory type in ioremap_prot() The only caller of ioremap_prot() outside of the generic ioremap() implementation is generic_access_phys(), which passes a 'pgprot_t' value determined from the user mapping of the target 'pfn' being accessed by the kernel. On arm64, the 'pgprot_t' contains all of the non-address bits from the pte, including the permission controls, and so we end up returning a new user mapping from ioremap_prot() which faults when accessed from the kernel on systems with PAN: | Unable to handle kernel read from unreadable memory at virtual address ffff80008ea89000 | ... | Call trace: | __memcpy_fromio+0x80/0xf8 | generic_access_phys+0x20c/0x2b8 | __access_remote_vm+0x46c/0x5b8 | access_remote_vm+0x18/0x30 | environ_read+0x238/0x3e8 | vfs_read+0xe4/0x2b0 | ksys_read+0xcc/0x178 | __arm64_sys_read+0x4c/0x68 Extract only the memory type from the user 'pgprot_t' in ioremap_prot() and assert that we're being passed a user mapping, to protect us against any changes in future that may require additional handling. To avoid falsely flagging users of ioremap(), provide our own ioremap() macro which simply wraps __ioremap_prot().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23346", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/REASQvEPfhjbb5nEMfVnA==": { "id": "/REASQvEPfhjbb5nEMfVnA==", "updater": "debian/updater", "name": "CVE-2026-68248", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915: Return NULL on error in active_instance Avoid returning \u0026node-\u003ebase when node is NULL due to OOM during GFP_ATOMIC allocation. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68248", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/SJ+Rrv1FPQP0mdKaNJOCg==": { "id": "/SJ+Rrv1FPQP0mdKaNJOCg==", "updater": "debian/updater", "name": "CVE-2024-35799", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encoder invokes a function that no longer exists. [How] Check if the function declaration is NULL in disable stream encoder.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35799", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/SiTRLCQLViYubpilZ0k0Q==": { "id": "/SiTRLCQLViYubpilZ0k0Q==", "updater": "debian/updater", "name": "CVE-2026-43119", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev-\u003ereq_status __hci_cmd_sync_sk() sets hdev-\u003ereq_status under hdev-\u003ereq_lock: hdev-\u003ereq_status = HCI_REQ_PEND; However, several other functions read or write hdev-\u003ereq_status without holding any lock: - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue) - hci_cmd_sync_complete() reads/writes from HCI event completion - hci_cmd_sync_cancel() / hci_cmd_sync_cancel_sync() read/write - hci_abort_conn() reads in connection abort path Since __hci_cmd_sync_sk() runs on hdev-\u003ereq_workqueue while hci_send_cmd_sync() runs on hdev-\u003eworkqueue, these are different workqueues that can execute concurrently on different CPUs. The plain C accesses constitute a data race. Add READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses to hdev-\u003ereq_status to prevent potential compiler optimizations that could affect correctness (e.g., load fusing in the wait_event condition or store reordering).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43119", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/VWikrEHhKeVKspNvUnevA==": { "id": "/VWikrEHhKeVKspNvUnevA==", "updater": "debian/updater", "name": "CVE-2026-68210", "description": "In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: unregister notifier on probe failure dcmi_graph_init() registers the async notifier before dcmi_probe() toggles the reset line. If reset_control_assert() or reset_control_deassert() fails afterwards, probe returns through err_cleanup and the driver core will not call dcmi_remove(). Unregister the notifier before cleaning it up on that error path, matching the successful remove path and the V4L2 async notifier lifetime rules. [hverkuil: added Fixes tag]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68210", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/gOLZIgdoycagHU6KFi2aQ==": { "id": "/gOLZIgdoycagHU6KFi2aQ==", "updater": "debian/updater", "name": "CVE-2025-21768", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels Some lwtunnels have a dst cache for post-transformation dst. If the packet destination did not change we may end up recording a reference to the lwtunnel in its own cache, and the lwtunnel state will never be freed. Discovered by the ioam6.sh test, kmemleak was recently fixed to catch per-cpu memory leaks. I'm not sure if rpl and seg6 can actually hit this, but in principle I don't see why not.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21768", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/iNADhKp6vmMCCjkrsQJCg==": { "id": "/iNADhKp6vmMCCjkrsQJCg==", "updater": "debian/updater", "name": "CVE-2026-68214", "description": "In the Linux kernel, the following vulnerability has been resolved: media: rtl2832: fix use-after-free in rtl2832_remove() cancel_delayed_work_sync() is called before i2c_mux_del_adapters() in rtl2832_remove(). While the cancel waits for any running instance of i2c_gate_work to finish, it does not prevent the timer from being rescheduled by a concurrent thread. During probe, the r820t_attach() call attempts I2C transfers through the mux adapter. These transfers go through i2c_mux_master_xfer(), which calls rtl2832_deselect() after the transfer completes, rescheduling i2c_gate_work via schedule_delayed_work(). If this transfer is still in flight when rtl2832_remove() runs, rtl2832_deselect() can reschedule i2c_gate_work after it has been cancelled, causing a use-after-free when kfree(dev) is called. Fix this by calling i2c_mux_del_adapters() before cancel_delayed_work_sync(). Once the mux adapter is unregistered, no new I2C transfers can go through it, so rtl2832_deselect() can no longer reschedule i2c_gate_work. The subsequent cancel_delayed_work_sync() is then guaranteed to be final.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68214", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/iyMD/CLlrovNCQN6DqV6Q==": { "id": "/iyMD/CLlrovNCQN6DqV6Q==", "updater": "debian/updater", "name": "CVE-2026-43115", "description": "In the Linux kernel, the following vulnerability has been resolved: srcu: Use irq_work to start GP in tiny SRCU Tiny SRCU's srcu_gp_start_if_needed() directly calls schedule_work(), which acquires the workqueue pool-\u003elock. This causes a lockdep splat when call_srcu() is called with a scheduler lock held, due to: call_srcu() [holding pi_lock] srcu_gp_start_if_needed() schedule_work() -\u003e pool-\u003elock workqueue_init() / create_worker() [holding pool-\u003elock] wake_up_process() -\u003e try_to_wake_up() -\u003e pi_lock Also add irq_work_sync() to cleanup_srcu_struct() to prevent a use-after-free if a queued irq_work fires after cleanup begins. Tested with rcutorture SRCU-T and no lockdep warnings. [ Thanks to Boqun for similar fix in patch \"rcu: Use an intermediate irq_work to start process_srcu()\" ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43115", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/k9s3Dvh147QROVEXNykPA==": { "id": "/k9s3Dvh147QROVEXNykPA==", "updater": "debian/updater", "name": "CVE-2026-68427", "description": "In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings __host1x_bo_unpin() drops the last reference to the mapping and frees it, so we can't dereference mapping afterwards. The cache itself outlives the mapping, so use the cache local variable instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68427", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/kW6pEn0Zy2tehKurgKtPQ==": { "id": "/kW6pEn0Zy2tehKurgKtPQ==", "updater": "debian/updater", "name": "CVE-2023-0597", "description": "A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-0597", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/mMYJM9zN4O/C1HrJJj88A==": { "id": "/mMYJM9zN4O/C1HrJJj88A==", "updater": "debian/updater", "name": "CVE-2026-14666", "description": "Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14666", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/mOKp220qBx69vW8tihtwQ==": { "id": "/mOKp220qBx69vW8tihtwQ==", "updater": "debian/updater", "name": "CVE-2026-45934", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation I have been observing a number of systems aborting at insert_dev_extents() in btrfs_create_pending_block_groups(). The following is a sample stack trace of such an abort coming from forced chunk allocation (typically behind CONFIG_BTRFS_EXPERIMENTAL) but this can theoretically happen to any DUP chunk allocation. [81.801] ------------[ cut here ]------------ [81.801] BTRFS: Transaction aborted (error -17) [81.801] WARNING: fs/btrfs/block-group.c:2876 at btrfs_create_pending_block_groups+0x721/0x770 [btrfs], CPU#1: bash/319 [81.802] Modules linked in: virtio_net btrfs xor zstd_compress raid6_pq null_blk [81.803] CPU: 1 UID: 0 PID: 319 Comm: bash Kdump: loaded Not tainted 6.19.0-rc6+ #319 NONE [81.803] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014 [81.804] RIP: 0010:btrfs_create_pending_block_groups+0x723/0x770 [btrfs] [81.806] RSP: 0018:ffffa36241a6bce8 EFLAGS: 00010282 [81.806] RAX: 000000000000000d RBX: ffff8e699921e400 RCX: 0000000000000000 [81.807] RDX: 0000000002040001 RSI: 00000000ffffffef RDI: ffffffffc0608bf0 [81.807] RBP: 00000000ffffffef R08: ffff8e69830f6000 R09: 0000000000000007 [81.808] R10: ffff8e699921e5e8 R11: 0000000000000000 R12: ffff8e6999228000 [81.808] R13: ffff8e6984d82000 R14: ffff8e69966a69c0 R15: ffff8e69aa47b000 [81.809] FS: 00007fec6bdd9740(0000) GS:ffff8e6b1b379000(0000) knlGS:0000000000000000 [81.809] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [81.810] CR2: 00005604833670f0 CR3: 0000000116679000 CR4: 00000000000006f0 [81.810] Call Trace: [81.810] \u003cTASK\u003e [81.810] __btrfs_end_transaction+0x3e/0x2b0 [btrfs] [81.811] btrfs_force_chunk_alloc_store+0xcd/0x140 [btrfs] [81.811] kernfs_fop_write_iter+0x15f/0x240 [81.812] vfs_write+0x264/0x500 [81.812] ksys_write+0x6c/0xe0 [81.812] do_syscall_64+0x66/0x770 [81.812] entry_SYSCALL_64_after_hwframe+0x76/0x7e [81.813] RIP: 0033:0x7fec6be66197 [81.814] RSP: 002b:00007fffb159dd30 EFLAGS: 00000202 ORIG_RAX: 0000000000000001 [81.815] RAX: ffffffffffffffda RBX: 00007fec6bdd9740 RCX: 00007fec6be66197 [81.815] RDX: 0000000000000002 RSI: 0000560483374f80 RDI: 0000000000000001 [81.816] RBP: 0000560483374f80 R08: 0000000000000000 R09: 0000000000000000 [81.816] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000002 [81.817] R13: 00007fec6bfb85c0 R14: 00007fec6bfb5ee0 R15: 00005604833729c0 [81.817] \u003c/TASK\u003e [81.817] irq event stamp: 20039 [81.818] hardirqs last enabled at (20047): [\u003cffffffff99a68302\u003e] __up_console_sem+0x52/0x60 [81.818] hardirqs last disabled at (20056): [\u003cffffffff99a682e7\u003e] __up_console_sem+0x37/0x60 [81.819] softirqs last enabled at (19470): [\u003cffffffff999d2b46\u003e] __irq_exit_rcu+0x96/0xc0 [81.819] softirqs last disabled at (19463): [\u003cffffffff999d2b46\u003e] __irq_exit_rcu+0x96/0xc0 [81.820] ---[ end trace 0000000000000000 ]--- [81.820] BTRFS: error (device dm-7 state A) in btrfs_create_pending_block_groups:2876: errno=-17 Object already exists Inspecting these aborts with drgn, I observed a pattern of overlapping chunk_maps. Note how stripe 1 of the first chunk overlaps in physical address with stripe 0 of the second chunk. Physical Start Physical End Length Logical Type Stripe ---------------------------------------------------------------------------------------------------- 0x0000000102500000 0x0000000142500000 1.0G 0x0000000641d00000 META|DUP 0/2 0x0000000142500000 0x0000000182500000 1.0G 0x0000000641d00000 META|DUP 1/2 0x0000000142500000 0x0000000182500000 1.0G 0x0000000601d00000 META|DUP 0/2 0x0000000182500000 0x00000001c2500000 1.0G 0x0000000601d00000 META|DUP 1/2 Now how could this possibly happen? All chunk allocation is ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45934", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/q/1NoaqqY53cTnf3GDbOA==": { "id": "/q/1NoaqqY53cTnf3GDbOA==", "updater": "debian/updater", "name": "CVE-2026-3644", "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3644", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "/qUM6+rqk8nGECur0ngdlg==": { "id": "/qUM6+rqk8nGECur0ngdlg==", "updater": "debian/updater", "name": "CVE-2026-41991", "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41991", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "02rBMXIw8e/W8DLaacuURA==": { "id": "02rBMXIw8e/W8DLaacuURA==", "updater": "debian/updater", "name": "CVE-2025-38590", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Remove skb secpath if xfrm state is not found Hardware returns a unique identifier for a decrypted packet's xfrm state, this state is looked up in an xarray. However, the state might have been freed by the time of this lookup. Currently, if the state is not found, only a counter is incremented. The secpath (sp) extension on the skb is not removed, resulting in sp-\u003elen becoming 0. Subsequently, functions like __xfrm_policy_check() attempt to access fields such as xfrm_input_state(skb)-\u003exso.type (which dereferences sp-\u003exvec[sp-\u003elen - 1]) without first validating sp-\u003elen. This leads to a crash when dereferencing an invalid state pointer. This patch prevents the crash by explicitly removing the secpath extension from the skb if the xfrm state is not found after hardware decryption. This ensures downstream functions do not operate on a zero-length secpath. BUG: unable to handle page fault for address: ffffffff000002c8 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 282e067 P4D 282e067 PUD 0 Oops: Oops: 0000 [#1] SMP CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:__xfrm_policy_check+0x61a/0xa30 Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0 03 48 98 49 01 c5 41 8b 45 00 83 e8 01 48 98 49 8b 44 c5 10 \u003c0f\u003e b6 80 c8 02 00 00 83 e0 0c 3c 04 0f 84 0c 02 00 00 31 ff 80 fa RSP: 0018:ffff88885fb04918 EFLAGS: 00010297 RAX: ffffffff00000000 RBX: 0000000000000002 RCX: 0000000000000000 RDX: 0000000000000002 RSI: 0000000000000002 RDI: 0000000000000000 RBP: ffffffff8311af80 R08: 0000000000000020 R09: 00000000c2eda353 R10: ffff88812be2bbc8 R11: 000000001faab533 R12: ffff88885fb049c8 R13: ffff88812be2bbc8 R14: 0000000000000000 R15: ffff88811896ae00 FS: 0000000000000000(0000) GS:ffff8888dca82000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffffff000002c8 CR3: 0000000243050002 CR4: 0000000000372eb0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: \u003cIRQ\u003e ? try_to_wake_up+0x108/0x4c0 ? udp4_lib_lookup2+0xbe/0x150 ? udp_lib_lport_inuse+0x100/0x100 ? __udp4_lib_lookup+0x2b0/0x410 __xfrm_policy_check2.constprop.0+0x11e/0x130 udp_queue_rcv_one_skb+0x1d/0x530 udp_unicast_rcv_skb+0x76/0x90 __udp4_lib_rcv+0xa64/0xe90 ip_protocol_deliver_rcu+0x20/0x130 ip_local_deliver_finish+0x75/0xa0 ip_local_deliver+0xc1/0xd0 ? ip_protocol_deliver_rcu+0x130/0x130 ip_sublist_rcv+0x1f9/0x240 ? ip_rcv_finish_core+0x430/0x430 ip_list_rcv+0xfc/0x130 __netif_receive_skb_list_core+0x181/0x1e0 netif_receive_skb_list_internal+0x200/0x360 ? mlx5e_build_rx_skb+0x1bc/0xda0 [mlx5_core] gro_receive_skb+0xfd/0x210 mlx5e_handle_rx_cqe_mpwrq+0x141/0x280 [mlx5_core] mlx5e_poll_rx_cq+0xcc/0x8e0 [mlx5_core] ? mlx5e_handle_rx_dim+0x91/0xd0 [mlx5_core] mlx5e_napi_poll+0x114/0xab0 [mlx5_core] __napi_poll+0x25/0x170 net_rx_action+0x32d/0x3a0 ? mlx5_eq_comp_int+0x8d/0x280 [mlx5_core] ? notifier_call_chain+0x33/0xa0 handle_softirqs+0xda/0x250 irq_exit_rcu+0x6d/0xc0 common_interrupt+0x81/0xa0 \u003c/IRQ\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38590", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "07URzmvpS7ZEQcLIdrixNA==": { "id": "07URzmvpS7ZEQcLIdrixNA==", "updater": "debian/updater", "name": "CVE-2026-12087", "description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-12087", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "09nI6dXLoEtf+3xPpjxkqQ==": { "id": "09nI6dXLoEtf+3xPpjxkqQ==", "updater": "debian/updater", "name": "CVE-2026-40228", "description": "In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-40228", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0E2oyk9T5Tu1U+CLXaiEEw==": { "id": "0E2oyk9T5Tu1U+CLXaiEEw==", "updater": "debian/updater", "name": "CVE-2025-71193", "description": "In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qusb2: Fix NULL pointer dereference on early suspend Enabling runtime PM before attaching the QPHY instance as driver data can lead to a NULL pointer dereference in runtime PM callbacks that expect valid driver data. There is a small window where the suspend callback may run after PM runtime enabling and before runtime forbid. This causes a sporadic crash during boot: ``` Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a1 [...] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 6.16.7+ #116 PREEMPT Workqueue: pm pm_runtime_work pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : qusb2_phy_runtime_suspend+0x14/0x1e0 [phy_qcom_qusb2] lr : pm_generic_runtime_suspend+0x2c/0x44 [...] ``` Attach the QPHY instance as driver data before enabling runtime PM to prevent NULL pointer dereference in runtime PM callbacks. Reorder pm_runtime_enable() and pm_runtime_forbid() to prevent a short window where an unnecessary runtime suspend can occur. Use the devres-managed version to ensure PM runtime is symmetrically disabled during driver removal for proper cleanup.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71193", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0EtUZyNBUfLwjGZbPM2VIw==": { "id": "0EtUZyNBUfLwjGZbPM2VIw==", "updater": "debian/updater", "name": "CVE-2026-43409", "description": "In the Linux kernel, the following vulnerability has been resolved: kprobes: avoid crash when rmmod/insmod after ftrace killed After we hit ftrace is killed by some errors, the kernel crash if we remove modules in which kprobe probes. BUG: unable to handle page fault for address: fffffbfff805000d PGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0 Oops: Oops: 0000 [#1] SMP KASAN PTI CPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G W OE Tainted: [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE RIP: 0010:kprobes_module_callback+0x89/0x790 RSP: 0018:ffff88812e157d30 EFLAGS: 00010a02 RAX: 1ffffffff805000d RBX: dffffc0000000000 RCX: ffffffff86a8de90 RDX: ffffed1025c2af9b RSI: 0000000000000008 RDI: ffffffffc0280068 RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1025c2af9a R10: ffff88812e157cd7 R11: 205d323130325420 R12: 0000000000000002 R13: ffffffffc0290488 R14: 0000000000000002 R15: ffffffffc0280040 FS: 00007fbc450dd740(0000) GS:ffff888420331000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: fffffbfff805000d CR3: 000000010f624000 CR4: 00000000000006f0 Call Trace: \u003cTASK\u003e notifier_call_chain+0xc6/0x280 blocking_notifier_call_chain+0x60/0x90 __do_sys_delete_module.constprop.0+0x32a/0x4e0 do_syscall_64+0x5d/0xfa0 entry_SYSCALL_64_after_hwframe+0x76/0x7e This is because the kprobe on ftrace does not correctly handles the kprobe_ftrace_disabled flag set by ftrace_kill(). To prevent this error, check kprobe_ftrace_disabled in __disarm_kprobe_ftrace() and skip all ftrace related operations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43409", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0GN6z/4AhTLCs/1UdBBmxw==": { "id": "0GN6z/4AhTLCs/1UdBBmxw==", "updater": "debian/updater", "name": "CVE-2026-64564", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf-\u003etransport (== chunk-\u003etransport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf-\u003etransport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf-\u003etransport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf-\u003etransport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (-\u003eipaddr, -\u003estate) and plants the dangling pointer into asoc-\u003epeer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64564", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0HOHcobRnpDN9ct7nb9VmQ==": { "id": "0HOHcobRnpDN9ct7nb9VmQ==", "updater": "debian/updater", "name": "CVE-2026-31579", "description": "In the Linux kernel, the following vulnerability has been resolved: wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit wg_netns_pre_exit() manually acquires rtnl_lock() inside the pernet .pre_exit callback. This causes a hung task when another thread holds rtnl_mutex - the cleanup_net workqueue (or the setup_net failure rollback path) blocks indefinitely in wg_netns_pre_exit() waiting to acquire the lock. Convert to .exit_rtnl, introduced in commit 7a60d91c690b (\"net: Add -\u003eexit_rtnl() hook to struct pernet_operations.\"), where the framework already holds RTNL and batches all callbacks under a single rtnl_lock()/rtnl_unlock() pair, eliminating the contention window. The rcu_assign_pointer(wg-\u003ecreating_net, NULL) is safe to move from .pre_exit to .exit_rtnl (which runs after synchronize_rcu()) because all RCU readers of creating_net either use maybe_get_net() - which returns NULL for a dying namespace with zero refcount - or access net-\u003euser_ns which remains valid throughout the entire ops_undo_list sequence. [ Jason: added __net_exit and __read_mostly annotations that were missing. ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31579", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0HtM1g1taJ19/JeX7mpPOQ==": { "id": "0HtM1g1taJ19/JeX7mpPOQ==", "updater": "debian/updater", "name": "CVE-2025-38705", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix null pointer access Writing a string without delimiters (' ', '\\n', '\\0') to the under gpu_od/fan_ctrl sysfs or pp_power_profile_mode for the CUSTOM profile will result in a null pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38705", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0IZsf9dz4Us+xRLW6BtuLA==": { "id": "0IZsf9dz4Us+xRLW6BtuLA==", "updater": "debian/updater", "name": "CVE-2024-35924", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Limit read size on v1.2 Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 to 256. In order to avoid overflowing reads for older systems, add a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35924", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0JY6fbv07QRBiECIH0qRrg==": { "id": "0JY6fbv07QRBiECIH0qRrg==", "updater": "debian/updater", "name": "CVE-2025-39732", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is required to be atomic, however ath11k_mac_disable_peer_fixed_rate() does not follow it as it might sleep. Consequently below warning is seen: BUG: sleeping function called from invalid context at wmi.c:304 Call Trace: \u003cTASK\u003e dump_stack_lvl __might_resched.cold ath11k_wmi_cmd_send ath11k_wmi_set_peer_param ath11k_mac_disable_peer_fixed_rate ieee80211_iterate_stations_atomic ath11k_mac_op_set_bitrate_mask.cold Change to ieee80211_iterate_stations_mtx() to fix this issue. Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39732", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0K3AIfDYtx7QdAwi8fy/tQ==": { "id": "0K3AIfDYtx7QdAwi8fy/tQ==", "updater": "debian/updater", "name": "CVE-2026-68288", "description": "In the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload before overwriting it with skb_copy_bits(). skb_put() reserves nla_total_size(payload_len), i.e. the header plus the NLA_ALIGN() padding, but only payload_len bytes are copied in. When payload_len is not a multiple of 4 the 1-3 padding bytes are never initialized and are leaked to user space inside the netlink message. KMSAN confirms the leak for the software path when the packet payload length is not 4-byte aligned: BUG: KMSAN: kernel-infoleak in _copy_to_iter _copy_to_iter __skb_datagram_iter skb_copy_datagram_iter netlink_recvmsg sock_recvmsg __sys_recvfrom Uninit was created at: kmem_cache_alloc_node_noprof __alloc_skb net_dm_packet_work Bytes 173-175 of 176 are uninitialized Use __nla_reserve(), which sets up the attribute header and zeroes the padding, instead of open coding the attribute construction.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68288", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0L20TVSGH+Xvumc2z925bQ==": { "id": "0L20TVSGH+Xvumc2z925bQ==", "updater": "debian/updater", "name": "CVE-2026-68280", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks for both runtime PM and system sleep. This causes the DSI clocks to be disabled twice: once during runtime suspend and again during system suspend, resulting in a WARN message from the clock framework when attempting to disable already-disabled clocks. [ 84.384540] clk:231:5 already disabled [ 84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac ... [ 84.579183] Call trace: [ 84.581624] clk_core_disable+0xa4/0xac [ 84.585457] clk_disable+0x30/0x4c [ 84.588857] cdns_dsi_suspend+0x20/0x58 [cdns_dsi] [ 84.593651] pm_generic_suspend+0x2c/0x44 [ 84.597661] ti_sci_pd_suspend+0xbc/0x15c [ 84.601670] dpm_run_callback+0x8c/0x14c [ 84.605588] __device_suspend+0x1a0/0x56c [ 84.609594] dpm_suspend+0x17c/0x21c [ 84.613165] dpm_suspend_start+0xa0/0xa8 [ 84.617083] suspend_devices_and_enter+0x12c/0x634 [ 84.621872] pm_suspend+0x1fc/0x368 To address this issue, replace UNIVERSAL_DEV_PM_OPS() with RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime PM, as the DRM framework manages system-wide power transitions through the bridge enable() and disable() hooks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68280", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0MTDMTjf9fjVojr+2WUZkA==": { "id": "0MTDMTjf9fjVojr+2WUZkA==", "updater": "debian/updater", "name": "CVE-2026-53258", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: fix leak if split 6 GHz scanning fails rdev-\u003eint_scan_req is leaked if cfg80211_scan() fails. Note that it's supposed to be released at ___cfg80211_scan_done() but this doesn't happen as rdev-\u003escan_req is NULL at that point, too, leading to the early return from the freeing function. unreferenced object 0xffff8881161d0800 (size 512): comm \"wpa_supplicant\", pid 379, jiffies 4294749765 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff ................ backtrace (crc c867fdb6): kmemleak_alloc+0x89/0x90 __kmalloc_noprof+0x2fd/0x410 cfg80211_scan+0x133/0x730 nl80211_trigger_scan+0xc69/0x1cc0 genl_family_rcv_msg_doit+0x204/0x2f0 genl_rcv_msg+0x431/0x6b0 netlink_rcv_skb+0x143/0x3f0 genl_rcv+0x27/0x40 netlink_unicast+0x4f6/0x820 netlink_sendmsg+0x797/0xce0 __sock_sendmsg+0xc4/0x160 ____sys_sendmsg+0x5e4/0x890 ___sys_sendmsg+0xf8/0x180 __sys_sendmsg+0x136/0x1e0 __x64_sys_sendmsg+0x76/0xc0 x64_sys_call+0x13f0/0x17d0 Found by Linux Verification Center (linuxtesting.org).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53258", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0MdjxnJHuxg0I0Sa279UwQ==": { "id": "0MdjxnJHuxg0I0Sa279UwQ==", "updater": "debian/updater", "name": "CVE-2008-4609", "description": "The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-4609", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0MmyGSoo3BjfDz/rvghu0w==": { "id": "0MmyGSoo3BjfDz/rvghu0w==", "updater": "debian/updater", "name": "CVE-2025-71109", "description": "In the Linux kernel, the following vulnerability has been resolved: MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits Since commit e424054000878 (\"MIPS: Tracing: Reduce the overhead of dynamic Function Tracer\"), the macro UASM_i_LA_mostly has been used, and this macro can generate more than 2 instructions. At the same time, the code in ftrace assumes that no more than 2 instructions can be generated, which is why it stores them in an int[2] array. However, as previously noted, the macro UASM_i_LA_mostly (and now UASM_i_LA) causes a buffer overflow when _mcount is beyond 32 bits. This leads to corruption of the variables located in the __read_mostly section. This corruption was observed because the variable __cpu_primary_thread_mask was corrupted, causing a hang very early during boot. This fix prevents the corruption by avoiding the generation of instructions if they could exceed 2 instructions in length. Fortunately, insn_la_mcount is only used if the instrumented code is located outside the kernel code section, so dynamic ftrace can still be used, albeit in a more limited scope. This is still preferable to corrupting memory and/or crashing the kernel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71109", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0MrCDPmbl4IB1C1qt/dJNw==": { "id": "0MrCDPmbl4IB1C1qt/dJNw==", "updater": "debian/updater", "name": "CVE-2024-38557", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Reload only IB representors upon lag disable/enable On lag disable, the bond IB device along with all of its representors are destroyed, and then the slaves' representors get reloaded. In case the slave IB representor load fails, the eswitch error flow unloads all representors, including ethernet representors, where the netdevs get detached and removed from lag bond. Such flow is inaccurate as the lag driver is not responsible for loading/unloading ethernet representors. Furthermore, the flow described above begins by holding lag lock to prevent bond changes during disable flow. However, when reaching the ethernet representors detachment from lag, the lag lock is required again, triggering the following deadlock: Call trace: __switch_to+0xf4/0x148 __schedule+0x2c8/0x7d0 schedule+0x50/0xe0 schedule_preempt_disabled+0x18/0x28 __mutex_lock.isra.13+0x2b8/0x570 __mutex_lock_slowpath+0x1c/0x28 mutex_lock+0x4c/0x68 mlx5_lag_remove_netdev+0x3c/0x1a0 [mlx5_core] mlx5e_uplink_rep_disable+0x70/0xa0 [mlx5_core] mlx5e_detach_netdev+0x6c/0xb0 [mlx5_core] mlx5e_netdev_change_profile+0x44/0x138 [mlx5_core] mlx5e_netdev_attach_nic_profile+0x28/0x38 [mlx5_core] mlx5e_vport_rep_unload+0x184/0x1b8 [mlx5_core] mlx5_esw_offloads_rep_load+0xd8/0xe0 [mlx5_core] mlx5_eswitch_reload_reps+0x74/0xd0 [mlx5_core] mlx5_disable_lag+0x130/0x138 [mlx5_core] mlx5_lag_disable_change+0x6c/0x70 [mlx5_core] // hold ldev-\u003elock mlx5_devlink_eswitch_mode_set+0xc0/0x410 [mlx5_core] devlink_nl_cmd_eswitch_set_doit+0xdc/0x180 genl_family_rcv_msg_doit.isra.17+0xe8/0x138 genl_rcv_msg+0xe4/0x220 netlink_rcv_skb+0x44/0x108 genl_rcv+0x40/0x58 netlink_unicast+0x198/0x268 netlink_sendmsg+0x1d4/0x418 sock_sendmsg+0x54/0x60 __sys_sendto+0xf4/0x120 __arm64_sys_sendto+0x30/0x40 el0_svc_common+0x8c/0x120 do_el0_svc+0x30/0xa0 el0_svc+0x20/0x30 el0_sync_handler+0x90/0xb8 el0_sync+0x160/0x180 Thus, upon lag enable/disable, load and unload only the IB representors of the slaves preventing the deadlock mentioned above. While at it, refactor the mlx5_esw_offloads_rep_load() function to have a static helper method for its internal logic, in symmetry with the representor unload design.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38557", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0MwmAAbL4wOCyh0/b/kddw==": { "id": "0MwmAAbL4wOCyh0/b/kddw==", "updater": "debian/updater", "name": "CVE-2026-5545", "description": "libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-5545", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0OtsAnxTbW0/IiNAzGzOSw==": { "id": "0OtsAnxTbW0/IiNAzGzOSw==", "updater": "debian/updater", "name": "CVE-2026-43309", "description": "In the Linux kernel, the following vulnerability has been resolved: md raid: fix hang when stopping arrays with metadata through dm-raid When using device-mapper's dm-raid target, stopping a RAID array can cause the system to hang under specific conditions. This occurs when: - A dm-raid managed device tree is suspended from top to bottom (the top-level RAID device is suspended first, followed by its underlying metadata and data devices) - The top-level RAID device is then removed Removing the top-level device triggers a hang in the following sequence: the dm-raid destructor calls md_stop(), which tries to flush the write-intent bitmap by writing to the metadata sub-devices. However, these devices are already suspended, making them unable to complete the write-intent operations and causing an indefinite block. Fix: - Prevent bitmap flushing when md_stop() is called from dm-raid destructor context and avoid a quiescing/unquescing cycle which could also cause I/O - Still allow write-intent bitmap flushing when called from dm-raid suspend context This ensures that RAID array teardown can complete successfully even when the underlying devices are in a suspended state. This second patch uses md_is_rdwr() to distinguish between suspend and destructor paths as elaborated on above.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43309", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0PA48EgploV9aVx5eXrXhA==": { "id": "0PA48EgploV9aVx5eXrXhA==", "updater": "debian/updater", "name": "CVE-2026-68303", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions. Since the vc4-drm gets removed before its dependent drivers (vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to get drvdata of its master and fails with a null dereference error. Use the data pointer passed to the unbind functions directly instead of dev_get_drvdata(master). This avoids using potentially freed memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68303", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0QszTeXFRafC+y9Bl5KyMw==": { "id": "0QszTeXFRafC+y9Bl5KyMw==", "updater": "debian/updater", "name": "CVE-2025-69647", "description": "GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69647", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0TmZZ5LEd0yAayUm31rvqA==": { "id": "0TmZZ5LEd0yAayUm31rvqA==", "updater": "debian/updater", "name": "CVE-2026-27622", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector\u003cunsigned int\u003e total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-27622", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0X9H30gbmWBuPE1VOfDMHQ==": { "id": "0X9H30gbmWBuPE1VOfDMHQ==", "updater": "debian/updater", "name": "CVE-2024-49914", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for pipe_ctx-\u003eplane_state in dcn20_program_pipe This commit addresses a null pointer dereference issue in the `dcn20_program_pipe` function. The issue could occur when `pipe_ctx-\u003eplane_state` is null. The fix adds a check to ensure `pipe_ctx-\u003eplane_state` is not null before accessing. This prevents a null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn20/dcn20_hwseq.c:1925 dcn20_program_pipe() error: we previously assumed 'pipe_ctx-\u003eplane_state' could be null (see line 1877)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49914", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0gA17o48zImKmwnZ3FkTlA==": { "id": "0gA17o48zImKmwnZ3FkTlA==", "updater": "debian/updater", "name": "CVE-2026-68121", "description": "In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68121", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0jSW5utK6X2RgUuKOjtT/g==": { "id": "0jSW5utK6X2RgUuKOjtT/g==", "updater": "debian/updater", "name": "CVE-2025-22043", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22043", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0k4T8D9OO0elHgqdOnSGtg==": { "id": "0k4T8D9OO0elHgqdOnSGtg==", "updater": "debian/updater", "name": "CVE-2009-3546", "description": "The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2009-3546", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libwmf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0lfDYmZXrLVXyJHmV4fhNg==": { "id": "0lfDYmZXrLVXyJHmV4fhNg==", "updater": "debian/updater", "name": "CVE-2024-27062", "description": "In the Linux kernel, the following vulnerability has been resolved: nouveau: lock the client object tree. It appears the client object tree has no locking unless I've missed something else. Fix races around adding/removing client objects, mostly vram bar mappings. 4562.099306] general protection fault, probably for non-canonical address 0x6677ed422bceb80c: 0000 [#1] PREEMPT SMP PTI [ 4562.099314] CPU: 2 PID: 23171 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27 [ 4562.099324] Hardware name: Gigabyte Technology Co., Ltd. Z390 I AORUS PRO WIFI/Z390 I AORUS PRO WIFI-CF, BIOS F8 11/05/2021 [ 4562.099330] RIP: 0010:nvkm_object_search+0x1d/0x70 [nouveau] [ 4562.099503] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 48 89 f8 48 85 f6 74 39 48 8b 87 a0 00 00 00 48 85 c0 74 12 \u003c48\u003e 8b 48 f8 48 39 ce 73 15 48 8b 40 10 48 85 c0 75 ee 48 c7 c0 fe [ 4562.099506] RSP: 0000:ffffa94cc420bbf8 EFLAGS: 00010206 [ 4562.099512] RAX: 6677ed422bceb814 RBX: ffff98108791f400 RCX: ffff9810f26b8f58 [ 4562.099517] RDX: 0000000000000000 RSI: ffff9810f26b9158 RDI: ffff98108791f400 [ 4562.099519] RBP: ffff9810f26b9158 R08: 0000000000000000 R09: 0000000000000000 [ 4562.099521] R10: ffffa94cc420bc48 R11: 0000000000000001 R12: ffff9810f02a7cc0 [ 4562.099526] R13: 0000000000000000 R14: 00000000000000ff R15: 0000000000000007 [ 4562.099528] FS: 00007f629c5017c0(0000) GS:ffff98142c700000(0000) knlGS:0000000000000000 [ 4562.099534] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4562.099536] CR2: 00007f629a882000 CR3: 000000017019e004 CR4: 00000000003706f0 [ 4562.099541] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4562.099542] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4562.099544] Call Trace: [ 4562.099555] \u003cTASK\u003e [ 4562.099573] ? die_addr+0x36/0x90 [ 4562.099583] ? exc_general_protection+0x246/0x4a0 [ 4562.099593] ? asm_exc_general_protection+0x26/0x30 [ 4562.099600] ? nvkm_object_search+0x1d/0x70 [nouveau] [ 4562.099730] nvkm_ioctl+0xa1/0x250 [nouveau] [ 4562.099861] nvif_object_map_handle+0xc8/0x180 [nouveau] [ 4562.099986] nouveau_ttm_io_mem_reserve+0x122/0x270 [nouveau] [ 4562.100156] ? dma_resv_test_signaled+0x26/0xb0 [ 4562.100163] ttm_bo_vm_fault_reserved+0x97/0x3c0 [ttm] [ 4562.100182] ? __mutex_unlock_slowpath+0x2a/0x270 [ 4562.100189] nouveau_ttm_fault+0x69/0xb0 [nouveau] [ 4562.100356] __do_fault+0x32/0x150 [ 4562.100362] do_fault+0x7c/0x560 [ 4562.100369] __handle_mm_fault+0x800/0xc10 [ 4562.100382] handle_mm_fault+0x17c/0x3e0 [ 4562.100388] do_user_addr_fault+0x208/0x860 [ 4562.100395] exc_page_fault+0x7f/0x200 [ 4562.100402] asm_exc_page_fault+0x26/0x30 [ 4562.100412] RIP: 0033:0x9b9870 [ 4562.100419] Code: 85 a8 f7 ff ff 8b 8d 80 f7 ff ff 89 08 e9 18 f2 ff ff 0f 1f 84 00 00 00 00 00 44 89 32 e9 90 fa ff ff 0f 1f 84 00 00 00 00 00 \u003c44\u003e 89 32 e9 f8 f1 ff ff 0f 1f 84 00 00 00 00 00 66 44 89 32 e9 e7 [ 4562.100422] RSP: 002b:00007fff9ba2dc70 EFLAGS: 00010246 [ 4562.100426] RAX: 0000000000000004 RBX: 000000000dd65e10 RCX: 000000fff0000000 [ 4562.100428] RDX: 00007f629a882000 RSI: 00007f629a882000 RDI: 0000000000000066 [ 4562.100432] RBP: 00007fff9ba2e570 R08: 0000000000000000 R09: 0000000123ddf000 [ 4562.100434] R10: 0000000000000001 R11: 0000000000000246 R12: 000000007fffffff [ 4562.100436] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 4562.100446] \u003c/TASK\u003e [ 4562.100448] Modules linked in: nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables libcrc32c nfnetlink cmac bnep sunrpc iwlmvm intel_rapl_msr intel_rapl_common snd_sof_pci_intel_cnl x86_pkg_temp_thermal intel_powerclamp snd_sof_intel_hda_common mac80211 coretemp snd_soc_acpi_intel_match kvm_intel snd_soc_acpi snd_soc_hdac_hda snd_sof_pci snd_sof_xtensa_dsp snd_sof_intel_hda_mlink ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27062", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0llwKVzNKYr3FDiLn1hJfQ==": { "id": "0llwKVzNKYr3FDiLn1hJfQ==", "updater": "debian/updater", "name": "CVE-2026-68309", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() mt76_connac_get_he_phy_cap routine can theoretically return NULL so check cap pointer before dereferencing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68309", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0qAz5+tC5TUL0H7+2lA3xg==": { "id": "0qAz5+tC5TUL0H7+2lA3xg==", "updater": "debian/updater", "name": "CVE-2025-37842", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: fsl-qspi: use devm function instead of driver remove Driver use devm APIs to manage clk/irq/resources and register the spi controller, but the legacy remove function will be called first during device detach and trigger kernel panic. Drop the remove function and use devm_add_action_or_reset() for driver cleanup to ensure the release sequence. Trigger kernel panic on i.MX8MQ by echo 30bb0000.spi \u003e/sys/bus/platform/drivers/fsl-quadspi/unbind", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37842", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0r8cGAtKxqmEroQrTr1a5A==": { "id": "0r8cGAtKxqmEroQrTr1a5A==", "updater": "debian/updater", "name": "CVE-2026-68183", "description": "In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix memory leaks and list corruption bugs Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error path. Switch pmem allocation from devm_kzalloc() to kzalloc() with explicit kfree() in the free path to match its list-managed lifetime. Remove the erroneous list_del(\u0026svc_data_mem) which corrupted the list head on failed lookups.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68183", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0t6ZhLO4siY+a7KyIW7bQA==": { "id": "0t6ZhLO4siY+a7KyIW7bQA==", "updater": "debian/updater", "name": "CVE-2024-57900", "description": "In the Linux kernel, the following vulnerability has been resolved: ila: serialize calls to nf_register_net_hooks() syzbot found a race in ila_add_mapping() [1] commit 031ae72825ce (\"ila: call nf_unregister_net_hooks() sooner\") attempted to fix a similar issue. Looking at the syzbot repro, we have concurrent ILA_CMD_ADD commands. Add a mutex to make sure at most one thread is calling nf_register_net_hooks(). [1] BUG: KASAN: slab-use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline] BUG: KASAN: slab-use-after-free in __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604 Read of size 4 at addr ffff888028f40008 by task dhcpcd/5501 CPU: 1 UID: 0 PID: 5501 Comm: dhcpcd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Call Trace: \u003cIRQ\u003e __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xc3/0x620 mm/kasan/report.c:489 kasan_report+0xd9/0x110 mm/kasan/report.c:602 rht_key_hashfn include/linux/rhashtable.h:159 [inline] __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604 rhashtable_lookup include/linux/rhashtable.h:646 [inline] rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline] ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:127 [inline] ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline] ila_nf_input+0x1ee/0x620 net/ipv6/ila/ila_xlat.c:185 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xbb/0x200 net/netfilter/core.c:626 nf_hook.constprop.0+0x42e/0x750 include/linux/netfilter.h:269 NF_HOOK include/linux/netfilter.h:312 [inline] ipv6_rcv+0xa4/0x680 net/ipv6/ip6_input.c:309 __netif_receive_skb_one_core+0x12e/0x1e0 net/core/dev.c:5672 __netif_receive_skb+0x1d/0x160 net/core/dev.c:5785 process_backlog+0x443/0x15f0 net/core/dev.c:6117 __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6883 napi_poll net/core/dev.c:6952 [inline] net_rx_action+0xa94/0x1010 net/core/dev.c:7074 handle_softirqs+0x213/0x8f0 kernel/softirq.c:561 __do_softirq kernel/softirq.c:595 [inline] invoke_softirq kernel/softirq.c:435 [inline] __irq_exit_rcu+0x109/0x170 kernel/softirq.c:662 irq_exit_rcu+0x9/0x30 kernel/softirq.c:678 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline] sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57900", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "0tX86Ghr6N4D6ISg4pUM4w==": { "id": "0tX86Ghr6N4D6ISg4pUM4w==", "updater": "debian/updater", "name": "CVE-2026-52944", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE FSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse attribute and saves it through xattr without any permission checks. This exposes two issues: 1) A client on a read-only share can change the sparse attribute on files it opened, even though the share is read-only. Other FSCTL write operations already check test_tree_conn_flag(work-\u003etcon, KSMBD_TREE_CONN_FLAG_WRITABLE), but FSCTL_SET_SPARSE does not. 2) Even on writable shares, clients without FILE_WRITE_DATA or FILE_WRITE_ATTRIBUTES access should not modify the sparse attribute. Similar handle-level checks exist in other functions but are missing here. Add both share-level writable check and per-handle access check. Use goto out on error to avoid leaking file references.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52944", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "10cNbQG657ri8WsAsUhByQ==": { "id": "10cNbQG657ri8WsAsUhByQ==", "updater": "debian/updater", "name": "CVE-2026-53017", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix data loss caused by incorrect use of nat_entry flag Data loss can occur when fsync is performed on a newly created file (before any checkpoint has been written) concurrently with a checkpoint operation. The scenario is as follows: create \u0026 write \u0026 fsync 'file A' write checkpoint - f2fs_do_sync_file // inline inode - f2fs_write_inode // inode folio is dirty - f2fs_write_checkpoint - f2fs_flush_merged_writes - f2fs_sync_node_pages - f2fs_flush_nat_entries - f2fs_fsync_node_pages // no dirty node - f2fs_need_inode_block_update // return false SPO and lost 'file A' f2fs_flush_nat_entries() sets the IS_CHECKPOINTED and HAS_LAST_FSYNC flags for the nat_entry, but this does not mean that the checkpoint has actually completed successfully. However, f2fs_need_inode_block_update() checks these flags and incorrectly assumes that the checkpoint has finished. The root cause is that the semantics of IS_CHECKPOINTED and HAS_LAST_FSYNC are only guaranteed after the checkpoint write fully completes. This patch modifies f2fs_need_inode_block_update() to acquire the sbi-\u003enode_write lock before reading the nat_entry flags, ensuring that once IS_CHECKPOINTED and HAS_LAST_FSYNC are observed to be set, the checkpoint operation has already completed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53017", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "131HLsto66s+BSz7ExU7PQ==": { "id": "131HLsto66s+BSz7ExU7PQ==", "updater": "debian/updater", "name": "CVE-2026-46274", "description": "In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq-\u003ehash_tail[] if the cancelled work was the tail of its hash bucket. When doing this, it checks whether the preceding entry in acct-\u003ework_list has the same hash value, but never checks that the predecessor is hashed at all. io_get_work_hash() is simply atomic_read(\u0026work-\u003eflags) \u003e\u003e IO_WQ_HASH_SHIFT, and the hash bits are never set for non-hashed work, so it returns 0. Thus, when a hashed bucket-0 work is cancelled while a non-hashed work is its list predecessor, the check spuriously passes and a pointer to the non-hashed io_kiocb is stored in wq-\u003ehash_tail[0]. Because non-hashed work is dequeued via the fast path in io_get_next_work(), which never touches hash_tail[], the stale pointer is never cleared. Therefore, after the non-hashed io_kiocb completes and is freed back to req_cachep, wq-\u003ehash_tail[0] is a dangling pointer. The io_wq is per-task (tctx-\u003eio_wq) and survives ring open/close, so the dangling pointer persists for the lifetime of the task; the next hashed bucket-0 enqueue dereferences it in io_wq_insert_work() and wq_list_add_after() writes through freed memory. Add the missing io_wq_is_hashed() check so a non-hashed predecessor never inherits a hash_tail[] slot.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46274", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "13jIQw5H6nkLwOd5/nXpCQ==": { "id": "13jIQw5H6nkLwOd5/nXpCQ==", "updater": "debian/updater", "name": "CVE-2024-40965", "description": "In the Linux kernel, the following vulnerability has been resolved: i2c: lpi2c: Avoid calling clk_get_rate during transfer Instead of repeatedly calling clk_get_rate for each transfer, lock the clock rate and cache the value. A deadlock has been observed while adding tlv320aic32x4 audio codec to the system. When this clock provider adds its clock, the clk mutex is locked already, it needs to access i2c, which in return needs the mutex for clk_get_rate as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40965", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "15mvvSzVZTLR+G7FdXvygg==": { "id": "15mvvSzVZTLR+G7FdXvygg==", "updater": "debian/updater", "name": "CVE-2026-43083", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace-\u003etype.bit6 is set: if (trace-\u003etype.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue-\u003eqdisc); This code can lead to an out-of-bounds access of the dev-\u003e_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb-\u003equeue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev-\u003enum_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43083", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1Dy5XyHBfkrD1EQOGZjNFA==": { "id": "1Dy5XyHBfkrD1EQOGZjNFA==", "updater": "debian/updater", "name": "CVE-2025-39707", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities HUBBUB structure is not initialized on DCE hardware, so check if it is NULL to avoid null dereference while accessing amdgpu_dm_capabilities file in debugfs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39707", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1FHhd29+E67AOWcm+GUqJQ==": { "id": "1FHhd29+E67AOWcm+GUqJQ==", "updater": "debian/updater", "name": "CVE-2016-10723", "description": "An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that \"the underlying problem is non-trivial to handle.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-10723", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1Fd2YODU8WjYM3TXmP23Pg==": { "id": "1Fd2YODU8WjYM3TXmP23Pg==", "updater": "debian/updater", "name": "CVE-2026-53224", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, but did not ensure that the INIT chunk is large enough to contain a complete INIT header. A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose length field is smaller than sizeof(struct sctp_init_chunk). Later, sctp_process_init() accesses INIT parameters unconditionally, which may lead to out-of-bounds reads. In addition, raw_addr_list_len is not fully validated against the remaining cookie payload. When cookie authentication is disabled, an attacker can supply an oversized raw_addr_list_len and cause sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The address parser also lacks sufficient bounds checks for parameter headers and lengths, allowing malformed address parameters to trigger out-of-bounds reads. Fix this by: - requiring the embedded INIT chunk length to be at least sizeof(struct sctp_init_chunk); - validating that the INIT chunk and raw address list together fit within the cookie payload; - verifying sufficient data exists for each address parameter header and payload before parsing it. Note that sctp_verify_init() must be called after sctp_unpack_cookie() and before sctp_process_init() when cookie authentication is disabled. This will be addressed in a separate patch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53224", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1INWm3M2WxieXT2qDaq7PA==": { "id": "1INWm3M2WxieXT2qDaq7PA==", "updater": "debian/updater", "name": "CVE-2024-53056", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy() In mtk_crtc_create(), if the call to mbox_request_channel() fails then we set the \"mtk_crtc-\u003ecmdq_client.chan\" pointer to NULL. In that situation, we do not call cmdq_pkt_create(). During the cleanup, we need to check if the \"mtk_crtc-\u003ecmdq_client.chan\" is NULL first before calling cmdq_pkt_destroy(). Calling cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and it will result in a NULL pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53056", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1Is+R/NfLg3TYOxSDnUaVg==": { "id": "1Is+R/NfLg3TYOxSDnUaVg==", "updater": "debian/updater", "name": "CVE-2024-26677", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of delayed ACKs to not set the reference serial number as they can't be used as an RTT reference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26677", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1L8o2LoXsizqmn3etiV0SQ==": { "id": "1L8o2LoXsizqmn3etiV0SQ==", "updater": "debian/updater", "name": "CVE-2026-34501", "description": "Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34501", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "apr-util", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1NI5gDrOF88LHCi6AdglUQ==": { "id": "1NI5gDrOF88LHCi6AdglUQ==", "updater": "debian/updater", "name": "CVE-2023-54030", "description": "In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv CQEs, it might get out of hand, hurt performance, and in the worst case scenario OOM the task.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54030", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1OXdOn2y4C9PfQZDckFodQ==": { "id": "1OXdOn2y4C9PfQZDckFodQ==", "updater": "debian/updater", "name": "CVE-2025-38045", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix debug actions order The order of actions taken for debug was implemented incorrectly. Now we implemented the dump split and do the FW reset only in the middle of the dump (rather than the FW killing itself on error.) As a result, some of the actions taken when applying the config will now crash the device, so we need to fix the order.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38045", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1QFm70wnr6bYuRxGyK0OHw==": { "id": "1QFm70wnr6bYuRxGyK0OHw==", "updater": "debian/updater", "name": "CVE-2026-23207", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer check in IRQ handler Now that all other accesses to curr_xfer are done under the lock, protect the curr_xfer NULL check in tegra_qspi_isr_thread() with the spinlock. Without this protection, the following race can occur: CPU0 (ISR thread) CPU1 (timeout path) ---------------- ------------------- if (!tqspi-\u003ecurr_xfer) // sees non-NULL spin_lock() tqspi-\u003ecurr_xfer = NULL spin_unlock() handle_*_xfer() spin_lock() t = tqspi-\u003ecurr_xfer // NULL! ... t-\u003elen ... // NULL dereference! With this patch, all curr_xfer accesses are now properly synchronized. Although all accesses to curr_xfer are done under the lock, in tegra_qspi_isr_thread() it checks for NULL, releases the lock and reacquires it later in handle_cpu_based_xfer()/handle_dma_based_xfer(). There is a potential for an update in between, which could cause a NULL pointer dereference. To handle this, add a NULL check inside the handlers after acquiring the lock. This ensures that if the timeout path has already cleared curr_xfer, the handler will safely return without dereferencing the NULL pointer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23207", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1RZWxSY70nQZs/BoyJpC7g==": { "id": "1RZWxSY70nQZs/BoyJpC7g==", "updater": "debian/updater", "name": "CVE-2026-64424", "description": "In the Linux kernel, the following vulnerability has been resolved: netpoll: fix a use-after-free on shutdown path There is a use-after-free error on netpoll, which is clearly detected by KASAN. BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0x3b/0x80 Read of size 1 at addr ... by task kworker/9:1 Workqueue: events queue_process Call Trace: skb_dequeue+0x1e/0xb0 queue_process+0x2c/0x600 process_scheduled_works+0x4b6/0x850 worker_thread+0x414/0x5a0 Allocated by task 242: __netpoll_setup+0x201/0x4a0 netpoll_setup+0x249/0x550 enabled_store+0x32f/0x380 Freed by task 0: kfree+0x1b7/0x540 rcu_core+0x3f8/0x7a0 The problem happens when there is a pending TX worker running in parallel with the cleanup path. This is what happens on netpoll shutdown path: 1) __netpoll_cleanup() is called 2) set dev-\u003enpinfo to NULL 3) call_rcu() with rcu_cleanup_netpoll_info() 3.1) rcu_cleanup_netpoll_info() tries to cancel all workers with cancel_delayed_work(), but doesn't wait for the worker to finish 4) and kfree(npinfo); Because 3.1) doesn't really cancel the work, as the comment says \"we can't call cancel_delayed_work_sync here, as we are in softirq\", the TX worker can run after 4). Tl;DR: queue_process() is not an RCU reader, it reaches npinfo through the work item via container_of(). Use disable_delayed_work_sync() to ensure the worker is completely stopped and prevent any future re-arming attempts. Once npinfo is set to NULL, senders will bail out and not queue new work. The disable flag ensures any in-flight re-arming attempts also fail silently. In the future, we can do the cleanup inline here without needing the npinfo-\u003ercu rcu_head, but that is net-next material.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64424", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1URpR/kkS5zJM9sTCGG3pw==": { "id": "1URpR/kkS5zJM9sTCGG3pw==", "updater": "debian/updater", "name": "CVE-2026-64305", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: qat - protect service table iterations with service_lock The service_table list is protected by service_lock when entries are added or removed (in adf_service_add() and adf_service_remove()), but several functions iterate over the list without holding this lock. A concurrent adf_service_register() or adf_service_unregister() call could modify the list during traversal, leading to list corruption or a use-after-free. Fix this by holding service_lock across all list_for_each_entry() iterations of service_table in adf_dev_init(), adf_dev_start(), adf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(), adf_dev_restarted_notify(), and adf_error_notifier(). The lock ordering is safe: callers of the static helpers (adf_dev_up() and adf_dev_down()) acquire state_lock before service_lock, and no event_hld callback or service_lock holder ever acquires state_lock in the reverse order.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64305", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1WJj58mYAh64tk3XzeRGcA==": { "id": "1WJj58mYAh64tk3XzeRGcA==", "updater": "debian/updater", "name": "CVE-2026-53076", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix OOB in pcpu_init_value An out-of-bounds read occurs when copying element from a BPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the same value_size that is not rounded up to 8 bytes. The issue happens when: 1. A CGROUP_STORAGE map is created with value_size not aligned to 8 bytes (e.g., 4 bytes) 2. A pcpu map is created with the same value_size (e.g., 4 bytes) 3. Update element in 2 with data in 1 pcpu_init_value assumes that all sources are rounded up to 8 bytes, and invokes copy_map_value_long to make a data copy, However, the assumption doesn't stand since there are some cases where the source may not be rounded up to 8 bytes, e.g., CGROUP_STORAGE, skb-\u003edata. the verifier verifies exactly the size that the source claims, not the size rounded up to 8 bytes by kernel, an OOB happens when the source has only 4 bytes while the copy size(4) is rounded up to 8.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53076", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1cAGedmPqnVqnE6FUIK/pQ==": { "id": "1cAGedmPqnVqnE6FUIK/pQ==", "updater": "debian/updater", "name": "CVE-2026-68376", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed by N HMAC identifiers. However, the array size was calculated using an extra 2 bytes instead of sizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers are configured, the HMAC-ALGO parameter stored in the endpoint is larger than the auth_hmacs buffer in the cookie. As a result, sctp_association_init() copies beyond the end of auth_hmacs when initializing the association, corrupting the adjacent auth_chunks field. This can lead to an invalid HMAC identifier being accepted and later cause an out-of-bounds read in sctp_auth_get_hmac(). Fix the array size calculation by including the full SCTP parameter header size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68376", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1kpr3WQfwsPlCOJYahwUqg==": { "id": "1kpr3WQfwsPlCOJYahwUqg==", "updater": "debian/updater", "name": "CVE-2026-6368", "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6368", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1lREQsvprqgku59eCPwJbA==": { "id": "1lREQsvprqgku59eCPwJbA==", "updater": "debian/updater", "name": "CVE-2026-68086", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream commit 044925f9b565 (\"mm: fs: remove filemap_nr_thps*() functions and their users\")] As-is, khugepaged and writable-file opening exclude each other. A file cannot be open writeable and have THPs (because the filesystem is not aware of them). khugepaged will never collapse file pages for files that are opened writeable. On an open(O_RDWR/O_WRONLY), the page cache for that particular file is dropped. This is fine because nothing could've been dirtied. However, there is an edge-case: collapse_file() might not be able to coexist with concurrent writers, but it can coexist with dirty folios (from previous writers). Therefore, the following can happen: open(file, O_RDWR) write(file) close(file) madvise(file_mapping, MADV_COLLAPSE, some non-dirty range) open(file, O_RDWR) nr_thps \u003e 0 truncate_inode_pages() /* THPs are cleared out, but so are the dirty folios */ When this edge-case happens, there is data loss, as the dirty folios are fully discarded. Fix it by fully writing back the page cache (and waiting) when collapsing file THPs. Doing so provides the guarantee that no dirty folio will be observed while there are active THPs. To fully ensure this is safe, the invalidate_lock needs to be held while doing the writeout, so that do_dentry_open()'s page cache truncation excludes this write-and-wait. As a side effect, move the nr_thps counter bumping outside the i_pages lock. This is correct since the counter itself is an atomic_t and the producer \u003c-\u003e consumer correctness is provided by a full memory barrier: smp_mb() in collapse_file()/memory barrier implied by full ordering in get_write_access() -\u003e atomic_inc_unless_negative().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68086", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1o5lA+NM0aNzCWTeAFzz4Q==": { "id": "1o5lA+NM0aNzCWTeAFzz4Q==", "updater": "debian/updater", "name": "CVE-2025-22103", "description": "In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv When delete l3s ipvlan: ip link del link eth0 ipvlan1 type ipvlan mode l3s This may cause a null pointer dereference: Call trace: ip_rcv_finish+0x48/0xd0 ip_rcv+0x5c/0x100 __netif_receive_skb_one_core+0x64/0xb0 __netif_receive_skb+0x20/0x80 process_backlog+0xb4/0x204 napi_poll+0xe8/0x294 net_rx_action+0xd8/0x22c __do_softirq+0x12c/0x354 This is because l3mdev_l3_rcv() visit dev-\u003el3mdev_ops after ipvlan_l3s_unregister() assign the dev-\u003el3mdev_ops to NULL. The process like this: (CPU1) | (CPU2) l3mdev_l3_rcv() | check dev-\u003epriv_flags: | master = skb-\u003edev; | | | ipvlan_l3s_unregister() | set dev-\u003epriv_flags | dev-\u003el3mdev_ops = NULL; | visit master-\u003el3mdev_ops | To avoid this by do not set dev-\u003el3mdev_ops when unregister l3s ipvlan.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22103", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1rtxSiqG0YoKdvUs0mjbww==": { "id": "1rtxSiqG0YoKdvUs0mjbww==", "updater": "debian/updater", "name": "CVE-2026-68269", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Add missing nospec on parallel submit slot Add missing Spectre mitigation for userspace controlled parallel submission slot. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68269", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1v78L0F0y9NkJWyNm5I/Gg==": { "id": "1v78L0F0y9NkJWyNm5I/Gg==", "updater": "debian/updater", "name": "CVE-2024-26869", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to truncate meta inode pages forcely Below race case can cause data corruption: Thread A\t\t\t\tGC thread \t\t\t\t\t- gc_data_segment \t\t\t\t\t - ra_data_block \t\t\t\t\t - locked meta_inode page - f2fs_inplace_write_data - invalidate_mapping_pages : fail to invalidate meta_inode page due to lock failure or dirty|writeback status - f2fs_submit_page_bio : write last dirty data to old blkaddr \t\t\t\t\t - move_data_block \t\t\t\t\t - load old data from meta_inode page \t\t\t\t\t - f2fs_submit_page_write \t\t\t\t\t : write old data to new blkaddr Because invalidate_mapping_pages() will skip invalidating page which has unclear status including locked, dirty, writeback and so on, so we need to use truncate_inode_pages_range() instead of invalidate_mapping_pages() to make sure meta_inode page will be dropped.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26869", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "1y4dDNJi+yTWzay2iOe/mQ==": { "id": "1y4dDNJi+yTWzay2iOe/mQ==", "updater": "debian/updater", "name": "CVE-2026-43338", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: reserve enough transaction items for qgroup ioctls Currently our qgroup ioctls don't reserve any space, they just do a transaction join, which does not reserve any space, neither for the quota tree updates nor for the delayed refs generated when updating the quota tree. The quota root uses the global block reserve, which is fine most of the time since we don't expect a lot of updates to the quota root, or to be too close to -ENOSPC such that other critical metadata updates need to resort to the global reserve. However this is not optimal, as not reserving proper space may result in a transaction abort due to not reserving space for delayed refs and then abusing the use of the global block reserve. For example, the following reproducer (which is unlikely to model any real world use case, but just to illustrate the problem), triggers such a transaction abort due to -ENOSPC when running delayed refs: $ cat test.sh #!/bin/bash DEV=/dev/nullb0 MNT=/mnt/nullb0 umount $DEV \u0026\u003e /dev/null # Limit device to 1G so that it's much faster to reproduce the issue. mkfs.btrfs -f -b 1G $DEV mount -o commit=600 $DEV $MNT fallocate -l 800M $MNT/filler btrfs quota enable $MNT for ((i = 1; i \u003c= 400000; i++)); do btrfs qgroup create 1/$i $MNT done umount $MNT When running this, we can see in dmesg/syslog that a transaction abort happened: [436.490] BTRFS error (device nullb0): failed to run delayed ref for logical 30408704 num_bytes 16384 type 176 action 1 ref_mod 1: -28 [436.493] ------------[ cut here ]------------ [436.494] BTRFS: Transaction aborted (error -28) [436.495] WARNING: fs/btrfs/extent-tree.c:2247 at btrfs_run_delayed_refs+0xd9/0x110 [btrfs], CPU#4: umount/2495372 [436.497] Modules linked in: btrfs loop (...) [436.508] CPU: 4 UID: 0 PID: 2495372 Comm: umount Tainted: G W 6.19.0-rc8-btrfs-next-225+ #1 PREEMPT(full) [436.510] Tainted: [W]=WARN [436.511] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [436.513] RIP: 0010:btrfs_run_delayed_refs+0xdf/0x110 [btrfs] [436.514] Code: 0f 82 ea (...) [436.518] RSP: 0018:ffffd511850b7d78 EFLAGS: 00010292 [436.519] RAX: 00000000ffffffe4 RBX: ffff8f120dad37e0 RCX: 0000000002040001 [436.520] RDX: 0000000000000002 RSI: 00000000ffffffe4 RDI: ffffffffc090fd80 [436.522] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffffffc04d1867 [436.523] R10: ffff8f18dc1fffa8 R11: 0000000000000003 R12: ffff8f173aa89400 [436.524] R13: 0000000000000000 R14: ffff8f173aa89400 R15: 0000000000000000 [436.526] FS: 00007fe59045d840(0000) GS:ffff8f192e22e000(0000) knlGS:0000000000000000 [436.527] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [436.528] CR2: 00007fe5905ff2b0 CR3: 000000060710a002 CR4: 0000000000370ef0 [436.530] Call Trace: [436.530] \u003cTASK\u003e [436.530] btrfs_commit_transaction+0x73/0xc00 [btrfs] [436.531] ? btrfs_attach_transaction_barrier+0x1e/0x70 [btrfs] [436.532] sync_filesystem+0x7a/0x90 [436.533] generic_shutdown_super+0x28/0x180 [436.533] kill_anon_super+0x12/0x40 [436.534] btrfs_kill_super+0x12/0x20 [btrfs] [436.534] deactivate_locked_super+0x2f/0xb0 [436.534] cleanup_mnt+0xea/0x180 [436.535] task_work_run+0x58/0xa0 [436.535] exit_to_user_mode_loop+0xed/0x480 [436.536] ? __x64_sys_umount+0x68/0x80 [436.536] do_syscall_64+0x2a5/0xf20 [436.537] entry_SYSCALL_64_after_hwframe+0x76/0x7e [436.537] RIP: 0033:0x7fe5906b6217 [436.538] Code: 0d 00 f7 (...) [436.540] RSP: 002b:00007ffcd87a61f8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 [436.541] RAX: 0000000000000000 RBX: 00005618b9ecadc8 RCX: 00007fe5906b6217 [436.541] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00005618b9ecb100 [436.542] RBP: 0000000000000000 R08: 00007ffcd87a4fe0 R09: 00000000ffffffff [436.544] R10: 0000000000000103 R11: ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43338", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2+1Rq6lvyXFZLzYVLzQGHg==": { "id": "2+1Rq6lvyXFZLzYVLzQGHg==", "updater": "debian/updater", "name": "CVE-2025-71225", "description": "In the Linux kernel, the following vulnerability has been resolved: md: suspend array while updating raid_disks via sysfs In raid1_reshape(), freeze_array() is called before modifying the r1bio memory pool (conf-\u003er1bio_pool) and conf-\u003eraid_disks, and unfreeze_array() is called after the update is completed. However, freeze_array() only waits until nr_sync_pending and (nr_pending - nr_queued) of all buckets reaches zero. When an I/O error occurs, nr_queued is increased and the corresponding r1bio is queued to either retry_list or bio_end_io_list. As a result, freeze_array() may unblock before these r1bios are released. This can lead to a situation where conf-\u003eraid_disks and the mempool have already been updated while queued r1bios, allocated with the old raid_disks value, are later released. Consequently, free_r1bio() may access memory out of bounds in put_all_bios() and release r1bios of the wrong size to the new mempool, potentially causing issues with the mempool as well. Since only normal I/O might increase nr_queued while an I/O error occurs, suspending the array avoids this issue. Note: Updating raid_disks via ioctl SET_ARRAY_INFO already suspends the array. Therefore, we suspend the array when updating raid_disks via sysfs to avoid this issue too.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71225", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "20WfS86dqjcN43OOzbzJHw==": { "id": "20WfS86dqjcN43OOzbzJHw==", "updater": "debian/updater", "name": "CVE-2023-26242", "description": "afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-26242", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "20rC8H84jJQdDsfgxlWDGQ==": { "id": "20rC8H84jJQdDsfgxlWDGQ==", "updater": "debian/updater", "name": "CVE-2026-63845", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 8d0cac9478a3f046279c657d6a2545de49ae675a)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63845", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "21bBfMmtWpw72atVduhNgw==": { "id": "21bBfMmtWpw72atVduhNgw==", "updater": "debian/updater", "name": "CVE-2004-0230", "description": "TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2004-0230", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "22wLUSnOfslxJaWCytMpKg==": { "id": "22wLUSnOfslxJaWCytMpKg==", "updater": "debian/updater", "name": "CVE-2026-68175", "description": "In the Linux kernel, the following vulnerability has been resolved: tracing: Fix resource leak on mmiotrace trace_pipe close The mmiotrace tracer was added May 12th 2008. At that time, resources created in pipe_open() could not be freed because there was not pipe_close function pointer of the tracer. The pipe_close function pointer was added in December 7th, 2009, but the mmiotrace tracer was not updated. mmio_pipe_open() allocates a header_iter and takes a pci_dev reference when trace_pipe is opened. mmio_close() frees them, but it was only wired to the tracer's .close callback. tracing_release_pipe() invokes .pipe_close, not .close, when the trace_pipe file is released. As a result, closing trace_pipe with the mmiotrace tracer active leaked the header_iter allocation and left a stale pci_dev reference. Set .pipe_close to mmio_close, matching how function_graph wires both callbacks to the same handler. Note, if the trace_pipe is read to completion, it will clean up the resources, but if one were to run: # head -n 1 /sys/kernel/tracing/trace_pipe VERSION 20070824 Over and over again, it would trigger a massive leak.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68175", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "24PxqvKQ7Ck9h0t1w2lO5Q==": { "id": "24PxqvKQ7Ck9h0t1w2lO5Q==", "updater": "debian/updater", "name": "CVE-2025-68188", "description": "In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()-\u003eflags.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68188", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "27nVgKdVp5Z2yN+WIh5Ajg==": { "id": "27nVgKdVp5Z2yN+WIh5Ajg==", "updater": "debian/updater", "name": "CVE-2026-45899", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache when splitting extent fails When the split extent fails, we might leave some extents still being processed and return an error directly, which will result in stale extent entries remaining in the extent status tree. So drop all of the remaining potentially stale extents if the splitting fails.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45899", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "29RQTKk7QHtywy1FBm7cYw==": { "id": "29RQTKk7QHtywy1FBm7cYw==", "updater": "debian/updater", "name": "CVE-2026-27171", "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-27171", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "zlib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2DgpNYTsr+vLsgB6jUu6qw==": { "id": "2DgpNYTsr+vLsgB6jUu6qw==", "updater": "debian/updater", "name": "CVE-2026-14668", "description": "Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14668", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2FzvTR+a3XQlWcXmD/u7sQ==": { "id": "2FzvTR+a3XQlWcXmD/u7sQ==", "updater": "debian/updater", "name": "CVE-2019-12382", "description": "An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12382", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2GxrERkUMtotDqNjHyQCbg==": { "id": "2GxrERkUMtotDqNjHyQCbg==", "updater": "debian/updater", "name": "CVE-2019-12379", "description": "An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12379", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2HTtDN23c79rRFsL7WaJ3A==": { "id": "2HTtDN23c79rRFsL7WaJ3A==", "updater": "debian/updater", "name": "CVE-2026-68434", "description": "In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms Commit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected platforms\") replaced the dnv_board setup and exit callbacks with PTR_IF(false, ...), which evaluates to NULL. However, the three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these function pointers without NULL checks, causing a NULL pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), or Snowridge (SNR) platform. Fix this by adding the missing NULL checks before calling the setup and exit callbacks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68434", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2HyLq00ETIjilxA0P7tDoA==": { "id": "2HyLq00ETIjilxA0P7tDoA==", "updater": "debian/updater", "name": "CVE-2024-58094", "description": "In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_truncate_nolock() Added a check for \"read-only\" mode in the `jfs_truncate_nolock` function to avoid errors related to writing to a read-only filesystem. Call stack: block_write_begin() { jfs_write_failed() { jfs_truncate() { jfs_truncate_nolock() { txEnd() { ... log = JFS_SBI(tblk-\u003esb)-\u003elog; // (log == NULL) If the `isReadOnly(ip)` condition is triggered in `jfs_truncate_nolock`, the function execution will stop, and no further data modification will occur. Instead, the `xtTruncate` function will be called with the \"COMMIT_WMAP\" flag, preventing modifications in \"read-only\" mode.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58094", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2Kd7B1qMo9h48Ei0g8TpUg==": { "id": "2Kd7B1qMo9h48Ei0g8TpUg==", "updater": "debian/updater", "name": "CVE-2011-4916", "description": "Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-4916", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2M/vHj3OiKkU7tGWIlYBoQ==": { "id": "2M/vHj3OiKkU7tGWIlYBoQ==", "updater": "debian/updater", "name": "CVE-2023-39616", "description": "AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-39616", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2NjwNSG4kcHNhy2M7KLz4w==": { "id": "2NjwNSG4kcHNhy2M7KLz4w==", "updater": "debian/updater", "name": "CVE-2023-52761", "description": "In the Linux kernel, the following vulnerability has been resolved: riscv: VMAP_STACK overflow detection thread-safe commit 31da94c25aea (\"riscv: add VMAP_STACK overflow detection\") added support for CONFIG_VMAP_STACK. If overflow is detected, CPU switches to `shadow_stack` temporarily before switching finally to per-cpu `overflow_stack`. If two CPUs/harts are racing and end up in over flowing kernel stack, one or both will end up corrupting each other state because `shadow_stack` is not per-cpu. This patch optimizes per-cpu overflow stack switch by directly picking per-cpu `overflow_stack` and gets rid of `shadow_stack`. Following are the changes in this patch - Defines an asm macro to obtain per-cpu symbols in destination register. - In entry.S, when overflow is detected, per-cpu overflow stack is located using per-cpu asm macro. Computing per-cpu symbol requires a temporary register. x31 is saved away into CSR_SCRATCH (CSR_SCRATCH is anyways zero since we're in kernel). Please see Links for additional relevant disccussion and alternative solution. Tested by `echo EXHAUST_STACK \u003e /sys/kernel/debug/provoke-crash/DIRECT` Kernel crash log below Insufficient stack space to handle exception!/debug/provoke-crash/DIRECT Task stack: [0xff20000010a98000..0xff20000010a9c000] Overflow stack: [0xff600001f7d98370..0xff600001f7d99370] CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34 Hardware name: riscv-virtio,qemu (DT) epc : __memset+0x60/0xfc ra : recursive_loop+0x48/0xc6 [lkdtm] epc : ffffffff808de0e4 ra : ffffffff0163a752 sp : ff20000010a97e80 gp : ffffffff815c0330 tp : ff600000820ea280 t0 : ff20000010a97e88 t1 : 000000000000002e t2 : 3233206874706564 s0 : ff20000010a982b0 s1 : 0000000000000012 a0 : ff20000010a97e88 a1 : 0000000000000000 a2 : 0000000000000400 a3 : ff20000010a98288 a4 : 0000000000000000 a5 : 0000000000000000 a6 : fffffffffffe43f0 a7 : 00007fffffffffff s2 : ff20000010a97e88 s3 : ffffffff01644680 s4 : ff20000010a9be90 s5 : ff600000842ba6c0 s6 : 00aaaaaac29e42b0 s7 : 00fffffff0aa3684 s8 : 00aaaaaac2978040 s9 : 0000000000000065 s10: 00ffffff8a7cad10 s11: 00ffffff8a76a4e0 t3 : ffffffff815dbaf4 t4 : ffffffff815dbaf4 t5 : ffffffff815dbab8 t6 : ff20000010a9bb48 status: 0000000200000120 badaddr: ff20000010a97e88 cause: 000000000000000f Kernel panic - not syncing: Kernel stack overflow CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34 Hardware name: riscv-virtio,qemu (DT) Call Trace: [\u003cffffffff80006754\u003e] dump_backtrace+0x30/0x38 [\u003cffffffff808de798\u003e] show_stack+0x40/0x4c [\u003cffffffff808ea2a8\u003e] dump_stack_lvl+0x44/0x5c [\u003cffffffff808ea2d8\u003e] dump_stack+0x18/0x20 [\u003cffffffff808dec06\u003e] panic+0x126/0x2fe [\u003cffffffff800065ea\u003e] walk_stackframe+0x0/0xf0 [\u003cffffffff0163a752\u003e] recursive_loop+0x48/0xc6 [lkdtm] SMP: stopping secondary CPUs ---[ end Kernel panic - not syncing: Kernel stack overflow ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52761", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2OZ7trlKRLnZsFv1sJvUVg==": { "id": "2OZ7trlKRLnZsFv1sJvUVg==", "updater": "debian/updater", "name": "CVE-2026-43173", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ethernet: xscale: Check for PTP support properly In ixp4xx_get_ts_info() ixp46x_ptp_find() is called unconditionally despite this feature only existing on ixp46x, leading to the following splat from tcpdump: root@OpenWrt:~# tcpdump -vv -X -i eth0 (...) Unable to handle kernel NULL pointer dereference at virtual address 00000238 when read (...) Call trace: ptp_clock_index from ixp46x_ptp_find+0x1c/0x38 ixp46x_ptp_find from ixp4xx_get_ts_info+0x4c/0x64 ixp4xx_get_ts_info from __ethtool_get_ts_info+0x90/0x108 __ethtool_get_ts_info from __dev_ethtool+0xa00/0x2648 __dev_ethtool from dev_ethtool+0x160/0x234 dev_ethtool from dev_ioctl+0x2cc/0x460 dev_ioctl from sock_ioctl+0x1ec/0x524 sock_ioctl from sys_ioctl+0x51c/0xa94 sys_ioctl from ret_fast_syscall+0x0/0x44 (...) Segmentation fault Check for ixp46x in ixp46x_ptp_find() before trying to set up PTP to avoid this. To avoid altering the returned error code from ixp4xx_hwtstamp_set() which before this patch was -EOPNOTSUPP, we return -EOPNOTSUPP from ixp4xx_hwtstamp_set() if ixp46x_ptp_find() fails no matter the error code. The helper function ixp46x_ptp_find() helper returns -ENODEV.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43173", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2Rj37iOfBDGFAoEcyBe2Wg==": { "id": "2Rj37iOfBDGFAoEcyBe2Wg==", "updater": "debian/updater", "name": "CVE-2025-21635", "description": "In the Linux kernel, the following vulnerability has been resolved: rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current-\u003ensproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons: - Inconsistency: getting info from the reader's/writer's netns vs only from the opener's netns. - current-\u003ensproxy can be NULL in some cases, resulting in an 'Oops' (null-ptr-deref), e.g. when the current task is exiting, as spotted by syzbot [1] using acct(2). The per-netns structure can be obtained from the table-\u003edata using container_of(), then the 'net' one can be retrieved from the listen socket (if available).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21635", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2TIb7FMvCnflY0kS4ZA16g==": { "id": "2TIb7FMvCnflY0kS4ZA16g==", "updater": "debian/updater", "name": "CVE-2026-62289", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-62289", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2TjC60sJ2qX3uuSPiJQTaw==": { "id": "2TjC60sJ2qX3uuSPiJQTaw==", "updater": "debian/updater", "name": "CVE-2024-53090", "description": "In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is called from AF_RXRPC whilst holding the -\u003enotify_lock, but it tries to take a ref on the afs_call struct in order to pass it to a work queue - but if the afs_call is already queued, we then have an extraneous ref that must be put... calling afs_put_call() may call back down into AF_RXRPC through rxrpc_kernel_shutdown_call(), however, which might try taking the -\u003enotify_lock again. This case isn't very common, however, so defer it to a workqueue. The oops looks something like: BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646 lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/7001/1646, .owner_cpu: 0 CPU: 0 UID: 0 PID: 1646 Comm: krxrpcio/7001 Not tainted 6.12.0-rc2-build3+ #4351 Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x47/0x70 do_raw_spin_lock+0x3c/0x90 rxrpc_kernel_shutdown_call+0x83/0xb0 afs_put_call+0xd7/0x180 rxrpc_notify_socket+0xa0/0x190 rxrpc_input_split_jumbo+0x198/0x1d0 rxrpc_input_data+0x14b/0x1e0 ? rxrpc_input_call_packet+0xc2/0x1f0 rxrpc_input_call_event+0xad/0x6b0 rxrpc_input_packet_on_conn+0x1e1/0x210 rxrpc_input_packet+0x3f2/0x4d0 rxrpc_io_thread+0x243/0x410 ? __pfx_rxrpc_io_thread+0x10/0x10 kthread+0xcf/0xe0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x24/0x40 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53090", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2UEXWkLtrRPgNGWIp1Hx1A==": { "id": "2UEXWkLtrRPgNGWIp1Hx1A==", "updater": "debian/updater", "name": "CVE-2024-27079", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix NULL domain on device release In the kdump kernel, the IOMMU operates in deferred_attach mode. In this mode, info-\u003edomain may not yet be assigned by the time the release_device function is called. It leads to the following crash in the crash kernel: BUG: kernel NULL pointer dereference, address: 000000000000003c ... RIP: 0010:do_raw_spin_lock+0xa/0xa0 ... _raw_spin_lock_irqsave+0x1b/0x30 intel_iommu_release_device+0x96/0x170 iommu_deinit_device+0x39/0xf0 __iommu_group_remove_device+0xa0/0xd0 iommu_bus_notifier+0x55/0xb0 notifier_call_chain+0x5a/0xd0 blocking_notifier_call_chain+0x41/0x60 bus_notify+0x34/0x50 device_del+0x269/0x3d0 pci_remove_bus_device+0x77/0x100 p2sb_bar+0xae/0x1d0 ... i801_probe+0x423/0x740 Use the release_domain mechanism to fix it. The scalable mode context entry which is not part of release domain should be cleared in release_device().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27079", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2Y8tgHjdLW66sj5oytXtRg==": { "id": "2Y8tgHjdLW66sj5oytXtRg==", "updater": "debian/updater", "name": "CVE-2026-68250", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68250", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2cW+3rxkcATjxvNqtyRwZQ==": { "id": "2cW+3rxkcATjxvNqtyRwZQ==", "updater": "debian/updater", "name": "CVE-2025-38127", "description": "In the Linux kernel, the following vulnerability has been resolved: ice: fix Tx scheduler error handling in XDP callback When the XDP program is loaded, the XDP callback adds new Tx queues. This means that the callback must update the Tx scheduler with the new queue number. In the event of a Tx scheduler failure, the XDP callback should also fail and roll back any changes previously made for XDP preparation. The previous implementation had a bug that not all changes made by the XDP callback were rolled back. This caused the crash with the following call trace: [ +9.549584] ice 0000:ca:00.0: Failed VSI LAN queue config for XDP, error: -5 [ +0.382335] Oops: general protection fault, probably for non-canonical address 0x50a2250a90495525: 0000 [#1] SMP NOPTI [ +0.010710] CPU: 103 UID: 0 PID: 0 Comm: swapper/103 Not tainted 6.14.0-net-next-mar-31+ #14 PREEMPT(voluntary) [ +0.010175] Hardware name: Intel Corporation M50CYP2SBSTD/M50CYP2SBSTD, BIOS SE5C620.86B.01.01.0005.2202160810 02/16/2022 [ +0.010946] RIP: 0010:__ice_update_sample+0x39/0xe0 [ice] [...] [ +0.002715] Call Trace: [ +0.002452] \u003cIRQ\u003e [ +0.002021] ? __die_body.cold+0x19/0x29 [ +0.003922] ? die_addr+0x3c/0x60 [ +0.003319] ? exc_general_protection+0x17c/0x400 [ +0.004707] ? asm_exc_general_protection+0x26/0x30 [ +0.004879] ? __ice_update_sample+0x39/0xe0 [ice] [ +0.004835] ice_napi_poll+0x665/0x680 [ice] [ +0.004320] __napi_poll+0x28/0x190 [ +0.003500] net_rx_action+0x198/0x360 [ +0.003752] ? update_rq_clock+0x39/0x220 [ +0.004013] handle_softirqs+0xf1/0x340 [ +0.003840] ? sched_clock_cpu+0xf/0x1f0 [ +0.003925] __irq_exit_rcu+0xc2/0xe0 [ +0.003665] common_interrupt+0x85/0xa0 [ +0.003839] \u003c/IRQ\u003e [ +0.002098] \u003cTASK\u003e [ +0.002106] asm_common_interrupt+0x26/0x40 [ +0.004184] RIP: 0010:cpuidle_enter_state+0xd3/0x690 Fix this by performing the missing unmapping of XDP queues from q_vectors and setting the XDP rings pointer back to NULL after all those queues are released. Also, add an immediate exit from the XDP callback in case of ring preparation failure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38127", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2cydAg9zvkUhWdDZ3rvr3g==": { "id": "2cydAg9zvkUhWdDZ3rvr3g==", "updater": "debian/updater", "name": "CVE-2025-39677", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix backlog accounting in qdisc_dequeue_internal This issue applies for the following qdiscs: hhf, fq, fq_codel, and fq_pie, and occurs in their change handlers when adjusting to the new limit. The problem is the following in the values passed to the subsequent qdisc_tree_reduce_backlog call given a tbf parent: When the tbf parent runs out of tokens, skbs of these qdiscs will be placed in gso_skb. Their peek handlers are qdisc_peek_dequeued, which accounts for both qlen and backlog. However, in the case of qdisc_dequeue_internal, ONLY qlen is accounted for when pulling from gso_skb. This means that these qdiscs are missing a qdisc_qstats_backlog_dec when dropping packets to satisfy the new limit in their change handlers. One can observe this issue with the following (with tc patched to support a limit of 0): export TARGET=fq tc qdisc del dev lo root tc qdisc add dev lo root handle 1: tbf rate 8bit burst 100b latency 1ms tc qdisc replace dev lo handle 3: parent 1:1 $TARGET limit 1000 echo ''; echo 'add child'; tc -s -d qdisc show dev lo ping -I lo -f -c2 -s32 -W0.001 127.0.0.1 2\u003e\u00261 \u003e/dev/null echo ''; echo 'after ping'; tc -s -d qdisc show dev lo tc qdisc change dev lo handle 3: parent 1:1 $TARGET limit 0 echo ''; echo 'after limit drop'; tc -s -d qdisc show dev lo tc qdisc replace dev lo handle 2: parent 1:1 sfq echo ''; echo 'post graft'; tc -s -d qdisc show dev lo The second to last show command shows 0 packets but a positive number (74) of backlog bytes. The problem becomes clearer in the last show command, where qdisc_purge_queue triggers qdisc_tree_reduce_backlog with the positive backlog and causes an underflow in the tbf parent's backlog (4096 Mb instead of 0). To fix this issue, the codepath for all clients of qdisc_dequeue_internal has been simplified: codel, pie, hhf, fq, fq_pie, and fq_codel. qdisc_dequeue_internal handles the backlog adjustments for all cases that do not directly use the dequeue handler. The old fq_codel_change limit adjustment loop accumulated the arguments to the subsequent qdisc_tree_reduce_backlog call through the cstats field. However, this is confusing and error prone as fq_codel_dequeue could also potentially mutate this field (which qdisc_dequeue_internal calls in the non gso_skb case), so we have unified the code here with other qdiscs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39677", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2fU9DFSbokep7QHBQAIDEA==": { "id": "2fU9DFSbokep7QHBQAIDEA==", "updater": "debian/updater", "name": "CVE-2024-56591", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Use disable_delayed_work_sync This makes use of disable_delayed_work_sync instead cancel_delayed_work_sync as it not only cancel the ongoing work but also disables new submit which is disarable since the object holding the work is about to be freed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56591", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2gIKJ24NaTvU5hH8MoOEHg==": { "id": "2gIKJ24NaTvU5hH8MoOEHg==", "updater": "debian/updater", "name": "CVE-2023-53336", "description": "In the Linux kernel, the following vulnerability has been resolved: media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings When ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run sensor-\u003eadev is not set yet. So if either of the dev_warn() calls about unknown values are hit this will lead to a NULL pointer deref. Set sensor-\u003eadev earlier, with a borrowed ref to avoid making unrolling on errors harder, to fix this.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53336", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2k3Srs8A63nD7VMc8eJGDg==": { "id": "2k3Srs8A63nD7VMc8eJGDg==", "updater": "debian/updater", "name": "CVE-2026-46245", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD init amdgpu_dm_hpd_init() may see connectors without a valid dc_link. The code already checks dc_link for the polling decision, but later unconditionally dereferences it when setting up HPD interrupts. Assign dc_link early and skip connectors where it is NULL. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c:940 amdgpu_dm_hpd_init() error: we previously assumed 'dc_link' could be null (see line 931) drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c 923 /* 924 * Analog connectors may be hot-plugged unlike other connector 925 * types that don't support HPD. Only poll analog connectors. 926 */ 927 use_polling |= 928 amdgpu_dm_connector-\u003edc_link \u0026\u0026 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ The patch adds this NULL check but hopefully it can be removed 929 dc_connector_supports_analog(amdgpu_dm_connector-\u003edc_link-\u003elink_id.id); 930 931 dc_link = amdgpu_dm_connector-\u003edc_link; dc_link assigned here. 932 933 /* 934 * Get a base driver irq reference for hpd ints for the lifetime 935 * of dm. Note that only hpd interrupt types are registered with 936 * base driver; hpd_rx types aren't. IOW, amdgpu_irq_get/put on 937 * hpd_rx isn't available. DM currently controls hpd_rx 938 * explicitly with dc_interrupt_set() 939 */ --\u003e 940 if (dc_link-\u003eirq_source_hpd != DC_IRQ_SOURCE_INVALID) { ^^^^^^^^^^^^^^^^^^^^^^^ If it's NULL then we are trouble because we dereference it here. 941 irq_type = dc_link-\u003eirq_source_hpd - DC_IRQ_SOURCE_HPD1; 942 /* 943 * TODO: There's a mismatch between mode_info.num_hpd 944 * and what bios reports as the # of connectors with hpd", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46245", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2lyKtAO8fWwobKAd5ksImw==": { "id": "2lyKtAO8fWwobKAd5ksImw==", "updater": "debian/updater", "name": "CVE-2026-11972", "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11972", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2ot4aIu0LulaiafAuekqiQ==": { "id": "2ot4aIu0LulaiafAuekqiQ==", "updater": "debian/updater", "name": "CVE-2024-49926", "description": "In the Linux kernel, the following vulnerability has been resolved: rcu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb() For kernels built with CONFIG_FORCE_NR_CPUS=y, the nr_cpu_ids is defined as NR_CPUS instead of the number of possible cpus, this will cause the following system panic: smpboot: Allowing 4 CPUs, 0 hotplug CPUs ... setup_percpu: NR_CPUS:512 nr_cpumask_bits:512 nr_cpu_ids:512 nr_node_ids:1 ... BUG: unable to handle page fault for address: ffffffff9911c8c8 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 0 PID: 15 Comm: rcu_tasks_trace Tainted: G W 6.6.21 #1 5dc7acf91a5e8e9ac9dcfc35bee0245691283ea6 RIP: 0010:rcu_tasks_need_gpcb+0x25d/0x2c0 RSP: 0018:ffffa371c00a3e60 EFLAGS: 00010082 CR2: ffffffff9911c8c8 CR3: 000000040fa20005 CR4: 00000000001706f0 Call Trace: \u003cTASK\u003e ? __die+0x23/0x80 ? page_fault_oops+0xa4/0x180 ? exc_page_fault+0x152/0x180 ? asm_exc_page_fault+0x26/0x40 ? rcu_tasks_need_gpcb+0x25d/0x2c0 ? __pfx_rcu_tasks_kthread+0x40/0x40 rcu_tasks_one_gp+0x69/0x180 rcu_tasks_kthread+0x94/0xc0 kthread+0xe8/0x140 ? __pfx_kthread+0x40/0x40 ret_from_fork+0x34/0x80 ? __pfx_kthread+0x40/0x40 ret_from_fork_asm+0x1b/0x80 \u003c/TASK\u003e Considering that there may be holes in the CPU numbers, use the maximum possible cpu number, instead of nr_cpu_ids, for configuring enqueue and dequeue limits. [ neeraj.upadhyay: Fix htmldocs build error reported by Stephen Rothwell ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49926", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2oxlB1EOQ09AptLb1N+Vtw==": { "id": "2oxlB1EOQ09AptLb1N+Vtw==", "updater": "debian/updater", "name": "CVE-2024-46834", "description": "In the Linux kernel, the following vulnerability has been resolved: ethtool: fail closed if we can't get max channel used in indirection tables Commit 0d1b7d6c9274 (\"bnxt: fix crashes when reducing ring count with active RSS contexts\") proves that allowing indirection table to contain channels with out of bounds IDs may lead to crashes. Currently the max channel check in the core gets skipped if driver can't fetch the indirection table or when we can't allocate memory. Both of those conditions should be extremely rare but if they do happen we should try to be safe and fail the channel change.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46834", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2tcTjjafTpV2Ov8GmqFflA==": { "id": "2tcTjjafTpV2Ov8GmqFflA==", "updater": "debian/updater", "name": "CVE-2026-68284", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock-\u003ecork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock-\u003ecork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock-\u003ecork = NULL frees the cork reacquires the socket lock msg_tx != psock-\u003ecork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported: BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0 msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock-\u003ecork cannot turn a shared message into an apparent local one.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68284", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2uOzzZZ2kCVXzbYFBm8+Hw==": { "id": "2uOzzZZ2kCVXzbYFBm8+Hw==", "updater": "debian/updater", "name": "CVE-2025-38039", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled When attempting to enable MQPRIO while HTB offload is already configured, the driver currently returns `-EINVAL` and triggers a `WARN_ON`, leading to an unnecessary call trace. Update the code to handle this case more gracefully by returning `-EOPNOTSUPP` instead, while also providing a helpful user message.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38039", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2xNoBNSp7fweMAQExE+o+Q==": { "id": "2xNoBNSp7fweMAQExE+o+Q==", "updater": "debian/updater", "name": "CVE-2026-5928", "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp-\u003e_IO_read_ptr) instead of the actual wide-stream read pointer (fp-\u003e_wide_data-\u003e_IO_read_ptr). The program crash may happen in cases where fp-\u003e_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-5928", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "2yv1l3MuYdv6baRDFoTAXw==": { "id": "2yv1l3MuYdv6baRDFoTAXw==", "updater": "debian/updater", "name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-9937", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "jbigkit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3+Zo5MGd6Ee9xwAYwT9nSw==": { "id": "3+Zo5MGd6Ee9xwAYwT9nSw==", "updater": "debian/updater", "name": "CVE-2024-50017", "description": "In the Linux kernel, the following vulnerability has been resolved: x86/mm/ident_map: Use gbpages only where full GB page should be mapped. When ident_pud_init() uses only GB pages to create identity maps, large ranges of addresses not actually requested can be included in the resulting table; a 4K request will map a full GB. This can include a lot of extra address space past that requested, including areas marked reserved by the BIOS. That allows processor speculation into reserved regions, that on UV systems can cause system halts. Only use GB pages when map creation requests include the full GB page of space. Fall back to using smaller 2M pages when only portions of a GB page are included in the request. No attempt is made to coalesce mapping requests. If a request requires a map entry at the 2M (pmd) level, subsequent mapping requests within the same 1G region will also be at the pmd level, even if adjacent or overlapping such requests could have been combined to map a full GB page. Existing usage starts with larger regions and then adds smaller regions, so this should not have any great consequence.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50017", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "304DlzeJN7v/P5lwODadIQ==": { "id": "304DlzeJN7v/P5lwODadIQ==", "updater": "debian/updater", "name": "CVE-2026-68129", "description": "In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the system is under extreme memory pressure, page allocations can fail during the Rx buffer refill loop. If the number of buffers posted to hardware falls below a critical low threshold and the refill loop exits due to allocation failures, the queue can stall: 1. The device drops incoming packets because there are no descriptors. 2. Since no packets are processed, no Rx completions are generated. 3. Because no completions occur, NAPI is never scheduled, preventing the refill loop from running again even after memory is freed. This results in a permanent queue stall. Resolve this by introducing a starvation recovery timer for each Rx queue. If the number of buffers posted to hardware falls below a critical low threshold, start a timer to periodically reschedule NAPI. Once NAPI runs and successfully refills the queue above the threshold, the timer is not rescheduled. The threshold is set to 32 because a single maximum-sized Receive Segment Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path. Lower thresholds (such as 8 or 16) would be insufficient to process a complete maximum-sized RSC packet, risking packet drops or unexpected hardware behavior under memory pressure. Setting the threshold to 32 guarantees a safe margin to handle at least one full RSC packet.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68129", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "334T6GRBjc5YGYpYynk7jA==": { "id": "334T6GRBjc5YGYpYynk7jA==", "updater": "debian/updater", "name": "CVE-2026-68176", "description": "In the Linux kernel, the following vulnerability has been resolved: tracing: Fix mmiotrace possible NULL dereferencing of hiter-\u003edev If the mmio_pipe_open() fails to find a PCI device, the hiter-\u003edev will be assigned to NULL. The mmiotrace read() function dereferences the hiter-\u003edev if hiter exists. Change the test of the read to not only check hiter being NULL, but also the hiter-\u003edev before dereferencing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68176", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3C0sccvTPaFIh87pG5TC1Q==": { "id": "3C0sccvTPaFIh87pG5TC1Q==", "updater": "debian/updater", "name": "CVE-2026-54240", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54240", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3FdoYCjfuaH69GQGMCkueA==": { "id": "3FdoYCjfuaH69GQGMCkueA==", "updater": "debian/updater", "name": "CVE-2026-14670", "description": "Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14670", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3Gnrg1HuF80NYk8sDg8vpw==": { "id": "3Gnrg1HuF80NYk8sDg8vpw==", "updater": "debian/updater", "name": "CVE-2019-16234", "description": "drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16234", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3HM9ZkaDf/qSqto+kg5bSQ==": { "id": "3HM9ZkaDf/qSqto+kg5bSQ==", "updater": "debian/updater", "name": "CVE-2026-46130", "description": "In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never split across parity blocks. This assumption is false. Consider v-\u003efec-\u003eblock_size == 4096 \u0026\u0026 v-\u003efec-\u003eroots == 17 \u0026\u0026 fio-\u003enbufs == 1, for example. In that case, each call to fec_decode_bufs() consumes v-\u003efec-\u003eroots * (fio-\u003enbufs \u003c\u003c DM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes. Considering that the parity data for each message block starts on a block boundary, the byte alignment in the parity data will iterate through 272*i mod 4096 until the 3 parity blocks have been consumed. On the 16th call (i=15), the alignment will be 4080 bytes into the first block. Only 16 bytes remain in that block, but 17 parity bytes will be needed. The code reads out-of-bounds from the parity block buffer. Fortunately this doesn't normally happen, since it can occur only for certain non-default values of fec_roots *and* when the maximum number of buffers couldn't be allocated due to low memory. For example with block_size=4096 only the following cases are affected: fec_roots=17: nbufs in [1, 3, 5, 15] fec_roots=19: nbufs in [1, 229] fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195] fec_roots=23: nbufs in [1, 89] Regardless, fix it by refactoring how the parity blocks are read.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46130", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3I+BoetlmVjDN6jsA7RnYA==": { "id": "3I+BoetlmVjDN6jsA7RnYA==", "updater": "debian/updater", "name": "CVE-2024-26947", "description": "In the Linux kernel, the following vulnerability has been resolved: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses Since commit a4d5613c4dc6 (\"arm: extend pfn_valid to take into account freed memory map alignment\") changes the semantics of pfn_valid() to check presence of the memory map for a PFN. A valid page for an address which is reserved but not mapped by the kernel[1], the system crashed during some uio test with the following memory layout: node 0: [mem 0x00000000c0a00000-0x00000000cc8fffff] node 0: [mem 0x00000000d0000000-0x00000000da1fffff] the uio layout is:0xc0900000, 0x100000 the crash backtrace like: Unable to handle kernel paging request at virtual address bff00000 [...] CPU: 1 PID: 465 Comm: startapp.bin Tainted: G O 5.10.0 #1 Hardware name: Generic DT based system PC is at b15_flush_kern_dcache_area+0x24/0x3c LR is at __sync_icache_dcache+0x6c/0x98 [...] (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98) (__sync_icache_dcache) from (set_pte_at+0x28/0x54) (set_pte_at) from (remap_pfn_range+0x1a0/0x274) (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio]) (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4) (__mmap_region) from (__do_mmap_mm+0x3ec/0x440) (__do_mmap_mm) from (do_mmap+0x50/0x58) (do_mmap) from (vm_mmap_pgoff+0xfc/0x188) (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4) (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c) Code: e0801001 e2423001 e1c00003 f57ff04f (ee070f3e) ---[ end trace 09cf0734c3805d52 ]--- Kernel panic - not syncing: Fatal exception So check if PG_reserved was set to solve this issue. [1]: https://lore.kernel.org/lkml/Zbtdue57RO0QScJM@linux.ibm.com/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26947", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3Krrzfra6fyC5xAOG8aVdA==": { "id": "3Krrzfra6fyC5xAOG8aVdA==", "updater": "debian/updater", "name": "CVE-2026-68329", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() need_sync is a per-IOMMU flag shared by all domains and devices behind that IOMMU. It is set whenever a command is queued with sync == true and cleared when a completion-wait (CWAIT) command is queued. However, a cleared need_sync only means that a covering CWAIT has been queued, not that all previously queued commands have actually completed in hardware. iommu_completion_wait() read need_sync locklessly and returned early when it was false. This breaks the \"block until all previously queued commands have completed\" contract in a multi-CPU scenario: CPU2: queue inv-B =\u003e need_sync = true CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N) CPU2: read need_sync == false =\u003e return 0 (no wait!) CPU2 returns without waiting for any sequence number even though its inv-B may not have completed yet (CWAIT(N), queued after inv-B, has not been signaled). CPU2 then proceeds to, for example, free page-table pages while the IOMMU can still walk stale translations, opening a use-after-free window. This is a logical race in the meaning of the flag, not a memory-visibility issue, so barriers alone do not help. Fix it without losing the optimization of avoiding redundant CWAIT commands: take iommu-\u003elock before testing need_sync, and when it is false do not return early but wait for the last allocated sequence number (cmd_sem_val). Since need_sync == false implies no sync command was queued after the last CWAIT, that CWAIT is FIFO-ordered after every not-yet-completed command, so waiting for its sequence number guarantees all prior commands (possibly queued by another CPU) have completed. The common path with pending work is unchanged and no extra hardware command is issued.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68329", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3TnfqY55bHsUZcxqm7CvkA==": { "id": "3TnfqY55bHsUZcxqm7CvkA==", "updater": "debian/updater", "name": "CVE-2026-56407", "description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56407", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3VkUenslT5nKy0iJQN6Utw==": { "id": "3VkUenslT5nKy0iJQN6Utw==", "updater": "debian/updater", "name": "CVE-2025-37777", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __smb2_lease_break_noti() Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed, but conn-\u003etcp_transport is freed. __smb2_lease_break_noti can be performed asynchronously when the connection is disconnected. __smb2_lease_break_noti calls ksmbd_conn_write, which can cause use-after-free when conn-\u003eksmbd_transport is already freed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37777", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3iEhx4hZJtBmBc6kQmlOuQ==": { "id": "3iEhx4hZJtBmBc6kQmlOuQ==", "updater": "debian/updater", "name": "CVE-2025-38132", "description": "In the Linux kernel, the following vulnerability has been resolved: coresight: holding cscfg_csdev_lock while removing cscfg from csdev There'll be possible race scenario for coresight config: CPU0 CPU1 (perf enable) load module cscfg_load_config_sets() activate config. // sysfs (sys_active_cnt == 1) ... cscfg_csdev_enable_active_config() lock(csdev-\u003ecscfg_csdev_lock) deactivate config // sysfs (sys_activec_cnt == 0) cscfg_unload_config_sets() \u003citerating config_csdev_list\u003e cscfg_remove_owned_csdev_configs() // here load config activate by CPU1 unlock(csdev-\u003ecscfg_csdev_lock) iterating config_csdev_list could be raced with config_csdev_list's entry delete. To resolve this race , hold csdev-\u003ecscfg_csdev_lock() while cscfg_remove_owned_csdev_configs()", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38132", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3jDKPTolYWHmJt68mR0ScA==": { "id": "3jDKPTolYWHmJt68mR0ScA==", "updater": "debian/updater", "name": "CVE-2024-47658", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce a produces a spinlock recursion warning. The reason is the fact that BH must be disabled during this process.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47658", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3kIHF9M2LBX4Rx2YoP5boA==": { "id": "3kIHF9M2LBX4Rx2YoP5boA==", "updater": "debian/updater", "name": "CVE-2026-68209", "description": "In the Linux kernel, the following vulnerability has been resolved: media: sun4i-csi: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. sun4i_csi_start_streaming() returned -EINVAL when no matching CSI format could be found, before any setup (scratch buffer allocation, pipeline start) had been performed. The remaining error paths already converge on the err_clear_dma_queue label, which calls return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi-\u003eqlock. Jump to that label directly: the intermediate err_disable_device / err_disable_pipeline / err_free_scratch_buffer labels are skipped, which is correct because nothing they would undo has happened yet. This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68209", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3lax9jHcdE4WSI3FQmqtaQ==": { "id": "3lax9jHcdE4WSI3FQmqtaQ==", "updater": "debian/updater", "name": "CVE-2026-46156", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() The switch case in loongson_gpu_fixup_dma_hang() may not DC2 or DC3, and readl(crtc_reg) will access with random address, because the \"device\" is from \"base+PCI_DEVICE_ID\", \"base\" is from \"pdev-\u003edevfn+1\". This is wrong when my platform inserts a discrete GPU: lspci -tv -[0000:00]-+-00.0 Loongson Technology LLC Hyper Transport Bridge Controller ... +-06.0 Loongson Technology LLC LG100 GPU +-06.2 Loongson Technology LLC Device 7a37 ... Add a default switch case to fix the panic as below: Kernel ade access[#1]: CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.6.136-loong64-desktop-hwe+ #4 pc 90000000017e5534 ra 90000000017e54c0 tp 90000001002f8000 sp 90000001002fb6c0 a0 80000efe00003100 a1 0000000000003100 a2 0000000000000000 a3 0000000000000002 a4 90000001002fb6b4 a5 900000087cdb58fd a6 90000000027af000 a7 0000000000000001 t0 00000000000085b9 t1 000000000000ffff t2 0000000000000000 t3 0000000000000000 t4 fffffffffffffffd t5 00000000fffb6d9c t6 0000000000083b00 t7 00000000000070c0 t8 900000087cdb4d94 u0 900000087cdb58fd s9 90000001002fb826 s0 90000000031c12c8 s1 7fffffffffffff00 s2 90000000031c12d0 s3 0000000000002710 s4 0000000000000000 s5 0000000000000000 s6 9000000100053000 s7 7fffffffffffff00 s8 90000000030d4000 ra: 90000000017e54c0 loongson_gpu_fixup_dma_hang+0x40/0x210 ERA: 90000000017e5534 loongson_gpu_fixup_dma_hang+0xb4/0x210 CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) PRMD: 00000004 (PPLV0 +PIE -PWE) EUEN: 00000000 (-FPE -SXE -ASXE -BTE) ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7) ESTAT: 00480000 [ADEM] (IS= ECode=8 EsubCode=1) BADV: 7fffffffffffff00 PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV) Modules linked in: Process swapper/0 (pid: 1, threadinfo=(____ptrval____), task=(____ptrval____)) Stack : 0000000000000006 90000001002fb778 90000001002fb704 0000000000000007 0000000016a65700 90000000017e5690 000000000000ffff ffffffffffffffff 900000000209f7c0 9000000100053000 900000000209f7a8 9000000000eebc08 0000000000000000 0000000000000000 0000000000000006 90000001002fb778 90000001000530b8 90000000027af000 0000000000000000 9000000100054000 9000000100053000 9000000000ebb70c 9000000100004c00 9000000004000001 90000001002fb7e4 bae765461f31cb12 0000000000000000 0000000000000000 0000000000000006 90000000027af000 0000000000000030 90000000027af000 900000087cd6f800 9000000100053000 0000000000000000 9000000000ebc560 7a2500147cdaf720 bae765461f31cb12 0000000000000001 0000000000000030 ... Call Trace: [\u003c90000000017e5534\u003e] loongson_gpu_fixup_dma_hang+0xb4/0x210 [\u003c9000000000eebc08\u003e] pci_fixup_device+0x108/0x280 [\u003c9000000000ebb70c\u003e] pci_setup_device+0x24c/0x690 [\u003c9000000000ebc560\u003e] pci_scan_single_device+0xe0/0x140 [\u003c9000000000ebc684\u003e] pci_scan_slot+0xc4/0x280 [\u003c9000000000ebdd00\u003e] pci_scan_child_bus_extend+0x60/0x3f0 [\u003c9000000000f5bc94\u003e] acpi_pci_root_create+0x2b4/0x420 [\u003c90000000017e5e74\u003e] pci_acpi_scan_root+0x2d4/0x440 [\u003c9000000000f5b02c\u003e] acpi_pci_root_add+0x21c/0x3a0 [\u003c9000000000f4ee54\u003e] acpi_bus_attach+0x1a4/0x3c0 [\u003c90000000010e200c\u003e] device_for_each_child+0x6c/0xe0 [\u003c9000000000f4bbf4\u003e] acpi_dev_for_each_child+0x44/0x70 [\u003c9000000000f4ef40\u003e] acpi_bus_attach+0x290/0x3c0 [\u003c90000000010e200c\u003e] device_for_each_child+0x6c/0xe0 [\u003c9000000000f4bbf4\u003e] acpi_dev_for_each_child+0x44/0x70 [\u003c9000000000f4ef40\u003e] acpi_bus_attach+0x290/0x3c0 [\u003c9000000000f5211c\u003e] acpi_bus_scan+0x6c/0x280 [\u003c900000000189c028\u003e] acpi_scan_init+0x194/0x310 [\u003c900000000189bc6c\u003e] acpi_init+0xcc/0x140 [\u003c9000000000220cdc\u003e] do_one_initcall+0x4c/0x310 [\u003c90000000018618fc\u003e] kernel_init_freeable+0x258/0x2d4 [\u003c900000000184326c\u003e] kernel_init+0x28/0x13c [\u003c9000000000222008\u003e] ret_from_kernel_thread+0xc/0xa4", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46156", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3qkUNBO5aPJqcJSUaSFBCg==": { "id": "3qkUNBO5aPJqcJSUaSFBCg==", "updater": "debian/updater", "name": "CVE-2026-53070", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmit_skb() udp_tunnel_xmit_skb() / udp_tunnel6_xmit_skb() are expected to run with BH disabled. After commit 6f1a9140ecda (\"add xmit recursion limit to tunnel xmit functions\"), on the path: udp(6)_tunnel_xmit_skb() -\u003e ip(6)tunnel_xmit() dev_xmit_recursion_inc()/dec() must stay balanced on the same CPU. Without local_bh_disable(), the context may move between CPUs, which can break the inc/dec pairing. This may lead to incorrect recursion level detection and cause packets to be dropped in ip(6)_tunnel_xmit() or __dev_queue_xmit(). Fix it by disabling BH around both IPv4 and IPv6 SCTP UDP xmit paths. In my testing, after enabling the SCTP over UDP: # ip net exec ha sysctl -w net.sctp.udp_port=9899 # ip net exec ha sysctl -w net.sctp.encap_port=9899 # ip net exec hb sysctl -w net.sctp.udp_port=9899 # ip net exec hb sysctl -w net.sctp.encap_port=9899 # ip net exec ha iperf3 -s - without this patch: # ip net exec hb iperf3 -c 192.168.0.1 --sctp [ 5] 0.00-10.00 sec 37.2 MBytes 31.2 Mbits/sec sender [ 5] 0.00-10.00 sec 37.1 MBytes 31.1 Mbits/sec receiver - with this patch: # ip net exec hb iperf3 -c 192.168.0.1 --sctp [ 5] 0.00-10.00 sec 3.14 GBytes 2.69 Gbits/sec sender [ 5] 0.00-10.00 sec 3.14 GBytes 2.69 Gbits/sec receiver", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53070", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "3sJJdZ2fQt+gHsMLZrLiCA==": { "id": "3sJJdZ2fQt+gHsMLZrLiCA==", "updater": "debian/updater", "name": "CVE-2026-23348", "description": "In the Linux kernel, the following vulnerability has been resolved: cxl: Fix race of nvdimm_bus object when creating nvdimm objects Found issue during running of cxl-translate.sh unit test. Adding a 3s sleep right before the test seems to make the issue reproduce fairly consistently. The cxl_translate module has dependency on cxl_acpi and causes orphaned nvdimm objects to reprobe after cxl_acpi is removed. The nvdimm_bus object is registered by the cxl_nvb object when cxl_acpi_probe() is called. With the nvdimm_bus object missing, __nd_device_register() will trigger NULL pointer dereference when accessing the dev-\u003eparent that points to \u0026nvdimm_bus-\u003edev. [ 192.884510] BUG: kernel NULL pointer dereference, address: 000000000000006c [ 192.895383] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20250812-19.fc42 08/12/2025 [ 192.897721] Workqueue: cxl_port cxl_bus_rescan_queue [cxl_core] [ 192.899459] RIP: 0010:kobject_get+0xc/0x90 [ 192.924871] Call Trace: [ 192.925959] \u003cTASK\u003e [ 192.926976] ? pm_runtime_init+0xb9/0xe0 [ 192.929712] __nd_device_register.part.0+0x4d/0xc0 [libnvdimm] [ 192.933314] __nvdimm_create+0x206/0x290 [libnvdimm] [ 192.936662] cxl_nvdimm_probe+0x119/0x1d0 [cxl_pmem] [ 192.940245] cxl_bus_probe+0x1a/0x60 [cxl_core] [ 192.943349] really_probe+0xde/0x380 This patch also relies on the previous change where devm_cxl_add_nvdimm_bridge() is called from drivers/cxl/pmem.c instead of drivers/cxl/core.c to ensure the dependency of cxl_acpi on cxl_pmem. 1. Set probe_type of cxl_nvb to PROBE_FORCE_SYNCHRONOUS to ensure the driver is probed synchronously when add_device() is called. 2. Add a check in __devm_cxl_add_nvdimm_bridge() to ensure that the cxl_nvb driver is attached during cxl_acpi_probe(). 3. Take the cxl_root uport_dev lock and the cxl_nvb-\u003edev lock in devm_cxl_add_nvdimm() before checking nvdimm_bus is valid. 4. Set cxl_nvdimm flag to CXL_NVD_F_INVALIDATED so cxl_nvdimm_probe() will exit with -EBUSY. The removal of cxl_nvdimm devices should prevent any orphaned devices from probing once the nvdimm_bus is gone. [ dj: Fixed 0-day reported kdoc issue. ] [ dj: Fix cxl_nvb reference leak on error. Gregory (kreview-0811365) ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23348", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "41FjDaPjaQzk7tn7JaMlRw==": { "id": "41FjDaPjaQzk7tn7JaMlRw==", "updater": "debian/updater", "name": "CVE-2024-50285", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operations If Client send simultaneous SMB operations to ksmbd, It exhausts too much memory through the \"ksmbd_work_cache”. It will cause OOM issue. ksmbd has a credit mechanism but it can't handle this problem. This patch add the check if it exceeds max credits to prevent this problem by assuming that one smb request consumes at least one credit.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50285", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "45wOtea4pyEVfVs+5FQItQ==": { "id": "45wOtea4pyEVfVs+5FQItQ==", "updater": "debian/updater", "name": "CVE-2013-4392", "description": "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "49G+2JpyxLGVZgvO4KOVDw==": { "id": "49G+2JpyxLGVZgvO4KOVDw==", "updater": "debian/updater", "name": "CVE-2026-6276", "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6276", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4BExWTUzjM87Vzt6iuYy6g==": { "id": "4BExWTUzjM87Vzt6iuYy6g==", "updater": "debian/updater", "name": "CVE-2026-68278", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband_append_payload() has three related bugs when processing device-provided sideband reply data: 1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken directly from the DP sideband header. If a device sends msg_len=0, curchunk_len is set to zero. The condition (curchunk_idx \u003e= curchunk_len) is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow). drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy() writes 255 bytes into msg[], both far out of bounds. 2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks until curchunk_idx reaches curchunk_len, writing up to 15 bytes past the end of chunk[] into msg[]. 3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256], so the memcpy can spill into adjacent struct fields. All three are reachable from any DP MST device that can forge sideband reply messages on a physical connection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68278", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4HhPzsELhG/UXDb85H5oYg==": { "id": "4HhPzsELhG/UXDb85H5oYg==", "updater": "debian/updater", "name": "CVE-2024-44942", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC syzbot reports a f2fs bug as below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/inline.c:258! CPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0 RIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258 Call Trace: f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834 f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline] __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline] f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315 do_writepages+0x35b/0x870 mm/page-writeback.c:2612 __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650 writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941 wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117 wb_do_writeback fs/fs-writeback.c:2264 [inline] wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304 process_one_work kernel/workqueue.c:3254 [inline] process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335 worker_thread+0x86d/0xd70 kernel/workqueue.c:3416 kthread+0x2f2/0x390 kernel/kthread.c:388 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 The root cause is: inline_data inode can be fuzzed, so that there may be valid blkaddr in its direct node, once f2fs triggers background GC to migrate the block, it will hit f2fs_bug_on() during dirty page writeback. Let's add sanity check on F2FS_INLINE_DATA flag in inode during GC, so that, it can forbid migrating inline_data inode's data block for fixing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-44942", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4K1mbxJj3BNAQaqE7t/g0g==": { "id": "4K1mbxJj3BNAQaqE7t/g0g==", "updater": "debian/updater", "name": "CVE-2026-56210", "description": "A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56210", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4KipMI43odMoxXzBPDPPTw==": { "id": "4KipMI43odMoxXzBPDPPTw==", "updater": "debian/updater", "name": "CVE-2026-31557", "description": "In the Linux kernel, the following vulnerability has been resolved: nvmet: move async event work off nvmet-wq For target nvmet_ctrl_free() flushes ctrl-\u003easync_event_work. If nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue completion for the same worker:- A. Async event work queued on nvmet-wq (prior to disconnect): nvmet_execute_async_event() queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work) nvmet_add_async_event() queue_work(nvmet_wq, \u0026ctrl-\u003easync_event_work) B. Full pre-work chain (RDMA CM path): nvmet_rdma_cm_handler() nvmet_rdma_queue_disconnect() __nvmet_rdma_queue_disconnect() queue_work(nvmet_wq, \u0026queue-\u003erelease_work) process_one_work() lock((wq_completion)nvmet-wq) \u003c--------- 1st nvmet_rdma_release_queue_work() C. Recursive path (same worker): nvmet_rdma_release_queue_work() nvmet_rdma_free_queue() nvmet_sq_destroy() nvmet_ctrl_put() nvmet_ctrl_free() flush_work(\u0026ctrl-\u003easync_event_work) __flush_work() touch_wq_lockdep_map() lock((wq_completion)nvmet-wq) \u003c--------- 2nd Lockdep splat: ============================================ WARNING: possible recursive locking detected 6.19.0-rc3nvme+ #14 Tainted: G N -------------------------------------------- kworker/u192:42/44933 is trying to acquire lock: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90 but task is already holding lock: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660 3 locks held by kworker/u192:42/44933: #0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660 #1: ffffc9000e6cbe28 ((work_completion)(\u0026queue-\u003erelease_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660 #2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530 Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma] Call Trace: __flush_work+0x268/0x530 nvmet_ctrl_free+0x140/0x310 [nvmet] nvmet_cq_put+0x74/0x90 [nvmet] nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma] nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma] process_one_work+0x206/0x660 worker_thread+0x184/0x320 kthread+0x10c/0x240 ret_from_fork+0x319/0x390 Move async event work to a dedicated nvmet-aen-wq to avoid reentrant flush on nvmet-wq.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31557", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4QfchxeDhLyOBwQdywbhbg==": { "id": "4QfchxeDhLyOBwQdywbhbg==", "updater": "debian/updater", "name": "CVE-2026-13595", "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-13595", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4QzwilesYlayDLcL7cX9Xg==": { "id": "4QzwilesYlayDLcL7cX9Xg==", "updater": "debian/updater", "name": "CVE-2026-57432", "description": "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-57432", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4Ue0mJ4LvJpt6XGU8X1WSw==": { "id": "4Ue0mJ4LvJpt6XGU8X1WSw==", "updater": "debian/updater", "name": "CVE-2026-68244", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Do not leak siblings[] on proto context error After a successful BALANCE/PARALLEL_SUBMIT extension on context creation, error during processing of next user extension leaks the siblings[] array. Fix that. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68244", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4Z81E9P4znFnu7c5edLYhg==": { "id": "4Z81E9P4znFnu7c5edLYhg==", "updater": "debian/updater", "name": "CVE-2018-10126", "description": "ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-10126", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4bp+O/hHtE2TomvTrC9RNw==": { "id": "4bp+O/hHtE2TomvTrC9RNw==", "updater": "debian/updater", "name": "CVE-2024-46730", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Ensure array index tg_inst won't be -1 [WHY \u0026 HOW] tg_inst will be a negative if timing_generator_count equals 0, which should be checked before used. This fixes 2 OVERRUN issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46730", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4fAqOoMQkPPDM8f1jeyBNg==": { "id": "4fAqOoMQkPPDM8f1jeyBNg==", "updater": "debian/updater", "name": "CVE-2026-64138", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64138", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4hLcUQApc7re7Y2zeJnb0Q==": { "id": "4hLcUQApc7re7Y2zeJnb0Q==", "updater": "debian/updater", "name": "CVE-2026-41069", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count \u003e 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41069", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4hTsMj8hVKY9LmF0edFYCQ==": { "id": "4hTsMj8hVKY9LmF0edFYCQ==", "updater": "debian/updater", "name": "CVE-2026-27456", "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-27456", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4mF8/FakY1sQvyJ5OVbHOA==": { "id": "4mF8/FakY1sQvyJ5OVbHOA==", "updater": "debian/updater", "name": "CVE-2026-64542", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev-\u003ecnf.accept_untracked_na without a NULL check, even though its only caller ndisc_recv_na() already fetched and NULL-checked idev for the same device. Both reads of dev-\u003eip6_ptr run in the same RCU read-side critical section, but a concurrent addrconf_ifdown() can clear dev-\u003eip6_ptr between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown() without the synchronize_net() that orders the unregister path, so the re-fetch returns NULL and oopses: BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974) Read of size 4 at addr 0000000000000364 Call Trace: \u003cIRQ\u003e ndisc_recv_na (net/ipv6/ndisc.c:974) icmpv6_rcv (net/ipv6/icmp.c:1193) ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479) ip6_input_finish (net/ipv6/ip6_input.c:534) ip6_input (net/ipv6/ip6_input.c:545) ip6_mc_input (net/ipv6/ip6_input.c:635) ipv6_rcv (net/ipv6/ip6_input.c:351) \u003c/IRQ\u003e It is reachable by an unprivileged user via a network namespace. Pass the caller's already validated idev instead of re-fetching it; the idev stays alive for the whole RCU critical section, so it is safe even after dev-\u003eip6_ptr has been cleared.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64542", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4pmVCkpcFnlXpeO2bi9bvg==": { "id": "4pmVCkpcFnlXpeO2bi9bvg==", "updater": "debian/updater", "name": "CVE-2023-6879", "description": "Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-6879", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4rNBEHiXgqYlYhIDoP5zSA==": { "id": "4rNBEHiXgqYlYhIDoP5zSA==", "updater": "debian/updater", "name": "CVE-2025-66861", "description": "An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66861", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4sWuzq5lKkghOSNsQUHWjw==": { "id": "4sWuzq5lKkghOSNsQUHWjw==", "updater": "debian/updater", "name": "CVE-2026-60002", "description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-60002", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4v9AfyCA9lnPveBYKs2uUQ==": { "id": "4v9AfyCA9lnPveBYKs2uUQ==", "updater": "debian/updater", "name": "CVE-2021-31879", "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-31879", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4wUIkilM6I3qGUwBON8lSw==": { "id": "4wUIkilM6I3qGUwBON8lSw==", "updater": "debian/updater", "name": "CVE-2026-53376", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53376", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "4ywdnWajkUpzJhpgBOXFZA==": { "id": "4ywdnWajkUpzJhpgBOXFZA==", "updater": "debian/updater", "name": "CVE-2024-53224", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Move events notifier registration to be after device registration Move pkey change work initialization and cleanup from device resources stage to notifier stage, since this is the stage which handles this work events. Fix a race between the device deregistration and pkey change work by moving MLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to ensure that the notifier is deregistered before the device during cleanup. Which ensures there are no works that are being executed after the device has already unregistered which can cause the panic below. BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1 Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023 Workqueue: events pkey_change_handler [mlx5_ib] RIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib] Code: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 \u003c4c\u003e 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40 RSP: 0018:ffffbcc54068be20 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36 RDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128 RBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001 R10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000 R13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905 FS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: mlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib] process_one_work+0x1e8/0x3c0 worker_thread+0x50/0x3b0 ? rescuer_thread+0x380/0x380 kthread+0x149/0x170 ? set_kthread_struct+0x50/0x50 ret_from_fork+0x22/0x30 Modules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core] CR2: 0000000000000000 ---[ end trace f6f8be4eae12f7bc ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53224", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "52axsosk1tD0T2LVgOLrtQ==": { "id": "52axsosk1tD0T2LVgOLrtQ==", "updater": "debian/updater", "name": "CVE-2026-56408", "description": "libexpat before 2.8.2 has an integer overflow in copyString.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56408", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "53zxUuzjClZZkScYUEBz4w==": { "id": "53zxUuzjClZZkScYUEBz4w==", "updater": "debian/updater", "name": "CVE-2019-12381", "description": "An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is disputed because new_ra is never used if it is NULL", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12381", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "544etN0zC93gGnD8yMmNnQ==": { "id": "544etN0zC93gGnD8yMmNnQ==", "updater": "debian/updater", "name": "CVE-2026-56392", "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56392", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "54ZbClVVUK2Kye4aOsmx1A==": { "id": "54ZbClVVUK2Kye4aOsmx1A==", "updater": "debian/updater", "name": "CVE-2025-38069", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops Fix a kernel oops found while testing the stm32_pcie Endpoint driver with handling of PERST# deassertion: During EP initialization, pci_epf_test_alloc_space() allocates all BARs, which are further freed if epc_set_bar() fails (for instance, due to no free inbound window). However, when pci_epc_set_bar() fails, the error path: pci_epc_set_bar() -\u003e pci_epf_free_space() does not clear the previous assignment to epf_test-\u003ereg[bar]. Then, if the host reboots, the PERST# deassertion restarts the BAR allocation sequence with the same allocation failure (no free inbound window), creating a double free situation since epf_test-\u003ereg[bar] was deallocated and is still non-NULL. Thus, make sure that pci_epf_alloc_space() and pci_epf_free_space() invocations are symmetric, and as such, set epf_test-\u003ereg[bar] to NULL when memory is freed. [kwilczynski: commit log]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38069", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "56ie/N1k4egyMQTtyui64w==": { "id": "56ie/N1k4egyMQTtyui64w==", "updater": "debian/updater", "name": "CVE-2026-68216", "description": "In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. pwc's start_streaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutex_lock_interruptible() was interrupted by a signal. Call the existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED before returning (matching the state already used by the pwc_isoc_init() error path in the same function). This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68216", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5BK0I9uVtsTWxIanNlMYUg==": { "id": "5BK0I9uVtsTWxIanNlMYUg==", "updater": "debian/updater", "name": "CVE-2026-31419", "description": "In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clones it for others. Concurrent slave enslave/release can mutate the slave list during RCU-protected iteration, changing which slave is \"last\" mid-loop. This causes the original skb to be double-consumed (double-freed). Replace the racy bond_is_last_slave() check with a simple index comparison (i + 1 == slaves_count) against the pre-snapshot slave count taken via READ_ONCE() before the loop. This preserves the zero-copy optimization for the last slave while making the \"last\" determination stable against concurrent list mutations. The UAF can trigger the following crash: ================================================================== BUG: KASAN: slab-use-after-free in skb_clone Read of size 8 at addr ffff888100ef8d40 by task exploit/147 CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY Call Trace: \u003cTASK\u003e dump_stack_lvl (lib/dump_stack.c:123) print_report (mm/kasan/report.c:379 mm/kasan/report.c:482) kasan_report (mm/kasan/report.c:597) skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334) bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593) dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887) __dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838) ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136) ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219) ip6_output (net/ipv6/ip6_output.c:250) ip6_send_skb (net/ipv6/ip6_output.c:1985) udp_v6_send_skb (net/ipv6/udp.c:1442) udpv6_sendmsg (net/ipv6/udp.c:1733) __sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) \u003c/TASK\u003e Allocated by task 147: Freed by task 147: The buggy address belongs to the object at ffff888100ef8c80 which belongs to the cache skbuff_head_cache of size 224 The buggy address is located 192 bytes inside of freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60) Memory state around the buggy address: ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb \u003effff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc ^ ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ==================================================================", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31419", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5C5sqkZA+SZJZWBO+v3goA==": { "id": "5C5sqkZA+SZJZWBO+v3goA==", "updater": "debian/updater", "name": "CVE-2023-49463", "description": "libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-49463", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5GKnVDsIRQ4aY8ICcomaOw==": { "id": "5GKnVDsIRQ4aY8ICcomaOw==", "updater": "debian/updater", "name": "CVE-2026-9538", "description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-9538", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5GhYAEdTvNxvxVlGZr2DUw==": { "id": "5GhYAEdTvNxvxVlGZr2DUw==", "updater": "debian/updater", "name": "CVE-2026-53267", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this issue while looking at a historic syzbot report [1]. A rule like the one below is enough to trigger the bug: table ip t { chain pre { type filter hook prerouting priority raw; ct zone set 1 ct original saddr 1.2.3.4 accept } } The first expression attaches a per-cpu template ct via nft_ct_set_zone_eval() (nf_ct_tmpl_alloc -\u003e kzalloc, tuple is all zero, nf_ct_l3num(ct) == 0). The next expression then calls nft_ct_get_eval() on the same skb, treats the template as a real ct and hits the 16-byte memcpy path. With dreg at NFT_REG32_15 this overflows past struct nft_regs on the kernel stack; with smaller dreg values it silently clobbers adjacent registers. Reject template ct at the eval entry and in nft_ct_get_fast_eval(), mirroring the check nft_ct_set_eval() already has. Additionally, bound the address copy in NFT_CT_SRC / NFT_CT_DST by priv-\u003elen instead of by nf_ct_l3num(ct): nf_ct_get_tuple() zeroes the tuple before pkt_to_tuple() fills in only the protocol-relevant leading bytes, so the trailing bytes of tuple-\u003e{src,dst}.u3.all are well-defined zero. priv-\u003elen is validated at rule load, so the copy size is now bounded by the destination register rather than by an untrusted field on the conntrack. [1]: https://syzkaller.appspot.com/bug?id=389cf09cb72926114fce90dc85a2c3231dcb647c", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53267", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5MdqoaIOPuW8RSkwuUUkQA==": { "id": "5MdqoaIOPuW8RSkwuUUkQA==", "updater": "debian/updater", "name": "CVE-2026-68189", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev-\u003elock to asynchronous command sync work. The worker holds hdev-\u003ereq_lock, but that lock does not serialize access to hdev-\u003euuids against add_uuid() and remove_uuid(), which update the list under hdev-\u003elock. The following interleaving can therefore occur: CPU0 (command sync work) CPU1 (management socket) fetch uuid from the list list_del(\u0026uuid-\u003elist) kfree(uuid) read uuid-\u003esize KASAN reports the resulting use-after-free: BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0 Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87 Workqueue: hci0 hci_cmd_sync_work Call Trace: eir_create+0xb8f/0xee0 hci_update_eir_sync+0x1c0/0x330 hci_cmd_sync_work+0x13c/0x290 process_one_work+0x63a/0x1070 worker_thread+0x45b/0xd10 Allocated by task 86: __kasan_kmalloc+0x8f/0xa0 add_uuid+0x18a/0x4b0 hci_sock_sendmsg+0x1033/0x1ea0 Freed by task 92: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 remove_uuid+0x25e/0x560 hci_sock_sendmsg+0x1033/0x1ea0 Hold hdev-\u003elock while generating and committing the class-of-device and EIR snapshots. Release it before sending an HCI command, so controller waits do not happen under the device lock. This protects all UUID list walks in these paths and restores the serialization lost in the command sync conversion.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68189", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5P81961ZqTSY2y9Cipt4Ng==": { "id": "5P81961ZqTSY2y9Cipt4Ng==", "updater": "debian/updater", "name": "CVE-2024-49940", "description": "In the Linux kernel, the following vulnerability has been resolved: l2tp: prevent possible tunnel refcount underflow When a session is created, it sets a backpointer to its tunnel. When the session refcount drops to 0, l2tp_session_free drops the tunnel refcount if session-\u003etunnel is non-NULL. However, session-\u003etunnel is set in l2tp_session_create, before the tunnel refcount is incremented by l2tp_session_register, which leaves a small window where session-\u003etunnel is non-NULL when the tunnel refcount hasn't been bumped. Moving the assignment to l2tp_session_register is trivial but l2tp_session_create calls l2tp_session_set_header_len which uses session-\u003etunnel to get the tunnel's encap. Add an encap arg to l2tp_session_set_header_len to avoid using session-\u003etunnel. If l2tpv3 sessions have colliding IDs, it is possible for l2tp_v3_session_get to race with l2tp_session_register and fetch a session which doesn't yet have session-\u003etunnel set. Add a check for this case.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49940", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5YLhda5cCl4IzztbHPgP+Q==": { "id": "5YLhda5cCl4IzztbHPgP+Q==", "updater": "debian/updater", "name": "CVE-2026-54369", "description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54369", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "acl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5YOJRTnjsjCt2E0ARGLcsQ==": { "id": "5YOJRTnjsjCt2E0ARGLcsQ==", "updater": "debian/updater", "name": "CVE-2026-53000", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: \"Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register the callbacks. However, in v5.14 I added the ability to dump the active netfilter hooks from userspace. This code will peek back into the nf_hook_ops that are available at the tail of the pointer-array blob used by the datapath. The nat hooks are special, because they are called indirectly from the central nat dispatcher hook. They are currently invisible to the nfnl hook dump subsystem though. But once that changes the nat ops structures have to be deferred too.\" Update nf_nat_register_fn() to deal with partial exposition of the hooks from error path which can be also an issue for nfnetlink_hook.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53000", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5Yd8bPgamMhmdpWlFThuzA==": { "id": "5Yd8bPgamMhmdpWlFThuzA==", "updater": "debian/updater", "name": "CVE-2025-68822", "description": "In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs caused by dev3_register_work The dev3_register_work delayed work item is initialized within alps_reconnect() and scheduled upon receipt of the first bare PS/2 packet from an external PS/2 device connected to the ALPS touchpad. During device detachment, the original implementation calls flush_workqueue() in psmouse_disconnect() to ensure completion of dev3_register_work. However, the flush_workqueue() in psmouse_disconnect() only blocks and waits for work items that were already queued to the workqueue prior to its invocation. Any work items submitted after flush_workqueue() is called are not included in the set of tasks that the flush operation awaits. This means that after flush_workqueue() has finished executing, the dev3_register_work could still be scheduled. Although the psmouse state is set to PSMOUSE_CMD_MODE in psmouse_disconnect(), the scheduling of dev3_register_work remains unaffected. The race condition can occur as follows: CPU 0 (cleanup path) | CPU 1 (delayed work) psmouse_disconnect() | psmouse_set_state() | flush_workqueue() | alps_report_bare_ps2_packet() alps_disconnect() | psmouse_queue_work() kfree(priv); // FREE | alps_register_bare_ps2_mouse() | priv = container_of(work...); // USE | priv-\u003edev3 // USE Add disable_delayed_work_sync() in alps_disconnect() to ensure that dev3_register_work is properly canceled and prevented from executing after the alps_data structure has been deallocated. This bug is identified by static analysis.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68822", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5aGW1SB62ChYqvixvhftXg==": { "id": "5aGW1SB62ChYqvixvhftXg==", "updater": "debian/updater", "name": "CVE-2026-22185", "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-22185", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5c4woM08z/CQiVzL2RiBWw==": { "id": "5c4woM08z/CQiVzL2RiBWw==", "updater": "debian/updater", "name": "CVE-2025-68431", "description": "libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68431", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5g0m2i3mcd+wd2w7F0Wv4Q==": { "id": "5g0m2i3mcd+wd2w7F0Wv4Q==", "updater": "debian/updater", "name": "CVE-2026-68161", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when net.sctp.udp_port is set, and stops/restarts them when the sysctl value changes. The netns exit path does not stop these sockets, so a namespace can be torn down while its SCTP UDP tunnel sockets are still installed. Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering the per-net sysctl table. This prevents new sysctl writes from racing in while the sockets are being released, and closes the sockets before the control socket is destroyed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68161", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5gUw7V1UhMnK6YoPfsX5eg==": { "id": "5gUw7V1UhMnK6YoPfsX5eg==", "updater": "debian/updater", "name": "CVE-2023-53231", "description": "In the Linux kernel, the following vulnerability has been resolved: erofs: Fix detection of atomic context Current check for atomic context is not sufficient as z_erofs_decompressqueue_endio can be called under rcu lock from blk_mq_flush_plug_list(). See the stacktrace [1] In such case we should hand off the decompression work for async processing rather than trying to do sync decompression in current context. Patch fixes the detection by checking for rcu_read_lock_any_held() and while at it use more appropriate !in_task() check than in_atomic(). Background: Historically erofs would always schedule a kworker for decompression which would incur the scheduling cost regardless of the context. But z_erofs_decompressqueue_endio() may not always be in atomic context and we could actually benefit from doing the decompression in z_erofs_decompressqueue_endio() if we are in thread context, for example when running with dm-verity. This optimization was later added in patch [2] which has shown improvement in performance benchmarks. ============================================== [1] Problem stacktrace [name:core\u0026]BUG: sleeping function called from invalid context at kernel/locking/mutex.c:291 [name:core\u0026]in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 1615, name: CpuMonitorServi [name:core\u0026]preempt_count: 0, expected: 0 [name:core\u0026]RCU nest depth: 1, expected: 0 CPU: 7 PID: 1615 Comm: CpuMonitorServi Tainted: G S W OE 6.1.25-android14-5-maybe-dirty-mainline #1 Hardware name: MT6897 (DT) Call trace: dump_backtrace+0x108/0x15c show_stack+0x20/0x30 dump_stack_lvl+0x6c/0x8c dump_stack+0x20/0x48 __might_resched+0x1fc/0x308 __might_sleep+0x50/0x88 mutex_lock+0x2c/0x110 z_erofs_decompress_queue+0x11c/0xc10 z_erofs_decompress_kickoff+0x110/0x1a4 z_erofs_decompressqueue_endio+0x154/0x180 bio_endio+0x1b0/0x1d8 __dm_io_complete+0x22c/0x280 clone_endio+0xe4/0x280 bio_endio+0x1b0/0x1d8 blk_update_request+0x138/0x3a4 blk_mq_plug_issue_direct+0xd4/0x19c blk_mq_flush_plug_list+0x2b0/0x354 __blk_flush_plug+0x110/0x160 blk_finish_plug+0x30/0x4c read_pages+0x2fc/0x370 page_cache_ra_unbounded+0xa4/0x23c page_cache_ra_order+0x290/0x320 do_sync_mmap_readahead+0x108/0x2c0 filemap_fault+0x19c/0x52c __do_fault+0xc4/0x114 handle_mm_fault+0x5b4/0x1168 do_page_fault+0x338/0x4b4 do_translation_fault+0x40/0x60 do_mem_abort+0x60/0xc8 el0_da+0x4c/0xe0 el0t_64_sync_handler+0xd4/0xfc el0t_64_sync+0x1a0/0x1a4 [2] Link: https://lore.kernel.org/all/20210317035448.13921-1-huangjianan@oppo.com/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53231", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5h5AKXgZ7vJkd6xJ9eKDGQ==": { "id": "5h5AKXgZ7vJkd6xJ9eKDGQ==", "updater": "debian/updater", "name": "CVE-2026-46219", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on unbind The state machine work is scheduled by the interrupt handler and therefore needs to be cancelled after disabling interrupts to avoid a potential use-after-free.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46219", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5iXA2QPCrnbK5zJICgTGpA==": { "id": "5iXA2QPCrnbK5zJICgTGpA==", "updater": "debian/updater", "name": "CVE-2026-53230", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using the PF's log_max_current_uc/mc_list capabilities. When querying a VF vport with a larger configured max (via devlink), the firmware response can overflow this buffer: BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core] Read of size 4 at addr ff1100013ffc8a12 by task kworker/u96:2/385 CPU: 12 UID: 0 PID: 385 Comm: kworker/u96:2 Not tainted 7.0.0-rc6+ #1 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009) Workqueue: mlx5_esw_wq esw_vport_change_handler [mlx5_core] Call Trace: \u003cTASK\u003e dump_stack_lvl+0x69/0xa0 print_report+0x176/0x4e4 kasan_report+0xc8/0x100 mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core] esw_update_vport_addr_list+0x2e3/0xda0 [mlx5_core] esw_vport_change_handle_locked+0xa1f/0x1060 [mlx5_core] esw_vport_change_handler+0x6a/0x90 [mlx5_core] process_one_work+0x87f/0x15e0 worker_thread+0x62b/0x1020 kthread+0x375/0x490 ret_from_fork+0x4dc/0x810 ret_from_fork_asm+0x11/0x20 \u003c/TASK\u003e Fix by querying the vport's own HCA caps to size the buffer correctly. Refactor the function to allocate and return the MAC list internally, removing the caller's dependency on knowing the correct max.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53230", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5jJsYB8Vm6Wq13rSxq91EA==": { "id": "5jJsYB8Vm6Wq13rSxq91EA==", "updater": "debian/updater", "name": "CVE-2026-68277", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Three sideband reply parsers read 16-bit fields as: val = (raw-\u003emsg[idx] \u003c\u003c 8) | (raw-\u003emsg[idx+1]); and check bounds only after the fact. When idx == raw-\u003ecurlen, raw-\u003emsg[idx+1] reads one byte past the received message data into the following struct fields (curchunk_len, curchunk_idx, curlen). Affected functions: - drm_dp_sideband_parse_enum_path_resources_ack() full_payload_bw_number and avail_payload_bw_number fields - drm_dp_sideband_parse_allocate_payload_ack() allocated_pbn field - drm_dp_sideband_parse_query_payload_ack() allocated_pbn field Fix by using a single combined check (idx + 2 \u003e curlen) before each 2-byte read. Since the check is strictly tighter than idx \u003e curlen, no separate step is needed. [added fixes tag]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68277", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5lZx/k7YcLQIp3NEG7huZg==": { "id": "5lZx/k7YcLQIp3NEG7huZg==", "updater": "debian/updater", "name": "CVE-2026-64076", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: eb_tables: close module init race sashiko reports for unrelated patch: Does the core ebtables initialization in ebtables.c suffer from a similar race? Once nf_register_sockopt() completes, the sockopts are exposed globally. sockopt has to be registered last, just like in ip/ip6/arptables.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64076", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5pSzSEvB4MWtJijvklug6g==": { "id": "5pSzSEvB4MWtJijvklug6g==", "updater": "debian/updater", "name": "CVE-2026-15741", "description": "SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \\sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15741", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5rlXhvFkSnde6aIX1KftWw==": { "id": "5rlXhvFkSnde6aIX1KftWw==", "updater": "debian/updater", "name": "CVE-2026-43413", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Fix NULL pointer exception during user_scan() user_scan() invokes updated sas_user_scan() for channel 0, and if successful, iteratively scans remaining channels (1 to shost-\u003emax_channel) via scsi_scan_host_selected() in commit 37c4e72b0651 (\"scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans\"). However, hisi_sas supports only one channel, and the current value of max_channel is 1. sas_user_scan() for channel 1 will trigger the following NULL pointer exception: [ 441.554662] Unable to handle kernel NULL pointer dereference at virtual address 00000000000008b0 [ 441.554699] Mem abort info: [ 441.554710] ESR = 0x0000000096000004 [ 441.554718] EC = 0x25: DABT (current EL), IL = 32 bits [ 441.554723] SET = 0, FnV = 0 [ 441.554726] EA = 0, S1PTW = 0 [ 441.554730] FSC = 0x04: level 0 translation fault [ 441.554735] Data abort info: [ 441.554737] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 441.554742] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 441.554747] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 441.554752] user pgtable: 4k pages, 48-bit VAs, pgdp=00000828377a6000 [ 441.554757] [00000000000008b0] pgd=0000000000000000, p4d=0000000000000000 [ 441.554769] Internal error: Oops: 0000000096000004 [#1] SMP [ 441.629589] Modules linked in: arm_spe_pmu arm_smmuv3_pmu tpm_tis_spi hisi_uncore_sllc_pmu hisi_uncore_pa_pmu hisi_uncore_l3c_pmu hisi_uncore_hha_pmu hisi_uncore_ddrc_pmu hisi_uncore_cpa_pmu hns3_pmu hisi_ptt hisi_pcie_pmu tpm_tis_core spidev spi_hisi_sfc_v3xx hisi_uncore_pmu spi_dw_mmio fuse hclge hclge_common hisi_sec2 hisi_hpre hisi_zip hisi_qm hns3 hisi_sas_v3_hw sm3_ce sbsa_gwdt hnae3 hisi_sas_main uacce hisi_dma i2c_hisi dm_mirror dm_region_hash dm_log dm_mod [ 441.670819] CPU: 46 UID: 0 PID: 6994 Comm: bash Kdump: loaded Not tainted 7.0.0-rc2+ #84 PREEMPT [ 441.691327] pstate: 81400009 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [ 441.698277] pc : sas_find_dev_by_rphy+0x44/0x118 [ 441.702896] lr : sas_find_dev_by_rphy+0x3c/0x118 [ 441.707502] sp : ffff80009abbba40 [ 441.710805] x29: ffff80009abbba40 x28: ffff082819a40008 x27: ffff082810c37c08 [ 441.717930] x26: ffff082810c37c28 x25: ffff082819a40290 x24: ffff082810c37c00 [ 441.725054] x23: 0000000000000000 x22: 0000000000000001 x21: ffff082819a40000 [ 441.732179] x20: ffff082819a40290 x19: 0000000000000000 x18: 0000000000000020 [ 441.739304] x17: 0000000000000000 x16: ffffb5dad6bda690 x15: 00000000ffffffff [ 441.746428] x14: ffff082814c3b26c x13: 00000000ffffffff x12: ffff082814c3b26a [ 441.753553] x11: 00000000000000c0 x10: 000000000000003a x9 : ffffb5dad5ea94f4 [ 441.760678] x8 : 000000000000003a x7 : ffff80009abbbab0 x6 : 0000000000000030 [ 441.767802] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 [ 441.774926] x2 : ffff08280f35a300 x1 : ffffb5dad7127180 x0 : 0000000000000000 [ 441.782053] Call trace: [ 441.784488] sas_find_dev_by_rphy+0x44/0x118 (P) [ 441.789095] sas_target_alloc+0x24/0xb0 [ 441.792920] scsi_alloc_target+0x290/0x330 [ 441.797010] __scsi_scan_target+0x88/0x258 [ 441.801096] scsi_scan_channel+0x74/0xb8 [ 441.805008] scsi_scan_host_selected+0x170/0x188 [ 441.809615] sas_user_scan+0xfc/0x148 [ 441.813267] store_scan+0x10c/0x180 [ 441.816743] dev_attr_store+0x20/0x40 [ 441.820398] sysfs_kf_write+0x84/0xa8 [ 441.824054] kernfs_fop_write_iter+0x130/0x1c8 [ 441.828487] vfs_write+0x2c0/0x370 [ 441.831880] ksys_write+0x74/0x118 [ 441.835271] __arm64_sys_write+0x24/0x38 [ 441.839182] invoke_syscall+0x50/0x120 [ 441.842919] el0_svc_common.constprop.0+0xc8/0xf0 [ 441.847611] do_el0_svc+0x24/0x38 [ 441.850913] el0_svc+0x38/0x158 [ 441.854043] el0t_64_sync_handler+0xa0/0xe8 [ 441.858214] el0t_64_sync+0x1ac/0x1b0 [ 441.861865] Code: aa1303e0 97ff70a8 34ffff80 d10a4273 (f9445a75) [ 441.867946] ---[ end trace 0000000000000000 ]--- Therefore ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43413", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5vQpVW4vLgKPy4ui5REMvw==": { "id": "5vQpVW4vLgKPy4ui5REMvw==", "updater": "debian/updater", "name": "CVE-2019-6110", "description": "In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-6110", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "5xeM1k+VvYcU/xV+hgDtwA==": { "id": "5xeM1k+VvYcU/xV+hgDtwA==", "updater": "debian/updater", "name": "CVE-2025-11494", "description": "A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11494", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6/WrFYuWPwgl9mKfkUaCJA==": { "id": "6/WrFYuWPwgl9mKfkUaCJA==", "updater": "debian/updater", "name": "CVE-2026-64389", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess-\u003esess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even when ksmbd_auth_ntlmv2() failed. With SMB3 multichannel binding, the failed authentication operates on an existing session and the session setup error path does not expire binding sessions. A client can send a binding session setup with a bad NT proof and KEY_XCH and still modify sess-\u003esess_key before STATUS_LOGON_FAILURE is returned. Relevant path: smb2_sess_setup() -\u003e conn-\u003ebinding = true -\u003e ntlm_authenticate() -\u003e session_user() -\u003e ksmbd_decode_ntlmssp_auth_blob() -\u003e ksmbd_auth_ntlmv2() -\u003e calc_ntlmv2_hash() -\u003e hmac_md5_usingrawkey(..., sess-\u003esess_key) -\u003e crypto_memneq() returns mismatch -\u003e KEY_XCH arc4_crypt(..., sess-\u003esess_key, ...) -\u003e out_err without expiring the binding session Derive the base session key into a local buffer and copy it to sess-\u003esess_key only after the proof matches. Return immediately on authentication failure so KEY_XCH is only processed after successful authentication.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64389", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "601t/MM1gE+tOeU7waDd0g==": { "id": "601t/MM1gE+tOeU7waDd0g==", "updater": "debian/updater", "name": "CVE-2026-56289", "description": "GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56289", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "62mRq4C9D2Fi3b6rCkQTcw==": { "id": "62mRq4C9D2Fi3b6rCkQTcw==", "updater": "debian/updater", "name": "CVE-2026-53106", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Do not allow deleting local storage in NMI Currently, local storage may deadlock when deferring freeing selem or local storage through kfree_rcu(), call_rcu() or call_rcu_tasks_trace() in NMI or reentrant. Since deleting selem in NMI is an unlikely use case, partially mitigate it by returning error when calling from bpf_xxx_storage_delete() helpers in NMI. Note that, it is still possible to deadlock through reentrant. A full mitigation requires returning error when irqs_disabled() is true, which, however is too heavy-handed for bpf_xxx_storage_delete(). The long-term solution requires _nolock versions of call_rcu. Another possible solution is to defer the free through irq_work [0], but it would grow the size of selem, which is non-ideal. The check is only needed in bpf_selem_unlink(), which is used by helpers and syscalls. bpf_selem_unlink_nofail() is fine as it is called during map and owner tear down that never run in NMI or reentrant. [0] https://lore.kernel.org/bpf/20260205190233.912-1-alexei.starovoitov@gmail.com/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53106", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "64hLJutN1wNAcS1ep0rAsA==": { "id": "64hLJutN1wNAcS1ep0rAsA==", "updater": "debian/updater", "name": "CVE-2026-58051", "description": "libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58051", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "68aTZzXBvZontWtIx/3b4g==": { "id": "68aTZzXBvZontWtIx/3b4g==", "updater": "debian/updater", "name": "CVE-2024-47662", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection [Why] These registers should not be read from driver and triggering the security violation when DMCUB work times out and diagnostics are collected blocks Z8 entry. [How] Remove the register read from DCN35.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47662", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "68eshzTKFcJRqXz/jgAEtA==": { "id": "68eshzTKFcJRqXz/jgAEtA==", "updater": "debian/updater", "name": "CVE-2024-53168", "description": "In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket BUG: KASAN: slab-use-after-free in tcp_write_timer_handler+0x156/0x3e0 Read of size 1 at addr ffff888111f322cd by task swapper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.12.0-rc4-dirty #7 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 Call Trace: \u003cIRQ\u003e dump_stack_lvl+0x68/0xa0 print_address_description.constprop.0+0x2c/0x3d0 print_report+0xb4/0x270 kasan_report+0xbd/0xf0 tcp_write_timer_handler+0x156/0x3e0 tcp_write_timer+0x66/0x170 call_timer_fn+0xfb/0x1d0 __run_timers+0x3f8/0x480 run_timer_softirq+0x9b/0x100 handle_softirqs+0x153/0x390 __irq_exit_rcu+0x103/0x120 irq_exit_rcu+0xe/0x20 sysvec_apic_timer_interrupt+0x76/0x90 \u003c/IRQ\u003e \u003cTASK\u003e asm_sysvec_apic_timer_interrupt+0x1a/0x20 RIP: 0010:default_idle+0xf/0x20 Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 33 f8 25 00 fb f4 \u003cfa\u003e c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 RSP: 0018:ffffffffa2007e28 EFLAGS: 00000242 RAX: 00000000000f3b31 RBX: 1ffffffff4400fc7 RCX: ffffffffa09c3196 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9f00590f RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed102360835d R10: ffff88811b041aeb R11: 0000000000000001 R12: 0000000000000000 R13: ffffffffa202d7c0 R14: 0000000000000000 R15: 00000000000147d0 default_idle_call+0x6b/0xa0 cpuidle_idle_call+0x1af/0x1f0 do_idle+0xbc/0x130 cpu_startup_entry+0x33/0x40 rest_init+0x11f/0x210 start_kernel+0x39a/0x420 x86_64_start_reservations+0x18/0x30 x86_64_start_kernel+0x97/0xa0 common_startup_64+0x13e/0x141 \u003c/TASK\u003e Allocated by task 595: kasan_save_stack+0x24/0x50 kasan_save_track+0x14/0x30 __kasan_slab_alloc+0x87/0x90 kmem_cache_alloc_noprof+0x12b/0x3f0 copy_net_ns+0x94/0x380 create_new_namespaces+0x24c/0x500 unshare_nsproxy_namespaces+0x75/0xf0 ksys_unshare+0x24e/0x4f0 __x64_sys_unshare+0x1f/0x30 do_syscall_64+0x70/0x180 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 100: kasan_save_stack+0x24/0x50 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x54/0x70 kmem_cache_free+0x156/0x5d0 cleanup_net+0x5d3/0x670 process_one_work+0x776/0xa90 worker_thread+0x2e2/0x560 kthread+0x1a8/0x1f0 ret_from_fork+0x34/0x60 ret_from_fork_asm+0x1a/0x30 Reproduction script: mkdir -p /mnt/nfsshare mkdir -p /mnt/nfs/netns_1 mkfs.ext4 /dev/sdb mount /dev/sdb /mnt/nfsshare systemctl restart nfs-server chmod 777 /mnt/nfsshare exportfs -i -o rw,no_root_squash *:/mnt/nfsshare ip netns add netns_1 ip link add name veth_1_peer type veth peer veth_1 ifconfig veth_1_peer 11.11.0.254 up ip link set veth_1 netns netns_1 ip netns exec netns_1 ifconfig veth_1 11.11.0.1 ip netns exec netns_1 /root/iptables -A OUTPUT -d 11.11.0.254 -p tcp \\ \t--tcp-flags FIN FIN -j DROP (note: In my environment, a DESTROY_CLIENTID operation is always sent immediately, breaking the nfs tcp connection.) ip netns exec netns_1 timeout -s 9 300 mount -t nfs -o proto=tcp,vers=4.1 \\ \t11.11.0.254:/mnt/nfsshare /mnt/nfs/netns_1 ip netns del netns_1 The reason here is that the tcp socket in netns_1 (nfs side) has been shutdown and closed (done in xs_destroy), but the FIN message (with ack) is discarded, and the nfsd side keeps sending retransmission messages. As a result, when the tcp sock in netns_1 processes the received message, it sends the message (FIN message) in the sending queue, and the tcp timer is re-established. When the network namespace is deleted, the net structure accessed by tcp's timer handler function causes problems. To fix this problem, let's hold netns refcnt for the tcp kernel socket as done in other modules. This is an ugly hack which can easily be backported to earlier kernels. A proper fix which cleans up the interfaces will follow, but may not be so easy to backport.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53168", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6D1DnfX30dlWWva3QgMcTw==": { "id": "6D1DnfX30dlWWva3QgMcTw==", "updater": "debian/updater", "name": "CVE-2025-68209", "description": "In the Linux kernel, the following vulnerability has been resolved: mlx5: Fix default values in create CQ Currently, CQs without a completion function are assigned the mlx5_add_cq_to_tasklet function by default. This is problematic since only user CQs created through the mlx5_ib driver are intended to use this function. Additionally, all CQs that will use doorbells instead of polling for completions must call mlx5_cq_arm. However, the default CQ creation flow leaves a valid value in the CQ's arm_db field, allowing FW to send interrupts to polling-only CQs in certain corner cases. These two factors would allow a polling-only kernel CQ to be triggered by an EQ interrupt and call a completion function intended only for user CQs, causing a null pointer exception. Some areas in the driver have prevented this issue with one-off fixes but did not address the root cause. This patch fixes the described issue by adding defaults to the create CQ flow. It adds a default dummy completion function to protect against null pointer exceptions, and it sets an invalid command sequence number by default in kernel CQs to prevent the FW from sending an interrupt to the CQ until it is armed. User CQs are responsible for their own initialization values. Callers of mlx5_core_create_cq are responsible for changing the completion function and arming the CQ per their needs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68209", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6DQLqxaGlg/lwlTdxRMONQ==": { "id": "6DQLqxaGlg/lwlTdxRMONQ==", "updater": "debian/updater", "name": "CVE-2026-68142", "description": "In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve-\u003enet. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve-\u003enet can rewrite a geneve device whose underlay lives in geneve-\u003enet. geneve_changelink() applies the new configuration against geneve-\u003enet: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve-\u003enet), so the same reasoning as the tunnel changelink series applies here. Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the \"require CAP_NET_ADMIN in the device netns for changelink\" series. Found by 0sec automated security-research tooling (https://0sec.ai).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68142", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6ES7hkRcIMPt5iPgfBeemg==": { "id": "6ES7hkRcIMPt5iPgfBeemg==", "updater": "debian/updater", "name": "CVE-2023-53367", "description": "In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: fix mem leak in capture user mappings This commit fixes a memory leak caused when clearing the user_mappings info when a new context is opened immediately after user_mapping is captured and a hard reset is performed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53367", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6F94GA2WFa6JdVf4FibsZQ==": { "id": "6F94GA2WFa6JdVf4FibsZQ==", "updater": "debian/updater", "name": "CVE-2026-46158", "description": "In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end. Some (unlikely) checks were returning directly instead of calling sock_put() to decrease the refcount. Jump to a new 'exit' label to call __sock_put() (which will become sock_put() in the next commit) to fix this potential leak. While at it, drop the '!msk' check which cannot happen because it is never reset, and explicitly mark the remaining one as \"unlikely\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46158", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6J3s3ytYuZnXwt5lQIqlhA==": { "id": "6J3s3ytYuZnXwt5lQIqlhA==", "updater": "debian/updater", "name": "CVE-2026-43118", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name or logging new dir entries for a directory, we always set the generation of the logged inode item to 0. This is to signal during log replay (in overwrite_item()), that we should not set the i_size since we only logged that an inode exists, so the i_size of the inode in the subvolume tree must be preserved (as when we log new names or that an inode exists, we don't log extents). This works fine except when we have already logged an inode in full mode or it's the first time we are logging an inode created in a past transaction, that inode has a new i_size of 0 and then we log a new name for the inode (due to a new hardlink or a rename), in which case we log an i_size of 0 for the inode and a generation of 0, which causes the log replay code to not update the inode's i_size to 0 (in overwrite_item()). An example scenario: mkdir /mnt/dir xfs_io -f -c \"pwrite 0 64K\" /mnt/dir/foo sync xfs_io -c \"truncate 0\" -c \"fsync\" /mnt/dir/foo ln /mnt/dir/foo /mnt/dir/bar xfs_io -c \"fsync\" /mnt/dir \u003cpower fail\u003e After log replay the file remains with a size of 64K. This is because when we first log the inode, when we fsync file foo, we log its current i_size of 0, and then when we create a hard link we log again the inode in exists mode (LOG_INODE_EXISTS) but we set a generation of 0 for the inode item we add to the log tree, so during log replay overwrite_item() sees that the generation is 0 and i_size is 0 so we skip updating the inode's i_size from 64K to 0. Fix this by making sure at fill_inode_item() we always log the real generation of the inode if it was logged in the current transaction with the i_size we logged before. Also if an inode created in a previous transaction is logged in exists mode only, make sure we log the i_size stored in the inode item located from the commit root, so that if we log multiple times that the inode exists we get the correct i_size. A test case for fstests will follow soon.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6OnemuwtxINSgBT1Ii+++A==": { "id": "6OnemuwtxINSgBT1Ii+++A==", "updater": "debian/updater", "name": "CVE-2026-12003", "description": "To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources. Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory. The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-12003", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Q7cSKnTxu+nzr2vFDnZQg==": { "id": "6Q7cSKnTxu+nzr2vFDnZQg==", "updater": "debian/updater", "name": "CVE-2024-58089", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_delalloc_range() failed [BUG] When running btrfs with block size (4K) smaller than page size (64K, aarch64), there is a very high chance to crash the kernel at generic/750, with the following messages: (before the call traces, there are 3 extra debug messages added) BTRFS warning (device dm-3): read-write for sector size 4096 with page size 65536 is experimental BTRFS info (device dm-3): checking UUID tree hrtimer: interrupt took 5451385 ns BTRFS error (device dm-3): cow_file_range failed, root=4957 inode=257 start=1605632 len=69632: -28 BTRFS error (device dm-3): run_delalloc_nocow failed, root=4957 inode=257 start=1605632 len=69632: -28 BTRFS error (device dm-3): failed to run delalloc range, root=4957 ino=257 folio=1572864 submit_bitmap=8-15 start=1605632 len=69632: -28 ------------[ cut here ]------------ WARNING: CPU: 2 PID: 3020984 at ordered-data.c:360 can_finish_ordered_extent+0x370/0x3b8 [btrfs] CPU: 2 UID: 0 PID: 3020984 Comm: kworker/u24:1 Tainted: G OE 6.13.0-rc1-custom+ #89 Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022 Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs] pc : can_finish_ordered_extent+0x370/0x3b8 [btrfs] lr : can_finish_ordered_extent+0x1ec/0x3b8 [btrfs] Call trace: can_finish_ordered_extent+0x370/0x3b8 [btrfs] (P) can_finish_ordered_extent+0x1ec/0x3b8 [btrfs] (L) btrfs_mark_ordered_io_finished+0x130/0x2b8 [btrfs] extent_writepage+0x10c/0x3b8 [btrfs] extent_write_cache_pages+0x21c/0x4e8 [btrfs] btrfs_writepages+0x94/0x160 [btrfs] do_writepages+0x74/0x190 filemap_fdatawrite_wbc+0x74/0xa0 start_delalloc_inodes+0x17c/0x3b0 [btrfs] btrfs_start_delalloc_roots+0x17c/0x288 [btrfs] shrink_delalloc+0x11c/0x280 [btrfs] flush_space+0x288/0x328 [btrfs] btrfs_async_reclaim_data_space+0x180/0x228 [btrfs] process_one_work+0x228/0x680 worker_thread+0x1bc/0x360 kthread+0x100/0x118 ret_from_fork+0x10/0x20 ---[ end trace 0000000000000000 ]--- BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1605632 OE len=16384 to_dec=16384 left=0 BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1622016 OE len=12288 to_dec=12288 left=0 Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1634304 OE len=8192 to_dec=4096 left=0 CPU: 1 UID: 0 PID: 3286940 Comm: kworker/u24:3 Tainted: G W OE 6.13.0-rc1-custom+ #89 Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022 Workqueue: btrfs_work_helper [btrfs] (btrfs-endio-write) pstate: 404000c5 (nZcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : process_one_work+0x110/0x680 lr : worker_thread+0x1bc/0x360 Call trace: process_one_work+0x110/0x680 (P) worker_thread+0x1bc/0x360 (L) worker_thread+0x1bc/0x360 kthread+0x100/0x118 ret_from_fork+0x10/0x20 Code: f84086a1 f9000fe1 53041c21 b9003361 (f9400661) ---[ end trace 0000000000000000 ]--- Kernel panic - not syncing: Oops: Fatal exception SMP: stopping secondary CPUs SMP: failed to stop secondary CPUs 2-3 Dumping ftrace buffer: (ftrace buffer empty) Kernel Offset: 0x275bb9540000 from 0xffff800080000000 PHYS_OFFSET: 0xffff8fbba0000000 CPU features: 0x100,00000070,00801250,8201720b [CAUSE] The above warning is triggered immediately after the delalloc range failure, this happens in the following sequence: - Range [1568K, 1636K) is dirty 1536K 1568K 1600K 1636K 1664K | |/////////|////////| | Where 1536K, 1600K and 1664K are page boundaries (64K page size) - Enter extent_writepage() for page 1536K - Enter run_delalloc_nocow() with locke ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58089", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6S0eyEO6j+/5Oru/7o8ifw==": { "id": "6S0eyEO6j+/5Oru/7o8ifw==", "updater": "debian/updater", "name": "CVE-2026-45961", "description": "In the Linux kernel, the following vulnerability has been resolved: gfs2: fix memory leaks in gfs2_fill_super error path Fix two memory leaks in the gfs2_fill_super() error handling path when transitioning a filesystem to read-write mode fails. First leak: kthread objects (thread_struct, task_struct, etc.) When gfs2_freeze_lock_shared() fails after init_threads() succeeds, the created kernel threads (logd and quotad) are never destroyed. This occurs because the fail_per_node label doesn't call gfs2_destroy_threads(). Second leak: quota bitmap buffer (8192 bytes) When gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but before other operations complete, the allocated quota bitmap is never freed. The fix moves thread cleanup to the fail_per_node label to handle all error paths uniformly. gfs2_destroy_threads() is safe to call unconditionally as it checks for NULL pointers. Quota cleanup is added in gfs2_make_fs_rw() to properly handle the withdrawal case where quota initialization succeeds but the filesystem is then withdrawn. Thread leak backtrace (gfs2_freeze_lock_shared failure): unreferenced object 0xffff88801d7bca80 (size 4480): copy_process+0x3a1/0x4670 kernel/fork.c:2422 kernel_clone+0xf3/0x6e0 kernel/fork.c:2779 kthread_create_on_node+0x100/0x150 kernel/kthread.c:478 init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611 gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265 Quota leak backtrace (gfs2_make_fs_rw failure): unreferenced object 0xffff88812de7c000 (size 8192): gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409 gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149 gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6SfR7C92OMaKw1U/fAorwA==": { "id": "6SfR7C92OMaKw1U/fAorwA==", "updater": "debian/updater", "name": "CVE-2025-1149", "description": "A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1149", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Tz82TUDik0TIK2cdfoqZg==": { "id": "6Tz82TUDik0TIK2cdfoqZg==", "updater": "debian/updater", "name": "CVE-2026-68181", "description": "In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device under device_lock on cleanup Fix couple of problems in mei_cl_bus_dev_release(): mei_cl_flush_queues() is running without lock. bus-\u003efile_list access after mei_dev_bus_put(bus) can become a use-after-free if this was the last reference to bus. Protect queues cleanup and WARN traversal by device lock there to avoid the concurrent access problems. Move WARN traversal before mei_dev_bus_put(bus). This file uses bus variable name for mei_device, adjust code of mei_cl_bus_dev_release() to use bus variable too.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68181", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Z4TXkcGmyMWqyaCyCnljA==": { "id": "6Z4TXkcGmyMWqyaCyCnljA==", "updater": "debian/updater", "name": "CVE-2026-14663", "description": "Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14663", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6Zbh3+Y2tosvSjDcFKP8Aw==": { "id": "6Zbh3+Y2tosvSjDcFKP8Aw==", "updater": "debian/updater", "name": "CVE-2026-53156", "description": "In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of error paths in which we call __nvmem_device_put() - which may end up freeing the underlying memory and other resources - and then keep on using the nvmem structure. Always put the reference to the nvmem device as the last step before returning the error code.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53156", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6ZwesWdsCQ+SFQKouk0D+Q==": { "id": "6ZwesWdsCQ+SFQKouk0D+Q==", "updater": "debian/updater", "name": "CVE-2024-42279", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer While transmitting with rx_len == 0, the RX FIFO is not going to be emptied in the interrupt handler. A subsequent transfer could then read crap from the previous transfer out of the RX FIFO into the start RX buffer. The core provides a register that will empty the RX and TX FIFOs, so do that before each transfer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42279", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6dBKp35A3yhlTjiBNtzTcw==": { "id": "6dBKp35A3yhlTjiBNtzTcw==", "updater": "debian/updater", "name": "CVE-2026-68335", "description": "In the Linux kernel, the following vulnerability has been resolved: rds: drop incoming messages that cross network namespace boundaries rds_find_bound() looks up the destination socket using a global rhashtable keyed solely on (addr, port, scope_id). Network namespaces are not part of the key, so a sender in netns A can deliver an incoming message (inc) to a socket that lives in a different netns B. When this happens, inc-\u003ei_conn points to an rds_connection whose c_net is netns A, but the receiving rs lives in netns B. Once the child process that created netns A exits, cleanup_net() calls rds_loop_exit_net() -\u003e rds_loop_kill_conns() -\u003e rds_conn_destroy(), freeing that connection. If the survivor socket in netns B still holds the inc, any subsequent dereference of inc-\u003ei_conn is a use-after-free. There are two dangerous sites in rds_clear_recv_queue(): 1. inc-\u003ei_conn-\u003ec_lcong (offset 88 of freed rds_connection, size 200) read via rds_recv_rcvbuf_delta() -- confirmed by KASAN. 2. inc-\u003ei_conn-\u003ec_trans-\u003einc_free(inc) (function pointer at offset 80) called via rds_inc_put() when the inc refcount reaches zero -- same race window, potential call-through-freed-object primitive. The bug is reachable from unprivileged user namespaces (CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8. Fix this by rejecting the delivery in rds_recv_incoming() when the socket returned by rds_find_bound() belongs to a different network namespace than the connection that carried the message. Use the existing rds_conn_net() / sock_net() helpers and net_eq() for the comparison.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68335", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6gtpOZpKlYN/fTuD2j7uyw==": { "id": "6gtpOZpKlYN/fTuD2j7uyw==", "updater": "debian/updater", "name": "CVE-2026-68353", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68353", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6nif13v4dYw7gjNbruZ0Rg==": { "id": "6nif13v4dYw7gjNbruZ0Rg==", "updater": "debian/updater", "name": "CVE-2026-45988", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry. Fix this by just discarding the packet; we will send another CHALLENGE packet and thereby elicit a further response. Similarly, discard an incoming CHALLENGE packet if we get an error whilst generating a RESPONSE; the server will send another CHALLENGE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45988", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6oQOPW/SOH/HZt4HVN1Sgg==": { "id": "6oQOPW/SOH/HZt4HVN1Sgg==", "updater": "debian/updater", "name": "CVE-2026-56403", "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56403", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6oeh+EDX7YG2y/U2/jlouw==": { "id": "6oeh+EDX7YG2y/U2/jlouw==", "updater": "debian/updater", "name": "CVE-2022-1210", "description": "A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-1210", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6p8Hozv8P/sKC+WoYVsDKQ==": { "id": "6p8Hozv8P/sKC+WoYVsDKQ==", "updater": "debian/updater", "name": "CVE-2026-15003", "description": "A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15003", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6pA/AAe40mAnWhJupYQJTQ==": { "id": "6pA/AAe40mAnWhJupYQJTQ==", "updater": "debian/updater", "name": "CVE-2026-64582", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(\u0026ip-\u003epending_mmaps); spin_unlock_bh(\u0026rxe-\u003epending_lock); /* ref == 1, no lock held */ ret = remap_vmalloc_range(vma, ip-\u003eobj, 0); /* walks PTEs */ [...] rxe_vma_open(vma); /* kref_get, ref → 2 */ remap_vmalloc_range_partial() walks PTEs without any lock. A concurrent DESTROY_CQ ioctl on another CPU calls: kref_put(\u0026q-\u003eip-\u003eref, rxe_mmap_release) /* ref 1→0 */ vfree(ip-\u003eobj) /* clears vmalloc PTEs mid-walk */ kfree(ip) /* frees rxe_mmap_info */ This yields: 1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the per-PTE race -\u003e vm_insert_page(NULL) → GPF in validate_page_before_insert 2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears it. User VMA holds a PTE to a free'd page which might eventually get reallocated later by vmalloc which allows the attacker to get a clean page-level UAF. It is worth noting that even though a page-level UAF is possible given the strong primitive, it is statistically very difficult to achieve given the very short time window (after the last insert_page and before the kref_get). The call trace are as below: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:validate_page_before_insert+0x32/0x300 Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 \u003c80\u003e 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5 RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008 RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00 R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20 FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0 Call Trace: \u003cTASK\u003e insert_page+0x8f/0x190 ? __pfx_insert_page+0x10/0x10 ? kasan_save_alloc_info+0x38/0x60 vm_insert_page+0x2e7/0x400 remap_vmalloc_range_partial+0x212/0x3e0 remap_vmalloc_range+0x6e/0xb0 ? __kasan_check_write+0x14/0x30 rxe_mmap+0x2e9/0x5d0 ib_uverbs_mmap+0x1ad/0x2c0 __mmap_region+0x12c2/0x2ad0 ? __pfx___mmap_region+0x10/0x10 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_prev_slot+0x360/0x39c0 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_next_slot+0x1e5b/0x2f40 ? __sanitizer_cov_trace_cmp8+0x18/0x30 ? unmapped_area_topdown+0x4dd/0x610 ? kfree+0x1b1/0x440 ? free_cpumask_var+0x16/0x30 ? __kasan_slab_free+0x7d/0xa0 ? __sanitizer_cov_trace_cmp8+0x18/0x30 mmap_region+0x2e6/0x3c0 do_mmap+0xa3e/0x12a0 ? __pfx_do_mmap+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? down_write_killable+0xba/0x160 ? __pfx_down_write_killable+0x10/0x10 ? __sanitizer_cov_trace_cmp4+0x16/0x30 vm_mmap_pgoff+0x2d4/0x4a0 ? __pfx_vm_mmap_pgoff+0x10/0x10 ? fget+0x1bf/0x270 ksys_mmap_pgoff+0x40c/0x690 ? __sanitizer_cov_trace_const_cmp4+0x16/0x30 ? __pfx_ksys_mmap_pgoff+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? _raw_spin_trylock+0xbb/0x130 ? __pfx__raw_spin_trylock+0x10/0x10 __x64_sys_mmap+0x135/0x1e0 x64_sys_c ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64582", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6tqG15NFTj8WQy8yBxg3gA==": { "id": "6tqG15NFTj8WQy8yBxg3gA==", "updater": "debian/updater", "name": "CVE-2026-47178", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-47178", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6u2nND/vhxXQDUUG6S6tPQ==": { "id": "6u2nND/vhxXQDUUG6S6tPQ==", "updater": "debian/updater", "name": "CVE-2026-68184", "description": "In the Linux kernel, the following vulnerability has been resolved: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL mmc_ioctl_cdrom_volume() first reads the audio control mode page into a 32-byte stack buffer with cgc-\u003ebuflen set to 24. If the device reports a block descriptor, the function increases cgc-\u003ebuflen to include that descriptor and reads the page again. For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list by moving cgc-\u003ebuffer forward by offset - 8 bytes. This drops the block descriptor from the outgoing payload and leaves a new 8-byte mode parameter header in front of the audio control page. However, cgc-\u003ebuflen is left unchanged. With a standard 8-byte block descriptor, cgc-\u003ebuffer points at buffer + 8 but cgc-\u003ebuflen remains 32. cdrom_mode_select() therefore asks the low level packet path to write 32 bytes from that adjusted pointer, reading 8 bytes past the end of the 32-byte stack buffer. This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on drives that return a non-zero block descriptor length, which helps explain why it has gone unnoticed. The overread is also sent to the device as extra MODE SELECT payload, so it may not produce an obvious local failure. Reduce cgc-\u003ebuflen by the same amount as the buffer pointer adjustment so the MODE SELECT transfer covers only the intended parameter list.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68184", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6uzFcJl+4SfrToHOfIjE/g==": { "id": "6uzFcJl+4SfrToHOfIjE/g==", "updater": "debian/updater", "name": "CVE-2026-68190", "description": "In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() rtw_get_wps_ie() iterates over IE data from network frames without validating that the IE header and payload fit within the remaining buffer before reading them. Specifically: - in_ie[cnt + 1] is read without checking cnt + 1 \u003c in_len - memcmp(\u0026in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check - in_ie[cnt + 1] is used as length without verifying payload fits Add bounds checks at the top of the loop body to break early if fewer than 2 bytes remain for the IE header, or if the declared payload extends past the end of the buffer. Also require at least 4 bytes of payload before comparing the WPS OUI.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68190", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6wB3SHb/Pw3K2aEF5Qy/JQ==": { "id": "6wB3SHb/Pw3K2aEF5Qy/JQ==", "updater": "debian/updater", "name": "CVE-2026-34543", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34543", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6wR7TzqM+LTXLTLlLsp6BA==": { "id": "6wR7TzqM+LTXLTLlLsp6BA==", "updater": "debian/updater", "name": "CVE-2026-68148", "description": "In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy 'fscrypt_direct_keys' table caches master keys that are used by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY. It's just a global table for all filesystems (since the keys can be provided by the legacy process-subscribed keyrings mechanism, which makes it difficult to reuse super_block::s_master_keys). The entries in it ('struct fscrypt_direct_key') do contain a super_block pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when the last inode that references the key is evicted. However, when finding the fscrypt_direct_key for an inode, we weren't actually comparing the super_block pointer. As a result, inodes with different super_blocks could point to the same fscrypt_direct_key. That could extend the lifetime of a fscrypt_direct_key beyond the super_block it points to, causing a use-after-free later. Fix this by creating distinct fscrypt_direct_key structs for distinct super_block structs. Note that this problem doesn't exist in the v2 policy equivalent (\"per-mode keys\"), since the data structures there are per super_block.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68148", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "6z/N4Az6vu/Ht80DdvVCEg==": { "id": "6z/N4Az6vu/Ht80DdvVCEg==", "updater": "debian/updater", "name": "CVE-2026-43317", "description": "In the Linux kernel, the following vulnerability has been resolved: most: core: fix leak on early registration failure A recent commit fixed a resource leak on early registration failures but for some reason left out the first error path which still leaks the resources associated with the interface. Fix up also the first error path so that the interface is always released on errors.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43317", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7/erHjcVbxG3II9T3g8TzQ==": { "id": "7/erHjcVbxG3II9T3g8TzQ==", "updater": "debian/updater", "name": "CVE-2019-12380", "description": "**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: This id is disputed as not being an issue because “All the code touched by the referenced commit runs only at boot, before any user processes are started. Therefore, there is no possibility for an unprivileged user to control it.”.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12380", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "71JlBQez3bAZP4d4xP2Llg==": { "id": "71JlBQez3bAZP4d4xP2Llg==", "updater": "debian/updater", "name": "CVE-2023-52624", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang. [How] Add dc_wake_and_execute_gpint() to wrap the wake, execute, sleep sequence. If the GPINT executes successfully then DMCUB will be put back into sleep after the optional response is returned. It functions similar to the inbox command interface.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52624", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "73+h9zz0/ADxJTs4lDS2qg==": { "id": "73+h9zz0/ADxJTs4lDS2qg==", "updater": "debian/updater", "name": "CVE-2025-0725", "description": "When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-0725", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "74TjW2pkixo+XKEdFIUK8A==": { "id": "74TjW2pkixo+XKEdFIUK8A==", "updater": "debian/updater", "name": "CVE-2024-36911", "description": "In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. The netvsc driver could free decrypted/shared pages if set_memory_decrypted() fails. Check the decrypted field in the gpadl to decide whether to free the memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36911", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "79WMS6tb+GafO7Jnk1cW9A==": { "id": "79WMS6tb+GafO7Jnk1cW9A==", "updater": "debian/updater", "name": "CVE-2024-54683", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: IDLETIMER: Fix for possible ABBA deadlock Deletion of the last rule referencing a given idletimer may happen at the same time as a read of its file in sysfs: | ====================================================== | WARNING: possible circular locking dependency detected | 6.12.0-rc7-01692-g5e9a28f41134-dirty #594 Not tainted | ------------------------------------------------------ | iptables/3303 is trying to acquire lock: | ffff8881057e04b8 (kn-\u003eactive#48){++++}-{0:0}, at: __kernfs_remove+0x20 | | but task is already holding lock: | ffffffffa0249068 (list_mutex){+.+.}-{3:3}, at: idletimer_tg_destroy_v] | | which lock already depends on the new lock. A simple reproducer is: | #!/bin/bash | | while true; do | iptables -A INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\" | iptables -D INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\" | done \u0026 | while true; do | cat /sys/class/xt_idletimer/timers/testme \u003e/dev/null | done Avoid this by freeing list_mutex right after deleting the element from the list, then continuing with the teardown.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-54683", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7AdvNmaPEJQFk5ZAY+XM1g==": { "id": "7AdvNmaPEJQFk5ZAY+XM1g==", "updater": "debian/updater", "name": "CVE-2026-46241", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration failure Make sure to disable and free the interrupts in case controller registration fails to avoid a potential use-after-free and resource leak. This issue was flagged by Sashiko when reviewing a controller deregistration fix.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7ApekoO6bPDdCOudsP0VLg==": { "id": "7ApekoO6bPDdCOudsP0VLg==", "updater": "debian/updater", "name": "CVE-2026-59995", "description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-59995", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7AuJGHgHvpeOIE8Xo+9Tiw==": { "id": "7AuJGHgHvpeOIE8Xo+9Tiw==", "updater": "debian/updater", "name": "CVE-2026-15742", "description": "Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15742", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7CspTksKQHFn5A13jATrGA==": { "id": "7CspTksKQHFn5A13jATrGA==", "updater": "debian/updater", "name": "CVE-2024-56742", "description": "In the Linux kernel, the following vulnerability has been resolved: vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() Fix an unwind issue in mlx5vf_add_migration_pages(). If a set of pages is allocated but fails to be added to the SG table, they need to be freed to prevent a memory leak. Any pages successfully added to the SG table will be freed as part of mlx5vf_free_data_buffer().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56742", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7FcjXbr6LhyyOlh0vreQ0Q==": { "id": "7FcjXbr6LhyyOlh0vreQ0Q==", "updater": "debian/updater", "name": "CVE-2024-43913", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme: apple: fix device reference counting Drivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl. Split the allocation side out to make the error handling boundary easier to navigate. The apple driver had been doing this wrong, leaking the controller device memory on a tagset failure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43913", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7ItuePxGlND/Uf0/PTPlTw==": { "id": "7ItuePxGlND/Uf0/PTPlTw==", "updater": "debian/updater", "name": "CVE-2026-68246", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68246", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7JqGXHi6j8X/siNtDOoeCQ==": { "id": "7JqGXHi6j8X/siNtDOoeCQ==", "updater": "debian/updater", "name": "CVE-2025-37834", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: don't try to reclaim hwpoison folio Syzkaller reports a bug as follows: Injecting memory failure for pfn 0x18b00e at process virtual address 0x20ffd000 Memory failure: 0x18b00e: dirty swapcache page still referenced by 2 users Memory failure: 0x18b00e: recovery action for dirty swapcache page: Failed page: refcount:2 mapcount:0 mapping:0000000000000000 index:0x20ffd pfn:0x18b00e memcg:ffff0000dd6d9000 anon flags: 0x5ffffe00482011(locked|dirty|arch_1|swapbacked|hwpoison|node=0|zone=2|lastcpupid=0xfffff) raw: 005ffffe00482011 dead000000000100 dead000000000122 ffff0000e232a7c9 raw: 0000000000020ffd 0000000000000000 00000002ffffffff ffff0000dd6d9000 page dumped because: VM_BUG_ON_FOLIO(!folio_test_uptodate(folio)) ------------[ cut here ]------------ kernel BUG at mm/swap_state.c:184! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP Modules linked in: CPU: 0 PID: 60 Comm: kswapd0 Not tainted 6.6.0-gcb097e7de84e #3 Hardware name: linux,dummy-virt (DT) pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : add_to_swap+0xbc/0x158 lr : add_to_swap+0xbc/0x158 sp : ffff800087f37340 x29: ffff800087f37340 x28: fffffc00052c0380 x27: ffff800087f37780 x26: ffff800087f37490 x25: ffff800087f37c78 x24: ffff800087f377a0 x23: ffff800087f37c50 x22: 0000000000000000 x21: fffffc00052c03b4 x20: 0000000000000000 x19: fffffc00052c0380 x18: 0000000000000000 x17: 296f696c6f662865 x16: 7461646f7470755f x15: 747365745f6f696c x14: 6f6621284f494c4f x13: 0000000000000001 x12: ffff600036d8b97b x11: 1fffe00036d8b97a x10: ffff600036d8b97a x9 : dfff800000000000 x8 : 00009fffc9274686 x7 : ffff0001b6c5cbd3 x6 : 0000000000000001 x5 : ffff0000c25896c0 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : ffff0000c25896c0 x0 : 0000000000000000 Call trace: add_to_swap+0xbc/0x158 shrink_folio_list+0x12ac/0x2648 shrink_inactive_list+0x318/0x948 shrink_lruvec+0x450/0x720 shrink_node_memcgs+0x280/0x4a8 shrink_node+0x128/0x978 balance_pgdat+0x4f0/0xb20 kswapd+0x228/0x438 kthread+0x214/0x230 ret_from_fork+0x10/0x20 I can reproduce this issue with the following steps: 1) When a dirty swapcache page is isolated by reclaim process and the page isn't locked, inject memory failure for the page. me_swapcache_dirty() clears uptodate flag and tries to delete from lru, but fails. Reclaim process will put the hwpoisoned page back to lru. 2) The process that maps the hwpoisoned page exits, the page is deleted the page will never be freed and will be in the lru forever. 3) If we trigger a reclaim again and tries to reclaim the page, add_to_swap() will trigger VM_BUG_ON_FOLIO due to the uptodate flag is cleared. To fix it, skip the hwpoisoned page in shrink_folio_list(). Besides, the hwpoison folio may not be unmapped by hwpoison_user_mappings() yet, unmap it in shrink_folio_list(), otherwise the folio will fail to be unmaped by hwpoison_user_mappings() since the folio isn't in lru list.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37834", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7MNcHEmPDkCtrqXYik1heg==": { "id": "7MNcHEmPDkCtrqXYik1heg==", "updater": "debian/updater", "name": "CVE-2026-5704", "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-5704", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7MfZgzd25Q7NVpvV5hOlMA==": { "id": "7MfZgzd25Q7NVpvV5hOlMA==", "updater": "debian/updater", "name": "CVE-2024-42241", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/shmem: disable PMD-sized page cache if needed For shmem files, it's possible that PMD-sized page cache can't be supported by xarray. For example, 512MB page cache on ARM64 when the base page size is 64KB can't be supported by xarray. It leads to errors as the following messages indicate when this sort of xarray entry is split. WARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 \\ nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject \\ nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\ ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse xfs \\ libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_net \\ net_failover virtio_console virtio_blk failover dimlib virtio_mmio CPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xas_split_alloc+0xf8/0x128 lr : split_huge_page_to_list_to_order+0x1c4/0x720 sp : ffff8000882af5f0 x29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768 x26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858 x23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000 x17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000 x14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020 x11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0 x5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace: xas_split_alloc+0xf8/0x128 split_huge_page_to_list_to_order+0x1c4/0x720 truncate_inode_partial_folio+0xdc/0x160 shmem_undo_range+0x2bc/0x6a8 shmem_fallocate+0x134/0x430 vfs_fallocate+0x124/0x2e8 ksys_fallocate+0x4c/0xa0 __arm64_sys_fallocate+0x24/0x38 invoke_syscall.constprop.0+0x7c/0xd8 do_el0_svc+0xb4/0xd0 el0_svc+0x44/0x1d8 el0t_64_sync_handler+0x134/0x150 el0t_64_sync+0x17c/0x180 Fix it by disabling PMD-sized page cache when HPAGE_PMD_ORDER is larger than MAX_PAGECACHE_ORDER. As Matthew Wilcox pointed, the page cache in a shmem file isn't represented by a multi-index entry and doesn't have this limitation when the xarry entry is split until commit 6b24ca4a1a8d (\"mm: Use multi-index entries in the page cache\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7PWa/1p3+m/2Cnct0TMQmg==": { "id": "7PWa/1p3+m/2Cnct0TMQmg==", "updater": "debian/updater", "name": "CVE-2025-38311", "description": "In the Linux kernel, the following vulnerability has been resolved: iavf: get rid of the crit lock Get rid of the crit lock. That frees us from the error prone logic of try_locks. Thanks to netdev_lock() by Jakub it is now easy, and in most cases we were protected by it already - replace crit lock by netdev lock when it was not the case. Lockdep reports that we should cancel the work under crit_lock [splat1], and that was the scheme we have mostly followed since [1] by Slawomir. But when that is done we still got into deadlocks [splat2]. So instead we should look at the bigger problem, namely \"weird locking/scheduling\" of the iavf. The first step to fix that is to remove the crit lock. I will followup with a -next series that simplifies scheduling/tasks. Cancel the work without netdev lock (weird unlock+lock scheme), to fix the [splat2] (which would be totally ugly if we would kept the crit lock). Extend protected part of iavf_watchdog_task() to include scheduling more work. Note that the removed comment in iavf_reset_task() was misplaced, it belonged to inside of the removed if condition, so it's gone now. [splat1] - w/o this patch - The deadlock during VF removal: WARNING: possible circular locking dependency detected sh/3825 is trying to acquire lock: ((work_completion)(\u0026(\u0026adapter-\u003ewatchdog_task)-\u003ework)){+.+.}-{0:0}, at: start_flush_work+0x1a1/0x470 but task is already holding lock: (\u0026adapter-\u003ecrit_lock){+.+.}-{4:4}, at: iavf_remove+0xd1/0x690 [iavf] which lock already depends on the new lock. [splat2] - when cancelling work under crit lock, w/o this series, \t see [2] for the band aid attempt WARNING: possible circular locking dependency detected sh/3550 is trying to acquire lock: ((wq_completion)iavf){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90 but task is already holding lock: (\u0026dev-\u003elock){+.+.}-{4:4}, at: iavf_remove+0xa6/0x6e0 [iavf] which lock already depends on the new lock. [1] fc2e6b3b132a (\"iavf: Rework mutexes for better synchronisation\") [2] https://github.com/pkitszel/linux/commit/52dddbfc2bb60294083f5711a158a", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38311", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7Qb81tXMISyKPC7YEKlyZg==": { "id": "7Qb81tXMISyKPC7YEKlyZg==", "updater": "debian/updater", "name": "CVE-2025-12839", "description": "Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-12839", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7XcpF7gQsSGccuF/A656dA==": { "id": "7XcpF7gQsSGccuF/A656dA==", "updater": "debian/updater", "name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-5686", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "shadow", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7apQYQajm57oxazpbOGuzw==": { "id": "7apQYQajm57oxazpbOGuzw==", "updater": "debian/updater", "name": "CVE-2026-63871", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() call hci_get_route() using iso_pi(sk)-\u003edst, iso_pi(sk)-\u003esrc, and iso_pi(sk)-\u003esrc_type without holding lock_sock(). These fields may be modified concurrently by connect() or setsockopt() on the same socket, resulting in data-races reported by KCSAN. Fix this by snapshotting the required fields under lock_sock() before calling hci_get_route(). BUG: KCSAN: data-race in memcmp+0x45/0xb0 race at unknown origin, with read to 0xffff8880122135cf of 1 bytes by task 333 on cpu 1: memcmp+0x45/0xb0 hci_get_route+0x27e/0x490 iso_connect_cis+0x4c/0xa10 iso_sock_connect+0x60e/0xb30 __sys_connect_file+0xbd/0xe0 __sys_connect+0xe0/0x110 __x64_sys_connect+0x40/0x50 x64_sys_call+0xcad/0x1c60 do_syscall_64+0x133/0x590 entry_SYSCALL_64_after_hwframe+0x77/0x7f", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63871", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7dVsv8lPa22N4ojcK5rlYw==": { "id": "7dVsv8lPa22N4ojcK5rlYw==", "updater": "debian/updater", "name": "CVE-2024-2236", "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-2236", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libgcrypt20", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7deukt0nx1nb4gAr399SPA==": { "id": "7deukt0nx1nb4gAr399SPA==", "updater": "debian/updater", "name": "CVE-2023-31081", "description": "An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb-\u003emux=NULL occurs, it executes vidtv_mux_stop_thread(dvb-\u003emux).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31081", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7eTva12msMAYR9wW2m9uvA==": { "id": "7eTva12msMAYR9wW2m9uvA==", "updater": "debian/updater", "name": "CVE-2025-40136", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - request reserved interrupt for virtual function The device interrupt vector 3 is an error interrupt for physical function and a reserved interrupt for virtual function. However, the driver has not registered the reserved interrupt for virtual function. When allocating interrupts, the number of interrupts is allocated based on powers of two, which includes this interrupt. When the system enables GICv4 and the virtual function passthrough to the virtual machine, releasing the interrupt in the driver triggers a warning. The WARNING report is: WARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4 Therefore, register a reserved interrupt for VF and set the IRQF_NO_AUTOEN flag to avoid that warning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40136", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7fFaZxYENGItC+DqHp8ghA==": { "id": "7fFaZxYENGItC+DqHp8ghA==", "updater": "debian/updater", "name": "CVE-2025-39720", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix refcount leak causing resource not released When ksmbd_conn_releasing(opinfo-\u003econn) returns true,the refcount was not decremented properly, causing a refcount leak that prevents the count from reaching zero and the memory from being released.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39720", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7gEkx7h7id09bJ3nUfeoDQ==": { "id": "7gEkx7h7id09bJ3nUfeoDQ==", "updater": "debian/updater", "name": "CVE-2024-53085", "description": "In the Linux kernel, the following vulnerability has been resolved: tpm: Lock TPM chip in tpm_pm_suspend() first Setting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can be racy according, as this leaves window for tpm_hwrng_read() to be called while the operation is in progress. The recent bug report gives also evidence of this behaviour. Aadress this by locking the TPM chip before checking any chip-\u003eflags both in tpm_pm_suspend() and tpm_hwrng_read(). Move TPM_CHIP_FLAG_SUSPENDED check inside tpm_get_random() so that it will be always checked only when the lock is reserved.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53085", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7kwW3ItNyNKm5qVpmNIbIw==": { "id": "7kwW3ItNyNKm5qVpmNIbIw==", "updater": "debian/updater", "name": "CVE-2026-64294", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: do file ownership checks with the proper mount idmap Ever since idmapped mounts were introduced, inode ownership checks (for side-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done against the nop_mnt_idmap, which completely ignores the file's mount's idmap. This results in odd edgecases like: 1) mount/bind-mount with an idmap userA:userB:1 2) userB runs an owner_or_capable() check on file that is owned by userA on-disk/in-memory, but owned by userB after idmap translation 3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied In the case of mincore/madvise MADV_PAGEOUT, this is usually benign, because file_permission(file, MAY_WRITE) will probably succeed, as it uses the proper idmap internally, but it does not need to be the case on e.g a 0444 file where even the owner itself doesn't have permissions to write to it. Since this is clearly not trivial to get right, introduce a file_owner_or_capable() that can carry the correct semantics, and switch the various users in mm to it. The issue was found by manual code inspection \u0026 an off-list discussion with Jan Kara.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64294", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7n9MSpyjqSnvfsNTBPI7MQ==": { "id": "7n9MSpyjqSnvfsNTBPI7MQ==", "updater": "debian/updater", "name": "CVE-2025-71065", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock As Jiaming Zhang and syzbot reported, there is potential deadlock in f2fs as below: Chain exists of: \u0026sbi-\u003ecp_rwsem --\u003e fs_reclaim --\u003e sb_internal#2 Possible unsafe locking scenario: CPU0 CPU1 ---- ---- rlock(sb_internal#2); lock(fs_reclaim); lock(sb_internal#2); rlock(\u0026sbi-\u003ecp_rwsem); *** DEADLOCK *** 3 locks held by kswapd0/73: #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat mm/vmscan.c:7015 [inline] #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: kswapd+0x951/0x2800 mm/vmscan.c:7389 #1: ffff8880118400e0 (\u0026type-\u003es_umount_key#50){.+.+}-{4:4}, at: super_trylock_shared fs/super.c:562 [inline] #1: ffff8880118400e0 (\u0026type-\u003es_umount_key#50){.+.+}-{4:4}, at: super_cache_scan+0x91/0x4b0 fs/super.c:197 #2: ffff888011840610 (sb_internal#2){.+.+}-{0:0}, at: f2fs_evict_inode+0x8d9/0x1b60 fs/f2fs/inode.c:890 stack backtrace: CPU: 0 UID: 0 PID: 73 Comm: kswapd0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_circular_bug+0x2ee/0x310 kernel/locking/lockdep.c:2043 check_noncircular+0x134/0x160 kernel/locking/lockdep.c:2175 check_prev_add kernel/locking/lockdep.c:3165 [inline] check_prevs_add kernel/locking/lockdep.c:3284 [inline] validate_chain+0xb9b/0x2140 kernel/locking/lockdep.c:3908 __lock_acquire+0xab9/0xd20 kernel/locking/lockdep.c:5237 lock_acquire+0x120/0x360 kernel/locking/lockdep.c:5868 down_read+0x46/0x2e0 kernel/locking/rwsem.c:1537 f2fs_down_read fs/f2fs/f2fs.h:2278 [inline] f2fs_lock_op fs/f2fs/f2fs.h:2357 [inline] f2fs_do_truncate_blocks+0x21c/0x10c0 fs/f2fs/file.c:791 f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:867 f2fs_truncate+0x489/0x7c0 fs/f2fs/file.c:925 f2fs_evict_inode+0x9f2/0x1b60 fs/f2fs/inode.c:897 evict+0x504/0x9c0 fs/inode.c:810 f2fs_evict_inode+0x1dc/0x1b60 fs/f2fs/inode.c:853 evict+0x504/0x9c0 fs/inode.c:810 dispose_list fs/inode.c:852 [inline] prune_icache_sb+0x21b/0x2c0 fs/inode.c:1000 super_cache_scan+0x39b/0x4b0 fs/super.c:224 do_shrink_slab+0x6ef/0x1110 mm/shrinker.c:437 shrink_slab_memcg mm/shrinker.c:550 [inline] shrink_slab+0x7ef/0x10d0 mm/shrinker.c:628 shrink_one+0x28a/0x7c0 mm/vmscan.c:4955 shrink_many mm/vmscan.c:5016 [inline] lru_gen_shrink_node mm/vmscan.c:5094 [inline] shrink_node+0x315d/0x3780 mm/vmscan.c:6081 kswapd_shrink_node mm/vmscan.c:6941 [inline] balance_pgdat mm/vmscan.c:7124 [inline] kswapd+0x147c/0x2800 mm/vmscan.c:7389 kthread+0x70e/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 \u003c/TASK\u003e The root cause is deadlock among four locks as below: kswapd - fs_reclaim\t\t\t\t--- Lock A - shrink_one - evict - f2fs_evict_inode - sb_start_intwrite\t\t\t--- Lock B - iput - evict - f2fs_evict_inode - sb_start_intwrite\t\t\t--- Lock B - f2fs_truncate - f2fs_truncate_blocks - f2fs_do_truncate_blocks - f2fs_lock_op\t\t\t--- Lock C ioctl - f2fs_ioc_commit_atomic_write - f2fs_lock_op\t\t\t\t--- Lock C - __f2fs_commit_atomic_write - __replace_atomic_write_block - f2fs_get_dnode_of_data - __get_node_folio - f2fs_check_nid_range - f2fs_handle_error - f2fs_record_errors - f2fs_down_write\t\t--- Lock D open - do_open - do_truncate - security_inode_need_killpriv - f2fs_getxattr - lookup_all_xattrs - f2fs_handle_error - f2fs_record_errors - f2fs_down_write\t\t--- Lock D - f2fs_commit_super - read_mapping_folio - filemap_alloc_folio_noprof - prepare_alloc_pages - fs_reclaim_acquire\t--- Lock A In order to a ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71065", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7pmzE7cjlb0lYdvy2/02Zw==": { "id": "7pmzE7cjlb0lYdvy2/02Zw==", "updater": "debian/updater", "name": "CVE-2025-37806", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot reported a NULL pointer dereference in __generic_file_write_iter. [1] Before the write operation is completed, the user executes ioctl[2] to clear the compress flag of the file, which causes the is_compressed() judgment to return 0, further causing the program to enter the wrong process and call the wrong ops ntfs_aops_cmpr, which triggers the null pointer dereference of write_begin. Use inode lock to synchronize ioctl and write to avoid this case. [1] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Mem abort info: ESR = 0x0000000086000006 EC = 0x21: IABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x06: level 2 translation fault user pgtable: 4k pages, 48-bit VAs, pgdp=000000011896d000 [0000000000000000] pgd=0800000118b44403, p4d=0800000118b44403, pud=0800000117517403, pmd=0000000000000000 Internal error: Oops: 0000000086000006 [#1] PREEMPT SMP Modules linked in: CPU: 0 UID: 0 PID: 6427 Comm: syz-executor347 Not tainted 6.13.0-rc3-syzkaller-g573067a5a685 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : 0x0 lr : generic_perform_write+0x29c/0x868 mm/filemap.c:4055 sp : ffff80009d4978a0 x29: ffff80009d4979c0 x28: dfff800000000000 x27: ffff80009d497bc8 x26: 0000000000000000 x25: ffff80009d497960 x24: ffff80008ba71c68 x23: 0000000000000000 x22: ffff0000c655dac0 x21: 0000000000001000 x20: 000000000000000c x19: 1ffff00013a92f2c x18: ffff0000e183aa1c x17: 0004060000000014 x16: ffff800083275834 x15: 0000000000000001 x14: 0000000000000000 x13: 0000000000000001 x12: ffff0000c655dac0 x11: 0000000000ff0100 x10: 0000000000ff0100 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 x5 : ffff80009d497980 x4 : ffff80009d497960 x3 : 0000000000001000 x2 : 0000000000000000 x1 : ffff0000e183a928 x0 : ffff0000d60b0fc0 Call trace: 0x0 (P) __generic_file_write_iter+0xfc/0x204 mm/filemap.c:4156 ntfs_file_write_iter+0x54c/0x630 fs/ntfs3/file.c:1267 new_sync_write fs/read_write.c:586 [inline] vfs_write+0x920/0xcf4 fs/read_write.c:679 ksys_write+0x15c/0x26c fs/read_write.c:731 __do_sys_write fs/read_write.c:742 [inline] __se_sys_write fs/read_write.c:739 [inline] __arm64_sys_write+0x7c/0x90 fs/read_write.c:739 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151 el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744 el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762 [2] ioctl$FS_IOC_SETFLAGS(r0, 0x40086602, \u0026(0x7f00000000c0)=0x20)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37806", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7q5Yr5iGk2TjQ1fwpKRx0A==": { "id": "7q5Yr5iGk2TjQ1fwpKRx0A==", "updater": "debian/updater", "name": "CVE-2025-37750", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in decryption with multichannel After commit f7025d861694 (\"smb: client: allocate crypto only for primary server\") and commit b0abcd65ec54 (\"smb: client: fix UAF in async decryption\"), the channels started reusing AEAD TFM from primary channel to perform synchronous decryption, but that can't done as there could be multiple cifsd threads (one per channel) simultaneously accessing it to perform decryption. This fixes the following KASAN splat when running fstest generic/249 with 'vers=3.1.1,multichannel,max_channels=4,seal' against Windows Server 2022: BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xba/0x110 Read of size 8 at addr ffff8881046c18a0 by task cifsd/986 CPU: 3 UID: 0 PID: 986 Comm: cifsd Not tainted 6.15.0-rc1 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41 04/01/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x5d/0x80 print_report+0x156/0x528 ? gf128mul_4k_lle+0xba/0x110 ? __virt_addr_valid+0x145/0x300 ? __phys_addr+0x46/0x90 ? gf128mul_4k_lle+0xba/0x110 kasan_report+0xdf/0x1a0 ? gf128mul_4k_lle+0xba/0x110 gf128mul_4k_lle+0xba/0x110 ghash_update+0x189/0x210 shash_ahash_update+0x295/0x370 ? __pfx_shash_ahash_update+0x10/0x10 ? __pfx_shash_ahash_update+0x10/0x10 ? __pfx_extract_iter_to_sg+0x10/0x10 ? ___kmalloc_large_node+0x10e/0x180 ? __asan_memset+0x23/0x50 crypto_ahash_update+0x3c/0xc0 gcm_hash_assoc_remain_continue+0x93/0xc0 crypt_message+0xe09/0xec0 [cifs] ? __pfx_crypt_message+0x10/0x10 [cifs] ? _raw_spin_unlock+0x23/0x40 ? __pfx_cifs_readv_from_socket+0x10/0x10 [cifs] decrypt_raw_data+0x229/0x380 [cifs] ? __pfx_decrypt_raw_data+0x10/0x10 [cifs] ? __pfx_cifs_read_iter_from_socket+0x10/0x10 [cifs] smb3_receive_transform+0x837/0xc80 [cifs] ? __pfx_smb3_receive_transform+0x10/0x10 [cifs] ? __pfx___might_resched+0x10/0x10 ? __pfx_smb3_is_transform_hdr+0x10/0x10 [cifs] cifs_demultiplex_thread+0x692/0x1570 [cifs] ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs] ? rcu_is_watching+0x20/0x50 ? rcu_lockdep_current_cpu_online+0x62/0xb0 ? find_held_lock+0x32/0x90 ? kvm_sched_clock_read+0x11/0x20 ? local_clock_noinstr+0xd/0xd0 ? trace_irq_enable.constprop.0+0xa8/0xe0 ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs] kthread+0x1fe/0x380 ? kthread+0x10f/0x380 ? __pfx_kthread+0x10/0x10 ? local_clock_noinstr+0xd/0xd0 ? ret_from_fork+0x1b/0x60 ? local_clock+0x15/0x30 ? lock_release+0x29b/0x390 ? rcu_is_watching+0x20/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x31/0x60 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37750", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7rOmgLxcgbnBpJsD3eacKg==": { "id": "7rOmgLxcgbnBpJsD3eacKg==", "updater": "debian/updater", "name": "CVE-2026-0864", "description": "When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-0864", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7une1X4kNaY52KKvp3/k8Q==": { "id": "7une1X4kNaY52KKvp3/k8Q==", "updater": "debian/updater", "name": "CVE-2025-38117", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Protect mgmt_pending list with its own lock This uses a mutex to protect from concurrent access of mgmt_pending list which can cause crashes like: ================================================================== BUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91 Read of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318 CPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 Call trace: show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C) __dump_stack+0x30/0x40 lib/dump_stack.c:94 dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120 print_address_description+0xa8/0x254 mm/kasan/report.c:408 print_report+0x68/0x84 mm/kasan/report.c:521 kasan_report+0xb0/0x110 mm/kasan/report.c:634 __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379 hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91 mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223 pending_find net/bluetooth/mgmt.c:947 [inline] remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445 hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712 hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832 sock_sendmsg_nosec net/socket.c:712 [inline] __sock_sendmsg net/socket.c:727 [inline] sock_write_iter+0x25c/0x378 net/socket.c:1131 new_sync_write fs/read_write.c:591 [inline] vfs_write+0x62c/0x97c fs/read_write.c:684 ksys_write+0x120/0x210 fs/read_write.c:736 __do_sys_write fs/read_write.c:747 [inline] __se_sys_write fs/read_write.c:744 [inline] __arm64_sys_write+0x7c/0x90 fs/read_write.c:744 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151 el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767 el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786 el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600 Allocated by task 7037: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x40/0x78 mm/kasan/common.c:68 kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562 poison_kmalloc_redzone mm/kasan/common.c:377 [inline] __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394 kasan_kmalloc include/linux/kasan.h:260 [inline] __do_kmalloc_node mm/slub.c:4327 [inline] __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339 kmalloc_noprof include/linux/slab.h:909 [inline] sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198 sk_alloc+0x44/0x3ac net/core/sock.c:2254 bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148 hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202 bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132 __sock_create+0x43c/0x91c net/socket.c:1541 sock_create net/socket.c:1599 [inline] __sys_socket_create net/socket.c:1636 [inline] __sys_socket+0xd4/0x1c0 net/socket.c:1683 __do_sys_socket net/socket.c:1697 [inline] __se_sys_socket net/socket.c:1695 [inline] __arm64_sys_socket+0x7c/0x94 net/socket.c:1695 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151 el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767 el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786 el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600 Freed by task 6607: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x40/0x78 mm/kasan/common.c:68 kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576 poison_slab_object mm/kasan/common.c:247 [inline] __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264 kasan_slab_free include/linux/kasan.h:233 [inline ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38117", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7x+psdYzd9mM2qtbmtW+mw==": { "id": "7x+psdYzd9mM2qtbmtW+mw==", "updater": "debian/updater", "name": "CVE-2026-68436", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc struct dc has grown large over time (most of it the two inlined dc_scratch_space copies) and now sits close to the page allocator's 4 MiB contiguous allocation limit. Its actual size is not fixed by the source alone, it also depends on the compiler and the .config, so it can easily cross 4 MiB, e.g. with a newer GCC or a config change. dc_create() allocates it with kzalloc(). Once struct dc exceeds 4 MiB the request is rounded up to order 11 (8 MiB), which is above MAX_PAGE_ORDER, so the page allocator warns and returns NULL. dc_create() then fails, DM init fails and amdgpu probe aborts with -EINVAL: WARNING: mm/page_alloc.c:5197 at __alloc_frozen_pages_noprof+0x2f9/0x380 dc_create+0x38/0x660 [amdgpu] amdgpu_dm_init+0x2d9/0x510 [amdgpu] dm_hw_init+0x1b/0x90 [amdgpu] amdgpu_device_init.cold+0x150d/0x1e13 [amdgpu] amdgpu_driver_load_kms+0x19/0x80 [amdgpu] amdgpu_pci_probe+0x1e2/0x4c0 [amdgpu] dc_create() then returns NULL and DM init fails, which aborts the whole GPU init and makes amdgpu probe fail with -EINVAL (\"hw_init of IP block \u003cdm\u003e failed -22\"), leaving the display unusable. The subsequent amdgpu_irq_put() warnings during teardown are just fallout of unwinding a half-initialized device. struct dc is a software-only bookkeeping structure that is never handed to hardware DMA and is only ever kept as an opaque pointer, so it does not require physically contiguous memory. Allocate it with kvzalloc() (and free it with kvfree()) so that the allocator can fall back to vmalloc() when a contiguous allocation of that size is not available, which also avoids the MAX_PAGE_ORDER warning entirely. v2: - Rebase to amd-staging-drm-next. (cherry picked from commit 991e0516a8072f2292681c6ae98a924ab0e32575)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68436", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7xkpS42Ar82kePpM49ESDQ==": { "id": "7xkpS42Ar82kePpM49ESDQ==", "updater": "debian/updater", "name": "CVE-2019-19378", "description": "In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-19378", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "7yPUXvIZ9otJoyV9YvQB+A==": { "id": "7yPUXvIZ9otJoyV9YvQB+A==", "updater": "debian/updater", "name": "CVE-2026-68425", "description": "In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment. That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response would not match any send. For kernel-handled RMPP DATA responses, require the existing ib_find_send_mad() match before entering RMPP reassembly. The matcher already checks the full TID, management class and source address/GID against the agent wait, backlog and in-flight send lists. If there is no match, drop the response without creating RMPP state. This leaves the RMPP window behavior unchanged and only rejects responses that have no corresponding request.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68425", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "80CwuXka1gaqTKme6aYJTA==": { "id": "80CwuXka1gaqTKme6aYJTA==", "updater": "debian/updater", "name": "CVE-2016-9115", "description": "Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9115", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "81GjLIh5V5cQwLLndqjzDg==": { "id": "81GjLIh5V5cQwLLndqjzDg==", "updater": "debian/updater", "name": "CVE-2023-52671", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix hang/underflow when transitioning to ODM4:1 [Why] Under some circumstances, disabling an OPTC and attempting to reclaim its OPP(s) for a different OPTC could cause a hang/underflow due to OPPs not being properly disconnected from the disabled OPTC. [How] Ensure that all OPPs are unassigned from an OPTC when it gets disabled.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52671", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "865AsH7FNuZXb9d7RiRkFw==": { "id": "865AsH7FNuZXb9d7RiRkFw==", "updater": "debian/updater", "name": "CVE-2023-54227", "description": "In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix tags leak when shrink nr_hw_queues Although we don't need to realloc set-\u003etags[] when shrink nr_hw_queues, we need to free them. Or these tags will be leaked. How to reproduce: 1. mount -t configfs configfs /mnt 2. modprobe null_blk nr_devices=0 submit_queues=8 3. mkdir /mnt/nullb/nullb0 4. echo 1 \u003e /mnt/nullb/nullb0/power 5. echo 4 \u003e /mnt/nullb/nullb0/submit_queues 6. rmdir /mnt/nullb/nullb0 In step 4, will alloc 9 tags (8 submit queues and 1 poll queue), then in step 5, new_nr_hw_queues = 5 (4 submit queues and 1 poll queue). At last in step 6, only these 5 tags are freed, the other 4 tags leaked.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54227", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8EaWp8elgqvtETTn1s9C+A==": { "id": "8EaWp8elgqvtETTn1s9C+A==", "updater": "debian/updater", "name": "CVE-2026-68322", "description": "In the Linux kernel, the following vulnerability has been resolved: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, inet6_addr_lst is never initialized because inet6_init() exits before addrconf_init() is called to initialize it. An attempt to bind an RDS socket to an ipv6 address results in a crash in __ipv6_chk_addr_and_flags() KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] RIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0 Call Trace: \u003cTASK\u003e ipv6_chk_addr+0x3b/0x50 rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp] rds_trans_get_preferred+0x15d/0x2d0 [rds] ? trace_hardirqs_on+0x2d/0x110 rds_bind+0x1433/0x1d60 [rds] ? rds_remove_bound+0xd50/0xd50 [rds] ? aa_af_perm+0x250/0x250 ? __might_fault+0xde/0x190 ? __sys_bind+0x1dc/0x210 __sys_bind+0x1dc/0x210 ? __ia32_sys_socketpair+0x100/0x100 ? restore_fpregs_from_fpstate+0x53/0x100 __x64_sys_bind+0x73/0xb0 ? syscall_enter_from_user_mode+0x1c/0x50 do_syscall_64+0x34/0x80 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 RIP: 0033:0x7f47f8269ea9 \u003c/TASK\u003e The following code reproduces the issue: struct sockaddr_in6 addr; s = socket(PF_RDS, SOCK_SEQPACKET, 0); memset(\u0026addr, 0, sizeof(addr)); inet_pton(AF_INET6, ADDRESS, \u0026addr.sin6_addr); addr.sin6_family = AF_INET6; addr.sin6_port = htons(PORT); bind(s, \u0026addr, sizeof(addr)); Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with Syzkaller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68322", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8JDDEQtcQoyLw8fKvkdvtA==": { "id": "8JDDEQtcQoyLw8fKvkdvtA==", "updater": "debian/updater", "name": "CVE-2026-46032", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT If loading L1's CR3 fails on a nested #VMEXIT, nested_svm_vmexit() returns an error code that is ignored by most callers, and continues to run L1 with corrupted state. A sane recovery is not possible in this case, and HW behavior is to cause a shutdown. Inject a triple fault instead, and do not return early from nested_svm_vmexit(). Continue cleaning up the vCPU state (e.g. clear pending exceptions), to handle the failure as gracefully as possible. From the APM: Upon #VMEXIT, the processor performs the following actions in order to return to the host execution context: ... if (illegal host state loaded, or exception while loading host state) shutdown else execute first host instruction following the VMRUN Remove the return value of nested_svm_vmexit(), which is mostly unchecked anyway.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46032", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8MP4w+9DQY+tiSu/rCDGow==": { "id": "8MP4w+9DQY+tiSu/rCDGow==", "updater": "debian/updater", "name": "CVE-2017-18018", "description": "In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-18018", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8NnG4EWsyzQmd5x6/PohVw==": { "id": "8NnG4EWsyzQmd5x6/PohVw==", "updater": "debian/updater", "name": "CVE-2025-40311", "description": "In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When IOMMU is enabled, dma_alloc_coherent() with GFP_USER may return addresses from the vmalloc range. If such an address is mapped without VM_MIXEDMAP, vm_insert_page() will trigger a BUG_ON due to the VM_PFNMAP restriction. Fix this by checking for vmalloc addresses and setting VM_MIXEDMAP in the VMA before mapping. This ensures safe mapping and avoids kernel crashes. The memory is still driver-allocated and cannot be accessed directly by userspace.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40311", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8VV2hxLjCmO9pEMGLA0x9w==": { "id": "8VV2hxLjCmO9pEMGLA0x9w==", "updater": "debian/updater", "name": "CVE-2022-3238", "description": "A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-3238", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8XxRH9NhjI4C1qTDFVnshA==": { "id": "8XxRH9NhjI4C1qTDFVnshA==", "updater": "debian/updater", "name": "CVE-2026-68446", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68446", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8Xzeresx+aYil0U4zoIbPw==": { "id": "8Xzeresx+aYil0U4zoIbPw==", "updater": "debian/updater", "name": "CVE-2026-46254", "description": "In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to handle unaligned dfa tables The dfa tables can originate from kernel or userspace and 8-byte alignment isn't always guaranteed and as such may trigger unaligned memory accesses on various architectures. Resulting in the following [   73.901376] WARNING: CPU: 0 PID: 341 at security/apparmor/match.c:316 aa_dfa_unpack+0x6cc/0x720 [   74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_panel_orientation_quirks backlight i2c_core configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 hid_generic usbhid sr_mod hid cdrom sd_mod ata_generic ohci_pci ehci_pci ehci_hcd ohci_hcd pata_ali libata sym53c8xx scsi_transport_spi tg3 scsi_mod usbcore libphy scsi_common mdio_bus usb_common [   74.428977] CPU: 0 UID: 0 PID: 341 Comm: apparmor_parser Not tainted 6.18.0-rc6+ #9 NONE [   74.536543] Call Trace: [   74.568561] [\u003c0000000000434c24\u003e] dump_stack+0x8/0x18 [   74.633757] [\u003c0000000000476438\u003e] __warn+0xd8/0x100 [   74.696664] [\u003c00000000004296d4\u003e] warn_slowpath_fmt+0x34/0x74 [   74.771006] [\u003c00000000008db28c\u003e] aa_dfa_unpack+0x6cc/0x720 [   74.843062] [\u003c00000000008e643c\u003e] unpack_pdb+0xbc/0x7e0 [   74.910545] [\u003c00000000008e7740\u003e] unpack_profile+0xbe0/0x1300 [   74.984888] [\u003c00000000008e82e0\u003e] aa_unpack+0xe0/0x6a0 [   75.051226] [\u003c00000000008e3ec4\u003e] aa_replace_profiles+0x64/0x1160 [   75.130144] [\u003c00000000008d4d90\u003e] policy_update+0xf0/0x280 [   75.201057] [\u003c00000000008d4fc8\u003e] profile_replace+0xa8/0x100 [   75.274258] [\u003c0000000000766bd0\u003e] vfs_write+0x90/0x420 [   75.340594] [\u003c00000000007670cc\u003e] ksys_write+0x4c/0xe0 [   75.406932] [\u003c0000000000767174\u003e] sys_write+0x14/0x40 [   75.472126] [\u003c0000000000406174\u003e] linux_sparc_syscall+0x34/0x44 [   75.548802] ---[ end trace 0000000000000000 ]--- [   75.609503] dfa blob stream 0xfff0000008926b96 not aligned. [   75.682695] Kernel unaligned access at TPC[8db2a8] aa_dfa_unpack+0x6e8/0x720 Work around it by using the get_unaligned_xx() helpers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46254", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8YPiey8As9kb5oGX07GXAQ==": { "id": "8YPiey8As9kb5oGX07GXAQ==", "updater": "debian/updater", "name": "CVE-2025-21723", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix possible crash when setting up bsg fails If bsg_setup_queue() fails, the bsg_queue is assigned a non-NULL value. Consequently, in mpi3mr_bsg_exit(), the condition \"if(!mrioc-\u003ebsg_queue)\" will not be satisfied, preventing execution from entering bsg_remove_queue(), which could lead to the following crash: BUG: kernel NULL pointer dereference, address: 000000000000041c Call Trace: \u003cTASK\u003e mpi3mr_bsg_exit+0x1f/0x50 [mpi3mr] mpi3mr_remove+0x6f/0x340 [mpi3mr] pci_device_remove+0x3f/0xb0 device_release_driver_internal+0x19d/0x220 unbind_store+0xa4/0xb0 kernfs_fop_write_iter+0x11f/0x200 vfs_write+0x1fc/0x3e0 ksys_write+0x67/0xe0 do_syscall_64+0x38/0x80 entry_SYSCALL_64_after_hwframe+0x78/0xe2", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21723", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8Ye9q4LnyzDb957ctelwBg==": { "id": "8Ye9q4LnyzDb957ctelwBg==", "updater": "debian/updater", "name": "CVE-2025-40077", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid overflow while left shift operation Should cast type of folio-\u003eindex from pgoff_t to loff_t to avoid overflow while left shift operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40077", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8azNbKhH8TuKXpL7oWx0hw==": { "id": "8azNbKhH8TuKXpL7oWx0hw==", "updater": "debian/updater", "name": "CVE-2024-53094", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES While running ISER over SIW, the initiator machine encounters a warning from skb_splice_from_iter() indicating that a slab page is being used in send_page. To address this, it is better to add a sendpage_ok() check within the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag should be disabled before entering the network stack. A similar issue has been discussed for NVMe in this thread: https://lore.kernel.org/all/20240530142417.146696-1-ofir.gal@volumez.com/ WARNING: CPU: 0 PID: 5342 at net/core/skbuff.c:7140 skb_splice_from_iter+0x173/0x320 Call Trace: tcp_sendmsg_locked+0x368/0xe40 siw_tx_hdt+0x695/0xa40 [siw] siw_qp_sq_process+0x102/0xb00 [siw] siw_sq_resume+0x39/0x110 [siw] siw_run_sq+0x74/0x160 [siw] kthread+0xd2/0x100 ret_from_fork+0x34/0x40 ret_from_fork_asm+0x1a/0x30", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53094", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8bJ6TvpmLYG/y2sOhV60fA==": { "id": "8bJ6TvpmLYG/y2sOhV60fA==", "updater": "debian/updater", "name": "CVE-2024-56538", "description": "In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any further userspace accesses to result in an error without further calls into this driver's internals.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56538", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8d4vfFuZtB02pD0yhIbT8g==": { "id": "8d4vfFuZtB02pD0yhIbT8g==", "updater": "debian/updater", "name": "CVE-2024-38630", "description": "In the Linux kernel, the following vulnerability has been resolved: watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger When the cpu5wdt module is removing, the origin code uses del_timer() to de-activate the timer. If the timer handler is running, del_timer() could not stop it and will return directly. If the port region is released by release_region() and then the timer handler cpu5wdt_trigger() calls outb() to write into the region that is released, the use-after-free bug will happen. Change del_timer() to timer_shutdown_sync() in order that the timer handler could be finished before the port region is released.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38630", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8fvdCdxGOPLTl/QZZmHYXQ==": { "id": "8fvdCdxGOPLTl/QZZmHYXQ==", "updater": "debian/updater", "name": "CVE-2026-45897", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them. A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45897", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8gbN0n+9VnrAx9TxfaZCjg==": { "id": "8gbN0n+9VnrAx9TxfaZCjg==", "updater": "debian/updater", "name": "CVE-2024-40999", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors consistency Validate that `first` flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a reset will occur. A new reset reason for RX data corruption has been added.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40999", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8hXgdgR3MyuUTqBbTATxRA==": { "id": "8hXgdgR3MyuUTqBbTATxRA==", "updater": "debian/updater", "name": "CVE-2024-31047", "description": "An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-31047", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8i7oY8t0v/hqoPfbdjDImQ==": { "id": "8i7oY8t0v/hqoPfbdjDImQ==", "updater": "debian/updater", "name": "CVE-2026-53107", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: don't kill URBs in interrupt context Serialization for the TX path was enforced by calling usb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before a previous URB was completed. usb_tx_block() can be called from interrupt context (e.g. in the HCD giveback path), so we can't always use it to kill in-flight URBs. Prevent sleeping during interrupt context by checking the tx_submitted anchor for existing URBs. We now return -EBUSY, to indicate there's a pending request.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53107", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8l0u4wAMOeupHbUARpHfuw==": { "id": "8l0u4wAMOeupHbUARpHfuw==", "updater": "debian/updater", "name": "CVE-2026-43419", "description": "In the Linux kernel, the following vulnerability has been resolved: ceph: fix memory leaks in ceph_mdsc_build_path() Add __putname() calls to error code paths that did not free the \"path\" pointer obtained by __getname(). If ownership of this pointer is not passed to the caller via path_info.path, the function must free it before returning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43419", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8muf76acbZmX8cloC5+CHg==": { "id": "8muf76acbZmX8cloC5+CHg==", "updater": "debian/updater", "name": "CVE-2025-71272", "description": "In the Linux kernel, the following vulnerability has been resolved: most: core: fix resource leak in most_register_interface error paths The function most_register_interface() did not correctly release resources if it failed early (before registering the device). In these cases, it returned an error code immediately, leaking the memory allocated for the interface. Fix this by initializing the device early via device_initialize() and calling put_device() on all error paths. The most_register_interface() is expected to call put_device() on error which frees the resources allocated in the caller. The put_device() either calls release_mdev() or dim2_release(), depending on the caller. Switch to using device_add() instead of device_register() to handle the split initialization.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71272", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8rwOy6z2QofRrkprYBngOw==": { "id": "8rwOy6z2QofRrkprYBngOw==", "updater": "debian/updater", "name": "CVE-2008-3234", "description": "sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-3234", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8s7wZf02zu7kRPi8BEuaOg==": { "id": "8s7wZf02zu7kRPi8BEuaOg==", "updater": "debian/updater", "name": "CVE-2026-53129", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/mbcache: cancel shrink work before destroying the cache mb_cache_destroy() calls shrinker_free() and then frees all cache entries and the cache itself, but it does not cancel the pending c_shrink_work work item first. If mb_cache_entry_create() schedules c_shrink_work via schedule_work() and the work item is still pending or running when mb_cache_destroy() runs, mb_cache_shrink_worker() will access the cache after its memory has been freed, causing a use-after-free. This is only reachable by a privileged user (root or CAP_SYS_ADMIN) who can trigger the last put of a mounted ext2/ext4/ocfs2 filesystem. Cancel the work item with cancel_work_sync() before calling shrinker_free(), ensuring the worker has finished and will not be rescheduled before the cache is torn down.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53129", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8vil060zSzr5ACC5lwj23w==": { "id": "8vil060zSzr5ACC5lwj23w==", "updater": "debian/updater", "name": "CVE-2024-49922", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before using them [WHAT \u0026 HOW] These pointers are null checked previously in the same function, indicating they might be null as reported by Coverity. As a result, they need to be checked when used again. This fixes 3 FORWARD_NULL issue reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49922", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8wnXl2a51yIxn7LxSeinXA==": { "id": "8wnXl2a51yIxn7LxSeinXA==", "updater": "debian/updater", "name": "CVE-2023-52648", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Unmap the surface before resetting it on a plane state Switch to a new plane state requires unreferencing of all held surfaces. In the work required for mob cursors the mapped surfaces started being cached but the variable indicating whether the surface is currently mapped was not being reset. This leads to crashes as the duplicated state, incorrectly, indicates the that surface is mapped even when no surface is present. That's because after unreferencing the surface it's perfectly possible for the plane to be backed by a bo instead of a surface. Reset the surface mapped flag when unreferencing the plane state surface to fix null derefs in cleanup. Fixes crashes in KDE KWin 6.0 on Wayland: Oops: 0000 [#1] PREEMPT SMP PTI CPU: 4 PID: 2533 Comm: kwin_wayland Not tainted 6.7.0-rc3-vmwgfx #2 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 RIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx] Code: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 \u003c48\u003e 8b 78 28 e8 e3 f\u003e RSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600 RBP: ffff969d4143dc50 R08: 0000000000000000 R09: ffffb6b98216f920 R10: 0000000000000003 R11: ffff969e7feb3b10 R12: 0000000000000000 R13: 0000000000000000 R14: 000000000000027b R15: ffff969d49c9fc00 FS: 00007f1e8f1b4180(0000) GS:ffff969e75f00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000028 CR3: 0000000104006004 CR4: 00000000003706f0 Call Trace: \u003cTASK\u003e ? __die+0x23/0x70 ? page_fault_oops+0x171/0x4e0 ? exc_page_fault+0x7f/0x180 ? asm_exc_page_fault+0x26/0x30 ? vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx] drm_atomic_helper_cleanup_planes+0x9b/0xc0 commit_tail+0xd1/0x130 drm_atomic_helper_commit+0x11a/0x140 drm_atomic_commit+0x97/0xd0 ? __pfx___drm_printfn_info+0x10/0x10 drm_atomic_helper_update_plane+0xf5/0x160 drm_mode_cursor_universal+0x10e/0x270 drm_mode_cursor_common+0x102/0x230 ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10 drm_ioctl_kernel+0xb2/0x110 drm_ioctl+0x26d/0x4b0 ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10 ? __pfx_drm_ioctl+0x10/0x10 vmw_generic_ioctl+0xa4/0x110 [vmwgfx] __x64_sys_ioctl+0x94/0xd0 do_syscall_64+0x61/0xe0 ? __x64_sys_ioctl+0xaf/0xd0 ? syscall_exit_to_user_mode+0x2b/0x40 ? do_syscall_64+0x70/0xe0 ? __x64_sys_ioctl+0xaf/0xd0 ? syscall_exit_to_user_mode+0x2b/0x40 ? do_syscall_64+0x70/0xe0 ? exc_page_fault+0x7f/0x180 entry_SYSCALL_64_after_hwframe+0x6e/0x76 RIP: 0033:0x7f1e93f279ed Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 \u003c89\u003e c2 3d 00 f0 ff f\u003e RSP: 002b:00007ffca0faf600 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 000055db876ed2c0 RCX: 00007f1e93f279ed RDX: 00007ffca0faf6c0 RSI: 00000000c02464bb RDI: 0000000000000015 RBP: 00007ffca0faf650 R08: 000055db87184010 R09: 0000000000000007 R10: 000055db886471a0 R11: 0000000000000246 R12: 00007ffca0faf6c0 R13: 00000000c02464bb R14: 0000000000000015 R15: 00007ffca0faf790 \u003c/TASK\u003e Modules linked in: snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_ine\u003e CR2: 0000000000000028 ---[ end trace 0000000000000000 ]--- RIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx] Code: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 \u003c48\u003e 8b 78 28 e8 e3 f\u003e RSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600 RBP: ffff969d4143 ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52648", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "8z+QHi4S4WDm6aWogE6kuw==": { "id": "8z+QHi4S4WDm6aWogE6kuw==", "updater": "debian/updater", "name": "CVE-2025-39746", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when hardware is unreliable In rare cases, ath10k may lose connection with the PCIe bus due to some unknown reasons, which could further lead to system crashes during resuming due to watchdog timeout: ath10k_pci 0000:01:00.0: wmi command 20486 timeout, restarting hardware ath10k_pci 0000:01:00.0: already restarting ath10k_pci 0000:01:00.0: failed to stop WMI vdev 0: -11 ath10k_pci 0000:01:00.0: failed to stop vdev 0: -11 ieee80211 phy0: PM: **** DPM device timeout **** Call Trace: panic+0x125/0x315 dpm_watchdog_set+0x54/0x54 dpm_watchdog_handler+0x57/0x57 call_timer_fn+0x31/0x13c At this point, all WMI commands will timeout and attempt to restart device. So set a threshold for consecutive restart failures. If the threshold is exceeded, consider the hardware is unreliable and all ath10k operations should be skipped to avoid system crash. fail_cont_count and pending_recovery are atomic variables, and do not involve complex conditional logic. Therefore, even if recovery check and reconfig complete are executed concurrently, the recovery mechanism will not be broken. Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00288-QCARMSWPZ-1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39746", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "96cHpmcS0fRAU0scCg6b9g==": { "id": "96cHpmcS0fRAU0scCg6b9g==", "updater": "debian/updater", "name": "CVE-2026-58016", "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58016", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "99HboD4nMyDk4tse/s9C4g==": { "id": "99HboD4nMyDk4tse/s9C4g==", "updater": "debian/updater", "name": "CVE-2026-68165", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate ranges in damon_set_regions() DAMON core logic assumes zero length regions don't exist. However, a few DAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT allow users to set empty monitoring target regions. This could result in WARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and divide-by-zero from damon_merge_two_regions(). For example, the WANR_ONCE() can be triggered like below. # grep DAMON_DEBUG_SANITY /boot/config-$(uname -r) # CONFIG_DAMON_DEBUG_SANITY=y # damo start # cd /sys/kernel/mm/damon/admin/kdamonds/0 # echo 0 \u003e contexts/0/targets/0/regions/0/start # echo 0 \u003e contexts/0/targets/0/regions/0/end # echo commit \u003e state # dmesg [....] [ 73.705780] ------------[ cut here ]------------ [ 73.707552] start 0 \u003e= end 0 [ 73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758 [...] All DAMON API callers eventually use damon_set_regions() to setup the regions. Add the validation logic in the function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68165", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "99x4WEH1muHpRR25VdE5CQ==": { "id": "99x4WEH1muHpRR25VdE5CQ==", "updater": "debian/updater", "name": "CVE-2026-68207", "description": "In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: unwind v4l2 device registration on probe error If the vpe_top resource is missing, vpe_probe() returns -ENODEV after v4l2_device_register() has succeeded. Probe failures do not call the driver's remove callback, so the v4l2 device remains registered on that error path. Route that failure through the existing v4l2_device_unregister() unwind label, matching the other errors after v4l2_device_register().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68207", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9CEbwXSM4zxlVIlqccQLuA==": { "id": "9CEbwXSM4zxlVIlqccQLuA==", "updater": "debian/updater", "name": "CVE-2024-26669", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When a qdisc is deleted from a net device the stack instructs the underlying driver to remove its flow offload callback from the associated filter block using the 'FLOW_BLOCK_UNBIND' command. The stack then continues to replay the removal of the filters in the block for this driver by iterating over the chains in the block and invoking the 'reoffload' operation of the classifier being used. In turn, the classifier in its 'reoffload' operation prepares and emits a 'FLOW_CLS_DESTROY' command for each filter. However, the stack does not do the same for chain templates and the underlying driver never receives a 'FLOW_CLS_TMPLT_DESTROY' command when a qdisc is deleted. This results in a memory leak [1] which can be reproduced using [2]. Fix by introducing a 'tmplt_reoffload' operation and have the stack invoke it with the appropriate arguments as part of the replay. Implement the operation in the sole classifier that supports chain templates (flower) by emitting the 'FLOW_CLS_TMPLT_{CREATE,DESTROY}' command based on whether a flow offload callback is being bound to a filter block or being unbound from one. As far as I can tell, the issue happens since cited commit which reordered tcf_block_offload_unbind() before tcf_block_flush_all_chains() in __tcf_block_put(). The order cannot be reversed as the filter block is expected to be freed after flushing all the chains. [1] unreferenced object 0xffff888107e28800 (size 2048): comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s) hex dump (first 32 bytes): b1 a6 7c 11 81 88 ff ff e0 5b b3 10 81 88 ff ff ..|......[...... 01 00 00 00 00 00 00 00 e0 aa b0 84 ff ff ff ff ................ backtrace: [\u003cffffffff81c06a68\u003e] __kmem_cache_alloc_node+0x1e8/0x320 [\u003cffffffff81ab374e\u003e] __kmalloc+0x4e/0x90 [\u003cffffffff832aec6d\u003e] mlxsw_sp_acl_ruleset_get+0x34d/0x7a0 [\u003cffffffff832bc195\u003e] mlxsw_sp_flower_tmplt_create+0x145/0x180 [\u003cffffffff832b2e1a\u003e] mlxsw_sp_flow_block_cb+0x1ea/0x280 [\u003cffffffff83a10613\u003e] tc_setup_cb_call+0x183/0x340 [\u003cffffffff83a9f85a\u003e] fl_tmplt_create+0x3da/0x4c0 [\u003cffffffff83a22435\u003e] tc_ctl_chain+0xa15/0x1170 [\u003cffffffff838a863c\u003e] rtnetlink_rcv_msg+0x3cc/0xed0 [\u003cffffffff83ac87f0\u003e] netlink_rcv_skb+0x170/0x440 [\u003cffffffff83ac6270\u003e] netlink_unicast+0x540/0x820 [\u003cffffffff83ac6e28\u003e] netlink_sendmsg+0x8d8/0xda0 [\u003cffffffff83793def\u003e] ____sys_sendmsg+0x30f/0xa80 [\u003cffffffff8379d29a\u003e] ___sys_sendmsg+0x13a/0x1e0 [\u003cffffffff8379d50c\u003e] __sys_sendmsg+0x11c/0x1f0 [\u003cffffffff843b9ce0\u003e] do_syscall_64+0x40/0xe0 unreferenced object 0xffff88816d2c0400 (size 1024): comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s) hex dump (first 32 bytes): 40 00 00 00 00 00 00 00 57 f6 38 be 00 00 00 00 @.......W.8..... 10 04 2c 6d 81 88 ff ff 10 04 2c 6d 81 88 ff ff ..,m......,m.... backtrace: [\u003cffffffff81c06a68\u003e] __kmem_cache_alloc_node+0x1e8/0x320 [\u003cffffffff81ab36c1\u003e] __kmalloc_node+0x51/0x90 [\u003cffffffff81a8ed96\u003e] kvmalloc_node+0xa6/0x1f0 [\u003cffffffff82827d03\u003e] bucket_table_alloc.isra.0+0x83/0x460 [\u003cffffffff82828d2b\u003e] rhashtable_init+0x43b/0x7c0 [\u003cffffffff832aed48\u003e] mlxsw_sp_acl_ruleset_get+0x428/0x7a0 [\u003cffffffff832bc195\u003e] mlxsw_sp_flower_tmplt_create+0x145/0x180 [\u003cffffffff832b2e1a\u003e] mlxsw_sp_flow_block_cb+0x1ea/0x280 [\u003cffffffff83a10613\u003e] tc_setup_cb_call+0x183/0x340 [\u003cffffffff83a9f85a\u003e] fl_tmplt_create+0x3da/0x4c0 [\u003cffffffff83a22435\u003e] tc_ctl_chain+0xa15/0x1170 [\u003cffffffff838a863c\u003e] rtnetlink_rcv_msg+0x3cc/0xed0 [\u003cffffffff83ac87f0\u003e] netlink_rcv_skb+0x170/0x440 [\u003cffffffff83ac6270\u003e] netlink_unicast+0x540/0x820 [\u003cffffffff83ac6e28\u003e] netlink_sendmsg+0x8d8/0xda0 [\u003cffffffff83793def\u003e] ____sys_sendmsg+0x30f/0xa80 [2] # tc qdisc add dev swp1 clsact # tc chain add dev swp1 ingress proto ip chain 1 flower dst_ip 0.0.0.0/32 # tc qdisc del dev ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26669", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9GMQf3G2BK87x6QUHgjgVg==": { "id": "9GMQf3G2BK87x6QUHgjgVg==", "updater": "debian/updater", "name": "CVE-2025-21961", "description": "In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When mb-xdp is set and return is XDP_PASS, packet is converted from xdp_buff to sk_buff with xdp_update_skb_shared_info() in bnxt_xdp_build_skb(). bnxt_xdp_build_skb() passes incorrect truesize argument to xdp_update_skb_shared_info(). The truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo-\u003enr_frags but the skb_shared_info was wiped by napi_build_skb() before. So it stores sinfo-\u003enr_frags before bnxt_xdp_build_skb() and use it instead of getting skb_shared_info from xdp_get_shared_info_from_buff(). Splat looks like: ------------[ cut here ]------------ WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590 Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3 RIP: 0010:skb_try_coalesce+0x504/0x590 Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff \u003c0f\u003e 0b e99 RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287 RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0 RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003 RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900 R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740 R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002 FS: 0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0 PKRU: 55555554 Call Trace: \u003cIRQ\u003e ? __warn+0x84/0x130 ? skb_try_coalesce+0x504/0x590 ? report_bug+0x18a/0x1a0 ? handle_bug+0x53/0x90 ? exc_invalid_op+0x14/0x70 ? asm_exc_invalid_op+0x16/0x20 ? skb_try_coalesce+0x504/0x590 inet_frag_reasm_finish+0x11f/0x2e0 ip_defrag+0x37a/0x900 ip_local_deliver+0x51/0x120 ip_sublist_rcv_finish+0x64/0x70 ip_sublist_rcv+0x179/0x210 ip_list_rcv+0xf9/0x130 How to reproduce: \u003cNode A\u003e ip link set $interface1 xdp obj xdp_pass.o ip link set $interface1 mtu 9000 up ip a a 10.0.0.1/24 dev $interface1 \u003cNode B\u003e ip link set $interfac2 mtu 9000 up ip a a 10.0.0.2/24 dev $interface2 ping 10.0.0.1 -s 65000 Following ping.py patch adds xdp-mb-pass case. so ping.py is going to be able to reproduce this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9LQ7cgc2lvnSN3tA95Jgmw==": { "id": "9LQ7cgc2lvnSN3tA95Jgmw==", "updater": "debian/updater", "name": "CVE-2018-15919", "description": "Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-15919", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9NrSuFGpsJVnFc/Q+9zqZA==": { "id": "9NrSuFGpsJVnFc/Q+9zqZA==", "updater": "debian/updater", "name": "CVE-2026-46229", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE but not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated VRAM with stale data from prior use observable by compute kernels. The GEM ioctl path already sets VRAM_CLEARED for all userspace allocations via amdgpu_gem_create_ioctl() and amdgpu_mode_dumb_create(). The KFD path was missing this flag, allowing stale page table remnants to leak into user buffers. This causes crashes in RCCL P2P transport where non-zero data in ptrExchange/head/tail fields corrupts the protocol handshake.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46229", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9VaE7bXXK/xO2n6nA1Zh+g==": { "id": "9VaE7bXXK/xO2n6nA1Zh+g==", "updater": "debian/updater", "name": "CVE-2026-45917", "description": "In the Linux kernel, the following vulnerability has been resolved: ipvs: do not keep dest_dst if dev is going down There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed. To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45917", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9Vis2TWH9z/j7AjEfl7VGA==": { "id": "9Vis2TWH9z/j7AjEfl7VGA==", "updater": "debian/updater", "name": "CVE-2026-53018", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid reading already updated pages during GC We found the following issue during fuzz testing: page: refcount:3 mapcount:0 mapping:00000000b6e89c65 index:0x18b2dc pfn:0x161ba9 memcg:f8ffff800e269c00 aops:f2fs_meta_aops ino:2 flags: 0x52880000000080a9(locked|waiters|uptodate|lru|private|zone=1|kasantag=0x4a) raw: 52880000000080a9 fffffffec6e17588 fffffffec0ccc088 a7ffff8067063618 raw: 000000000018b2dc 0000000000000009 00000003ffffffff f8ffff800e269c00 page dumped because: VM_BUG_ON_FOLIO(folio_test_uptodate(folio)) page_owner tracks the page as allocated post_alloc_hook+0x58c/0x5ec prep_new_page+0x34/0x284 get_page_from_freelist+0x2dcc/0x2e8c __alloc_pages_noprof+0x280/0x76c __folio_alloc_noprof+0x18/0xac __filemap_get_folio+0x6bc/0xdc4 pagecache_get_page+0x3c/0x104 do_garbage_collect+0x5c78/0x77a4 f2fs_gc+0xd74/0x25f0 gc_thread_func+0xb28/0x2930 kthread+0x464/0x5d8 ret_from_fork+0x10/0x20 ------------[ cut here ]------------ kernel BUG at mm/filemap.c:1563! folio_end_read+0x140/0x168 f2fs_finish_read_bio+0x5c4/0xb80 f2fs_read_end_io+0x64c/0x708 bio_endio+0x85c/0x8c0 blk_update_request+0x690/0x127c scsi_end_request+0x9c/0xb8c scsi_io_completion+0xf0/0x250 scsi_finish_command+0x430/0x45c scsi_complete+0x178/0x6d4 blk_mq_complete_request+0xcc/0x104 scsi_done_internal+0x214/0x454 scsi_done+0x24/0x34 which is similar to the problem reported by syzbot: https://syzkaller.appspot.com/bug?extid=3686758660f980b402dc This case is consistent with the description in commit 9bf1a3f (\"f2fs: avoid GC causing encrypted file corrupted\"): Page 1 is moved from blkaddr A to blkaddr B by move_data_block, and after being written it is marked as uptodate. Then, Page 1 is moved from blkaddr B to blkaddr C, VM_BUG_ON_FOLIO was triggered in the endio initiated by ra_data_block. There is no need to read Page 1 again from blkaddr B, since it has already been updated. Therefore, avoid initiating I/O in this case.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53018", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9VoBuFaXdnhHPgibGyhpfA==": { "id": "9VoBuFaXdnhHPgibGyhpfA==", "updater": "debian/updater", "name": "CVE-2025-8224", "description": "A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8224", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9bLphFFEm/w48fWObkf4Kw==": { "id": "9bLphFFEm/w48fWObkf4Kw==", "updater": "debian/updater", "name": "CVE-2026-23383", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing struct bpf_plt contains a u64 target field. Currently, the BPF JIT allocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT buffer. Because the base address of the JIT buffer can be 4-byte aligned (e.g., ending in 0x4 or 0xc), the relative padding logic in build_plt() fails to ensure that target lands on an 8-byte boundary. This leads to two issues: 1. UBSAN reports misaligned-access warnings when dereferencing the structure. 2. More critically, target is updated concurrently via WRITE_ONCE() in bpf_arch_text_poke() while the JIT'd code executes ldr. On arm64, 64-bit loads/stores are only guaranteed to be single-copy atomic if they are 64-bit aligned. A misaligned target risks a torn read, causing the JIT to jump to a corrupted address. Fix this by increasing the allocation alignment requirement to 8 bytes (sizeof(u64)) in bpf_jit_binary_pack_alloc(). This anchors the base of the JIT buffer to an 8-byte boundary, allowing the relative padding math in build_plt() to correctly align the target field.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23383", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9c20tP8YyQIYlvInrc9qUg==": { "id": "9c20tP8YyQIYlvInrc9qUg==", "updater": "debian/updater", "name": "CVE-2025-68304", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: lookup hci_conn on RX path on protocol side The hdev lock/lookup/unlock/use pattern in the packet RX path doesn't ensure hci_conn* is not concurrently modified/deleted. This locking appears to be leftover from before conn_hash started using RCU commit bf4c63252490b (\"Bluetooth: convert conn hash to RCU\") and not clear if it had purpose since then. Currently, there are code paths that delete hci_conn* from elsewhere than the ordered hdev-\u003eworkqueue where the RX work runs in. E.g. commit 5af1f84ed13a (\"Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync\") introduced some of these, and there probably were a few others before it. It's better to do the locking so that even if these run concurrently no UAF is possible. Move the lookup of hci_conn and associated socket-specific conn to protocol recv handlers, and do them within a single critical section to cover hci_conn* usage and lookup. syzkaller has reported a crash that appears to be this issue: [Task hdev-\u003eworkqueue] [Task 2] hci_disconnect_all_sync l2cap_recv_acldata(hcon) hci_conn_get(hcon) hci_abort_conn_sync(hcon) hci_dev_lock hci_dev_lock hci_conn_del(hcon) v-------------------------------- hci_dev_unlock hci_conn_put(hcon) conn = hcon-\u003el2cap_data (UAF)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68304", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9g7xBDIkdEIdlbmN8c78nQ==": { "id": "9g7xBDIkdEIdlbmN8c78nQ==", "updater": "debian/updater", "name": "CVE-2023-53529", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix memory leak in rtw88_usb Kmemleak shows the following leak arising from routine in the usb probe routine: unreferenced object 0xffff895cb29bba00 (size 512): comm \"(udev-worker)\", pid 534, jiffies 4294903932 (age 102751.088s) hex dump (first 32 bytes): 77 30 30 30 00 00 00 00 02 2f 2d 2b 30 00 00 00 w000...../-+0... 02 00 2a 28 00 00 00 00 ff 55 ff ff ff 00 00 00 ..*(.....U...... backtrace: [\u003cffffffff9265fa36\u003e] kmalloc_trace+0x26/0x90 [\u003cffffffffc17eec41\u003e] rtw_usb_probe+0x2f1/0x680 [rtw_usb] [\u003cffffffffc03e19fd\u003e] usb_probe_interface+0xdd/0x2e0 [usbcore] [\u003cffffffff92b4f2fe\u003e] really_probe+0x18e/0x3d0 [\u003cffffffff92b4f5b8\u003e] __driver_probe_device+0x78/0x160 [\u003cffffffff92b4f6bf\u003e] driver_probe_device+0x1f/0x90 [\u003cffffffff92b4f8df\u003e] __driver_attach+0xbf/0x1b0 [\u003cffffffff92b4d350\u003e] bus_for_each_dev+0x70/0xc0 [\u003cffffffff92b4e51e\u003e] bus_add_driver+0x10e/0x210 [\u003cffffffff92b50935\u003e] driver_register+0x55/0xf0 [\u003cffffffffc03e0708\u003e] usb_register_driver+0x88/0x140 [usbcore] [\u003cffffffff92401153\u003e] do_one_initcall+0x43/0x210 [\u003cffffffff9254f42a\u003e] do_init_module+0x4a/0x200 [\u003cffffffff92551d1c\u003e] __do_sys_finit_module+0xac/0x120 [\u003cffffffff92ee6626\u003e] do_syscall_64+0x56/0x80 [\u003cffffffff9300006a\u003e] entry_SYSCALL_64_after_hwframe+0x46/0xb0 The leak was verified to be real by unloading the driver, which resulted in a dangling pointer to the allocation. The allocated memory is freed in rtw_usb_intf_deinit().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53529", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9gK+Gqf4Vya04XVvFGXJtw==": { "id": "9gK+Gqf4Vya04XVvFGXJtw==", "updater": "debian/updater", "name": "CVE-2026-63848", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63848", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9hBTSrmMYUQVapaLCp1VhA==": { "id": "9hBTSrmMYUQVapaLCp1VhA==", "updater": "debian/updater", "name": "CVE-2024-49568", "description": "In the Linux kernel, the following vulnerability has been resolved: net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg When receiving proposal msg in server, the fields v2_ext_offset/ eid_cnt/ism_gid_cnt in proposal msg are from the remote client and can not be fully trusted. Especially the field v2_ext_offset, once exceed the max value, there has the chance to access wrong address, and crash may happen. This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt before using them.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49568", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9hXvJPuYbS6CLXFycAJ99w==": { "id": "9hXvJPuYbS6CLXFycAJ99w==", "updater": "debian/updater", "name": "CVE-2026-45943", "description": "In the Linux kernel, the following vulnerability has been resolved: erofs: fix inline data read failure for ztailpacking pclusters Compressed folios for ztailpacking pclusters must be valid before adding these pclusters to I/O chains. Otherwise, z_erofs_decompress_pcluster() may assume they are already valid and then trigger a NULL pointer dereference. It is somewhat hard to reproduce because the inline data is in the same block as the tail of the compressed indexes, which are usually read just before. However, it may still happen if a fatal signal arrives while read_mapping_folio() is running, as shown below: erofs: (device dm-1): z_erofs_pcluster_begin: failed to get inline data -4 Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 ... pc : z_erofs_decompress_queue+0x4c8/0xa14 lr : z_erofs_decompress_queue+0x160/0xa14 sp : ffffffc08b3eb3a0 x29: ffffffc08b3eb570 x28: ffffffc08b3eb418 x27: 0000000000001000 x26: ffffff8086ebdbb8 x25: ffffff8086ebdbb8 x24: 0000000000000001 x23: 0000000000000008 x22: 00000000fffffffb x21: dead000000000700 x20: 00000000000015e7 x19: ffffff808babb400 x18: ffffffc089edc098 x17: 00000000c006287d x16: 00000000c006287d x15: 0000000000000004 x14: ffffff80ba8f8000 x13: 0000000000000004 x12: 00000006589a77c9 x11: 0000000000000015 x10: 0000000000000000 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 000000000000003f x5 : 0000000000000040 x4 : ffffffffffffffe0 x3 : 0000000000000020 x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: z_erofs_decompress_queue+0x4c8/0xa14 z_erofs_runqueue+0x908/0x97c z_erofs_read_folio+0x128/0x228 filemap_read_folio+0x68/0x128 filemap_get_pages+0x44c/0x8b4 filemap_read+0x12c/0x5b8 generic_file_read_iter+0x4c/0x15c do_iter_readv_writev+0x188/0x1e0 vfs_iter_read+0xac/0x1a4 backing_file_read_iter+0x170/0x34c ovl_read_iter+0xf0/0x140 vfs_read+0x28c/0x344 ksys_read+0x80/0xf0 __arm64_sys_read+0x24/0x34 invoke_syscall+0x60/0x114 el0_svc_common+0x88/0xe4 do_el0_svc+0x24/0x30 el0_svc+0x40/0xa8 el0t_64_sync_handler+0x70/0xbc el0t_64_sync+0x1bc/0x1c0 Fix this by reading the inline data before allocating and adding the pclusters to the I/O chains.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45943", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9hmYdgk6YhZjkk5kRAej1A==": { "id": "9hmYdgk6YhZjkk5kRAej1A==", "updater": "debian/updater", "name": "CVE-2026-47254", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-47254", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9idvVOsyaQdFcV+qdxfyoQ==": { "id": "9idvVOsyaQdFcV+qdxfyoQ==", "updater": "debian/updater", "name": "CVE-2026-52990", "description": "In the Linux kernel, the following vulnerability has been resolved: fsnotify: fix inode reference leak in fsnotify_recalc_mask() fsnotify_recalc_mask() fails to handle the return value of __fsnotify_recalc_mask(), which may return an inode pointer that needs to be released via fsnotify_drop_object() when the connector's HAS_IREF flag transitions from set to cleared. This manifests as a hung task with the following call trace: INFO: task umount:1234 blocked for more than 120 seconds. Call Trace: __schedule schedule fsnotify_sb_delete generic_shutdown_super kill_anon_super cleanup_mnt task_work_run do_exit do_group_exit The race window that triggers the iref leak: Thread A (adding mark) Thread B (removing mark) ────────────────────── ──────────────────────── fsnotify_add_mark_locked(): fsnotify_add_mark_list(): spin_lock(conn-\u003elock) add mark_B(evictable) to list spin_unlock(conn-\u003elock) return /* ---- gap: no lock held ---- */ fsnotify_detach_mark(mark_A): spin_lock(mark_A-\u003elock) clear ATTACHED flag on mark_A spin_unlock(mark_A-\u003elock) fsnotify_put_mark(mark_A) fsnotify_recalc_mask(): spin_lock(conn-\u003elock) __fsnotify_recalc_mask(): /* mark_A skipped: ATTACHED cleared */ /* only mark_B(evictable) remains */ want_iref = false has_iref = true /* not yet cleared */ -\u003e HAS_IREF transitions true -\u003e false -\u003e returns inode pointer spin_unlock(conn-\u003elock) /* BUG: return value discarded! * iput() and fsnotify_put_sb_watched_objects() * are never called */ Fix this by deferring the transition true -\u003e false of HAS_IREF flag from fsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52990", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9kPxv89eatdt3SCRDIz9QA==": { "id": "9kPxv89eatdt3SCRDIz9QA==", "updater": "debian/updater", "name": "CVE-2026-68299", "description": "In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc-\u003ercd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4-\u003eprotocol != IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth-\u003eh_proto != ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68299", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9kW5Q4QIU/r33UUcynzNXg==": { "id": "9kW5Q4QIU/r33UUcynzNXg==", "updater": "debian/updater", "name": "CVE-2026-68313", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: fix infinite loop in __tipc_nl_compat_dumpit cmd-\u003edumpit callback can return a negative errno, causing an infinite loop due to the while(len) condition. As the loop never terminates, genl_mutex is never released, and other tasks waiting on it starve in D state. Check dumpit's return value, propagate it and jump to err_out on error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68313", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9o4tvTk91flE9SCiUSP70Q==": { "id": "9o4tvTk91flE9SCiUSP70Q==", "updater": "debian/updater", "name": "CVE-2025-71198", "description": "In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL event_spec field, indicating support for IIO events. However, event detection is not supported for all sensors, and if userspace tries to configure accelerometer wakeup events on a sensor device that does not support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL pointer when trying to write to the wakeup register. Define an additional struct iio_chan_spec array whose members have a NULL event_spec field, and use this array instead of st_lsm6dsx_acc_channels for sensors without event detection capability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71198", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9pBu5jCd64qlIVwlW2NNSw==": { "id": "9pBu5jCd64qlIVwlW2NNSw==", "updater": "debian/updater", "name": "CVE-2026-53229", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK branch of mlx5e_xmit_xdp_buff(), when sq-\u003exmit_xdp_frame() returns false (e.g. XDPSQ is full), the function returns without unmapping the DMA address or freeing the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on success, so the completion path cannot recover these entries. With CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind: DMA-API: pci 0000:08:00.0: device driver has pending DMA allocations while released from device [count=1116] One of leaked entries details: [device address=0x000000010ffd7028] [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy] WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180 ... DMA-API: Mapped at: debug_dma_map_phys+0x4b/0xd0 dma_map_phys+0xfd/0x2d0 mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core] mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core] mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core] Add the missing unmap + xdp_return_frame, matching the cleanup already done in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch, so no per-frag unmap is needed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53229", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9qs74TofCJ6nuFrBMs8T/Q==": { "id": "9qs74TofCJ6nuFrBMs8T/Q==", "updater": "debian/updater", "name": "CVE-2026-68118", "description": "In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-socket path in tcp_check_req() accepts an in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A non-exact RST therefore removes the request instead of eliciting a challenge ACK. RFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in SYN-RECEIVED: an exact RST resets the connection, while a non-exact in-window RST must trigger a challenge ACK and be dropped. Apply that check before the ACK-field validation, following the RFC sequence-number, RST, then ACK processing order. Factor the per-netns challenge ACK quota out of tcp_send_challenge_ack() so request sockets can share it. Use the request socket's send_ack() callback and its own out-of-window ACK timestamp to send and rate-limit the response.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9sEDdvSMwzMV2kaQDYeUkA==": { "id": "9sEDdvSMwzMV2kaQDYeUkA==", "updater": "debian/updater", "name": "CVE-2026-68187", "description": "In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value is derived from bprm-\u003ep \u003e\u003e PAGE_SHIFT. The index variable is an unsigned long. If bprm-\u003ep drops below PAGE_SIZE and stop becomes zero the loop condition index \u003e= stop is always true. After the index == 0 iteration the decrement wraps to ULONG_MAX and bprm-\u003epage[ULONG_MAX] reads sizeof(void *) bytes in front of the array. The pointer has wrapped to -1. That garbage pointer is then passed to kmap_local_page() and PAGE_SIZE bytes are copied from wherever that lands into the stack of the process being created. And the loop doesn't terminate either... Getting there only requires bprm-\u003ep \u003c PAGE_SIZE. On !MMU bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only constraint on how far bprm-\u003ep is pushed down is valid_arg_len(), i.e. that each individual string still fits in what is left. bprm-\u003ep starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a single argument or environment string of a little over 31 pages leaves it in the first page: Oops - load access fault [#1] CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1 epc : __memcpy+0xd4/0xf8 ra : transfer_args_to_stack+0xaa/0xae s4 : ffffffffffffffff s2 : 0000000000000000 a1 : ffffffdc98000000 a2 : 0000000000001000 status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005 [\u003c801a5324\u003e] __memcpy+0xd4/0xf8 [\u003c800d5f6a\u003e] load_flat_binary+0x43a/0x65e [\u003c800a2de4\u003e] bprm_execve+0x1d4/0x316 [\u003c800a351a\u003e] do_execveat_common+0x12e/0x138 [\u003c800a3d44\u003e] __riscv_sys_execve+0x38/0x4e Kernel panic - not syncing: Fatal exception in interrupt This is an arcane bug but we should still fix it. Count down from MAX_ARG_PAGES so the loop ends when index reaches stop, stop == 0 included. The iterations performed are unchanged for every other value of stop. Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used by binfmt_flat and binfmt_elf_fdpic on nommu only. The loop predates git history. commit 7e7ec6a93434 (\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used part of the first page. The condition and the decrement are unchanged from 2.6.12-rc2.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68187", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9u8cQ+3Wzfyz/hps0KxpaA==": { "id": "9u8cQ+3Wzfyz/hps0KxpaA==", "updater": "debian/updater", "name": "CVE-2026-49295", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-49295", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9uTlw6qkJF9H+PeJLKzcYA==": { "id": "9uTlw6qkJF9H+PeJLKzcYA==", "updater": "debian/updater", "name": "CVE-2026-53313", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: if (!dc_dmub_srv || !dc_dmub_srv-\u003edmub) and then call DC_LOG_ERROR() inside that block. DC_LOG_ERROR() uses dc_dmub_srv-\u003ectx internally. So if dc_dmub_srv is NULL, the logging itself can dereference a NULL pointer and cause a crash. Fix this by splitting the checks. First check if dc_dmub_srv is NULL and return immediately. Then check dc_dmub_srv-\u003edmub and log the error only when dc_dmub_srv is valid. Fixes the below: ../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961) ../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53313", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9w+bEJrWIFDCRXqCmLqPag==": { "id": "9w+bEJrWIFDCRXqCmLqPag==", "updater": "debian/updater", "name": "CVE-2007-3477", "description": "The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-3477", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libwmf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9xPy9U3WOy/2+H4t0fpNJw==": { "id": "9xPy9U3WOy/2+H4t0fpNJw==", "updater": "debian/updater", "name": "CVE-2024-43824", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init() Instead of getting the epc_features from pci_epc_get_features() API, use the cached pci_epf_test::epc_features value to avoid the NULL check. Since the NULL check is already performed in pci_epf_test_bind(), having one more check in pci_epf_test_core_init() is redundant and it is not possible to hit the NULL pointer dereference. Also with commit a01e7214bef9 (\"PCI: endpoint: Remove \"core_init_notifier\" flag\"), 'epc_features' got dereferenced without the NULL check, leading to the following false positive Smatch warning: drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed 'epc_features' could be null (see line 747) Thus, remove the redundant NULL check and also use the epc_features:: {msix_capable/msi_capable} flags directly to avoid local variables. [kwilczynski: commit log]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43824", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "9yjo/byOytI0IkYgkukiDQ==": { "id": "9yjo/byOytI0IkYgkukiDQ==", "updater": "debian/updater", "name": "CVE-2026-56410", "description": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56410", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A0op+L+JbMa3xmsB6bfM0Q==": { "id": "A0op+L+JbMa3xmsB6bfM0Q==", "updater": "debian/updater", "name": "CVE-2025-11412", "description": "A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11412", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A13dtLHylURUHZNefxlSHg==": { "id": "A13dtLHylURUHZNefxlSHg==", "updater": "debian/updater", "name": "CVE-2024-42155", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys is accessible, this key material should only be visible to the calling process. So wipe all copies of protected- or secure-keys from stack, even in case of an error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42155", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A2tELXXEKzN52RK4u1VO4A==": { "id": "A2tELXXEKzN52RK4u1VO4A==", "updater": "debian/updater", "name": "CVE-2022-25265", "description": "In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-25265", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A5MLttzZQ3XDsFCByj0agw==": { "id": "A5MLttzZQ3XDsFCByj0agw==", "updater": "debian/updater", "name": "CVE-2025-9165", "description": "A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because \"this is a memory leak on a command line tool that is about to exit anyway\". In the reply the project maintainer declares this issue as \"a simple 'bug' when leaving the command line tool and (...) not a security issue at all\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-9165", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A5VZss399+5q0Kh9sFgjOQ==": { "id": "A5VZss399+5q0Kh9sFgjOQ==", "updater": "debian/updater", "name": "CVE-2026-63983", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: fix packet loop on netem when duplicate is on When netem duplicates a packet it re-enqueues the copy at the root qdisc. If another netem sits in the tree the copy can be duplicated again, recursing until the stack or memory is exhausted. The original duplication guard temporarily zeroed q-\u003eduplicate around the re-enqueue, but that does not cover all cases because it is per-qdisc state shared across all concurrent enqueue paths and is not safe without additional locking. Use the skb tc_depth field introduced in an earlier patch: - increment it on the duplicate before re-enqueue - skip duplication for any skb whose tc_depth is already non-zero. This marks the packet itself rather than mutating qdisc state, therefore it is safe regardless of tree topology or concurrency.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63983", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A5edsP7XEH6D4cmvYBsj+w==": { "id": "A5edsP7XEH6D4cmvYBsj+w==", "updater": "debian/updater", "name": "CVE-2024-36968", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev-\u003ele_mtu may not fall in the valid range. Move MTU from hci_dev to hci_conn to validate MTU and stop the connection process earlier if MTU is invalid. Also, add a missing validation in read_buffer_size() and make it return an error value if the validation fails. Now hci_conn_add() returns ERR_PTR() as it can fail due to the both a kzalloc failure and invalid MTU value. divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 0 PID: 67 Comm: kworker/u5:0 Tainted: G W 6.9.0-rc5+ #20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Workqueue: hci0 hci_rx_work RIP: 0010:l2cap_le_flowctl_init+0x19e/0x3f0 net/bluetooth/l2cap_core.c:547 Code: e8 17 17 0c 00 66 41 89 9f 84 00 00 00 bf 01 00 00 00 41 b8 02 00 00 00 4c 89 fe 4c 89 e2 89 d9 e8 27 17 0c 00 44 89 f0 31 d2 \u003c66\u003e f7 f3 89 c3 ff c3 4d 8d b7 88 00 00 00 4c 89 f0 48 c1 e8 03 42 RSP: 0018:ffff88810bc0f858 EFLAGS: 00010246 RAX: 00000000000002a0 RBX: 0000000000000000 RCX: dffffc0000000000 RDX: 0000000000000000 RSI: ffff88810bc0f7c0 RDI: ffffc90002dcb66f RBP: ffff88810bc0f880 R08: aa69db2dda70ff01 R09: 0000ffaaaaaaaaaa R10: 0084000000ffaaaa R11: 0000000000000000 R12: ffff88810d65a084 R13: dffffc0000000000 R14: 00000000000002a0 R15: ffff88810d65a000 FS: 0000000000000000(0000) GS:ffff88811ac00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000020000100 CR3: 0000000103268003 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace: \u003cTASK\u003e l2cap_le_connect_req net/bluetooth/l2cap_core.c:4902 [inline] l2cap_le_sig_cmd net/bluetooth/l2cap_core.c:5420 [inline] l2cap_le_sig_channel net/bluetooth/l2cap_core.c:5486 [inline] l2cap_recv_frame+0xe59d/0x11710 net/bluetooth/l2cap_core.c:6809 l2cap_recv_acldata+0x544/0x10a0 net/bluetooth/l2cap_core.c:7506 hci_acldata_packet net/bluetooth/hci_core.c:3939 [inline] hci_rx_work+0x5e5/0xb20 net/bluetooth/hci_core.c:4176 process_one_work kernel/workqueue.c:3254 [inline] process_scheduled_works+0x90f/0x1530 kernel/workqueue.c:3335 worker_thread+0x926/0xe70 kernel/workqueue.c:3416 kthread+0x2e3/0x380 kernel/kthread.c:388 ret_from_fork+0x5c/0x90 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 \u003c/TASK\u003e Modules linked in: ---[ end trace 0000000000000000 ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36968", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "A7Yp8lXwx3uwqC6eEl/MIQ==": { "id": "A7Yp8lXwx3uwqC6eEl/MIQ==", "updater": "debian/updater", "name": "CVE-2024-40998", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state-\u003elock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs-\u003elock: ext4_fill_super ext4_register_sysfs // sysfs registered msg_ratelimit_interval_ms // Other processes modify rs-\u003einterval to // non-zero via msg_ratelimit_interval_ms ext4_orphan_cleanup ext4_msg(sb, KERN_INFO, \"Errors on filesystem, \" __ext4_msg ___ratelimit(\u0026(EXT4_SB(sb)-\u003es_msg_ratelimit_state) if (!rs-\u003einterval) // do nothing if interval is 0 return 1; raw_spin_trylock_irqsave(\u0026rs-\u003elock, flags) raw_spin_trylock(lock) _raw_spin_trylock __raw_spin_trylock spin_acquire(\u0026lock-\u003edep_map, 0, 1, _RET_IP_) lock_acquire __lock_acquire register_lock_class assign_lock_key dump_stack(); ratelimit_state_init(\u0026sbi-\u003es_msg_ratelimit_state, 5 * HZ, 10); raw_spin_lock_init(\u0026rs-\u003elock); // init rs-\u003elock here and get the following dump_stack: ========================================================= INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn't initialize this object before use? turning off the locking correctness validator. CPU: 12 PID: 753 Comm: mount Tainted: G E 6.7.0-rc6-next-20231222 #504 [...] Call Trace: dump_stack_lvl+0xc5/0x170 dump_stack+0x18/0x30 register_lock_class+0x740/0x7c0 __lock_acquire+0x69/0x13a0 lock_acquire+0x120/0x450 _raw_spin_trylock+0x98/0xd0 ___ratelimit+0xf6/0x220 __ext4_msg+0x7f/0x160 [ext4] ext4_orphan_cleanup+0x665/0x740 [ext4] __ext4_fill_super+0x21ea/0x2b10 [ext4] ext4_fill_super+0x14d/0x360 [ext4] [...] ========================================================= Normally interval is 0 until s_msg_ratelimit_state is initialized, so ___ratelimit() does nothing. But registering sysfs precedes initializing rs-\u003elock, so it is possible to change rs-\u003einterval to a non-zero value via the msg_ratelimit_interval_ms interface of sysfs while rs-\u003elock is uninitialized, and then a call to ext4_msg triggers the problem by accessing an uninitialized rs-\u003elock. Therefore register sysfs after all initializations are complete to avoid such problems.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40998", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ABdl7tHgbWbJkXgHXYjkaA==": { "id": "ABdl7tHgbWbJkXgHXYjkaA==", "updater": "debian/updater", "name": "CVE-2025-6141", "description": "A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-6141", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ACZllLUORfDLpn3ve8yFBg==": { "id": "ACZllLUORfDLpn3ve8yFBg==", "updater": "debian/updater", "name": "CVE-2026-43129", "description": "In the Linux kernel, the following vulnerability has been resolved: ima: verify the previous kernel's IMA buffer lies in addressable RAM Patch series \"Address page fault in ima_restore_measurement_list()\", v3. When the second-stage kernel is booted via kexec with a limiting command line such as \"mem=\u003csize\u003e\" we observe a pafe fault that happens. BUG: unable to handle page fault for address: ffff97793ff47000 RIP: ima_restore_measurement_list+0xdc/0x45a #PF: error_code(0x0000) not-present page This happens on x86_64 only, as this is already fixed in aarch64 in commit: cbf9c4b9617b (\"of: check previous kernel's ima-kexec-buffer against memory bounds\") This patch (of 3): When the second-stage kernel is booted with a limiting command line (e.g. \"mem=\u003csize\u003e\"), the IMA measurement buffer handed over from the previous kernel may fall outside the addressable RAM of the new kernel. Accessing such a buffer can fault during early restore. Introduce a small generic helper, ima_validate_range(), which verifies that a physical [start, end] range for the previous-kernel IMA buffer lies within addressable memory: \t- On x86, use pfn_range_is_mapped(). \t- On OF based architectures, use page_is_ram().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43129", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AFIUpz1Y4Fkx6mpVvjmUUA==": { "id": "AFIUpz1Y4Fkx6mpVvjmUUA==", "updater": "debian/updater", "name": "CVE-2026-4873", "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-4873", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AOC74CEOMieqF4QnNIHpHw==": { "id": "AOC74CEOMieqF4QnNIHpHw==", "updater": "debian/updater", "name": "CVE-2019-6988", "description": "An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-6988", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AR1mIh++KWFwOpNBMSCtcg==": { "id": "AR1mIh++KWFwOpNBMSCtcg==", "updater": "debian/updater", "name": "CVE-2019-1010024", "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-1010024", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AS9W4vbMqGdpKVw9iOwZAQ==": { "id": "AS9W4vbMqGdpKVw9iOwZAQ==", "updater": "debian/updater", "name": "CVE-2024-10524", "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-10524", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AVqsLa8FiT6DFdwPobOf2w==": { "id": "AVqsLa8FiT6DFdwPobOf2w==", "updater": "debian/updater", "name": "CVE-2026-45186", "description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45186", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AYQU3Kryw6wN3SdT6aXSMg==": { "id": "AYQU3Kryw6wN3SdT6aXSMg==", "updater": "debian/updater", "name": "CVE-2024-42139", "description": "In the Linux kernel, the following vulnerability has been resolved: ice: Fix improper extts handling Extts events are disabled and enabled by the application ts2phc. However, in case where the driver is removed when the application is running, a specific extts event remains enabled and can cause a kernel crash. As a side effect, when the driver is reloaded and application is started again, remaining extts event for the channel from a previous run will keep firing and the message \"extts on unexpected channel\" might be printed to the user. To avoid that, extts events shall be disabled when PTP is released.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42139", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ad7lED91xtuO5R2vruVbvw==": { "id": "Ad7lED91xtuO5R2vruVbvw==", "updater": "debian/updater", "name": "CVE-2026-59996", "description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-59996", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AepvaOoHpgY77IKxvqCVwA==": { "id": "AepvaOoHpgY77IKxvqCVwA==", "updater": "debian/updater", "name": "CVE-2024-49923", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags [WHAT \u0026 HOW] \"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it cannot be a null pointer. Let's pass a valid pointer to avoid null dereference. This fixes 2 FORWARD_NULL issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49923", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Aj16ChfAS29bZiI21jI7Vw==": { "id": "Aj16ChfAS29bZiI21jI7Vw==", "updater": "debian/updater", "name": "CVE-2026-68354", "description": "In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing fragment, the code checks whether the new fragment also closes the gap to the next or previous list entry. Those neighbor lookups currently assume that the current fragment always has a real next or previous fragment. At a list edge, the next or previous entry is the list head, not a struct fwnet_fragment_info. The gap checks also compare against the old edge of the current fragment instead of the edge after adding the new fragment. As a result, a fragment that bridges two existing ranges may leave two adjacent ranges unmerged, so fwnet_pd_is_complete() can miss a complete datagram. Check for the list head before looking up the neighboring fragment, and compare the neighbor against the new fragment's far edge when deciding whether to merge all three ranges. This issue was found by a static analysis checker and confirmed by manual source review.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68354", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Akpq9uDUovUJk/ST/qplwA==": { "id": "Akpq9uDUovUJk/ST/qplwA==", "updater": "debian/updater", "name": "CVE-2025-40097", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_component_manager_init function The __component_match_add function may assign the 'matchptr' pointer the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced. The call stack leading to the error looks like this: hda_component_manager_init |-\u003e component_match_add |-\u003e component_match_add_release |-\u003e __component_match_add ( ... ,**matchptr, ... ) |-\u003e *matchptr = ERR_PTR(-ENOMEM); // assign |-\u003e component_master_add_with_match( ... match) |-\u003e component_match_realloc(match, match-\u003enum); // dereference Add IS_ERR() check to prevent the crash. Found by Linux Verification Center (linuxtesting.org) with SVACE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40097", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AlsHKe6pwvjWLCwYVvZHJg==": { "id": "AlsHKe6pwvjWLCwYVvZHJg==", "updater": "debian/updater", "name": "CVE-2023-6240", "description": "A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-6240", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AqPsePg/x9foozdu9m7x0g==": { "id": "AqPsePg/x9foozdu9m7x0g==", "updater": "debian/updater", "name": "CVE-2025-39927", "description": "In the Linux kernel, the following vulnerability has been resolved: ceph: fix race condition validating r_parent before applying state Add validation to ensure the cached parent directory inode matches the directory info in MDS replies. This prevents client-side race conditions where concurrent operations (e.g. rename) cause r_parent to become stale between request initiation and reply processing, which could lead to applying state changes to incorrect directory inodes. [ idryomov: folded a kerneldoc fixup and a follow-up fix from Alex to move CEPH_CAP_PIN reference when r_parent is updated: When the parent directory lock is not held, req-\u003er_parent can become stale and is updated to point to the correct inode. However, the associated CEPH_CAP_PIN reference was not being adjusted. The CEPH_CAP_PIN is a reference on an inode that is tracked for accounting purposes. Moving this pin is important to keep the accounting balanced. When the pin was not moved from the old parent to the new one, it created two problems: The reference on the old, stale parent was never released, causing a reference leak. A reference for the new parent was never acquired, creating the risk of a reference underflow later in ceph_mdsc_release_request(). This patch corrects the logic by releasing the pin from the old parent and acquiring it for the new parent when r_parent is switched. This ensures reference accounting stays balanced. ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39927", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "AqeVD5NxLS+weKkPZyFjMg==": { "id": "AqeVD5NxLS+weKkPZyFjMg==", "updater": "debian/updater", "name": "CVE-2026-53377", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu Previously, in case there was no more work to do, recover worker wouldn't trigger recovery and would instead rely on the gpu going to sleep and then resuming when more work is submitted. Recover_worker will first increment the fence of the hung ring so, if there's only one job submitted to a ring and that causes an hang, it will early out. There's no guarantee that the gpu will suspend and resume before more work is submitted and if the gpu is in a hung state it will stay in that state and probably trigger a timeout again. Just stop checking and always recover the gpu. Patchwork: https://patchwork.freedesktop.org/patch/704066/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53377", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Awx1BfuojP61w6bh1ny39w==": { "id": "Awx1BfuojP61w6bh1ny39w==", "updater": "debian/updater", "name": "CVE-2026-52988", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase Publish new hooks in the list into the basechain/flowtable using splice_list_rcu() to ensure netlink dump list traversal via rcu is safe while concurrent ruleset update is going on.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52988", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Azszg4XRyhbQzS0iD4UYPA==": { "id": "Azszg4XRyhbQzS0iD4UYPA==", "updater": "debian/updater", "name": "CVE-2026-68130", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer destroy_previous_session() until after NTLM authentication In ntlm_authenticate(), destroy_previous_session() is called using a user pointer resolved from the client-supplied NTLM blob username field before the NTLMv2 response is validated. An authenticated attacker can set the NTLM blob username to match a victim account and set PreviousSessionId to the victim's session ID; destroy_previous_session() destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob() subsequently rejects the request with -EPERM. Move destroy_previous_session() and the prev_id assignment to after ksmbd_decode_ntlmssp_auth_blob() returns success and use sess-\u003euser rather than the pre-authentication lookup result. This matches the ordering already used by krb5_authenticate(), where destroy_previous_session() is called only after ksmbd_krb5_authenticate() returns success.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68130", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B/9cE6Ouzx84LJq7Bh1ZUA==": { "id": "B/9cE6Ouzx84LJq7Bh1ZUA==", "updater": "debian/updater", "name": "CVE-2026-68082", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_32(p) at the num_lockers field has no preceding bounds check. ceph_start_decoding() accepts struct_len=0 as valid -- the internal ceph_decode_need(p, end, 0, bad) always passes -- so when an OSD sends struct_len=0, ceph_start_decoding() returns success with p == end. The immediately following bare ceph_decode_32(p) then reads 4 bytes past the validated buffer boundary. The garbage value is passed directly to kzalloc_objs() as the locker count. The sibling function decode_watchers() in osd_client.c already uses ceph_decode_32_safe() after its own ceph_start_decoding() call. decode_lockers() was the only site using the bare variant. 2. ceph_decode_8(p) after the decode_locker() loop has no preceding bounds check. If an OSD crafts num_lockers such that the loop advances p exactly to end, the subsequent bare ceph_decode_8(p) reads one byte past the validated buffer boundary. The result is passed directly into *type, which is used as a lock type discriminator by callers, giving an OSD-controlled one-byte OOB read with direct influence over the lock type field. Fix both by replacing bare operations with their safe variants: ceph_decode_32(p) -\u003e ceph_decode_32_safe(p, end, *num_lockers, err_inval) ceph_decode_8(p) -\u003e ceph_decode_8_safe(p, end, *type, err_free_lockers) The goto targets differ intentionally: err_inval: is a new label returning -EINVAL directly. It is used for the pre-allocation failure path where *lockers is not yet allocated and must not be passed to ceph_free_lockers(). err_free_lockers: is the existing label. It is used for the post-allocation failure path where *lockers is allocated and must be freed. ret is set to -EINVAL before ceph_decode_8_safe() so that err_free_lockers returns the correct error code on bounds violation. Without this, err_free_lockers would return a stale ret value (0 from the successful decode_locker() loop), silently swallowing the error. -EINVAL is correct for both failure paths. The data received from the OSD is structurally malformed. -ENOMEM would misrepresent the failure class to callers and to stable@ backporters triaging error paths. Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition). [ idryomov: trim changelog, formatting ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68082", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B/seqlJe9e/N8mUU5WStLg==": { "id": "B/seqlJe9e/N8mUU5WStLg==", "updater": "debian/updater", "name": "CVE-2025-69646", "description": "Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69646", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B0VlhADEhd0NkhsaLhpQSA==": { "id": "B0VlhADEhd0NkhsaLhpQSA==", "updater": "debian/updater", "name": "CVE-2026-68238", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Release VFCT ACPI table reference amdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table() but never releases it. acpi_get_table() takes a reference on the table (incrementing its validation_count and mapping it on the 0-\u003e1 transition); without a paired acpi_put_table() the mapping is leaked on every call, whether or not a matching VBIOS image is found. Route all exit paths after the table is acquired through a common acpi_put_table(). The VBIOS image is copied out with kmemdup() before the table is released, so it remains valid for the caller. (cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68238", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B1JjtK21NVnmDCEZc2qsZw==": { "id": "B1JjtK21NVnmDCEZc2qsZw==", "updater": "debian/updater", "name": "CVE-2023-6039", "description": "A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-6039", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B8KsBsV6XL5o0MASDvIxkg==": { "id": "B8KsBsV6XL5o0MASDvIxkg==", "updater": "debian/updater", "name": "CVE-2025-37747", "description": "In the Linux kernel, the following vulnerability has been resolved: perf: Fix hang while freeing sigtrap event Perf can hang while freeing a sigtrap event if a related deferred signal hadn't managed to be sent before the file got closed: perf_event_overflow() task_work_add(perf_pending_task) fput() task_work_add(____fput()) task_work_run() ____fput() perf_release() perf_event_release_kernel() _free_event() perf_pending_task_sync() task_work_cancel() -\u003e FAILED rcuwait_wait_event() Once task_work_run() is running, the list of pending callbacks is removed from the task_struct and from this point on task_work_cancel() can't remove any pending and not yet started work items, hence the task_work_cancel() failure and the hang on rcuwait_wait_event(). Task work could be changed to remove one work at a time, so a work running on the current task can always cancel a pending one, however the wait / wake design is still subject to inverted dependencies when remote targets are involved, as pictured by Oleg: T1 T2 fd = perf_event_open(pid =\u003e T2-\u003epid); fd = perf_event_open(pid =\u003e T1-\u003epid); close(fd) close(fd) \u003cIRQ\u003e \u003cIRQ\u003e perf_event_overflow() perf_event_overflow() task_work_add(perf_pending_task) task_work_add(perf_pending_task) \u003c/IRQ\u003e \u003c/IRQ\u003e fput() fput() task_work_add(____fput()) task_work_add(____fput()) task_work_run() task_work_run() ____fput() ____fput() perf_release() perf_release() perf_event_release_kernel() perf_event_release_kernel() _free_event() _free_event() perf_pending_task_sync() perf_pending_task_sync() rcuwait_wait_event() rcuwait_wait_event() Therefore the only option left is to acquire the event reference count upon queueing the perf task work and release it from the task work, just like it was done before 3a5465418f5f (\"perf: Fix event leak upon exec and file release\") but without the leaks it fixed. Some adjustments are necessary to make it work: * A child event might dereference its parent upon freeing. Care must be taken to release the parent last. * Some places assuming the event doesn't have any reference held and therefore can be freed right away must instead put the reference and let the reference counting to its job.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37747", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "B9YYU+s2Cvva7QJUDtHgtA==": { "id": "B9YYU+s2Cvva7QJUDtHgtA==", "updater": "debian/updater", "name": "CVE-2024-35904", "description": "In the Linux kernel, the following vulnerability has been resolved: selinux: avoid dereference of garbage after mount failure In case kern_mount() fails and returns an error pointer return in the error branch instead of continuing and dereferencing the error pointer. While on it drop the never read static variable selinuxfs_mount.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35904", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BD42nQToL1fdszU+AsHeUA==": { "id": "BD42nQToL1fdszU+AsHeUA==", "updater": "debian/updater", "name": "CVE-2024-41008", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm-\u003etask_info handling This patch changes the handling and lifecycle of vm-\u003etask_info object. The major changes are: - vm-\u003etask_info is a dynamically allocated ptr now, and its uasge is reference counted. - introducing two new helper funcs for task_info lifecycle management - amdgpu_vm_get_task_info: reference counts up task_info before returning this info - amdgpu_vm_put_task_info: reference counts down task_info - last put to task_info() frees task_info from the vm. This patch also does logistical changes required for existing usage of vm-\u003etask_info. V2: Do not block all the prints when task_info not found (Felix) V3: Fixed review comments from Felix - Fix wrong indentation - No debug message for -ENOMEM - Add NULL check for task_info - Do not duplicate the debug messages (ti vs no ti) - Get first reference of task_info in vm_init(), put last in vm_fini() V4: Fixed review comments from Felix - fix double reference increment in create_task_info - change amdgpu_vm_get_task_info_pasid - additional changes in amdgpu_gem.c while porting", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41008", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BE7WNDXAZtKdqmbO+76HPg==": { "id": "BE7WNDXAZtKdqmbO+76HPg==", "updater": "debian/updater", "name": "CVE-2025-38140", "description": "In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone write plugs dm_revalidate_zones() only allowed new or previously unzoned devices to call blk_revalidate_disk_zones(). If the device was already zoned, disk-\u003enr_zones would always equal md-\u003enr_zones, so dm_revalidate_zones() returned without doing any work. This would make the zoned settings for the device not match the new table. If the device had zone write plug resources, it could run into errors like bdev_zone_is_seq() reading invalid memory because disk-\u003econv_zones_bitmap was the wrong size. If the device doesn't have any zone write plug resources, calling blk_revalidate_disk_zones() will always correctly update device. If blk_revalidate_disk_zones() fails, it can still overwrite or clear the current disk-\u003enr_zones value. In this case, DM must restore the previous value of disk-\u003enr_zones, so that the zoned settings will continue to match the previous value that it fell back to. If the device already has zone write plug resources, blk_revalidate_disk_zones() will not correctly update them, if it is called for arbitrary zoned device changes. Since there is not much need for this ability, the easiest solution is to disallow any table reloads that change the zoned settings, for devices that already have zone plug resources. Specifically, if a device already has zone plug resources allocated, it can only switch to another zoned table that also emulates zone append. Also, it cannot change the device size or the zone size. A device can switch to an error target.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38140", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BHVVtbEjnE6kNRkkovl+lw==": { "id": "BHVVtbEjnE6kNRkkovl+lw==", "updater": "debian/updater", "name": "CVE-2026-64572", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on insert error path fib_table_insert() publishes new_fa into the leaf's fa_list with fib_insert_alias() before calling the fib entry notifiers. When a notifier fails, the error path removes new_fa with fib_remove_alias() (hlist_del_rcu) and frees it right away with kmem_cache_free(). fib_table_lookup() walks that list under rcu_read_lock() only, so a concurrent lookup that already reached new_fa keeps reading it after the free: BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601) Read of size 1 at addr ffff88810676d4eb by task exploit/297 Call Trace: fib_table_lookup (net/ipv4/fib_trie.c:1601) ip_route_output_key_hash_rcu (net/ipv4/route.c:2814) ip_route_output_key_hash (net/ipv4/route.c:2705) __ip4_datagram_connect (net/ipv4/datagram.c:49) udp_connect (net/ipv4/udp.c:2144) __sys_connect (net/socket.c:2167) __x64_sys_connect (net/socket.c:2173) do_syscall_64 entry_SYSCALL_64_after_hwframe which belongs to the cache ip_fib_alias of size 56 Triggering the error path needs CAP_NET_ADMIN and a registered fib notifier that can reject a route; a netdevsim device whose IPv4 FIB resource is exhausted is enough. Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already does for a fib_alias removed from the trie.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64572", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BJSkSr7uOl+9xHp0ryZ62w==": { "id": "BJSkSr7uOl+9xHp0ryZ62w==", "updater": "debian/updater", "name": "CVE-2026-43271", "description": "In the Linux kernel, the following vulnerability has been resolved: md-cluster: fix NULL pointer dereference in process_metadata_update The function process_metadata_update() blindly dereferences the 'thread' pointer (acquired via rcu_dereference_protected) within the wait_event() macro. While the code comment states \"daemon thread must exist\", there is a valid race condition window during the MD array startup sequence (md_run): 1. bitmap_load() is called, which invokes md_cluster_ops-\u003ejoin(). 2. join() starts the \"cluster_recv\" thread (recv_daemon). 3. At this point, recv_daemon is active and processing messages. 4. However, mddev-\u003ethread (the main MD thread) is not initialized until later in md_run(). If a METADATA_UPDATED message is received from a remote node during this specific window, process_metadata_update() will be called while mddev-\u003ethread is still NULL, leading to a kernel panic. To fix this, we must validate the 'thread' pointer. If it is NULL, we release the held lock (no_new_dev_lockres) and return early, safely ignoring the update request as the array is not yet fully ready to process it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43271", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BQpEk418T4vUlcMfNVAdmQ==": { "id": "BQpEk418T4vUlcMfNVAdmQ==", "updater": "debian/updater", "name": "CVE-2024-26768", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC] With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these platforms. MAX_CORE_PIC is the maximum cpu number in MADT table (max physical number) which can exceed the supported maximum cpu number (NR_CPUS, max logical number), but kernel should not crash. Kernel should boot cpus with NR_CPUS, let the remainder cpus stay in BIOS. The potential crash reason is that the array acpi_core_pic[NR_CPUS] can be overflowed when parsing MADT table, and it is obvious that CORE_PIC should be corresponding to physical core rather than logical core, so it is better to define the array as acpi_core_pic[MAX_CORE_PIC]. With the patch, system can boot up 64 vcpus with qemu parameter -smp 128, otherwise system will crash with the following message. [ 0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000420000004259, era == 90000000037a5f0c, ra == 90000000037a46ec [ 0.000000] Oops[#1]: [ 0.000000] CPU: 0 PID: 0 Comm: swapper Not tainted 6.8.0-rc2+ #192 [ 0.000000] Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022 [ 0.000000] pc 90000000037a5f0c ra 90000000037a46ec tp 9000000003c90000 sp 9000000003c93d60 [ 0.000000] a0 0000000000000019 a1 9000000003d93bc0 a2 0000000000000000 a3 9000000003c93bd8 [ 0.000000] a4 9000000003c93a74 a5 9000000083c93a67 a6 9000000003c938f0 a7 0000000000000005 [ 0.000000] t0 0000420000004201 t1 0000000000000000 t2 0000000000000001 t3 0000000000000001 [ 0.000000] t4 0000000000000003 t5 0000000000000000 t6 0000000000000030 t7 0000000000000063 [ 0.000000] t8 0000000000000014 u0 ffffffffffffffff s9 0000000000000000 s0 9000000003caee98 [ 0.000000] s1 90000000041b0480 s2 9000000003c93da0 s3 9000000003c93d98 s4 9000000003c93d90 [ 0.000000] s5 9000000003caa000 s6 000000000a7fd000 s7 000000000f556b60 s8 000000000e0a4330 [ 0.000000] ra: 90000000037a46ec platform_init+0x214/0x250 [ 0.000000] ERA: 90000000037a5f0c efi_runtime_init+0x30/0x94 [ 0.000000] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) [ 0.000000] PRMD: 00000000 (PPLV0 -PIE -PWE) [ 0.000000] EUEN: 00000000 (-FPE -SXE -ASXE -BTE) [ 0.000000] ECFG: 00070800 (LIE=11 VS=7) [ 0.000000] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0) [ 0.000000] BADV: 0000420000004259 [ 0.000000] PRID: 0014c010 (Loongson-64bit, Loongson-3A5000) [ 0.000000] Modules linked in: [ 0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____)) [ 0.000000] Stack : 9000000003c93a14 9000000003800898 90000000041844f8 90000000037a46ec [ 0.000000] 000000000a7fd000 0000000008290000 0000000000000000 0000000000000000 [ 0.000000] 0000000000000000 0000000000000000 00000000019d8000 000000000f556b60 [ 0.000000] 000000000a7fd000 000000000f556b08 9000000003ca7700 9000000003800000 [ 0.000000] 9000000003c93e50 9000000003800898 9000000003800108 90000000037a484c [ 0.000000] 000000000e0a4330 000000000f556b60 000000000a7fd000 000000000f556b08 [ 0.000000] 9000000003ca7700 9000000004184000 0000000000200000 000000000e02b018 [ 0.000000] 000000000a7fd000 90000000037a0790 9000000003800108 0000000000000000 [ 0.000000] 0000000000000000 000000000e0a4330 000000000f556b60 000000000a7fd000 [ 0.000000] 000000000f556b08 000000000eaae298 000000000eaa5040 0000000000200000 [ 0.000000] ... [ 0.000000] Call Trace: [ 0.000000] [\u003c90000000037a5f0c\u003e] efi_runtime_init+0x30/0x94 [ 0.000000] [\u003c90000000037a46ec\u003e] platform_init+0x214/0x250 [ 0.000000] [\u003c90000000037a484c\u003e] setup_arch+0x124/0x45c [ 0.000000] [\u003c90000000037a0790\u003e] start_kernel+0x90/0x670 [ 0.000000] [\u003c900000000378b0d8\u003e] kernel_entry+0xd8/0xdc", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26768", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BUICuyNb/ouszFn+JmeQAw==": { "id": "BUICuyNb/ouszFn+JmeQAw==", "updater": "debian/updater", "name": "CVE-2026-45894", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a \"torn\" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow the \"Guidance to Software for Invalidations\" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware before proceeding. 3. Execute the required invalidation sequence (PASID cache, IOTLB, and Device-TLB flush) to ensure the hardware has released all cached references. 4. Only after the flushes are complete, zero out the remaining fields of the PASID entry. Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are visible to the hardware before the Present bit is set.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45894", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Bbaaaw6EQCYgnB/RTt5DJA==": { "id": "Bbaaaw6EQCYgnB/RTt5DJA==", "updater": "debian/updater", "name": "CVE-2026-68099", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_add_overflow() unconditionally writes the truncated sum into *d even on overflow, per its contract in include/linux/overflow.h. The four check_add_overflow() guards in set_posix_acl_entries_dacl() and set_ntacl_dacl() break out of the ACE-building loops on overflow, but the truncated *size is then consumed downstream at the end of set_ntacl_dacl(): pndacl-\u003esize = cpu_to_le16(le16_to_cpu(pndacl-\u003esize) + size); This produces an on-wire NT ACL whose pndacl-\u003esize under-reports the bytes actually written by the preceding fill_ace_for_sid()/memcpy() calls, yielding a malformed ACL that can trigger out-of-bounds reads when re-parsed by clients or ksmbd itself. Restore *size to its pre-addition value on each overflow branch (via `*size -= ace_sz` / `size -= nt_ace_size`) so that after the break, *size once again holds the cumulative size of the successfully-written ACEs. The committed ACL is then truncated-but-self-consistent rather than malformed. The ksmbd DACL builders are the only check_add_overflow() sites found where an overflow path breaks out of a loop and the destination value is consumed afterward. The other nearby break-style cases either return -EINVAL on overflow (transport_ipc.c) or break without consuming the overflowed destination value afterward (buildid.c).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68099", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BeYK25cFjXVIucBOE9TZxg==": { "id": "BeYK25cFjXVIucBOE9TZxg==", "updater": "debian/updater", "name": "CVE-2025-37880", "description": "In the Linux kernel, the following vulnerability has been resolved: um: work around sched_yield not yielding in time-travel mode sched_yield by a userspace may not actually cause scheduling in time-travel mode as no time has passed. In the case seen it appears to be a badly implemented userspace spinlock in ASAN. Unfortunately, with time-travel it causes an extreme slowdown or even deadlock depending on the kernel configuration (CONFIG_UML_MAX_USERSPACE_ITERATIONS). Work around it by accounting time to the process whenever it executes a sched_yield syscall.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37880", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BfCej9ITNGiYvMRyg3dQRA==": { "id": "BfCej9ITNGiYvMRyg3dQRA==", "updater": "debian/updater", "name": "CVE-2013-7445", "description": "The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2013-7445", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Bic4QWky/M3PTMfYe54QyA==": { "id": "Bic4QWky/M3PTMfYe54QyA==", "updater": "debian/updater", "name": "CVE-2026-64507", "description": "In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64507", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Bl1L7YkfYfRri1aHtOK8Iw==": { "id": "Bl1L7YkfYfRri1aHtOK8Iw==", "updater": "debian/updater", "name": "CVE-2010-4563", "description": "The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2010-4563", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BlWzFLDGsRIdIr+8T/estA==": { "id": "BlWzFLDGsRIdIr+8T/estA==", "updater": "debian/updater", "name": "CVE-2025-38096", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW error iwl_trans_reclaim is warning if it is called when the FW is not alive. But if it is called when there is a pending restart, i.e. after a FW error, there is no need to warn, instead - return silently.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38096", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BtqbO6KS0TZcYikpFy82Cw==": { "id": "BtqbO6KS0TZcYikpFy82Cw==", "updater": "debian/updater", "name": "CVE-2025-68755", "description": "In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I2C driver has been completely broken for five years without anyone noticing so remove the driver from staging. Specifically, commit 723de0f9171e (\"staging: most: remove device from interface structure\") started requiring drivers to set the interface device pointer before registration, but the I2C driver was never updated which results in a NULL pointer dereference if anyone ever tries to probe it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68755", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BxmPqE51CJB5JIKaQ3E3/A==": { "id": "BxmPqE51CJB5JIKaQ3E3/A==", "updater": "debian/updater", "name": "CVE-2024-53687", "description": "In the Linux kernel, the following vulnerability has been resolved: riscv: Fix IPIs usage in kfence_protect_page() flush_tlb_kernel_range() may use IPIs to flush the TLBs of all the cores, which triggers the following warning when the irqs are disabled: [ 3.455330] WARNING: CPU: 1 PID: 0 at kernel/smp.c:815 smp_call_function_many_cond+0x452/0x520 [ 3.456647] Modules linked in: [ 3.457218] CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 6.12.0-rc7-00010-g91d3de7240b8 #1 [ 3.457416] Hardware name: QEMU QEMU Virtual Machine, BIOS [ 3.457633] epc : smp_call_function_many_cond+0x452/0x520 [ 3.457736] ra : on_each_cpu_cond_mask+0x1e/0x30 [ 3.457786] epc : ffffffff800b669a ra : ffffffff800b67c2 sp : ff2000000000bb50 [ 3.457824] gp : ffffffff815212b8 tp : ff6000008014f080 t0 : 000000000000003f [ 3.457859] t1 : ffffffff815221e0 t2 : 000000000000000f s0 : ff2000000000bc10 [ 3.457920] s1 : 0000000000000040 a0 : ffffffff815221e0 a1 : 0000000000000001 [ 3.457953] a2 : 0000000000010000 a3 : 0000000000000003 a4 : 0000000000000000 [ 3.458006] a5 : 0000000000000000 a6 : ffffffffffffffff a7 : 0000000000000000 [ 3.458042] s2 : ffffffff815223be s3 : 00fffffffffff000 s4 : ff600001ffe38fc0 [ 3.458076] s5 : ff600001ff950d00 s6 : 0000000200000120 s7 : 0000000000000001 [ 3.458109] s8 : 0000000000000001 s9 : ff60000080841ef0 s10: 0000000000000001 [ 3.458141] s11: ffffffff81524812 t3 : 0000000000000001 t4 : ff60000080092bc0 [ 3.458172] t5 : 0000000000000000 t6 : ff200000000236d0 [ 3.458203] status: 0000000200000100 badaddr: ffffffff800b669a cause: 0000000000000003 [ 3.458373] [\u003cffffffff800b669a\u003e] smp_call_function_many_cond+0x452/0x520 [ 3.458593] [\u003cffffffff800b67c2\u003e] on_each_cpu_cond_mask+0x1e/0x30 [ 3.458625] [\u003cffffffff8000e4ca\u003e] __flush_tlb_range+0x118/0x1ca [ 3.458656] [\u003cffffffff8000e6b2\u003e] flush_tlb_kernel_range+0x1e/0x26 [ 3.458683] [\u003cffffffff801ea56a\u003e] kfence_protect+0xc0/0xce [ 3.458717] [\u003cffffffff801e9456\u003e] kfence_guarded_free+0xc6/0x1c0 [ 3.458742] [\u003cffffffff801e9d6c\u003e] __kfence_free+0x62/0xc6 [ 3.458764] [\u003cffffffff801c57d8\u003e] kfree+0x106/0x32c [ 3.458786] [\u003cffffffff80588cf2\u003e] detach_buf_split+0x188/0x1a8 [ 3.458816] [\u003cffffffff8058708c\u003e] virtqueue_get_buf_ctx+0xb6/0x1f6 [ 3.458839] [\u003cffffffff805871da\u003e] virtqueue_get_buf+0xe/0x16 [ 3.458880] [\u003cffffffff80613d6a\u003e] virtblk_done+0x5c/0xe2 [ 3.458908] [\u003cffffffff8058766e\u003e] vring_interrupt+0x6a/0x74 [ 3.458930] [\u003cffffffff800747d8\u003e] __handle_irq_event_percpu+0x7c/0xe2 [ 3.458956] [\u003cffffffff800748f0\u003e] handle_irq_event+0x3c/0x86 [ 3.458978] [\u003cffffffff800786cc\u003e] handle_simple_irq+0x9e/0xbe [ 3.459004] [\u003cffffffff80073934\u003e] generic_handle_domain_irq+0x1c/0x2a [ 3.459027] [\u003cffffffff804bf87c\u003e] imsic_handle_irq+0xba/0x120 [ 3.459056] [\u003cffffffff80073934\u003e] generic_handle_domain_irq+0x1c/0x2a [ 3.459080] [\u003cffffffff804bdb76\u003e] riscv_intc_aia_irq+0x24/0x34 [ 3.459103] [\u003cffffffff809d0452\u003e] handle_riscv_irq+0x2e/0x4c [ 3.459133] [\u003cffffffff809d923e\u003e] call_on_irq_stack+0x32/0x40 So only flush the local TLB and let the lazy kfence page fault handling deal with the faults which could happen when a core has an old protected pte version cached in its TLB. That leads to potential inaccuracies which can be tolerated when using kfence.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53687", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "BycQ8Iao7X8iaC2posSHiw==": { "id": "BycQ8Iao7X8iaC2posSHiw==", "updater": "debian/updater", "name": "CVE-2023-53523", "description": "In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: fix time stamp counter initialization If the gs_usb device driver is unloaded (or unbound) before the interface is shut down, the USB stack first calls the struct usb_driver::disconnect and then the struct net_device_ops::ndo_stop callback. In gs_usb_disconnect() all pending bulk URBs are killed, i.e. no more RX'ed CAN frames are send from the USB device to the host. Later in gs_can_close() a reset control message is send to each CAN channel to remove the controller from the CAN bus. In this race window the USB device can still receive CAN frames from the bus and internally queue them to be send to the host. At least in the current version of the candlelight firmware, the queue of received CAN frames is not emptied during the reset command. After loading (or binding) the gs_usb driver, new URBs are submitted during the struct net_device_ops::ndo_open callback and the candlelight firmware starts sending its already queued CAN frames to the host. However, this scenario was not considered when implementing the hardware timestamp function. The cycle counter/time counter infrastructure is set up (gs_usb_timestamp_init()) after the USBs are submitted, resulting in a NULL pointer dereference if timecounter_cyc2time() (via the call chain: gs_usb_receive_bulk_callback() -\u003e gs_usb_set_timestamp() -\u003e gs_usb_skb_set_timestamp()) is called too early. Move the gs_usb_timestamp_init() function before the URBs are submitted to fix this problem. For a comprehensive solution, we need to consider gs_usb devices with more than 1 channel. The cycle counter/time counter infrastructure is setup per channel, but the RX URBs are per device. Once gs_can_open() of _a_ channel has been called, and URBs have been submitted, the gs_usb_receive_bulk_callback() can be called for _all_ available channels, even for channels that are not running, yet. As cycle counter/time counter has not set up, this will again lead to a NULL pointer dereference. Convert the cycle counter/time counter from a \"per channel\" to a \"per device\" functionality. Also set it up, before submitting any URBs to the device. Further in gs_usb_receive_bulk_callback(), don't process any URBs for not started CAN channels, only resubmit the URB.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53523", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C2rkTVkGbhSsyKrmiRle6w==": { "id": "C2rkTVkGbhSsyKrmiRle6w==", "updater": "debian/updater", "name": "CVE-2024-27408", "description": "In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27408", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C7PpoYskxK6iD21JtQVTfg==": { "id": "C7PpoYskxK6iD21JtQVTfg==", "updater": "debian/updater", "name": "CVE-2026-53292", "description": "In the Linux kernel, the following vulnerability has been resolved: net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind syzbot reported a kernel BUG triggered from pn_socket_sendmsg() via pn_socket_autobind(): kernel BUG at net/phonet/socket.c:213! RIP: 0010:pn_socket_autobind net/phonet/socket.c:213 [inline] RIP: 0010:pn_socket_sendmsg+0x240/0x250 net/phonet/socket.c:421 Call Trace: sock_sendmsg_nosec+0x112/0x150 net/socket.c:797 __sock_sendmsg net/socket.c:812 [inline] __sys_sendto+0x402/0x590 net/socket.c:2280 ... pn_socket_autobind() calls pn_socket_bind() with port 0 and, on -EINVAL, assumes the socket was already bound and asserts that the port is non-zero: err = pn_socket_bind(sock, ..., sizeof(struct sockaddr_pn)); if (err != -EINVAL) return err; BUG_ON(!pn_port(pn_sk(sock-\u003esk)-\u003esobject)); return 0; /* socket was already bound */ However pn_socket_bind() also returns -EINVAL when sk-\u003esk_state is not TCP_CLOSE, even when the socket has never been bound and pn_port() is still 0. In that case the BUG_ON() fires and panics the kernel from a user-triggerable path. Treat the \"bind returned -EINVAL but pn_port() is still 0\" case as a regular error and propagate -EINVAL to the caller instead of crashing. Existing callers already translate a non-zero return from pn_socket_autobind() into -ENOBUFS/-EAGAIN, so returning -EINVAL here only changes behaviour from panic to a normal errno.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53292", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C7tVHOY8u481+kV8QvenfA==": { "id": "C7tVHOY8u481+kV8QvenfA==", "updater": "debian/updater", "name": "CVE-2026-63940", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't have to worry about underflowing the length, and to allow for WARNing on trying to configure the scratch area with len==0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63940", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "C9wNKgQaGWqBeCwo1E9bcQ==": { "id": "C9wNKgQaGWqBeCwo1E9bcQ==", "updater": "debian/updater", "name": "CVE-2026-53401", "description": "In the Linux kernel, the following vulnerability has been resolved: fbdev: omap2: fix use-after-free in omapfb_mmap omapfb_mmap() has a race condition with OMAPFB_SETUP_PLANE ioctl that can lead to use-after-free: The fb_mmap() entry point holds mm_lock but not lock (fb_info-\u003elock), while ioctl handlers like OMAPFB_SETUP_PLANE hold lock but not mm_lock. This allows concurrent execution. In omapfb_mmap(): 1. rg = omapfb_get_mem_region(ofbi-\u003eregion); // Get old region ref 2. start = omapfb_get_region_paddr(ofbi); // Read from NEW region 3. len = fix-\u003esmem_len; // Read from NEW region 4. vm_iomap_memory(vma, start, len); // Map NEW region memory 5. atomic_inc(\u0026rg-\u003emap_count); // Increment OLD region! Concurrently, OMAPFB_SETUP_PLANE can: - Reassign ofbi-\u003eregion = new_rg - Update fix-\u003esmem_len - OMAPFB_SETUP_MEM then checks NEW region's map_count (0!) and frees it This leaves userspace with a mapping to freed physical memory. The fix is to read all required values (start, len) from the same region reference (rg) that will have its map_count incremented, preventing the region from being freed while still mapped.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53401", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CBXpgXWZVGhSJGbFah0a1w==": { "id": "CBXpgXWZVGhSJGbFah0a1w==", "updater": "debian/updater", "name": "CVE-2026-23393", "description": "In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in softirq context under rcu_read_lock (without RTNL) and can re-schedule ccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_sync() returning and kfree_rcu() being called. The following is a simple race scenario: cpu0 cpu1 mep_delete_implementation() cancel_delayed_work_sync(ccm_rx_dwork); br_cfm_frame_rx() // peer_mep still in hlist if (peer_mep-\u003eccm_defect) ccm_rx_timer_start() queue_delayed_work(ccm_rx_dwork) hlist_del_rcu(\u0026peer_mep-\u003ehead); kfree_rcu(peer_mep, rcu); ccm_rx_work_expired() // on freed peer_mep To prevent this, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync() in both peer MEP deletion paths, so that subsequent queue_delayed_work() calls from br_cfm_frame_rx() are silently rejected. The cc_peer_disable() helper retains cancel_delayed_work_sync() because it is also used for the CC enable/disable toggle path where the work must remain re-schedulable.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23393", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CD5zzBd12kSBWciGkqLjZA==": { "id": "CD5zzBd12kSBWciGkqLjZA==", "updater": "debian/updater", "name": "CVE-2025-22070", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.: setfacl -m default:group:simpsons:rwx parentdir then creating a subdirectory crashed 9p client, as v9fs_fid_add() call in function v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL (since dafbe689736) even though the subsequent v9fs_set_create_acl() call expects a valid non-NULL 'fid' pointer: [ 37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000 ... [ 37.322338] Call Trace: [ 37.323043] \u003cTASK\u003e [ 37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434) [ 37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714) [ 37.325532] ? search_module_extables (kernel/module/main.c:3733) [ 37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.328006] ? search_bpf_extables (kernel/bpf/core.c:804) [ 37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538) [ 37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574) [ 37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet [ 37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p [ 37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p [ 37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p [ 37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p [ 37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p [ 37.338590] vfs_mkdir (fs/namei.c:4313) [ 37.339535] do_mkdirat (fs/namei.c:4336) [ 37.340465] __x64_sys_mkdir (fs/namei.c:4354) [ 37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Fix this by simply swapping the sequence of these two calls in v9fs_vfs_mkdir_dotl(), i.e. calling v9fs_set_create_acl() before v9fs_fid_add().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22070", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CDrNE8A4NBsnPAqoIUYOkw==": { "id": "CDrNE8A4NBsnPAqoIUYOkw==", "updater": "debian/updater", "name": "CVE-2011-4915", "description": "fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-4915", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CK0gQPCPQM+aEJCCq53cDA==": { "id": "CK0gQPCPQM+aEJCCq53cDA==", "updater": "debian/updater", "name": "CVE-2021-26934", "description": "An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-26934", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CLneAUk9k5p+117hZeCApw==": { "id": "CLneAUk9k5p+117hZeCApw==", "updater": "debian/updater", "name": "CVE-2023-52452", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix accesses to uninit stack slots Privileged programs are supposed to be able to read uninitialized stack memory (ever since 6715df8d5) but, before this patch, these accesses were permitted inconsistently. In particular, accesses were permitted above state-\u003eallocated_stack, but not below it. In other words, if the stack was already \"large enough\", the access was permitted, but otherwise the access was rejected instead of being allowed to \"grow the stack\". This undesired rejection was happening in two places: - in check_stack_slot_within_bounds() - in check_stack_range_initialized() This patch arranges for these accesses to be permitted. A bunch of tests that were relying on the old rejection had to change; all of them were changed to add also run unprivileged, in which case the old behavior persists. One tests couldn't be updated - global_func16 - because it can't run unprivileged for other reasons. This patch also fixes the tracking of the stack size for variable-offset reads. This second fix is bundled in the same commit as the first one because they're inter-related. Before this patch, writes to the stack using registers containing a variable offset (as opposed to registers with fixed, known values) were not properly contributing to the function's needed stack size. As a result, it was possible for a program to verify, but then to attempt to read out-of-bounds data at runtime because a too small stack had been allocated for it. Each function tracks the size of the stack it needs in bpf_subprog_info.stack_depth, which is maintained by update_stack_depth(). For regular memory accesses, check_mem_access() was calling update_state_depth() but it was passing in only the fixed part of the offset register, ignoring the variable offset. This was incorrect; the minimum possible value of that register should be used instead. This tracking is now fixed by centralizing the tracking of stack size in grow_stack_state(), and by lifting the calls to grow_stack_state() to check_stack_access_within_bounds() as suggested by Andrii. The code is now simpler and more convincingly tracks the correct maximum stack size. check_stack_range_initialized() can now rely on enough stack having been allocated for the access; this helps with the fix for the first issue. A few tests were changed to also check the stack depth computation. The one that fails without this patch is verifier_var_off:stack_write_priv_vs_unpriv.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52452", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CM6brgFmfIaakm9l757eVQ==": { "id": "CM6brgFmfIaakm9l757eVQ==", "updater": "debian/updater", "name": "CVE-2026-68093", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug If a vCPU stays scheduled out (or blocked) while the last pCPU it ran on goes through a hotplug cycle (online-\u003eoffline-\u003eonline), and the vCPU then resumes execution on the same pCPU, then it is possible for it to run with an ASID that has now been assigned to a different vCPU, resulting in stale TLB translations being used. svm_enable_virtualization_cpu() resets asid_generation to 1 and sets next_asid to max_asid + 1 on every CPU online event, including hotplug cycles. Because next_asid starts beyond the pool boundary, the first call to new_asid() after an online event always wraps the pool, incrementing asid_generation to 2 and assigning ASIDs starting from min_asid. Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding asid_generation=2 and ASID=N from before the hotplug event: 1. CPU-X goes offline and back online: asid_generation resets to 1, next_asid = max_asid + 1. 2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping the pool and consuming ASIDs starting from min_asid. Eventually vCPU-B from a different VM is assigned asid_generation=2, ASID=N — the same ASID that vCPU-A held before the hotplug. 3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb-\u003ecpu is unchanged so the migration branch is skipped. Its saved asid_generation=2 matches sd-\u003easid_generation=2, so the generation check silently passes and vCPU-A continues running with ASID=N — the same ASID just freshly assigned to vCPU-B. Both vCPUs from different VMs now run on CPU-X with the same ASID, causing them to share NPT TLB entries and producing stale translations. The collision manifests as a KVM internal error (Suberror: 1, emulation failure). The NPT page fault reports a faulting GPA far outside the VM's physical memory range — a sign of stale TLB translations being used. KVM falls back to instruction emulation, which fails on FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not implement. Fix this by incrementing asid_generation instead of resetting it to 1 in svm_enable_virtualization_cpu(). On module load, asid_generation starts at 0 (memset) and the increment produces 1, identical to the old behaviour. On subsequent hotplug cycles the generation advances beyond any value a vCPU previously observed on this CPU, so the generation check in pre_svm_run() reliably forces new_asid() on every vCPU after every hotplug cycle.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68093", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CSDuo5+yBjRvBzy9+2BbuA==": { "id": "CSDuo5+yBjRvBzy9+2BbuA==", "updater": "debian/updater", "name": "CVE-2026-53143", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow. During CRIU checkpoint of an SDMA queue on Navi3x: - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer, leaking 1536 bytes of adjacent GTT memory to userspace During CRIU restore: - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer, corrupting 1536 bytes of adjacent GTT memory (often the ring buffer or neighboring MQDs) This is a copy-paste regression unique to v11. All other ASIC backends (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants. Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly handle the smaller v11_sdma_mqd structure, matching the pattern used in other MQD managers. (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53143", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CZMZO0J+3/q6iPxizT+6tQ==": { "id": "CZMZO0J+3/q6iPxizT+6tQ==", "updater": "debian/updater", "name": "CVE-2026-68315", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU \u003e 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68315", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CZdODvItVtmOQOQwVO8dIg==": { "id": "CZdODvItVtmOQOQwVO8dIg==", "updater": "debian/updater", "name": "CVE-2023-1916", "description": "A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-1916", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cao09ITIaY7Bv2VChcHNSQ==": { "id": "Cao09ITIaY7Bv2VChcHNSQ==", "updater": "debian/updater", "name": "CVE-2026-68453", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf length", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68453", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cby6yBvWiqge200e7H4cpA==": { "id": "Cby6yBvWiqge200e7H4cpA==", "updater": "debian/updater", "name": "CVE-2026-68249", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68249", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CdgEydujtCeBhG5XiZmOUg==": { "id": "CdgEydujtCeBhG5XiZmOUg==", "updater": "debian/updater", "name": "CVE-2026-68241", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/mst: limit DP MST ESI service loop The loop in intel_dp_check_mst_status() keeps servicing interrupts originating from the sink without bound. Add an upper bound to the new interrupts occurring during interrupt processing to not get stuck on potentially stuck sink devices. Use arbitrary 32 tries to clear incoming interrupts in one go. Discovered using AI-assisted static analysis confirmed by Intel Product Security. Note: The condition likely pre-dates the commit in the Fixes: tag, but this is about as far back as a backport has any chance of succeeding. Before that, the retry had a goto. (cherry picked from commit b4ea5272133059acb493cc36599071a9e852ec2e)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ceca9Wrlp9YR4qlWnU8ocw==": { "id": "Ceca9Wrlp9YR4qlWnU8ocw==", "updater": "debian/updater", "name": "CVE-2026-64348", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: free iso schedules on failed submit EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in urb-\u003ehcpriv until iso_stream_schedule() and the link helpers consume it. If the controller is no longer accessible, or usb_hcd_link_urb_to_ep() fails, submit jumps to done_not_linked before that handoff happens and leaks the staged schedule still attached to urb-\u003ehcpriv. Free the staged schedule from done_not_linked when submit fails before the URB is linked and clear urb-\u003ehcpriv after the free. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64 allyesconfig build showed no new warnings. As we do not have an EHCI host controller with a USB isochronous device to test with, no runtime testing was able to be performed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64348", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CipgWP1TNrEuX30sXyiVDA==": { "id": "CipgWP1TNrEuX30sXyiVDA==", "updater": "debian/updater", "name": "CVE-2026-53237", "description": "In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: fix NULL pointer dereference in suspend/resume mvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO banks during suspend/resume, but not all banks have PWM functionality. GPIO banks without PWM have mvchip-\u003emvpwm set to NULL. Calling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer dereference when it tries to access mvpwm-\u003eblink_select. Unable to handle kernel NULL pointer dereference at virtual address 00000020 when write [00000020] *pgd=00000000 Internal error: Oops: 815 [#1] PREEMPT ARM Modules linked in: CPU: 0 UID: 0 PID: 406 Comm: sh Not tainted 6.12.74-rt12-yocto-standard-g4e96f98fb7db-dirty #353 Hardware name: Marvell Armada 370/XP (Device Tree) PC is at regmap_mmio_read+0x38/0x54 LR is at regmap_mmio_read+0x38/0x54 pc : [\u003cc05fd2ac\u003e] lr : [\u003cc05fd2ac\u003e] psr: 200f0013 sp : f0c11d10 ip : 00000000 fp : c100d2f0 r10: c14fb854 r9 : 00000000 r8 : 00000000 r7 : c1799c00 r6 : 00000020 r5 : 00000020 r4 : c179c7c0 r3 : f0a231a0 r2 : 00000020 r1 : 00000020 r0 : 00000000 Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment none Control: 10c5387d Table: 135ec059 DAC: 00000051 Call trace: regmap_mmio_read from _regmap_bus_reg_read+0x78/0xac _regmap_bus_reg_read from _regmap_read+0x60/0x154 _regmap_read from regmap_read+0x3c/0x60 regmap_read from mvebu_gpio_suspend+0xa4/0x14c mvebu_gpio_suspend from dpm_run_callback+0x54/0x180 dpm_run_callback from device_suspend+0x124/0x630 device_suspend from dpm_suspend+0x124/0x270 dpm_suspend from dpm_suspend_start+0x64/0x6c dpm_suspend_start from suspend_devices_and_enter+0x140/0x8e8 suspend_devices_and_enter from pm_suspend+0x2fc/0x308 pm_suspend from state_store+0x6c/0xc8 state_store from kernfs_fop_write_iter+0x10c/0x1f8 kernfs_fop_write_iter from vfs_write+0x270/0x468 vfs_write from ksys_write+0x70/0xf0 ksys_write from ret_fast_syscall+0x0/0x54 Add a NULL check for mvchip-\u003emvpwm before calling the PWM suspend/resume functions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53237", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Cs99NDR/2aWXIUslX4V9Sg==": { "id": "Cs99NDR/2aWXIUslX4V9Sg==", "updater": "debian/updater", "name": "CVE-2026-32777", "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32777", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "CssqY71pYe1Q3wka2HbNKQ==": { "id": "CssqY71pYe1Q3wka2HbNKQ==", "updater": "debian/updater", "name": "CVE-2025-37861", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue When the task management thread processes reply queues while the reset thread resets them, the task management thread accesses an invalid queue ID (0xFFFF), set by the reset thread, which points to unallocated memory, causing a crash. Add flag 'io_admin_reset_sync' to synchronize access between the reset, I/O, and admin threads. Before a reset, the reset handler sets this flag to block I/O and admin processing threads. If any thread bypasses the initial check, the reset thread waits up to 10 seconds for processing to finish. If the wait exceeds 10 seconds, the controller is marked as unrecoverable.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37861", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ctoz44zltdVfu3psq14Exw==": { "id": "Ctoz44zltdVfu3psq14Exw==", "updater": "debian/updater", "name": "CVE-2025-61147", "description": "strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-61147", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Czqm8H7741oaglDeK6CQXw==": { "id": "Czqm8H7741oaglDeK6CQXw==", "updater": "debian/updater", "name": "CVE-2024-26458", "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26458", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D+e0V9WHhxi4n8xiC8i18w==": { "id": "D+e0V9WHhxi4n8xiC8i18w==", "updater": "debian/updater", "name": "CVE-2024-46729", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix incorrect size calculation for loop [WHY] fe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is lager than the array size. [HOW] Divide byte size 20 by its element size. This fixes 2 OVERRUN issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46729", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D03Adkd0D6klk/oxgxcglg==": { "id": "D03Adkd0D6klk/oxgxcglg==", "updater": "debian/updater", "name": "CVE-2024-26758", "description": "In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore suspended array in md_check_recovery() mddev_suspend() never stop sync_thread, hence it doesn't make sense to ignore suspended array in md_check_recovery(), which might cause sync_thread can't be unregistered. After commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following hang can be triggered by test shell/integrity-caching.sh: 1) suspend the array: raid_postsuspend mddev_suspend 2) stop the array: raid_dtr md_stop __md_stop_writes stop_sync_thread set_bit(MD_RECOVERY_INTR, \u0026mddev-\u003erecovery); md_wakeup_thread_directly(mddev-\u003esync_thread); wait_event(..., !test_bit(MD_RECOVERY_RUNNING, \u0026mddev-\u003erecovery)) 3) sync thread done: md_do_sync set_bit(MD_RECOVERY_DONE, \u0026mddev-\u003erecovery); md_wakeup_thread(mddev-\u003ethread); 4) daemon thread can't unregister sync thread: md_check_recovery if (mddev-\u003esuspended) return; -\u003e return directly md_read_sync_thread clear_bit(MD_RECOVERY_RUNNING, \u0026mddev-\u003erecovery); -\u003e MD_RECOVERY_RUNNING can't be cleared, hence step 2 hang; This problem is not just related to dm-raid, fix it by ignoring suspended array in md_check_recovery(). And follow up patches will improve dm-raid better to frozen sync thread during suspend.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26758", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D1By26h2T5U+g0sTT5l5FQ==": { "id": "D1By26h2T5U+g0sTT5l5FQ==", "updater": "debian/updater", "name": "CVE-2026-68097", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but does not verify that the declared ACE size contains all sub-authorities described by that field. An undersized ACE can therefore be copied and later make the POSIX ACL deduplication walk inspect data beyond the copied ACE boundary. The existing initial bound check is also too small. It only ensures that the ACE size field is accessible before set_ntacl_dacl() reads sid.num_subauth farther into the input buffer. Require enough input for the fixed SID header before accessing num_subauth, reject ACEs smaller than that header, and skip ACEs whose declared size cannot contain the complete SID. This makes the validation consistent with the other ACE walk paths.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68097", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D1lGDgRmVddpsy/krPkJWA==": { "id": "D1lGDgRmVddpsy/krPkJWA==", "updater": "debian/updater", "name": "CVE-2024-58241", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregister_dev This make use of disable_work_* on hci_unregister_dev since the hci_dev is about to be freed new submissions are not disarable.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D1lO466zGDJ2CIR+V5bEmg==": { "id": "D1lO466zGDJ2CIR+V5bEmg==", "updater": "debian/updater", "name": "CVE-2026-68357", "description": "In the Linux kernel, the following vulnerability has been resolved: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() When a watchdog governor is unregistered, it updates existing watchdog devices that were using this governor by falling back to `default_gov`. If the governor being unregistered is currently set as `default_gov`, the `default_gov` is never cleared. This leads to 2 use-after-free issues: 1. New watchdog devices registered after this point will inherit the dangling `default_gov`. 2. Existing watchdog devices using the unregistered governor will have their `wdd-\u003egov` reassigned to the dangling `default_gov`. Fix the UAF by clearing `default_gov` if it matches the governor being unregistered.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68357", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D3XFmzgwlaUj5224Ty8BXA==": { "id": "D3XFmzgwlaUj5224Ty8BXA==", "updater": "debian/updater", "name": "CVE-2024-50009", "description": "In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value cpufreq_cpu_get may return NULL. To avoid NULL-dereference check it and return in case of error. Found by Linux Verification Center (linuxtesting.org) with SVACE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50009", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D6W/s3VZQKE8xMh57eUkZw==": { "id": "D6W/s3VZQKE8xMh57eUkZw==", "updater": "debian/updater", "name": "CVE-2023-3164", "description": "A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-3164", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D74mlxiMppsGNMizdZlOXg==": { "id": "D74mlxiMppsGNMizdZlOXg==", "updater": "debian/updater", "name": "CVE-2026-16768", "description": "A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-16768", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gdk-pixbuf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D7hEv7Md38UxkdoufM/Uug==": { "id": "D7hEv7Md38UxkdoufM/Uug==", "updater": "debian/updater", "name": "CVE-2026-64212", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it In iwl_mld_remove_link, the link-\u003efw_id is saved at the beginning of the function so we have it after we freed the link. But the link pointer can be NULL, and is not checked when the fw_id is stored. Fix it by simply freeing the link at the end of the function. fFixes: 0e66a39f4f0e (\"wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link()\")", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64212", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D7yI+RxqvpHcdBC67a88Cg==": { "id": "D7yI+RxqvpHcdBC67a88Cg==", "updater": "debian/updater", "name": "CVE-2020-36694", "description": "An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-36694", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "D9VI64lZjFQsFF2NnyKSTw==": { "id": "D9VI64lZjFQsFF2NnyKSTw==", "updater": "debian/updater", "name": "CVE-2024-43872", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup under heavy CEQE load CEQEs are handled in interrupt handler currently. This may cause the CPU core staying in interrupt context too long and lead to soft lockup under heavy load. Handle CEQEs in BH workqueue and set an upper limit for the number of CEQE handled by a single call of work handler.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43872", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DDyc4d9FxDQMYN4Q8LEQAA==": { "id": "DDyc4d9FxDQMYN4Q8LEQAA==", "updater": "debian/updater", "name": "CVE-2026-68422", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If we have an unexpected reloc_root for our root, we jump to the out label but never drop the reference we obtained for root, resulting in a leak. Add a missing btrfs_put_root() call.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68422", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DEvkWQMQdNGeGi8iOnJX8g==": { "id": "DEvkWQMQdNGeGi8iOnJX8g==", "updater": "debian/updater", "name": "CVE-2026-7010", "description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-7010", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DJp7nKlC0fmEasL8DScwkw==": { "id": "DJp7nKlC0fmEasL8DScwkw==", "updater": "debian/updater", "name": "CVE-2026-23448", "description": "In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset: if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) \u003e skb_in-\u003elen) but the second check omits it: if ((sizeof(struct usb_cdc_ncm_ndp16) + ret * (sizeof(struct usb_cdc_ncm_dpe16))) \u003e skb_in-\u003elen) This validates the DPE array size against the total skb length as if the NDP were at offset 0, rather than at ndpoffset. When the NDP is placed near the end of the NTB (large wNdpIndex), the DPE entries can extend past the skb data buffer even though the check passes. cdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating the DPE array. Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23448", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DKLM8rvwKJ6+fHZ/qapkKQ==": { "id": "DKLM8rvwKJ6+fHZ/qapkKQ==", "updater": "debian/updater", "name": "CVE-2025-55160", "description": "ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-55160", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DMCt/mrj+Z0rWRq22nL0ZQ==": { "id": "DMCt/mrj+Z0rWRq22nL0ZQ==", "updater": "debian/updater", "name": "CVE-2026-66032", "description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-66032", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DOO695SndYXuHis5ZYF2fg==": { "id": "DOO695SndYXuHis5ZYF2fg==", "updater": "debian/updater", "name": "CVE-2025-71227", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't WARN for connections on invalid channels It's not clear (to me) how exactly syzbot managed to hit this, but it seems conceivable that e.g. regulatory changed and has disabled a channel between scanning (channel is checked to be usable by cfg80211_get_ies_channel_number) and connecting on the channel later. With one scenario that isn't covered elsewhere described above, the warning isn't good, replace it with a (more informative) error message.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71227", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DQ+fBbiyBgmY3FUEecFZxw==": { "id": "DQ+fBbiyBgmY3FUEecFZxw==", "updater": "debian/updater", "name": "CVE-2026-68352", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi-\u003eis_wmm_enabled. Add a check that the total IE length fits within the buffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68352", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DQTeeBmq/WUyAFVYi9GppQ==": { "id": "DQTeeBmq/WUyAFVYi9GppQ==", "updater": "debian/updater", "name": "CVE-2025-40025", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer for non inode dnode As syzbot reported below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/file.c:1243! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5354 Comm: syz.0.0 Not tainted 6.17.0-rc1-syzkaller-00211-g90d970cade8e #0 PREEMPT(full) RIP: 0010:f2fs_truncate_hole+0x69e/0x6c0 fs/f2fs/file.c:1243 Call Trace: \u003cTASK\u003e f2fs_punch_hole+0x2db/0x330 fs/f2fs/file.c:1306 f2fs_fallocate+0x546/0x990 fs/f2fs/file.c:2018 vfs_fallocate+0x666/0x7e0 fs/open.c:342 ksys_fallocate fs/open.c:366 [inline] __do_sys_fallocate fs/open.c:371 [inline] __se_sys_fallocate fs/open.c:369 [inline] __x64_sys_fallocate+0xc0/0x110 fs/open.c:369 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f1e65f8ebe9 w/ a fuzzed image, f2fs may encounter panic due to it detects inconsistent truncation range in direct node in f2fs_truncate_hole(). The root cause is: a non-inode dnode may has the same footer.ino and footer.nid, so the dnode will be parsed as an inode, then ADDRS_PER_PAGE() may return wrong blkaddr count which may be 923 typically, by chance, dn.ofs_in_node is equal to 923, then count can be calculated to 0 in below statement, later it will trigger panic w/ f2fs_bug_on(, count == 0 || ...). \tcount = min(end_offset - dn.ofs_in_node, pg_end - pg_start); This patch introduces a new node_type NODE_TYPE_NON_INODE, then allowing passing the new_type to sanity_check_node_footer in f2fs_get_node_folio() to detect corruption that a non-inode dnode has the same footer.ino and footer.nid. Scripts to reproduce: mkfs.f2fs -f /dev/vdb mount /dev/vdb /mnt/f2fs touch /mnt/f2fs/foo touch /mnt/f2fs/bar dd if=/dev/zero of=/mnt/f2fs/foo bs=1M count=8 umount /mnt/f2fs inject.f2fs --node --mb i_nid --nid 4 --idx 0 --val 5 /dev/vdb mount /dev/vdb /mnt/f2fs xfs_io /mnt/f2fs/foo -c \"fpunch 6984k 4k\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40025", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DSPfaFg7hLhEsc2fToRgLw==": { "id": "DSPfaFg7hLhEsc2fToRgLw==", "updater": "debian/updater", "name": "CVE-2025-38261", "description": "In the Linux kernel, the following vulnerability has been resolved: riscv: save the SR_SUM status over switches When threads/tasks are switched we need to ensure the old execution's SR_SUM state is saved and the new thread has the old SR_SUM state restored. The issue was seen under heavy load especially with the syz-stress tool running, with crashes as follows in schedule_tail: Unable to handle kernel access to user memory without uaccess routines at virtual address 000000002749f0d0 Oops [#1] Modules linked in: CPU: 1 PID: 4875 Comm: syz-executor.0 Not tainted 5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 #0 Hardware name: riscv-virtio,qemu (DT) epc : schedule_tail+0x72/0xb2 kernel/sched/core.c:4264 ra : task_pid_vnr include/linux/sched.h:1421 [inline] ra : schedule_tail+0x70/0xb2 kernel/sched/core.c:4264 epc : ffffffe00008c8b0 ra : ffffffe00008c8ae sp : ffffffe025d17ec0 gp : ffffffe005d25378 tp : ffffffe00f0d0000 t0 : 0000000000000000 t1 : 0000000000000001 t2 : 00000000000f4240 s0 : ffffffe025d17ee0 s1 : 000000002749f0d0 a0 : 000000000000002a a1 : 0000000000000003 a2 : 1ffffffc0cfac500 a3 : ffffffe0000c80cc a4 : 5ae9db91c19bbe00 a5 : 0000000000000000 a6 : 0000000000f00000 a7 : ffffffe000082eba s2 : 0000000000040000 s3 : ffffffe00eef96c0 s4 : ffffffe022c77fe0 s5 : 0000000000004000 s6 : ffffffe067d74e00 s7 : ffffffe067d74850 s8 : ffffffe067d73e18 s9 : ffffffe067d74e00 s10: ffffffe00eef96e8 s11: 000000ae6cdf8368 t3 : 5ae9db91c19bbe00 t4 : ffffffc4043cafb2 t5 : ffffffc4043cafba t6 : 0000000000040000 status: 0000000000000120 badaddr: 000000002749f0d0 cause: 000000000000000f Call Trace: [\u003cffffffe00008c8b0\u003e] schedule_tail+0x72/0xb2 kernel/sched/core.c:4264 [\u003cffffffe000005570\u003e] ret_from_exception+0x0/0x14 Dumping ftrace buffer: (ftrace buffer empty) ---[ end trace b5f8f9231dc87dda ]--- The issue comes from the put_user() in schedule_tail (kernel/sched/core.c) doing the following: asmlinkage __visible void schedule_tail(struct task_struct *prev) { ... if (current-\u003eset_child_tid) put_user(task_pid_vnr(current), current-\u003eset_child_tid); ... } the put_user() macro causes the code sequence to come out as follows: 1:\t__enable_user_access() 2:\treg = task_pid_vnr(current); 3:\t*current-\u003eset_child_tid = reg; 4:\t__disable_user_access() The problem is that we may have a sleeping function as argument which could clear SR_SUM causing the panic above. This was fixed by evaluating the argument of the put_user() macro outside the user-enabled section in commit 285a76bb2cf5 (\"riscv: evaluate put_user() arg before enabling user access\")\" In order for riscv to take advantage of unsafe_get/put_XXX() macros and to avoid the same issue we had with put_user() and sleeping functions we must ensure code flow can go through switch_to() from within a region of code with SR_SUM enabled and come back with SR_SUM still enabled. This patch addresses the problem allowing future work to enable full use of unsafe_get/put_XXX() macros without needing to take a CSR bit flip cost on every access. Make switch_to() save and restore SR_SUM.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38261", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DTKWI1xT2s8d7ZdCcH14Dg==": { "id": "DTKWI1xT2s8d7ZdCcH14Dg==", "updater": "debian/updater", "name": "CVE-2026-68408", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock When a netlink socket that owns a PMSR session is closed, cfg80211_release_pmsr() clears the request's nl_portid and queues pmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously. If the interface tears down concurrently, cfg80211_pmsr_wdev_down() is called under wiphy_lock and calls cancel_work_sync(\u0026pmsr_free_wk) to wait for any running work. The work function acquires wiphy_lock via guard(wiphy) before calling process_abort. This is a deadlock: wdev_down holds wiphy_lock and blocks inside cancel_work_sync(); pmsr_free_wk blocks trying to acquire that same wiphy_lock. Neither thread can proceed. The same deadlock is reachable from cfg80211_leave_locked(), which calls cfg80211_pmsr_wdev_down() for all interface types under wiphy_lock. Fix this by converting pmsr_free_wk from a plain work_struct to a wiphy_work. The wiphy_work dispatcher holds wiphy_lock when running work items, so the explicit guard(wiphy) in the work function is no longer needed. wiphy_work_cancel() can be called safely while holding wiphy_lock - since wiphy_lock prevents the work from running concurrently, wiphy_work_cancel() never blocks, eliminating the deadlock. Remove the cancel_work_sync() for pmsr_free_wk from the NETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally just before it, already cancels any pending work under wiphy_lock via wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68408", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DTa20HYXjXs/P3Zs9HN/QQ==": { "id": "DTa20HYXjXs/P3Zs9HN/QQ==", "updater": "debian/updater", "name": "CVE-2026-23213", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Disable MMIO access during SMU Mode 1 reset During Mode 1 reset, the ASIC undergoes a reset cycle and becomes temporarily inaccessible via PCIe. Any attempt to access MMIO registers during this window (e.g., from interrupt handlers or other driver threads) can result in uncompleted PCIe transactions, leading to NMI panics or system hangs. To prevent this, set the `no_hw_access` flag to true immediately after triggering the reset. This signals other driver components to skip register accesses while the device is offline. A memory barrier `smp_mb()` is added to ensure the flag update is globally visible to all cores before the driver enters the sleep/wait state. (cherry picked from commit 7edb503fe4b6d67f47d8bb0dfafb8e699bb0f8a4)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23213", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DTqW4x46QrHUeNdsdW0MbA==": { "id": "DTqW4x46QrHUeNdsdW0MbA==", "updater": "debian/updater", "name": "CVE-2026-23137", "description": "In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a memory leak. Fix this by using scope-based cleanup helper __free(kfree) for automatic resource cleanup. This ensures unittest_data is automatically freed when it goes out of scope in error paths. For the success path, use retain_and_null_ptr() to transfer ownership of the memory to the device tree and prevent double freeing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23137", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DUf93g2uSh44oAMP/2IC5g==": { "id": "DUf93g2uSh44oAMP/2IC5g==", "updater": "debian/updater", "name": "CVE-2026-23374", "description": "In the Linux kernel, the following vulnerability has been resolved: blktrace: fix __this_cpu_read/write in preemptible context tracing_record_cmdline() internally uses __this_cpu_read() and __this_cpu_write() on the per-CPU variable trace_cmdline_save, and trace_save_cmdline() explicitly asserts preemption is disabled via lockdep_assert_preemption_disabled(). These operations are only safe when preemption is off, as they were designed to be called from the scheduler context (probe_wakeup_sched_switch() / probe_wakeup()). __blk_add_trace() was calling tracing_record_cmdline(current) early in the blk_tracer path, before ring buffer reservation, from process context where preemption is fully enabled. This triggers the following using blktests/blktrace/002: blktrace/002 (blktrace ftrace corruption with sysfs trace) [failed] runtime 0.367s ... 0.437s something found in dmesg: [ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33 [ 81.239580] null_blk: disk nullb1 created [ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516 [ 81.362842] caller is tracing_record_cmdline+0x10/0x40 [ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full) [ 81.362877] Tainted: [N]=TEST [ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 81.362881] Call Trace: [ 81.362884] \u003cTASK\u003e [ 81.362886] dump_stack_lvl+0x8d/0xb0 ... (See '/mnt/sda/blktests/results/nodev/blktrace/002.dmesg' for the entire message) [ 81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33 [ 81.239580] null_blk: disk nullb1 created [ 81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516 [ 81.362842] caller is tracing_record_cmdline+0x10/0x40 [ 81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G N 7.0.0-rc1lblk+ #84 PREEMPT(full) [ 81.362877] Tainted: [N]=TEST [ 81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 81.362881] Call Trace: [ 81.362884] \u003cTASK\u003e [ 81.362886] dump_stack_lvl+0x8d/0xb0 [ 81.362895] check_preemption_disabled+0xce/0xe0 [ 81.362902] tracing_record_cmdline+0x10/0x40 [ 81.362923] __blk_add_trace+0x307/0x5d0 [ 81.362934] ? lock_acquire+0xe0/0x300 [ 81.362940] ? iov_iter_extract_pages+0x101/0xa30 [ 81.362959] blk_add_trace_bio+0x106/0x1e0 [ 81.362968] submit_bio_noacct_nocheck+0x24b/0x3a0 [ 81.362979] ? lockdep_init_map_type+0x58/0x260 [ 81.362988] submit_bio_wait+0x56/0x90 [ 81.363009] __blkdev_direct_IO_simple+0x16c/0x250 [ 81.363026] ? __pfx_submit_bio_wait_endio+0x10/0x10 [ 81.363038] ? rcu_read_lock_any_held+0x73/0xa0 [ 81.363051] blkdev_read_iter+0xc1/0x140 [ 81.363059] vfs_read+0x20b/0x330 [ 81.363083] ksys_read+0x67/0xe0 [ 81.363090] do_syscall_64+0xbf/0xf00 [ 81.363102] entry_SYSCALL_64_after_hwframe+0x76/0x7e [ 81.363106] RIP: 0033:0x7f281906029d [ 81.363111] Code: 31 c0 e9 c6 fe ff ff 50 48 8d 3d 66 63 0a 00 e8 59 ff 01 00 66 0f 1f 84 00 00 00 00 00 80 3d 41 33 0e 00 00 74 17 31 c0 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 5b c3 66 2e 0f 1f 84 00 00 00 00 00 48 83 ec [ 81.363113] RSP: 002b:00007ffca127dd48 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 81.363120] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f281906029d [ 81.363122] RDX: 0000000000001000 RSI: 0000559f8bfae000 RDI: 0000000000000000 [ 81.363123] RBP: 0000000000001000 R08: 0000002863a10a81 R09: 00007f281915f000 [ 81.363124] R10: 00007f2818f77b60 R11: 0000000000000246 R12: 0000559f8bfae000 [ 81.363126] R13: 0000000000000000 R14: 0000000000000000 R15: 000000000000000a [ 81.363142] \u003c/TASK\u003e The same BUG fires from blk_add_trace_plug(), blk_add_trace_unplug(), and blk_add_trace_rq() paths as well. The purpose of tracin ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23374", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DVtv7ccp2q3OpewgYQvjSQ==": { "id": "DVtv7ccp2q3OpewgYQvjSQ==", "updater": "debian/updater", "name": "CVE-2025-0840", "description": "A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-0840", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DWmwcDyd4pU5vUlN1XDyCg==": { "id": "DWmwcDyd4pU5vUlN1XDyCg==", "updater": "debian/updater", "name": "CVE-2026-68336", "description": "In the Linux kernel, the following vulnerability has been resolved: bonding: fix devconf_all NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the devconf_all is never initialized because inet6_init() exits before addrconf_init() is called which initializes it. bond_send_validate(), however, will still call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to NULL derefence of net-\u003eipv6.devconf_all in ip6_pol_route(). BUG: kernel NULL pointer dereference, address: 000000000000000c [...] Workqueue: bond0 bond_arp_monitor [bonding] RIP: 0010:ip6_pol_route+0x69/0x480 [...] Call Trace: \u003cTASK\u003e ? srso_return_thunk+0x5/0x5f ? __pfx_ip6_pol_route_output+0x10/0x10 fib6_rule_lookup+0xfe/0x260 ? wakeup_preempt+0x8a/0x90 ? srso_return_thunk+0x5/0x5f ? srso_return_thunk+0x5/0x5f ? sched_balance_rq+0x369/0x810 ip6_route_output_flags+0xd7/0x170 bond_ns_send_all+0xde/0x280 [bonding] bond_ab_arp_probe+0x296/0x320 [bonding] ? srso_return_thunk+0x5/0x5f bond_activebackup_arp_mon+0xb4/0x2c0 [bonding] process_one_work+0x196/0x370 worker_thread+0x1af/0x320 ? srso_return_thunk+0x5/0x5f ? __pfx_worker_thread+0x10/0x10 kthread+0xe3/0x120 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x199/0x260 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e Fix this by adding ipv6_mod_enabled() condition check in the caller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68336", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DgELrwVlzyF6LUyCItuo/A==": { "id": "DgELrwVlzyF6LUyCItuo/A==", "updater": "debian/updater", "name": "CVE-2024-35951", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr() Subject: [PATCH] drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr() If some the pages or sgt allocation failed, we shouldn't release the pages ref we got earlier, otherwise we will end up with unbalanced get/put_pages() calls. We should instead leave everything in place and let the BO release function deal with extra cleanup when the object is destroyed, or let the fault handler try again next time it's called.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35951", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DgsLnFbbR+zE3+SFeqm4/w==": { "id": "DgsLnFbbR+zE3+SFeqm4/w==", "updater": "debian/updater", "name": "CVE-2026-68112", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68112", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Diaroq/WqYpF8rJ936nxtw==": { "id": "Diaroq/WqYpF8rJ936nxtw==", "updater": "debian/updater", "name": "CVE-2026-53025", "description": "In the Linux kernel, the following vulnerability has been resolved: greybus: raw: fix use-after-free on cdev close This addresses a use-after-free bug when a raw bundle is disconnected but its chardev is still opened by an application. When the application releases the cdev, it causes the following panic when init on free is enabled (CONFIG_INIT_ON_FREE_DEFAULT_ON=y): refcount_t: underflow; use-after-free. WARNING: CPU: 0 PID: 139 at lib/refcount.c:28 refcount_warn_saturate+0xd0/0x130 ... Call Trace: \u003cTASK\u003e cdev_put+0x18/0x30 __fput+0x255/0x2a0 __x64_sys_close+0x3d/0x80 do_syscall_64+0xa4/0x290 entry_SYSCALL_64_after_hwframe+0x77/0x7f The cdev is contained in the \"gb_raw\" structure, which is freed in the disconnect operation. When the cdev is released at a later time, cdev_put gets an address that points to freed memory. To fix this use-after-free, convert the struct device from a pointer to being embedded, that makes the lifetime of the cdev and of this device the same. Then, use cdev_device_add, which guarantees that the device won't be released until all references to the cdev have been released. Finally, delegate the freeing of the structure to the device release function, instead of freeing immediately in the disconnect callback.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53025", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DjJF3Cvfh4VoqiOq+lbgBA==": { "id": "DjJF3Cvfh4VoqiOq+lbgBA==", "updater": "debian/updater", "name": "CVE-2025-13151", "description": "Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-13151", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libtasn1-6", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DnoLLxMGws+PXaby9k1hQw==": { "id": "DnoLLxMGws+PXaby9k1hQw==", "updater": "debian/updater", "name": "CVE-2026-1965", "description": "libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work. An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1... The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`. Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-1965", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DtV4sdV1hSPQ0AIl8cr61A==": { "id": "DtV4sdV1hSPQ0AIl8cr61A==", "updater": "debian/updater", "name": "CVE-2024-47691", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid use-after-free in f2fs_stop_gc_thread() syzbot reports a f2fs bug as below: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114 print_report+0xe8/0x550 mm/kasan/report.c:491 kasan_report+0x143/0x180 mm/kasan/report.c:601 kasan_check_range+0x282/0x290 mm/kasan/generic.c:189 instrument_atomic_read_write include/linux/instrumented.h:96 [inline] atomic_fetch_add_relaxed include/linux/atomic/atomic-instrumented.h:252 [inline] __refcount_add include/linux/refcount.h:184 [inline] __refcount_inc include/linux/refcount.h:241 [inline] refcount_inc include/linux/refcount.h:258 [inline] get_task_struct include/linux/sched/task.h:118 [inline] kthread_stop+0xca/0x630 kernel/kthread.c:704 f2fs_stop_gc_thread+0x65/0xb0 fs/f2fs/gc.c:210 f2fs_do_shutdown+0x192/0x540 fs/f2fs/file.c:2283 f2fs_ioc_shutdown fs/f2fs/file.c:2325 [inline] __f2fs_ioctl+0x443a/0xbe60 fs/f2fs/file.c:4325 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:907 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f The root cause is below race condition, it may cause use-after-free issue in sbi-\u003egc_th pointer. - remount - f2fs_remount - f2fs_stop_gc_thread - kfree(gc_th) \t\t\t\t- f2fs_ioc_shutdown \t\t\t\t - f2fs_do_shutdown \t\t\t\t - f2fs_stop_gc_thread \t\t\t\t - kthread_stop(gc_th-\u003ef2fs_gc_task) : sbi-\u003egc_thread = NULL; We will call f2fs_do_shutdown() in two paths: - for f2fs_ioc_shutdown() path, we should grab sb-\u003es_umount semaphore for fixing. - for f2fs_shutdown() path, it's safe since caller has already grabbed sb-\u003es_umount semaphore.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47691", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Dv8HkcDBMS+SJaMU3YocwA==": { "id": "Dv8HkcDBMS+SJaMU3YocwA==", "updater": "debian/updater", "name": "CVE-2024-57360", "description": "https://www.gnu.org/software/binutils/ nm \u003e=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57360", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Dvyktamg43GwH2r9Vyku/g==": { "id": "Dvyktamg43GwH2r9Vyku/g==", "updater": "debian/updater", "name": "CVE-2025-39886", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() Currently, calling bpf_map_kmalloc_node() from __bpf_async_init() can cause various locking issues; see the following stack trace (edited for style) as one example: ... [10.011566] do_raw_spin_lock.cold [10.011570] try_to_wake_up (5) double-acquiring the same [10.011575] kick_pool rq_lock, causing a hardlockup [10.011579] __queue_work [10.011582] queue_work_on [10.011585] kernfs_notify [10.011589] cgroup_file_notify [10.011593] try_charge_memcg (4) memcg accounting raises an [10.011597] obj_cgroup_charge_pages MEMCG_MAX event [10.011599] obj_cgroup_charge_account [10.011600] __memcg_slab_post_alloc_hook [10.011603] __kmalloc_node_noprof ... [10.011611] bpf_map_kmalloc_node [10.011612] __bpf_async_init [10.011615] bpf_timer_init (3) BPF calls bpf_timer_init() [10.011617] bpf_prog_xxxxxxxxxxxxxxxx_fcg_runnable [10.011619] bpf__sched_ext_ops_runnable [10.011620] enqueue_task_scx (2) BPF runs with rq_lock held [10.011622] enqueue_task [10.011626] ttwu_do_activate [10.011629] sched_ttwu_pending (1) grabs rq_lock ... The above was reproduced on bpf-next (b338cf849ec8) by modifying ./tools/sched_ext/scx_flatcg.bpf.c to call bpf_timer_init() during ops.runnable(), and hacking the memcg accounting code a bit to make a bpf_timer_init() call more likely to raise an MEMCG_MAX event. We have also run into other similar variants (both internally and on bpf-next), including double-acquiring cgroup_file_kn_lock, the same worker_pool::lock, etc. As suggested by Shakeel, fix this by using __GFP_HIGH instead of GFP_ATOMIC in __bpf_async_init(), so that e.g. if try_charge_memcg() raises an MEMCG_MAX event, we call __memcg_memory_event() with @allow_spinning=false and avoid calling cgroup_file_notify() there. Depends on mm patch \"memcg: skip cgroup_file_notify if spinning is not allowed\": https://lore.kernel.org/bpf/20250905201606.66198-1-shakeel.butt@linux.dev/ v0 approach s/bpf_map_kmalloc_node/bpf_mem_alloc/ https://lore.kernel.org/bpf/20250905061919.439648-1-yepeilin@google.com/ v1 approach: https://lore.kernel.org/bpf/20250905234547.862249-1-yepeilin@google.com/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39886", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "DyfgvZwD3+UhyLH1t8vttA==": { "id": "DyfgvZwD3+UhyLH1t8vttA==", "updater": "debian/updater", "name": "CVE-2020-14304", "description": "A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-14304", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E+efV15Gp/rLngRKACg3fg==": { "id": "E+efV15Gp/rLngRKACg3fg==", "updater": "debian/updater", "name": "CVE-2024-47752", "description": "In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix H264 stateless decoder smatch warning Fix a smatch static checker warning on vdec_h264_req_if.c. Which leads to a kernel crash when fb is NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47752", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E2SmzNbrYzbd3ehJM5ldYQ==": { "id": "E2SmzNbrYzbd3ehJM5ldYQ==", "updater": "debian/updater", "name": "CVE-2024-53134", "description": "In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: correct remove path The check condition should be 'i \u003c bc-\u003eonecell_data.num_domains', not 'bc-\u003eonecell_data.num_domains' which will make the look never finish and cause kernel panic. Also disable runtime to address \"imx93-blk-ctrl 4ac10000.system-controller: Unbalanced pm_runtime_enable!\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53134", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "E2erXXyfGoHicKp15iuNEQ==": { "id": "E2erXXyfGoHicKp15iuNEQ==", "updater": "debian/updater", "name": "CVE-2026-64025", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and defers to psock-\u003esaved_data_ready when a TLS RX context is present, avoiding a conflict with the TLS strparser's ownership of the receive queue (commit e91de6afa81c, \"bpf: Fix running sk_skb program types with ktls\"). sk_psock_verdict_data_ready() has no equivalent guard. When a socket is inserted into a sockmap (BPF_SK_SKB_VERDICT) before TLS RX is configured, tls_sw_strparser_arm() saves sk_psock_verdict_data_ready as rx_ctx-\u003esaved_data_ready. On data arrival: tls_data_ready -\u003e tls_strp_data_ready -\u003e tls_rx_msg_ready -\u003e saved_data_ready() = sk_psock_verdict_data_ready() -\u003e tcp_read_skb() drains sk_receive_queue via __skb_unlink() without calling tcp_eat_skb(), so copied_seq is not advanced. tls_strp_msg_load() then finds tcp_inq() \u003e= full_len (stale), calls tcp_recv_skb() on the now-empty queue, hits WARN_ON_ONCE(!first), and returns with rx_ctx-\u003estrp.anchor.frag_list pointing at a psock-owned (potentially freed) skb. tls_decrypt_sg() subsequently walks that frag_list: use-after-free. Apply the same fix as sk_psock_strp_data_ready(): if a TLS RX context is present, call psock-\u003esaved_data_ready (sock_def_readable) to wake recv() waiters and return immediately, leaving the receive queue untouched. TLS retains sole ownership of the queue and decrypts the record normally through tls_sw_recvmsg().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64025", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EAlLhi+f9W1iGlSW/XZEEQ==": { "id": "EAlLhi+f9W1iGlSW/XZEEQ==", "updater": "debian/updater", "name": "CVE-2026-58011", "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58011", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ECGZX1xSn5skLpWJCsWTpA==": { "id": "ECGZX1xSn5skLpWJCsWTpA==", "updater": "debian/updater", "name": "CVE-2025-21714", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr. Without this change, we could try to invalidate this mr twice, which in turn could result in queuing a MR work destroy twice, and eventually the second work could execute after the MR was freed due to the first work, causing a user after free and trace below. refcount_t: underflow; use-after-free. WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130 Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay zram zsmalloc fuse [last unloaded: ib_uverbs] CPU: 2 PID: 12178 Comm: kworker/u20:5 Not tainted 6.5.0-rc1_net_next_mlx5_58c644e #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Workqueue: events_unbound free_implicit_child_mr_work [mlx5_ib] RIP: 0010:refcount_warn_saturate+0x12b/0x130 Code: 48 c7 c7 38 95 2a 82 c6 05 bc c6 fe 00 01 e8 0c 66 aa ff 0f 0b 5b c3 48 c7 c7 e0 94 2a 82 c6 05 a7 c6 fe 00 01 e8 f5 65 aa ff \u003c0f\u003e 0b 5b c3 90 8b 07 3d 00 00 00 c0 74 12 83 f8 01 74 13 8d 50 ff RSP: 0018:ffff8881008e3e40 EFLAGS: 00010286 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000027 RDX: ffff88852c91b5c8 RSI: 0000000000000001 RDI: ffff88852c91b5c0 RBP: ffff8881dacd4e00 R08: 00000000ffffffff R09: 0000000000000019 R10: 000000000000072e R11: 0000000063666572 R12: ffff88812bfd9e00 R13: ffff8881c792d200 R14: ffff88810011c005 R15: ffff8881002099c0 FS: 0000000000000000(0000) GS:ffff88852c900000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f5694b5e000 CR3: 00000001153f6003 CR4: 0000000000370ea0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: \u003cTASK\u003e ? refcount_warn_saturate+0x12b/0x130 free_implicit_child_mr_work+0x180/0x1b0 [mlx5_ib] process_one_work+0x1cc/0x3c0 worker_thread+0x218/0x3c0 kthread+0xc6/0xf0 ret_from_fork+0x1f/0x30 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21714", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ECNIyveMfVfcwQzGnTen7g==": { "id": "ECNIyveMfVfcwQzGnTen7g==", "updater": "debian/updater", "name": "CVE-2026-53284", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after successful writes [WARNING] With extra warning on dirty extent buffers at umount (aka, the next patch in the series), test case generic/388 can trigger the following warning about dirty extent buffers at unmount time: BTRFS critical (device dm-2 state E): emergency shutdown BTRFS error (device dm-2 state E): error while writing out transaction: -30 BTRFS warning (device dm-2 state E): Skipping commit of aborted transaction. BTRFS error (device dm-2 state EA): Transaction 9 aborted (error -30) BTRFS: error (device dm-2 state EA) in cleanup_transaction:2068: errno=-30 Readonly filesystem BTRFS info (device dm-2 state EA): forced readonly BTRFS info (device dm-2 state EA): last unmount of filesystem 4fbf2e15-f941-49a0-bc7c-716315d2777c ------------[ cut here ]------------ WARNING: disk-io.c:3311 at invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs], CPU#8: umount/914368 CPU: 8 UID: 0 PID: 914368 Comm: umount Tainted: G OE 7.1.0-rc1-custom+ #372 PREEMPT(full) 2de38db8d1deae71fde295430a0ff3ab98ccf596 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs] Call Trace: \u003cTASK\u003e close_ctree+0x52e/0x574 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd] generic_shutdown_super+0x89/0x1a0 kill_anon_super+0x16/0x40 btrfs_kill_super+0x16/0x20 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd] deactivate_locked_super+0x2d/0xb0 cleanup_mnt+0xdc/0x140 task_work_run+0x5a/0xa0 exit_to_user_mode_loop+0x123/0x4b0 do_syscall_64+0x243/0x7c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 \u003c/TASK\u003e ---[ end trace 0000000000000000 ]--- BTRFS warning (device dm-2 state EA): unable to release extent buffer 30539776 owner 9 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30621696 owner 257 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30638080 owner 258 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30654464 owner 7 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30703616 owner 2 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30720000 owner 10 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30736384 owner 4 gen 9 refs 2 flags 0x7 BTRFS warning (device dm-2 state EA): unable to release extent buffer 30752768 owner 11 gen 9 refs 2 flags 0x7 I'm using a stripped down version, which seems to trigger the warning more reliably: _fsstress_pid=\"\" workload() { \tdmesg -C \tmkfs.btrfs -f -K $dev \u003e /dev/null \techo 1 \u003e /sys/kernel/debug/clear_warn_once \tmount $dev $mnt \t$fsstress -w -n 1024 -p 4 -d $mnt \u0026 \t_fsstress_pid=$! \tsleep 0 \t$godown $mnt \tpkill --echo -PIPE fsstress \u003e /dev/null \twait $_fsstress_pid \tunset _fsstress_pid \tumount $mnt \tif dmesg | grep -q \"WARNING\"; then \t\tfail \tfi } for (( i = 0; i \u003c $runtime; i++ )); do \techo \"=== $i/$runtime ===\" \tworkload done [CAUSE] Inside btrfs_write_and_wait_transaction(), we first try to write all dirty ebs, then wait for them to finish. After that we call btrfs_extent_io_tree_release() to free all extent states from dirty_pages io tree. However if we hit an error from btrfs_write_marked_extent(), then we still call btrfs_extent_io_tree_release() to clear that dirty_pages io tree, which may contain dirty records that we haven't yet submitted. Furthermore, the later transaction cleanup path will utilize that dirty_pages io tree to properly cleanup those dirty ebs, but since it's already empty, no dirty ebs are properly cleaned up, thus will later trigger the warnings inside invalidate_btree_folios(). ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53284", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EEy4+NI4yL8RKqCOZipymw==": { "id": "EEy4+NI4yL8RKqCOZipymw==", "updater": "debian/updater", "name": "CVE-2026-68411", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: clamp virtio RX length before skb_put hwsim_virtio_rx_work() passes the virtqueue used-ring length reported by the device straight to skb_put() on a fixed-size receive skb. A backend reporting a length larger than the skb tailroom drives skb_put() past the buffer end and hits skb_over_panic() -- a host-triggerable guest panic (denial of service). Clamp the length to the skb's available room before skb_put(). A conforming device never reports more than the posted buffer size, so valid frames are unaffected; a truncated over-report then fails the length/header checks in hwsim_virtio_handle_cmd() and is dropped, so truncating rather than dropping here cannot be turned into a parsing problem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68411", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EGnO71PPbM9rWb9+S75duw==": { "id": "EGnO71PPbM9rWb9+S75duw==", "updater": "debian/updater", "name": "CVE-2026-68360", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after \"io start\" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68360", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EJ33qgRazVLqeAKxd/8pXw==": { "id": "EJ33qgRazVLqeAKxd/8pXw==", "updater": "debian/updater", "name": "CVE-2023-53429", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: don't check PageError in __extent_writepage __extent_writepage currenly sets PageError whenever any error happens, and the also checks for PageError to decide if to call error handling. This leads to very unclear responsibility for cleaning up on errors. In the VM and generic writeback helpers the basic idea is that once I/O is fired off all error handling responsibility is delegated to the end I/O handler. But if that end I/O handler sets the PageError bit, and the submitter checks it, the bit could in some cases leak into the submission context for fast enough I/O. Fix this by simply not checking PageError and just using the local ret variable to check for submission errors. This also fundamentally solves the long problem documented in a comment in __extent_writepage by never leaking the error bit into the submission context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53429", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EJB8Y62Fej4Lt+APLoeA0Q==": { "id": "EJB8Y62Fej4Lt+APLoeA0Q==", "updater": "debian/updater", "name": "CVE-2024-56583", "description": "In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix warning in migrate_enable for boosted tasks When running the following command: while true; do stress-ng --cyclic 30 --timeout 30s --minimize --quiet done a warning is eventually triggered: WARNING: CPU: 43 PID: 2848 at kernel/sched/deadline.c:794 setup_new_dl_entity+0x13e/0x180 ... Call Trace: \u003cTASK\u003e ? show_trace_log_lvl+0x1c4/0x2df ? enqueue_dl_entity+0x631/0x6e0 ? setup_new_dl_entity+0x13e/0x180 ? __warn+0x7e/0xd0 ? report_bug+0x11a/0x1a0 ? handle_bug+0x3c/0x70 ? exc_invalid_op+0x14/0x70 ? asm_exc_invalid_op+0x16/0x20 enqueue_dl_entity+0x631/0x6e0 enqueue_task_dl+0x7d/0x120 __do_set_cpus_allowed+0xe3/0x280 __set_cpus_allowed_ptr_locked+0x140/0x1d0 __set_cpus_allowed_ptr+0x54/0xa0 migrate_enable+0x7e/0x150 rt_spin_unlock+0x1c/0x90 group_send_sig_info+0xf7/0x1a0 ? kill_pid_info+0x1f/0x1d0 kill_pid_info+0x78/0x1d0 kill_proc_info+0x5b/0x110 __x64_sys_kill+0x93/0xc0 do_syscall_64+0x5c/0xf0 entry_SYSCALL_64_after_hwframe+0x6e/0x76 RIP: 0033:0x7f0dab31f92b This warning occurs because set_cpus_allowed dequeues and enqueues tasks with the ENQUEUE_RESTORE flag set. If the task is boosted, the warning is triggered. A boosted task already had its parameters set by rt_mutex_setprio, and a new call to setup_new_dl_entity is unnecessary, hence the WARN_ON call. Check if we are requeueing a boosted task and avoid calling setup_new_dl_entity if that's the case.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56583", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EKglEnYYYfnDpkNpBIJPLA==": { "id": "EKglEnYYYfnDpkNpBIJPLA==", "updater": "debian/updater", "name": "CVE-2026-64320", "description": "In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then added to a small kzalloc'd buffer that holds the discovery log page and the result is passed straight to nvmet_copy_to_sgl(), which memcpy()s data_len bytes out to the host with no source-side bound check: u64 offset = nvmet_get_log_page_offset(req-\u003ecmd); /* 64-bit host */ size_t data_len = nvmet_get_log_page_len(req-\u003ecmd); /* 32-bit host */ ... if (offset \u0026 0x3) { ... } /* only check */ ... alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req); buffer = kzalloc(alloc_len, GFP_KERNEL); ... status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len); The Discovery controller is unauthenticated -- nvmet_host_allowed() returns true unconditionally for the discovery subsystem -- so the call is reachable pre-authentication by any TCP/RDMA/FC peer that can reach the nvmet target. With a discovery log page of ~1 KiB, an attacker requesting up to 4 KiB starting at offset == alloc_len reads the next slab page out and gets its content returned over the fabric (an empirical run on a default nvmet-tcp loopback target leaked 81 canonical kernel pointers in one Get Log Page response). Pointing the offset at unmapped kernel memory faults the in-kernel memcpy and crashes (or panics, on panic_on_oops=1) the target host instead. The attacker-controlled source-side offset pattern \"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)\" is unique to nvmet_execute_disc_get_log_page in the entire nvmet codebase: every other Get Log Page handler in admin-cmd.c either ignores lpo (and silently starts every response at offset 0) or tracks a local destination offset with a fixed source pointer. Validate the host-supplied offset against the log page size, cap the copy length to what is actually available, and zero-fill any remainder of the host transfer buffer. The zero-fill matches the existing short-response pattern in nvmet_execute_get_log_changed_ns() (admin-cmd.c) and prevents leaking transport SGL contents when the host asks for more bytes than the log page contains.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64320", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ENsHyD6BH0uRYy4OOg9ikA==": { "id": "ENsHyD6BH0uRYy4OOg9ikA==", "updater": "debian/updater", "name": "CVE-2024-49919", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for head_pipe in dcn201_acquire_free_pipe_for_layer This commit addresses a potential null pointer dereference issue in the `dcn201_acquire_free_pipe_for_layer` function. The issue could occur when `head_pipe` is null. The fix adds a check to ensure `head_pipe` is not null before asserting it. If `head_pipe` is null, the function returns NULL to prevent a potential null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn201/dcn201_resource.c:1016 dcn201_acquire_free_pipe_for_layer() error: we previously assumed 'head_pipe' could be null (see line 1010)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49919", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EWhxjOpXqq00D0eBpMcpRQ==": { "id": "EWhxjOpXqq00D0eBpMcpRQ==", "updater": "debian/updater", "name": "CVE-2026-64391", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64391", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EYn2BjEWyvSrwQm3hD7uvg==": { "id": "EYn2BjEWyvSrwQm3hD7uvg==", "updater": "debian/updater", "name": "CVE-2020-0347", "description": "In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136658008", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-0347", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EnkqWTVrWXoijqIWOFr68w==": { "id": "EnkqWTVrWXoijqIWOFr68w==", "updater": "debian/updater", "name": "CVE-2026-47247", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-47247", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EqGiuiFVwruyN8bfEkimAA==": { "id": "EqGiuiFVwruyN8bfEkimAA==", "updater": "debian/updater", "name": "CVE-2007-2243", "description": "OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-2243", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Eqs0OpFbkAnFRvfxseQQ5g==": { "id": "Eqs0OpFbkAnFRvfxseQQ5g==", "updater": "debian/updater", "name": "CVE-2026-6469", "description": "Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6469", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Er+X62T35/FYbVBB3GMZvA==": { "id": "Er+X62T35/FYbVBB3GMZvA==", "updater": "debian/updater", "name": "CVE-2025-21967", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_free_work_struct -\u003einterim_entry of ksmbd_work could be deleted after oplock is freed. We don't need to manage it with linked list. The interim request could be immediately sent whenever a oplock break wait is needed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21967", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Es8gDnTR4NlprvEhI8DsyQ==": { "id": "Es8gDnTR4NlprvEhI8DsyQ==", "updater": "debian/updater", "name": "CVE-2026-40250", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan-\u003ewidth * chan-\u003ebytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-40250", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "EzI+oZVjbP41VkNLC9FD9g==": { "id": "EzI+oZVjbP41VkNLC9FD9g==", "updater": "debian/updater", "name": "CVE-2026-68302", "description": "In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again. pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head. The affected sites are: amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads iph-\u003esaddr. amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/ ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address. amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(), then writes the L2 header. amt_membership_query_handler() caches the AMT header, the outer and inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several pulls, then reads and writes them. amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache ip_hdr()/ipv6_hdr() and the current group record and read the record count from the report header inside the record loop, across the *_mc_may_pull() calls. amt_update_handler() caches ip_hdr() and the AMT membership-update header before pskb_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp() and the report handler, then reads iph-\u003edaddr and amtmu-\u003enonce / amtmu-\u003eresponse_mac. Fix each site by either snapshotting the scalar that is used after the pull before the first pull runs, or re-deriving the header pointer from the skb after the last pull that can move the head. Values that are stable across the pull (source and group address, the response MAC and nonce, the record count, the outer source MAC) are snapshotted; pointers that are written through or read repeatedly are re-derived.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68302", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F/fb6BDcJgFpKT7ts1WqjQ==": { "id": "F/fb6BDcJgFpKT7ts1WqjQ==", "updater": "debian/updater", "name": "CVE-2026-64160", "description": "In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in -\u003eremote_i_size and -\u003ezero_point Fix potential tearing in using -\u003eremote_i_size and -\u003ezero_point by copying i_size_read() and i_size_write() and using the same seqcount as for i_size. We need to make sure that netfslib and the filesystems that use it always hold i_lock whilst updating any of the sizes to prevent i_size_seqcount from getting corrupted.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64160", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F0G9v3Y1nWxDqdEHKjHhqA==": { "id": "F0G9v3Y1nWxDqdEHKjHhqA==", "updater": "debian/updater", "name": "CVE-2023-53447", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: don't reset unchangable mount option in f2fs_remount() syzbot reports a bug as below: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] PREEMPT SMP KASAN RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942 Call Trace: lock_acquire+0x1e3/0x520 kernel/locking/lockdep.c:5691 __raw_write_lock include/linux/rwlock_api_smp.h:209 [inline] _raw_write_lock+0x2e/0x40 kernel/locking/spinlock.c:300 __drop_extent_tree+0x3ac/0x660 fs/f2fs/extent_cache.c:1100 f2fs_drop_extent_tree+0x17/0x30 fs/f2fs/extent_cache.c:1116 f2fs_insert_range+0x2d5/0x3c0 fs/f2fs/file.c:1664 f2fs_fallocate+0x4e4/0x6d0 fs/f2fs/file.c:1838 vfs_fallocate+0x54b/0x6b0 fs/open.c:324 ksys_fallocate fs/open.c:347 [inline] __do_sys_fallocate fs/open.c:355 [inline] __se_sys_fallocate fs/open.c:353 [inline] __x64_sys_fallocate+0xbd/0x100 fs/open.c:353 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The root cause is race condition as below: - since it tries to remount rw filesystem, so that do_remount won't call sb_prepare_remount_readonly to block fallocate, there may be race condition in between remount and fallocate. - in f2fs_remount(), default_options() will reset mount option to default one, and then update it based on result of parse_options(), so there is a hole which race condition can happen. Thread A\t\t\tThread B - f2fs_fill_super - parse_options - clear_opt(READ_EXTENT_CACHE) - f2fs_remount - default_options - set_opt(READ_EXTENT_CACHE) \t\t\t\t- f2fs_fallocate \t\t\t\t - f2fs_insert_range \t\t\t\t - f2fs_drop_extent_tree \t\t\t\t - __drop_extent_tree \t\t\t\t - __may_extent_tree \t\t\t\t - test_opt(READ_EXTENT_CACHE) return true \t\t\t\t - write_lock(\u0026et-\u003elock) access NULL pointer - parse_options - clear_opt(READ_EXTENT_CACHE)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53447", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F1OvjISK96LVSPFgK1ON4Q==": { "id": "F1OvjISK96LVSPFgK1ON4Q==", "updater": "debian/updater", "name": "CVE-2025-1365", "description": "A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1365", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F4LulQAYnY9rA1Yhcz1gdg==": { "id": "F4LulQAYnY9rA1Yhcz1gdg==", "updater": "debian/updater", "name": "CVE-2026-23118", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix data-race warning and potential load/store tearing Fix the following: BUG: KCSAN: data-race in rxrpc_peer_keepalive_worker / rxrpc_send_data_packet which is reporting an issue with the reads and writes to -\u003elast_tx_at in: conn-\u003epeer-\u003elast_tx_at = ktime_get_seconds(); and: keepalive_at = peer-\u003elast_tx_at + RXRPC_KEEPALIVE_TIME; The lockless accesses to these to values aren't actually a problem as the read only needs an approximate time of last transmission for the purposes of deciding whether or not the transmission of a keepalive packet is warranted yet. Also, as -\u003elast_tx_at is a 64-bit value, tearing can occur on a 32-bit arch. Fix both of these by switching to an unsigned int for -\u003elast_tx_at and only storing the LSW of the time64_t. It can then be reconstructed at need provided no more than 68 years has elapsed since the last transmission.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "F8iw2hivo7VOfY6T6lVssg==": { "id": "F8iw2hivo7VOfY6T6lVssg==", "updater": "debian/updater", "name": "CVE-2026-31729", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_notify_common() The connector number extracted from CCI via UCSI_CCI_CONNECTOR() is a 7-bit field (0-127) that is used to index into the connector array in ucsi_connector_change(). However, the array is only allocated for the number of connectors reported by the device (typically 2-4 entries). A malicious or malfunctioning device could report an out-of-range connector number in the CCI, causing an out-of-bounds array access in ucsi_connector_change(). Add a bounds check in ucsi_notify_common(), the central point where CCI is parsed after arriving from hardware, so that bogus connector numbers are rejected before they propagate further.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31729", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FCB29/uJidMwx2jZdSpxiA==": { "id": "FCB29/uJidMwx2jZdSpxiA==", "updater": "debian/updater", "name": "CVE-2026-63974", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63974", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FClPDjyyXuDXkVInXpQ8TQ==": { "id": "FClPDjyyXuDXkVInXpQ8TQ==", "updater": "debian/updater", "name": "CVE-2026-23394", "description": "In the Linux kernel, the following vulnerability has been resolved: af_unix: Give up GC if MSG_PEEK intervened. Igor Ushakov reported that GC purged the receive queue of an alive socket due to a race with MSG_PEEK with a nice repro. This is the exact same issue previously fixed by commit cbcf01128d0a (\"af_unix: fix garbage collect vs MSG_PEEK\"). After GC was replaced with the current algorithm, the cited commit removed the locking dance in unix_peek_fds() and reintroduced the same issue. The problem is that MSG_PEEK bumps a file refcount without interacting with GC. Consider an SCC containing sk-A and sk-B, where sk-A is close()d but can be recv()ed via sk-B. The bad thing happens if sk-A is recv()ed with MSG_PEEK from sk-B and sk-B is close()d while GC is checking unix_vertex_dead() for sk-A and sk-B. GC thread User thread --------- ----------- unix_vertex_dead(sk-A) -\u003e true \u003c------. \\ `------ recv(sk-B, MSG_PEEK) invalidate !! -\u003e sk-A's file refcount : 1 -\u003e 2 close(sk-B) -\u003e sk-B's file refcount : 2 -\u003e 1 unix_vertex_dead(sk-B) -\u003e true Initially, sk-A's file refcount is 1 by the inflight fd in sk-B recvq. GC thinks sk-A is dead because the file refcount is the same as the number of its inflight fds. However, sk-A's file refcount is bumped silently by MSG_PEEK, which invalidates the previous evaluation. At this moment, sk-B's file refcount is 2; one by the open fd, and one by the inflight fd in sk-A. The subsequent close() releases one refcount by the former. Finally, GC incorrectly concludes that both sk-A and sk-B are dead. One option is to restore the locking dance in unix_peek_fds(), but we can resolve this more elegantly thanks to the new algorithm. The point is that the issue does not occur without the subsequent close() and we actually do not need to synchronise MSG_PEEK with the dead SCC detection. When the issue occurs, close() and GC touch the same file refcount. If GC sees the refcount being decremented by close(), it can just give up garbage-collecting the SCC. Therefore, we only need to signal the race during MSG_PEEK with a proper memory barrier to make it visible to the GC. Let's use seqcount_t to notify GC when MSG_PEEK occurs and let it defer the SCC to the next run. This way no locking is needed on the MSG_PEEK side, and we can avoid imposing a penalty on every MSG_PEEK unnecessarily. Note that we can retry within unix_scc_dead() if MSG_PEEK is detected, but we do not do so to avoid hung task splat from abusive MSG_PEEK calls.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23394", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FEuiyn3Aju19ZoBdSagxJg==": { "id": "FEuiyn3Aju19ZoBdSagxJg==", "updater": "debian/updater", "name": "CVE-2026-63816", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE)\t\t- shrink - f2fs_gc - gc_data_segment - ra_data_block(cow_inode) - mapping = F2FS_I(inode)-\u003eatomic_inode-\u003ei_mapping : f2fs_is_cow_file(cow_inode) is true \t\t\t\t\t\t - f2fs_evict_inode(atomic_inode) \t\t\t\t\t\t - clear_inode_flag(fi-\u003ecow_inode, FI_COW_FILE) \t\t\t\t\t\t - F2FS_I(fi-\u003ecow_inode)-\u003eatomic_inode = NULL \t\t\t\t\t\t ... \t\t\t\t\t\t - truncate_inode_pages_final(atomic_inode) - f2fs_grab_cache_folio(mapping) : create folio in atomic_inode-\u003emapping \t\t\t\t\t\t - clear_inode(atomic_inode) \t\t\t\t\t\t - BUG_ON(atomic_inode-\u003ei_data.nrpages) We need to add a reference on fi-\u003eatomic_inode before using its mapping field during garbage collection, otherwise, it will cause UAF issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63816", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FHdwzMKhciLU2Fxy3C/l9A==": { "id": "FHdwzMKhciLU2Fxy3C/l9A==", "updater": "debian/updater", "name": "CVE-2026-31692", "description": "In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged user with a user namespace to create interfaces in arbitrary network namespaces, including init_net. Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer namespace before allowing device creation to proceed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31692", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FJpIbicmNxXfM2KinGJfnw==": { "id": "FJpIbicmNxXfM2KinGJfnw==", "updater": "debian/updater", "name": "CVE-2026-45993", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add spectre boundry for syscall dispatch table The LoongArch syscall number is directly controlled by userspace, but does not have a array_index_nospec() boundry to prevent access past the syscall function pointer tables.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45993", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FOCiciYW31UdVFnx5ltZBg==": { "id": "FOCiciYW31UdVFnx5ltZBg==", "updater": "debian/updater", "name": "CVE-2026-1502", "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-1502", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FQizKMX/v1MT9QGLib3ifw==": { "id": "FQizKMX/v1MT9QGLib3ifw==", "updater": "debian/updater", "name": "CVE-2016-9113", "description": "There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image-\u003ecomps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9113", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FRliugf8XYS2sR8UKkFcdA==": { "id": "FRliugf8XYS2sR8UKkFcdA==", "updater": "debian/updater", "name": "CVE-2025-23130", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic once fallocation fails for pinfile syzbot reports a f2fs bug as below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/segment.c:2746! CPU: 0 UID: 0 PID: 5323 Comm: syz.0.0 Not tainted 6.13.0-rc2-syzkaller-00018-g7cb1b4663150 #0 RIP: 0010:get_new_segment fs/f2fs/segment.c:2746 [inline] RIP: 0010:new_curseg+0x1f52/0x1f70 fs/f2fs/segment.c:2876 Call Trace: \u003cTASK\u003e __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3210 f2fs_allocate_new_section fs/f2fs/segment.c:3224 [inline] f2fs_allocate_pinning_section+0xfa/0x4e0 fs/f2fs/segment.c:3238 f2fs_expand_inode_data+0x696/0xca0 fs/f2fs/file.c:1830 f2fs_fallocate+0x537/0xa10 fs/f2fs/file.c:1940 vfs_fallocate+0x569/0x6e0 fs/open.c:327 do_vfs_ioctl+0x258c/0x2e40 fs/ioctl.c:885 __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x80/0x170 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Concurrent pinfile allocation may run out of free section, result in panic in get_new_segment(), let's expand pin_sem lock coverage to include f2fs_gc(), so that we can make sure to reclaim enough free space for following allocation. In addition, do below changes to enhance error path handling: - call f2fs_bug_on() only in non-pinfile allocation path in get_new_segment(). - call reset_curseg_fields() to reset all fields of curseg in new_curseg()", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-23130", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FSIPRFtfRo70nIMzV4j75Q==": { "id": "FSIPRFtfRo70nIMzV4j75Q==", "updater": "debian/updater", "name": "CVE-2017-13693", "description": "The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-13693", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FVeDQej7MCAjLzDoM9qgXg==": { "id": "FVeDQej7MCAjLzDoM9qgXg==", "updater": "debian/updater", "name": "CVE-2026-48959", "description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip-\u003enew($zip, Name =\u003e $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-48959", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FYe7Wa0fVzI7RmAJoXf+VQ==": { "id": "FYe7Wa0fVzI7RmAJoXf+VQ==", "updater": "debian/updater", "name": "CVE-2024-57872", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove() This will ensure that the scsi host is cleaned up properly using scsi_host_dev_release(). Otherwise, it may lead to memory leaks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57872", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FaQ53XEw5WDkvjBzOQpAIA==": { "id": "FaQ53XEw5WDkvjBzOQpAIA==", "updater": "debian/updater", "name": "CVE-2026-64573", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV parser In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is \"while (idx \u003c length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a size_t (12), so \"length\" is converted to size_t and any firmware-supplied \"length\" \u003c 12 makes the subtraction wrap to a huge value. The loop body then reads a 12-byte struct tlv_type_nvm past the end of the short vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it). Rewrite the bound as \"idx + sizeof(struct tlv_type_nvm) \u003c= length\"; both operands are non-negative, so it no longer underflows and a \"length\" too small for one record correctly skips the loop. BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421) Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52 Workqueue: hci0 hci_power_on Call Trace: ... kasan_report (mm/kasan/report.c:595) qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617) qca_uart_setup (drivers/bluetooth/btqca.c:948) qca_setup (drivers/bluetooth/hci_qca.c:2029) hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438) hci_dev_open_sync (net/bluetooth/hci_sync.c:5227) hci_power_on (net/bluetooth/hci_core.c:920) process_one_work (kernel/workqueue.c:3322) worker_thread (kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64573", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FeWrBJujMl45wBsMuJwWow==": { "id": "FeWrBJujMl45wBsMuJwWow==", "updater": "debian/updater", "name": "CVE-2015-3276", "description": "The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FepmO5xv4FfIjhOQ4Ibfgg==": { "id": "FepmO5xv4FfIjhOQ4Ibfgg==", "updater": "debian/updater", "name": "CVE-2025-71188", "description": "In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71188", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FgYhTgnbuVdz9vvZG/SOpA==": { "id": "FgYhTgnbuVdz9vvZG/SOpA==", "updater": "debian/updater", "name": "CVE-2025-40160", "description": "In the Linux kernel, the following vulnerability has been resolved: xen/events: Return -EEXIST for bound VIRQs Change find_virq() to return -EEXIST when a VIRQ is bound to a different CPU than the one passed in. With that, remove the BUG_ON() from bind_virq_to_irq() to propogate the error upwards. Some VIRQs are per-cpu, but others are per-domain or global. Those must be bound to CPU0 and can then migrate elsewhere. The lookup for per-domain and global will probably fail when migrated off CPU 0, especially when the current CPU is tracked. This now returns -EEXIST instead of BUG_ON(). A second call to bind a per-domain or global VIRQ is not expected, but make it non-fatal to avoid trying to look up the irq, since we don't know which per_cpu(virq_to_irq) it will be in.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40160", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FhmnYUCZZmwMA62xsJ7fxA==": { "id": "FhmnYUCZZmwMA62xsJ7fxA==", "updater": "debian/updater", "name": "CVE-2026-64241", "description": "In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks Address several teardown issues and resource leaks in the driver's remove path and error handling: 1. Debounce clock reference leak: The debounce clock (bank-\u003edb_clk) is obtained using of_clk_get() which increments the clock's reference count, but clk_put() is never called. Register a devm action to cleanly release it on unbind. Note that of_clk_get(..., 1) remains necessary over devm_clk_get() because the DT binding does not define clock-names, precluding name-based lookup. 2. Unregistered chained IRQ handler: The chained IRQ handler is not disconnected in remove(). If a stray interrupt fires after the driver is removed, the kernel attempts to execute a stale handler, leading to a panic. Fix this by clearing the handler in remove(). 3. IRQ domain leak: The linear IRQ domain and its generic chips are allocated manually during probe but never removed. Remove the IRQ domain during driver teardown to free the associated generic chips and mappings. [Bartosz: don't emit an error message on devres allocation failure]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FkO1xyFl3QSN8mmAxDhcqA==": { "id": "FkO1xyFl3QSN8mmAxDhcqA==", "updater": "debian/updater", "name": "CVE-2023-52355", "description": "An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52355", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FlEYOi02huntZhTu3xrArQ==": { "id": "FlEYOi02huntZhTu3xrArQ==", "updater": "debian/updater", "name": "CVE-2024-27057", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Workaround for crashed firmware on system suspend When the system is suspended while audio is active, the sof_ipc4_pcm_hw_free() is invoked to reset the pipelines since during suspend the DSP is turned off, streams will be re-started after resume. If the firmware crashes during while audio is running (or when we reset the stream before suspend) then the sof_ipc4_set_multi_pipeline_state() will fail with IPC error and the state change is interrupted. This will cause misalignment between the kernel and firmware state on next DSP boot resulting errors returned by firmware for IPC messages, eventually failing the audio resume. On stream close the errors are ignored so the kernel state will be corrected on the next DSP boot, so the second boot after the DSP panic. If sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() then state parameter is SOF_IPC4_PIPE_RESET and only in this case. Treat a forced pipeline reset similarly to how we treat a pcm_free by ignoring error on state sending to allow the kernel's state to be consistent with the state the firmware will have after the next boot.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27057", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fn+CsGgMYWH5eh2+nmnd4g==": { "id": "Fn+CsGgMYWH5eh2+nmnd4g==", "updater": "debian/updater", "name": "CVE-2026-53083", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix RCU stall in bpf_fd_array_map_clear() Add a missing cond_resched() in bpf_fd_array_map_clear() loop. For PROG_ARRAY maps with many entries this loop calls prog_array_map_poke_run() per entry which can be expensive, and without yielding this can cause RCU stalls under load: rcu: Stack dump where RCU GP kthread last ran: CPU: 0 UID: 0 PID: 30932 Comm: kworker/0:2 Not tainted 6.14.0-13195-g967e8def1100 #2 PREEMPT(undef) Workqueue: events prog_array_map_clear_deferred RIP: 0010:write_comp_data+0x38/0x90 kernel/kcov.c:246 Call Trace: \u003cTASK\u003e prog_array_map_poke_run+0x77/0x380 kernel/bpf/arraymap.c:1096 __fd_array_map_delete_elem+0x197/0x310 kernel/bpf/arraymap.c:925 bpf_fd_array_map_clear kernel/bpf/arraymap.c:1000 [inline] prog_array_map_clear_deferred+0x119/0x1b0 kernel/bpf/arraymap.c:1141 process_one_work+0x898/0x19d0 kernel/workqueue.c:3238 process_scheduled_works kernel/workqueue.c:3319 [inline] worker_thread+0x770/0x10b0 kernel/workqueue.c:3400 kthread+0x465/0x880 kernel/kthread.c:464 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:153 ret_from_fork_asm+0x19/0x30 arch/x86/entry/entry_64.S:245 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53083", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FqN9MEddiJrhptEcz05UTg==": { "id": "FqN9MEddiJrhptEcz05UTg==", "updater": "debian/updater", "name": "CVE-2025-69648", "description": "GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69648", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FthYp8iOz/26jfLVwXB8zw==": { "id": "FthYp8iOz/26jfLVwXB8zw==", "updater": "debian/updater", "name": "CVE-2025-38080", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Increase block_sequence array size [Why] It's possible to generate more than 50 steps in hwss_build_fast_sequence, for example with a 6-pipe asic where all pipes are in one MPC chain. This overflows the block_sequence buffer and corrupts block_sequence_steps, causing a crash. [How] Expand block_sequence to 100 items. A naive upper bound on the possible number of steps for a 6-pipe asic, ignoring the potential for steps to be mutually exclusive, is 91 with current code, therefore 100 is sufficient.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38080", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FudvHFdemDy5PhXvCA5sUg==": { "id": "FudvHFdemDy5PhXvCA5sUg==", "updater": "debian/updater", "name": "CVE-2026-68349", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover continuation in carl9170_rx_stream() copies the full tlen from the second USB transfer instead of capping at rx_failover_missing bytes. When both transfers are near maximum size, the total exceeds the 65535-byte failover SKB, triggering skb_over_panic. Limit the copy size to the missing byte count. [Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68349", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fv1xZ6eCn6XkYWWsyTGbDw==": { "id": "Fv1xZ6eCn6XkYWWsyTGbDw==", "updater": "debian/updater", "name": "CVE-2026-9669", "description": "bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-9669", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "FwYFV0OFCW//qyPsOZ72+g==": { "id": "FwYFV0OFCW//qyPsOZ72+g==", "updater": "debian/updater", "name": "CVE-2026-53368", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion with the checkpoint path, which can result in an incorrect inode block marking state. The scenario is as follows: create \u0026 write \u0026 fsync 'file A' write checkpoint - f2fs_do_sync_file // inline inode - f2fs_write_inode // inode folio is dirty - f2fs_write_checkpoint - f2fs_flush_merged_writes - f2fs_sync_node_pages - f2fs_fsync_node_pages // no dirty node - f2fs_need_inode_block_update // return true - f2fs_fsync_node_pages // inode dirtied - f2fs_need_dentry_mark //return true - f2fs_flush_nat_entries - f2fs_write_checkpoint end - __write_node_folio // inode with DENT_BIT_SHIFT set SPO, \"fsck --dry-run\" find inode has already checkpointed but still with DENT_BIT_SHIFT set The state observed by f2fs_need_dentry_mark() can differ from the state observed in __write_node_folio() after acquiring sbi-\u003enode_write. The root cause is that the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after the checkpoint write has fully completed. This patch moves set_dentry_mark() into __write_node_folio() and protects it with the sbi-\u003enode_write lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53368", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Fy01J7BLzA/Xpm61ujj0tA==": { "id": "Fy01J7BLzA/Xpm61ujj0tA==", "updater": "debian/updater", "name": "CVE-2024-27041", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix NULL checks for adev-\u003edm.dc in amdgpu_dm_fini() Since 'adev-\u003edm.dc' in amdgpu_dm_fini() might turn out to be NULL before the call to dc_enable_dmub_notifications(), check beforehand to ensure there will not be a possible NULL-ptr-deref there. Also, since commit 1e88eb1b2c25 (\"drm/amd/display: Drop CONFIG_DRM_AMD_DC_HDCP\") there are two separate checks for NULL in 'adev-\u003edm.dc' before dc_deinit_callbacks() and dc_dmub_srv_destroy(). Clean up by combining them all under one 'if'. Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27041", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G2iV9eBpaZfZ03f0d0t/rA==": { "id": "G2iV9eBpaZfZ03f0d0t/rA==", "updater": "debian/updater", "name": "CVE-2024-50217", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() Mounting btrfs from two images (which have the same one fsid and two different dev_uuids) in certain executing order may trigger an UAF for variable 'device-\u003ebdev_file' in __btrfs_free_extra_devids(). And following are the details: 1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs devices by ioctl(BTRFS_IOC_SCAN_DEV): / btrfs_device_1 → loop0 fs_device \\ btrfs_device_2 → loop1 2. mount /dev/loop0 /mnt btrfs_open_devices btrfs_device_1-\u003ebdev_file = btrfs_get_bdev_and_sb(loop0) btrfs_device_2-\u003ebdev_file = btrfs_get_bdev_and_sb(loop1) btrfs_fill_super open_ctree fail: btrfs_close_devices // -ENOMEM \t btrfs_close_bdev(btrfs_device_1) fput(btrfs_device_1-\u003ebdev_file) \t // btrfs_device_1-\u003ebdev_file is freed \t btrfs_close_bdev(btrfs_device_2) fput(btrfs_device_2-\u003ebdev_file) 3. mount /dev/loop1 /mnt btrfs_open_devices btrfs_get_bdev_and_sb(\u0026bdev_file) // EIO, btrfs_device_1-\u003ebdev_file is not assigned, // which points to a freed memory area btrfs_device_2-\u003ebdev_file = btrfs_get_bdev_and_sb(loop1) btrfs_fill_super open_ctree btrfs_free_extra_devids if (btrfs_device_1-\u003ebdev_file) fput(btrfs_device_1-\u003ebdev_file) // UAF ! Fix it by setting 'device-\u003ebdev_file' as 'NULL' after closing the btrfs_device in btrfs_close_one_device().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50217", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G5V+qv7EnKUSx9A7fkr1ig==": { "id": "G5V+qv7EnKUSx9A7fkr1ig==", "updater": "debian/updater", "name": "CVE-2025-21673", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realizes it should exit the loop, so @server-\u003ehostname can't be freed as long as cifsd thread isn't done. Otherwise the following can happen: RIP: 0010:__slab_free+0x223/0x3c0 Code: 5e 41 5f c3 cc cc cc cc 4c 89 de 4c 89 cf 44 89 44 24 08 4c 89 1c 24 e8 fb cf 8e 00 44 8b 44 24 08 4c 8b 1c 24 e9 5f fe ff ff \u003c0f\u003e 0b 41 f7 45 08 00 0d 21 00 0f 85 2d ff ff ff e9 1f ff ff ff 80 RSP: 0018:ffffb26180dbfd08 EFLAGS: 00010246 RAX: ffff8ea34728e510 RBX: ffff8ea34728e500 RCX: 0000000000800068 RDX: 0000000000800068 RSI: 0000000000000000 RDI: ffff8ea340042400 RBP: ffffe112041ca380 R08: 0000000000000001 R09: 0000000000000000 R10: 6170732e31303000 R11: 70726f632e786563 R12: ffff8ea34728e500 R13: ffff8ea340042400 R14: ffff8ea34728e500 R15: 0000000000800068 FS: 0000000000000000(0000) GS:ffff8ea66fd80000(0000) 000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ffc25376080 CR3: 000000012a2ba001 CR4: PKRU: 55555554 Call Trace: \u003cTASK\u003e ? show_trace_log_lvl+0x1c4/0x2df ? show_trace_log_lvl+0x1c4/0x2df ? __reconnect_target_unlocked+0x3e/0x160 [cifs] ? __die_body.cold+0x8/0xd ? die+0x2b/0x50 ? do_trap+0xce/0x120 ? __slab_free+0x223/0x3c0 ? do_error_trap+0x65/0x80 ? __slab_free+0x223/0x3c0 ? exc_invalid_op+0x4e/0x70 ? __slab_free+0x223/0x3c0 ? asm_exc_invalid_op+0x16/0x20 ? __slab_free+0x223/0x3c0 ? extract_hostname+0x5c/0xa0 [cifs] ? extract_hostname+0x5c/0xa0 [cifs] ? __kmalloc+0x4b/0x140 __reconnect_target_unlocked+0x3e/0x160 [cifs] reconnect_dfs_server+0x145/0x430 [cifs] cifs_handle_standard+0x1ad/0x1d0 [cifs] cifs_demultiplex_thread+0x592/0x730 [cifs] ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs] kthread+0xdd/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x29/0x50 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21673", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G8YItgV0rZhbyR5nCdBBFA==": { "id": "G8YItgV0rZhbyR5nCdBBFA==", "updater": "debian/updater", "name": "CVE-2026-53220", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_rcu() return without a NULL check, causing a kernel panic when the bridge port has been removed between the original hook invocation and an NFQUEUE reinject. A mere NULL check isn't sufficient, however. As sashiko review points out userspace can not only remove the port from the bridge, it could also place the device in a different virtual device, e.g. macvlan. If this happens, we must drop the packet, there is no way for us to reinject it into the bridge path. Switch to _upper API, we don't need the bridge port structure. Also, this fix keeps another bug intact: Both nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER too aggressive, which prevents certain logging features when queueing in bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old CONFIG_BRIDGE_NETFILTER cruft is off. Fixes tag is a common ancestor, this was always broken.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53220", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "G9rxX0ybHgw86Jv3kSVS4g==": { "id": "G9rxX0ybHgw86Jv3kSVS4g==", "updater": "debian/updater", "name": "CVE-2026-46226", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: fsl: fix controller deregistration Make sure to deregister the controller before releasing underlying resources like DMA during driver unbind.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46226", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GBLYo/Hpg17ZmUp20DxbBA==": { "id": "GBLYo/Hpg17ZmUp20DxbBA==", "updater": "debian/updater", "name": "CVE-2025-38042", "description": "In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma-glue: Drop skip_fdq argument from k3_udma_glue_reset_rx_chn The user of k3_udma_glue_reset_rx_chn() e.g. ti_am65_cpsw_nuss can run on multiple platforms having different DMA architectures. On some platforms there can be one FDQ for all flows in the RX channel while for others there is a separate FDQ for each flow in the RX channel. So far we have been relying on the skip_fdq argument of k3_udma_glue_reset_rx_chn(). Instead of relying on the user to provide this information, infer it based on DMA architecture during k3_udma_glue_request_rx_chn() and save it in an internal flag 'single_fdq'. Use that flag at k3_udma_glue_reset_rx_chn() to deicide if the FDQ needs to be cleared for every flow or just for flow 0. Fixes the below issue on ti_am65_cpsw_nuss driver on AM62-SK. \u003e ip link set eth1 down \u003e ip link set eth0 down \u003e ethtool -L eth0 rx 8 \u003e ip link set eth0 up \u003e modprobe -r ti_am65_cpsw_nuss [ 103.045726] ------------[ cut here ]------------ [ 103.050505] k3_knav_desc_pool size 512000 != avail 64000 [ 103.050703] WARNING: CPU: 1 PID: 450 at drivers/net/ethernet/ti/k3-cppi-desc-pool.c:33 k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [ 103.068810] Modules linked in: ti_am65_cpsw_nuss(-) k3_cppi_desc_pool snd_soc_hdmi_codec crct10dif_ce snd_soc_simple_card snd_soc_simple_card_utils display_connector rtc_ti_k3 k3_j72xx_bandgap tidss drm_client_lib snd_soc_davinci_mcas p drm_dma_helper tps6598x phylink snd_soc_ti_udma rti_wdt drm_display_helper snd_soc_tlv320aic3x_i2c typec at24 phy_gmii_sel snd_soc_ti_edma snd_soc_tlv320aic3x sii902x snd_soc_ti_sdma sa2ul omap_mailbox drm_kms_helper authenc cfg80211 r fkill fuse drm drm_panel_orientation_quirks backlight ip_tables x_tables ipv6 [last unloaded: k3_cppi_desc_pool] [ 103.119950] CPU: 1 UID: 0 PID: 450 Comm: modprobe Not tainted 6.13.0-rc7-00001-g9c5e3435fa66 #1011 [ 103.119968] Hardware name: Texas Instruments AM625 SK (DT) [ 103.119974] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 103.119983] pc : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [ 103.148007] lr : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [ 103.154709] sp : ffff8000826ebbc0 [ 103.158015] x29: ffff8000826ebbc0 x28: ffff0000090b6300 x27: 0000000000000000 [ 103.165145] x26: 0000000000000000 x25: 0000000000000000 x24: ffff0000019df6b0 [ 103.172271] x23: ffff0000019df6b8 x22: ffff0000019df410 x21: ffff8000826ebc88 [ 103.179397] x20: 000000000007d000 x19: ffff00000a3b3000 x18: 0000000000000000 [ 103.186522] x17: 0000000000000000 x16: 0000000000000000 x15: 000001e8c35e1cde [ 103.193647] x14: 0000000000000396 x13: 000000000000035c x12: 0000000000000000 [ 103.200772] x11: 000000000000003a x10: 00000000000009c0 x9 : ffff8000826eba20 [ 103.207897] x8 : ffff0000090b6d20 x7 : ffff00007728c180 x6 : ffff00007728c100 [ 103.215022] x5 : 0000000000000001 x4 : ffff000000508a50 x3 : ffff7ffff6146000 [ 103.222147] x2 : 0000000000000000 x1 : e300b4173ee6b200 x0 : 0000000000000000 [ 103.229274] Call trace: [ 103.231714] k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] (P) [ 103.238408] am65_cpsw_nuss_free_rx_chns+0x28/0x4c [ti_am65_cpsw_nuss] [ 103.244942] devm_action_release+0x14/0x20 [ 103.249040] release_nodes+0x3c/0x68 [ 103.252610] devres_release_all+0x8c/0xdc [ 103.256614] device_unbind_cleanup+0x18/0x60 [ 103.260876] device_release_driver_internal+0xf8/0x178 [ 103.266004] driver_detach+0x50/0x9c [ 103.269571] bus_remove_driver+0x6c/0xbc [ 103.273485] driver_unregister+0x30/0x60 [ 103.277401] platform_driver_unregister+0x14/0x20 [ 103.282096] am65_cpsw_nuss_driver_exit+0x18/0xff4 [ti_am65_cpsw_nuss] [ 103.288620] __arm64_sys_delete_module+0x17c/0x25c [ 103.293404] invoke_syscall+0x44/0x100 [ 103.297149] el0_svc_common.constprop.0+0xc0/0xe0 [ 103.301845] do_el0_svc+0x1c/0x28 [ 103.305155] el0_svc+0x28/0x98 ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38042", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GDwbfYxe5K2nm+263r+ovA==": { "id": "GDwbfYxe5K2nm+263r+ovA==", "updater": "debian/updater", "name": "CVE-2024-25742", "description": "In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-25742", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GF6tUVJPrzwKahsYQCql3Q==": { "id": "GF6tUVJPrzwKahsYQCql3Q==", "updater": "debian/updater", "name": "CVE-2025-22057", "description": "In the Linux kernel, the following vulnerability has been resolved: net: decrease cached dst counters in dst_release Upstream fix ac888d58869b (\"net: do not delay dst_entries_add() in dst_release()\") moved decrementing the dst count from dst_destroy to dst_release to avoid accessing already freed data in case of netns dismantle. However in case CONFIG_DST_CACHE is enabled and OvS+tunnels are used, this fix is incomplete as the same issue will be seen for cached dsts: Unable to handle kernel paging request at virtual address ffff5aabf6b5c000 Call trace: percpu_counter_add_batch+0x3c/0x160 (P) dst_release+0xec/0x108 dst_cache_destroy+0x68/0xd8 dst_destroy+0x13c/0x168 dst_destroy_rcu+0x1c/0xb0 rcu_do_batch+0x18c/0x7d0 rcu_core+0x174/0x378 rcu_core_si+0x18/0x30 Fix this by invalidating the cache, and thus decrementing cached dst counters, in dst_release too.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22057", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GJrvy9jffG4zI55Mbn9hPQ==": { "id": "GJrvy9jffG4zI55Mbn9hPQ==", "updater": "debian/updater", "name": "CVE-2018-12928", "description": "In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-12928", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GMyNpSQdt3P3zg1eWylfrQ==": { "id": "GMyNpSQdt3P3zg1eWylfrQ==", "updater": "debian/updater", "name": "CVE-2026-53232", "description": "In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events. This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53232", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GT1RFwTTfZX7UTrjVIuvcg==": { "id": "GT1RFwTTfZX7UTrjVIuvcg==", "updater": "debian/updater", "name": "CVE-2025-15367", "description": "The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15367", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GVvZ1pyqS4BMw8vAHqz3pw==": { "id": "GVvZ1pyqS4BMw8vAHqz3pw==", "updater": "debian/updater", "name": "CVE-2026-53330", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval() [Why \u0026 How] The aux_rd_interval array in struct dc_lttpr_caps is declared with MAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset parameter passed to dp_get_eq_aux_rd_interval() can be as large as MAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD. This leads to an out-of-bounds read of aux_rd_interval[7] when offset is 8. Fix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to accommodate the full range of valid repeater counts defined by the DP spec. (cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53330", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GWR1J92TJBEfZUdv9nbrxw==": { "id": "GWR1J92TJBEfZUdv9nbrxw==", "updater": "debian/updater", "name": "CVE-2026-53615", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53615", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GYeUqbv2q0crIzEsMTVjoA==": { "id": "GYeUqbv2q0crIzEsMTVjoA==", "updater": "debian/updater", "name": "CVE-2024-27011", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak in map from abort path The delete set command does not rely on the transaction object for element removal, therefore, a combination of delete element + delete set from the abort path could result in restoring twice the refcount of the mapping. Check for inactive element in the next generation for the delete element command in the abort path, skip restoring state if next generation bit has been already cleared. This is similar to the activate logic using the set walk iterator. [ 6170.286929] ------------[ cut here ]------------ [ 6170.286939] WARNING: CPU: 6 PID: 790302 at net/netfilter/nf_tables_api.c:2086 nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.287071] Modules linked in: [...] [ 6170.287633] CPU: 6 PID: 790302 Comm: kworker/6:2 Not tainted 6.9.0-rc3+ #365 [ 6170.287768] RIP: 0010:nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.287886] Code: df 48 8d 7d 58 e8 69 2e 3b df 48 8b 7d 58 e8 80 1b 37 df 48 8d 7d 68 e8 57 2e 3b df 48 8b 7d 68 e8 6e 1b 37 df 48 89 ef eb c4 \u003c0f\u003e 0b 48 83 c4 08 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 0f [ 6170.287895] RSP: 0018:ffff888134b8fd08 EFLAGS: 00010202 [ 6170.287904] RAX: 0000000000000001 RBX: ffff888125bffb28 RCX: dffffc0000000000 [ 6170.287912] RDX: 0000000000000003 RSI: ffffffffa20298ab RDI: ffff88811ebe4750 [ 6170.287919] RBP: ffff88811ebe4700 R08: ffff88838e812650 R09: fffffbfff0623a55 [ 6170.287926] R10: ffffffff8311d2af R11: 0000000000000001 R12: ffff888125bffb10 [ 6170.287933] R13: ffff888125bffb10 R14: dead000000000122 R15: dead000000000100 [ 6170.287940] FS: 0000000000000000(0000) GS:ffff888390b00000(0000) knlGS:0000000000000000 [ 6170.287948] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 6170.287955] CR2: 00007fd31fc00710 CR3: 0000000133f60004 CR4: 00000000001706f0 [ 6170.287962] Call Trace: [ 6170.287967] \u003cTASK\u003e [ 6170.287973] ? __warn+0x9f/0x1a0 [ 6170.287986] ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288092] ? report_bug+0x1b1/0x1e0 [ 6170.287986] ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288092] ? report_bug+0x1b1/0x1e0 [ 6170.288104] ? handle_bug+0x3c/0x70 [ 6170.288112] ? exc_invalid_op+0x17/0x40 [ 6170.288120] ? asm_exc_invalid_op+0x1a/0x20 [ 6170.288132] ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables] [ 6170.288243] ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288366] ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables] [ 6170.288483] nf_tables_trans_destroy_work+0x588/0x590 [nf_tables]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27011", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GZouk0sDd/thoSYrZ82zZg==": { "id": "GZouk0sDd/thoSYrZ82zZg==", "updater": "debian/updater", "name": "CVE-2021-45346", "description": "A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-45346", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GajE3N1YQ6FfS4SAySC7ag==": { "id": "GajE3N1YQ6FfS4SAySC7ag==", "updater": "debian/updater", "name": "CVE-2025-39762", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: add null check [WHY] Prevents null pointer dereferences to enhance function robustness [HOW] Adds early null check and return false if invalid.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39762", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GbgKUjPpUdUMMrRRtGYntg==": { "id": "GbgKUjPpUdUMMrRRtGYntg==", "updater": "debian/updater", "name": "CVE-2023-54107", "description": "In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: dropping parent refcount after pd_free_fn() is done Some cgroup policies will access parent pd through child pd even after pd_offline_fn() is done. If pd_free_fn() for parent is called before child, then UAF can be triggered. Hence it's better to guarantee the order of pd_free_fn(). Currently refcount of parent blkg is dropped in __blkg_release(), which is before pd_free_fn() is called in blkg_free_work_fn() while blkg_free_work_fn() is called asynchronously. This patch make sure pd_free_fn() called from removing cgroup is ordered by delaying dropping parent refcount after calling pd_free_fn() for child. BTW, pd_free_fn() will also be called from blkcg_deactivate_policy() from deleting device, and following patches will guarantee the order.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54107", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GdrnB+j3VN7L66G2VDQT/w==": { "id": "GdrnB+j3VN7L66G2VDQT/w==", "updater": "debian/updater", "name": "CVE-2026-45940", "description": "In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix oops when split header is enabled For GMAC4, when split header is enabled, in some rare cases, the hardware does not fill buf2 of the first descriptor with payload. Thus we cannot assume buf2 is always fully filled if it is not the last descriptor. Otherwise, the length of buf2 of the second descriptor will be calculated wrong and cause an oops: Unable to handle kernel paging request at virtual address ffff00019246bfc0 ... x2 : 0000000000000040 x1 : ffff00019246bfc0 x0 : ffff00009246c000 Call trace: dcache_inval_poc+0x28/0x58 (P) dma_direct_sync_single_for_cpu+0x38/0x6c __dma_sync_single_for_cpu+0x34/0x6c stmmac_napi_poll_rx+0x8f0/0xb60 __napi_poll.constprop.0+0x30/0x144 net_rx_action+0x160/0x274 handle_softirqs+0x1b8/0x1fc ... To fix this, the PL bit-field in RDES3 register is used for all descriptors, whether it is the last descriptor or not.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45940", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Gfnrd/Qq3NY0ytzgSjsjfw==": { "id": "Gfnrd/Qq3NY0ytzgSjsjfw==", "updater": "debian/updater", "name": "CVE-2026-43167", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: always flush state and policy upon NETDEV_UNREGISTER event syzbot is reporting that \"struct xfrm_state\" refcount is leaking. unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 2 ref_tracker: netdev@ffff888052f24618 has 1/1 users at __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline] netdev_tracker_alloc include/linux/netdevice.h:4412 [inline] xfrm_dev_state_add+0x3a5/0x1080 net/xfrm/xfrm_device.c:316 xfrm_state_construct net/xfrm/xfrm_user.c:986 [inline] xfrm_add_sa+0x34ff/0x5fa0 net/xfrm/xfrm_user.c:1022 xfrm_user_rcv_msg+0x58e/0xc00 net/xfrm/xfrm_user.c:3507 netlink_rcv_skb+0x158/0x420 net/netlink/af_netlink.c:2550 xfrm_netlink_rcv+0x71/0x90 net/xfrm/xfrm_user.c:3529 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x5aa/0x870 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x8c8/0xdd0 net/netlink/af_netlink.c:1894 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa5d/0xc30 net/socket.c:2592 ___sys_sendmsg+0x134/0x1d0 net/socket.c:2646 __sys_sendmsg+0x16d/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f This is because commit d77e38e612a0 (\"xfrm: Add an IPsec hardware offloading API\") implemented xfrm_dev_unregister() as no-op despite xfrm_dev_state_add() from xfrm_state_construct() acquires a reference to \"struct net_device\". I guess that that commit expected that NETDEV_DOWN event is fired before NETDEV_UNREGISTER event fires, and also assumed that xfrm_dev_state_add() is called only if (dev-\u003efeatures \u0026 NETIF_F_HW_ESP) != 0. Sabrina Dubroca identified steps to reproduce the same symptoms as below. echo 0 \u003e /sys/bus/netdevsim/new_device dev=$(ls -1 /sys/bus/netdevsim/devices/netdevsim0/net/) ip xfrm state add src 192.168.13.1 dst 192.168.13.2 proto esp \\ spi 0x1000 mode tunnel aead 'rfc4106(gcm(aes))' $key 128 \\ offload crypto dev $dev dir out ethtool -K $dev esp-hw-offload off echo 0 \u003e /sys/bus/netdevsim/del_device Like these steps indicate, the NETIF_F_HW_ESP bit can be cleared after xfrm_dev_state_add() acquired a reference to \"struct net_device\". Also, xfrm_dev_state_add() does not check for the NETIF_F_HW_ESP bit when acquiring a reference to \"struct net_device\". Commit 03891f820c21 (\"xfrm: handle NETDEV_UNREGISTER for xfrm device\") re-introduced the NETDEV_UNREGISTER event to xfrm_dev_event(), but that commit for unknown reason chose to share xfrm_dev_down() between the NETDEV_DOWN event and the NETDEV_UNREGISTER event. I guess that that commit missed the behavior in the previous paragraph. Therefore, we need to re-introduce xfrm_dev_unregister() in order to release the reference to \"struct net_device\" by unconditionally flushing state and policy.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43167", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Gg4J4X4MbNfkoXKGRDGfqw==": { "id": "Gg4J4X4MbNfkoXKGRDGfqw==", "updater": "debian/updater", "name": "CVE-2025-15224", "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15224", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GihEukOx/EVvJDmdnw71zw==": { "id": "GihEukOx/EVvJDmdnw71zw==", "updater": "debian/updater", "name": "CVE-2026-68287", "description": "In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and NET_DM_ATTR_TIMESTAMP). On 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS, nla_put_u64_64bit() may append a 4-byte NET_DM_ATTR_PAD attribute for 64-bit alignment. However, net_dm_packet_report_size() and net_dm_hw_packet_report_size() used nla_total_size(sizeof(u64)) instead of nla_total_size_64bit(sizeof(u64)), budgeting 12 bytes instead of up to 16 bytes. This under-estimation of SKB size can lead to an skb_over_panic() when __nla_reserve() or skb_put() is subsequently called. Fix this by using nla_total_size_64bit(sizeof(u64)) in both size calculations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68287", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GjZqVvRzaJEGIN3eGK1g9g==": { "id": "GjZqVvRzaJEGIN3eGK1g9g==", "updater": "debian/updater", "name": "CVE-2026-45858", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 When allocating initialized blocks from a large unwritten extent, or when splitting an unwritten extent during end I/O and converting it to initialized, there is currently a potential issue of stale data if the extent needs to be split in the middle. 0 A B N [UUUUUUUUUUUU] U: unwritten extent [--DDDDDDDD--] D: valid data |\u003c- -\u003e| ----\u003e this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_ENTIRE_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and mark the entire extent from 0 to N as written. 0 A B N [WWWWWWWWWWWW] W: written extent [SSDDDDDDDDZZ] Z: zeroed, S: stale data ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and left a stale written extent from 0 to A. 0 A B N [WW|WWWWWWWWWW] [SS|DDDDDDDDZZ] Fix this by pass EXT4_EXT_DATA_PARTIAL_VALID1 to ext4_split_extent_at() when splitting at B, don't convert the entire extent to written and left it as unwritten after zeroing out B to N. The remaining work is just like the standard two-part split. ext4_split_extent() will pass the EXT4_EXT_DATA_VALID2 flag when it calls ext4_split_extent_at() for the second time, allowing it to properly handle the split. If the split is successful, it will keep extent from 0 to A as unwritten.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45858", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Gn+PhE9phsL43pvVHeJqsg==": { "id": "Gn+PhE9phsL43pvVHeJqsg==", "updater": "debian/updater", "name": "CVE-2026-68242", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix NULL deref on sched_engine alloc failure Avoid using intel_context_put() before intel_context_init() in execlists_create_virtual() as the kref_put() inside would lead to NULL deref on the IOCTL path when sched_engine allocation fails. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 4f2a12f2d50e9f48227656e4dcbd6423506be31d)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68242", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GqTJcsBL/Jz1hT2nxRpDEw==": { "id": "GqTJcsBL/Jz1hT2nxRpDEw==", "updater": "debian/updater", "name": "CVE-2026-43049", "description": "In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down. If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow. We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43049", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GqYY7wlQYv1joWZwNaBehg==": { "id": "GqYY7wlQYv1joWZwNaBehg==", "updater": "debian/updater", "name": "CVE-2026-31486", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect regulator operations with mutex The regulator operations pmbus_regulator_get_voltage(), pmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage() access PMBus registers and shared data but were not protected by the update_lock mutex. This could lead to race conditions. However, adding mutex protection directly to these functions causes a deadlock because pmbus_regulator_notify() (which calls regulator_notifier_call_chain()) is often called with the mutex already held (e.g., from pmbus_fault_handler()). If a regulator callback then calls one of the now-protected voltage functions, it will attempt to acquire the same mutex. Rework pmbus_regulator_notify() to utilize a worker function to send notifications outside of the mutex protection. Events are stored as atomics in a per-page bitmask and processed by the worker. Initialize the worker and its associated data during regulator registration, and ensure it is cancelled on device removal using devm_add_action_or_reset(). While at it, remove the unnecessary include of linux/of.h.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31486", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GtrnpVR3O3zqXqNcQVnSdg==": { "id": "GtrnpVR3O3zqXqNcQVnSdg==", "updater": "debian/updater", "name": "CVE-2026-64434", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan-\u003econn. If the connection is torn down while the timer is running or pending, chan-\u003econn can be freed, leading to a use-after-free when the timer worker attempts to lock conn-\u003elock: | BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] | BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] | BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 | Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83 | | CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full) | Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 | Workqueue: events l2cap_chan_timeout | Call Trace: | \u003cTASK\u003e | instrument_atomic_read_write include/linux/instrumented.h:112 [inline] | atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] | mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 | l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422 | process_one_work kernel/workqueue.c:3326 [inline] | process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 | worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 | ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 | \u003c/TASK\u003e | | Allocated by task 320: | l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075 | l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452 | hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline] | hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760 | hci_event_func net/bluetooth/hci_event.c:7796 [inline] | hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847 | hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040 | process_one_work kernel/workqueue.c:3326 [inline] | process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 | worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 | ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 | | Freed by task 322: | hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline] | hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736 | hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405 | hci_dev_do_close net/bluetooth/hci_core.c:502 [inline] | hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679 | vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690 | __fput+0x369/0x890 fs/file_table.c:510 | task_work_run+0x160/0x1d0 kernel/task_work.c:233 | get_signal+0xf5b/0x1120 kernel/signal.c:2810 | arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337 | __exit_to_user_mode_loop kernel/entry/common.c:64 [inline] | exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98 | do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100 | entry_SYSCALL_64_after_hwframe+0x77/0x7f | | The buggy address belongs to the object at ffff8881298d9400 | which belongs to the cache kmalloc-512 of size 512 | The buggy address is located 336 bytes inside of | freed 512-byte region [ffff8881298d9400, ffff8881298d9600) Fix it by having chan-\u003econn hold a reference to l2cap_conn (via l2cap_conn_get) when the channel is added to the connection, and releasing it in the channel destructor. This ensures the l2cap_conn remains alive as long as the channel exists. A new FLAG_DEL channel flag is introduced to indicate that the ch ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64434", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GuCBWhZkPdgB6JAffd0vyQ==": { "id": "GuCBWhZkPdgB6JAffd0vyQ==", "updater": "debian/updater", "name": "CVE-2026-56405", "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56405", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GwDIWcE/e/Kt96ryrmbvAw==": { "id": "GwDIWcE/e/Kt96ryrmbvAw==", "updater": "debian/updater", "name": "CVE-2023-53706", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/vmemmap/devdax: fix kernel crash when probing devdax devices commit 4917f55b4ef9 (\"mm/sparse-vmemmap: improve memory savings for compound devmaps\") added support for using optimized vmmemap for devdax devices. But how vmemmap mappings are created are architecture specific. For example, powerpc with hash translation doesn't have vmemmap mappings in init_mm page table instead they are bolted table entries in the hardware page table vmemmap_populate_compound_pages() used by vmemmap optimization code is not aware of these architecture-specific mapping. Hence allow architecture to opt for this feature. I selected architectures supporting HUGETLB_PAGE_OPTIMIZE_VMEMMAP option as also supporting this feature. This patch fixes the below crash on ppc64. BUG: Unable to handle kernel data access on write at 0xc00c000100400038 Faulting instruction address: 0xc000000001269d90 Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries Modules linked in: CPU: 7 PID: 1 Comm: swapper/0 Not tainted 6.3.0-rc5-150500.34-default+ #2 5c90a668b6bbd142599890245c2fb5de19d7d28a Hardware name: IBM,9009-42G POWER9 (raw) 0x4e0202 0xf000005 of:IBM,FW950.40 (VL950_099) hv:phyp pSeries NIP: c000000001269d90 LR: c0000000004c57d4 CTR: 0000000000000000 REGS: c000000003632c30 TRAP: 0300 Not tainted (6.3.0-rc5-150500.34-default+) MSR: 8000000000009033 \u003cSF,EE,ME,IR,DR,RI,LE\u003e CR: 24842228 XER: 00000000 CFAR: c0000000004c57d0 DAR: c00c000100400038 DSISR: 42000000 IRQMASK: 0 .... NIP [c000000001269d90] __init_single_page.isra.74+0x14/0x4c LR [c0000000004c57d4] __init_zone_device_page+0x44/0xd0 Call Trace: [c000000003632ed0] [c000000003632f60] 0xc000000003632f60 (unreliable) [c000000003632f10] [c0000000004c5ca0] memmap_init_zone_device+0x170/0x250 [c000000003632fe0] [c0000000005575f8] memremap_pages+0x2c8/0x7f0 [c0000000036330c0] [c000000000557b5c] devm_memremap_pages+0x3c/0xa0 [c000000003633100] [c000000000d458a8] dev_dax_probe+0x108/0x3e0 [c0000000036331a0] [c000000000d41430] dax_bus_probe+0xb0/0x140 [c0000000036331d0] [c000000000cef27c] really_probe+0x19c/0x520 [c000000003633260] [c000000000cef6b4] __driver_probe_device+0xb4/0x230 [c0000000036332e0] [c000000000cef888] driver_probe_device+0x58/0x120 [c000000003633320] [c000000000cefa6c] __device_attach_driver+0x11c/0x1e0 [c0000000036333a0] [c000000000cebc58] bus_for_each_drv+0xa8/0x130 [c000000003633400] [c000000000ceefcc] __device_attach+0x15c/0x250 [c0000000036334a0] [c000000000ced458] bus_probe_device+0x108/0x110 [c0000000036334f0] [c000000000ce92dc] device_add+0x7fc/0xa10 [c0000000036335b0] [c000000000d447c8] devm_create_dev_dax+0x1d8/0x530 [c000000003633640] [c000000000d46b60] __dax_pmem_probe+0x200/0x270 [c0000000036337b0] [c000000000d46bf0] dax_pmem_probe+0x20/0x70 [c0000000036337d0] [c000000000d2279c] nvdimm_bus_probe+0xac/0x2b0 [c000000003633860] [c000000000cef27c] really_probe+0x19c/0x520 [c0000000036338f0] [c000000000cef6b4] __driver_probe_device+0xb4/0x230 [c000000003633970] [c000000000cef888] driver_probe_device+0x58/0x120 [c0000000036339b0] [c000000000cefd08] __driver_attach+0x1d8/0x240 [c000000003633a30] [c000000000cebb04] bus_for_each_dev+0xb4/0x130 [c000000003633a90] [c000000000cee564] driver_attach+0x34/0x50 [c000000003633ab0] [c000000000ced878] bus_add_driver+0x218/0x300 [c000000003633b40] [c000000000cf1144] driver_register+0xa4/0x1b0 [c000000003633bb0] [c000000000d21a0c] __nd_driver_register+0x5c/0x100 [c000000003633c10] [c00000000206a2e8] dax_pmem_init+0x34/0x48 [c000000003633c30] [c0000000000132d0] do_one_initcall+0x60/0x320 [c000000003633d00] [c0000000020051b0] kernel_init_freeable+0x360/0x400 [c000000003633de0] [c000000000013764] kernel_init+0x34/0x1d0 [c000000003633e50] [c00000000000de14] ret_from_kernel_thread+0x5c/0x64", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53706", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Gx00DehD2xRAI3D63RVOjA==": { "id": "Gx00DehD2xRAI3D63RVOjA==", "updater": "debian/updater", "name": "CVE-2026-68364", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix ISM dc_lock deadlock during suspend [Why] System hang observed during suspend/resume while video is playing. amdgpu_dm_ism_disable() is called under dc_lock and waits for ISM delayed work via disable_delayed_work_sync(). The work handlers themselves take dc_lock, producing an ABBA deadlock when a worker is in flight at suspend time. [How] Split the disable path into two phases with opposite locking contracts: 1. amdgpu_dm_ism_disable() -- quiesces workers, must NOT hold dc_lock. 2. amdgpu_dm_ism_force_full_power() (new) -- drives the ISM FSM back to FULL_POWER_RUNNING, must hold dc_lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68364", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "GzbJOUxG2RBo8VcUzgwjjg==": { "id": "GzbJOUxG2RBo8VcUzgwjjg==", "updater": "debian/updater", "name": "CVE-2026-68431", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated dialect does not provide transform handling. On an SMB 2.1 connection, a short transform packet therefore reaches init_smb2_rsp_hdr(), which interprets the request as a full SMB2 header and reads beyond the request allocation. The copied fields can then be returned to the unauthenticated client. Compression transforms are converted to ordinary SMB2 messages before protocol validation. After that conversion, validate ordinary SMB2 requests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption transform requests to contain both a transform header and an SMB2 header. This rejects truncated requests before work allocation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68431", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H+FYqkEurnu4jymCjwERfA==": { "id": "H+FYqkEurnu4jymCjwERfA==", "updater": "debian/updater", "name": "CVE-2024-26740", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: use the backlog for mirred ingress The test Davide added in commit ca22da2fbd69 (\"act_mirred: use the backlog for nested calls to mirred ingress\") hangs our testing VMs every 10 or so runs, with the familiar tcp_v4_rcv -\u003e tcp_v4_rcv deadlock reported by lockdep. The problem as previously described by Davide (see Link) is that if we reverse flow of traffic with the redirect (egress -\u003e ingress) we may reach the same socket which generated the packet. And we may still be holding its socket lock. The common solution to such deadlocks is to put the packet in the Rx backlog, rather than run the Rx path inline. Do that for all egress -\u003e ingress reversals, not just once we started to nest mirred calls. In the past there was a concern that the backlog indirection will lead to loss of error reporting / less accurate stats. But the current workaround does not seem to address the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26740", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H/zWlIpN8aMvffie7AG76A==": { "id": "H/zWlIpN8aMvffie7AG76A==", "updater": "debian/updater", "name": "CVE-2026-45892", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache after doing PARTIAL_VALID1 zeroout When splitting an unwritten extent in the middle and converting it to initialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent. Assume we have an unwritten file and buffered write in the middle of it without dioread_nolock enabled, it will allocate blocks as written extent. 0 A B N [UUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDD--] D: valid data |\u003c- -\u003e| ----\u003e this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and leave the entire extent as unwritten. 0 A B N [UUUUUUUUUUUU] on-disk extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDDZZ] Z: zeroed data ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and leave an written extent from A to N. 0 A B N [UUWWWWWWWWWW] on-disk extent W: written extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDDZZ] Finally ext4_map_create_blocks() only insert extent A to B to the extent status tree, and leave an stale unwritten extent in the status tree. 0 A B N [UUWWWWWWWWWW] on-disk extent W: written extent [UUWWWWWWWWUU] extent status tree [--DDDDDDDDZZ] Fix this issue by always cached extent status entry after zeroing out the second part.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45892", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H09h9nd7ZlHJ8LRncQ4cfQ==": { "id": "H09h9nd7ZlHJ8LRncQ4cfQ==", "updater": "debian/updater", "name": "CVE-2026-58014", "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58014", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H1V1G2DPgYUppmsrLKmg5A==": { "id": "H1V1G2DPgYUppmsrLKmg5A==", "updater": "debian/updater", "name": "CVE-2026-60001", "description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-60001", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "H3+fTqUBus2576Wg9ZAwEQ==": { "id": "H3+fTqUBus2576Wg9ZAwEQ==", "updater": "debian/updater", "name": "CVE-2026-68407", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68407", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HAjZuZl9VR4oQ2xpcqiI0g==": { "id": "HAjZuZl9VR4oQ2xpcqiI0g==", "updater": "debian/updater", "name": "CVE-2026-68343", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response also contains a PathConsumed value that is later used for DFS path parsing. If a malformed response provides a PathConsumed value larger than the search name, later DFS parsing can advance beyond the end of the path. Validate PathConsumed against the search name length before storing it in the parsed referral.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68343", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HBrSz1uIhsdeuDCH3ewyoA==": { "id": "HBrSz1uIhsdeuDCH3ewyoA==", "updater": "debian/updater", "name": "CVE-2018-6829", "description": "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-6829", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libgcrypt20", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HJ9IDZvGKgGm0SpI03Kblw==": { "id": "HJ9IDZvGKgGm0SpI03Kblw==", "updater": "debian/updater", "name": "CVE-2025-38709", "description": "In the Linux kernel, the following vulnerability has been resolved: loop: Avoid updating block size under exclusive owner Syzbot came up with a reproducer where a loop device block size is changed underneath a mounted filesystem. This causes a mismatch between the block device block size and the block size stored in the superblock causing confusion in various places such as fs/buffer.c. The particular issue triggered by syzbot was a warning in __getblk_slow() due to requested buffer size not matching block device block size. Fix the problem by getting exclusive hold of the loop device to change its block size. This fails if somebody (such as filesystem) has already an exclusive ownership of the block device and thus prevents modifying the loop device under some exclusive owner which doesn't expect it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38709", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HLibYccak0sZKoSNsE6IZg==": { "id": "HLibYccak0sZKoSNsE6IZg==", "updater": "debian/updater", "name": "CVE-2024-2379", "description": "libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-2379", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HLlE7mJEwNb5ro7Kr4vxZA==": { "id": "HLlE7mJEwNb5ro7Kr4vxZA==", "updater": "debian/updater", "name": "CVE-2026-43153", "description": "In the Linux kernel, the following vulnerability has been resolved: xfs: remove xfs_attr_leaf_hasname The calling convention of xfs_attr_leaf_hasname() is problematic, because it returns a NULL buffer when xfs_attr3_leaf_read fails, a valid buffer when xfs_attr3_leaf_lookup_int returns -ENOATTR or -EEXIST, and a non-NULL buffer pointer for an already released buffer when xfs_attr3_leaf_lookup_int fails with other error values. Fix this by simply open coding xfs_attr_leaf_hasname in the callers, so that the buffer release code is done by each caller of xfs_attr3_leaf_read.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43153", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HPnaw8TA8UZeJfoQkXai2g==": { "id": "HPnaw8TA8UZeJfoQkXai2g==", "updater": "debian/updater", "name": "CVE-2026-68355", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() When the first entry in msdu_details has a zero buffer address, the code accesses msdu_details[i - 1] with i == 0, causing a buffer underflow. Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding a separate check for i == 0 before the main condition to prevent the out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68355", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HPo+h/lLn08f9CNb4yjX9g==": { "id": "HPo+h/lLn08f9CNb4yjX9g==", "updater": "debian/updater", "name": "CVE-2026-31675", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_enqueue(), the packet corruption logic uses get_random_u32_below(skb_headlen(skb)) to select an index for modifying skb-\u003edata. When an AF_PACKET TX_RING sends fully non-linear packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0. Passing 0 to get_random_u32_below() takes the variable-ceil slow path which returns an unconstrained 32-bit random integer. Using this unconstrained value as an offset into skb-\u003edata results in an out-of-bounds memory access. Fix this by verifying skb_headlen(skb) is non-zero before attempting to corrupt the linear data area. Fully non-linear packets will silently bypass the corruption logic.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31675", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HUcdim+MD+uinTOZqB/5xA==": { "id": "HUcdim+MD+uinTOZqB/5xA==", "updater": "debian/updater", "name": "CVE-2026-53090", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix ld_{abs,ind} failure path analysis in subprogs Usage of ld_{abs,ind} instructions got extended into subprogs some time ago via commit 09b28d76eac4 (\"bpf: Add abnormal return checks.\"). These are only allowed in subprograms when the latter are BTF annotated and have scalar return types. The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 + exit) from legacy cBPF times. While the enforcement is on scalar return types, the verifier must also simulate the path of abnormal exit if the packet data load via ld_{abs,ind} failed. This is currently not the case. Fix it by having the verifier simulate both success and failure paths, and extend it in similar ways as we do for tail calls. The success path (r0=unknown, continue to next insn) is pushed onto stack for later validation and the r0=0 and return to the caller is done on the fall-through side.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53090", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HV3kDbwF/ANeXw+eGIqqSA==": { "id": "HV3kDbwF/ANeXw+eGIqqSA==", "updater": "debian/updater", "name": "CVE-2026-68124", "description": "In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent rx buffer overflow The MCTP serial receive state machine reads a frame length byte in mctp_serial_push_header() case 2 and validates it upper-bound-only: \tif (c \u003e MCTP_SERIAL_FRAME_MTU) { \t\tdev-\u003erxstate = STATE_ERR; \t} else { \t\tdev-\u003erxlen = c; \t\tdev-\u003erxpos = 0; \t\tdev-\u003erxstate = STATE_DATA; \t\t... \t} A length of zero passes this check, so rxlen is set to 0 and the state machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the incoming byte is stored and rxpos incremented before the terminator is \tdev-\u003erxbuf[dev-\u003erxpos] = c; \tdev-\u003erxpos++; \tdev-\u003erxstate = STATE_DATA; \tif (dev-\u003erxpos == dev-\u003erxlen) { \t\tdev-\u003erxpos = 0; \t\tdev-\u003erxstate = STATE_TRAILER; \t} With rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is already 1 on the first data byte), so subsequent bytes are written past the end of the fixed 74-byte rxbuf, which is the last member of the netdev private area. Every following data byte is an attacker-controlled 1-byte out-of-bounds heap write, and the overflow continues until a frame (0x7e) or escape byte resets the parser -- effectively unbounded. Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line discipline and bring the resulting mctpserialN netdev up, after which the bytes arrive via the tty receive path. Route a zero-length frame straight to STATE_TRAILER instead of STATE_DATA. The trailer/framing bytes are still consumed, and the frame resolves to a zero-length skb that the MCTP core rejects; the parser never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can no longer occur. KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this change): UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370 index 74 is out of range for type 'u8 [74]' BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf Write of size 1 at addr ... by task kworker/u16:0 mctp_serial_tty_receive_buf tty_ldisc_receive_buf flush_to_ldisc Allocated by task 152: alloc_netdev_mqs mctp_serial_open v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so the trailer/framing bytes are still consumed (Jeremy Kerr). Found by 0sec automated security-research tooling (https://0sec.ai).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68124", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HVLGllsBehzSBhTEViMXWg==": { "id": "HVLGllsBehzSBhTEViMXWg==", "updater": "debian/updater", "name": "CVE-2023-51792", "description": "Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-51792", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HWAHML6vgJHoz8eWpR0Tfg==": { "id": "HWAHML6vgJHoz8eWpR0Tfg==", "updater": "debian/updater", "name": "CVE-2026-68286", "description": "In the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were called after spin_unlock_irqrestore(\u0026...drop_queue.lock, flags), when local IRQs had already been re-enabled. Tracepoint probes can execute in IRQ or softirq context. On 32-bit architectures, u64_stats_update_begin() disables preemption but not interrupts, relying on seqcount writes. If a nested interrupt occurs on the same CPU during the 64-bit stats update, the reentrant seqcount update can corrupt the seqcount state or stats value. Fix this by performing the 64-bit per-CPU stats update before releasing drop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain disabled during the u64_stats update.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68286", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HbRvfbMLW4w7vP8bgDCrkw==": { "id": "HbRvfbMLW4w7vP8bgDCrkw==", "updater": "debian/updater", "name": "CVE-2025-68334", "description": "In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Add support for Van Gogh SoC The ROG Xbox Ally (non-X) SoC features a similar architecture to the Steam Deck. While the Steam Deck supports S3 (s2idle causes a crash), this support was dropped by the Xbox Ally which only S0ix suspend. Since the handler is missing here, this causes the device to not suspend and the AMD GPU driver to crash while trying to resume afterwards due to a power hang.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68334", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HhS2mtMKZlbYlHszwIEmdg==": { "id": "HhS2mtMKZlbYlHszwIEmdg==", "updater": "debian/updater", "name": "CVE-2025-12781", "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-12781", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HkgQtDnxOCfhb030V2ZyYg==": { "id": "HkgQtDnxOCfhb030V2ZyYg==", "updater": "debian/updater", "name": "CVE-2026-18220", "description": "An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access. A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system(). Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code. Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18220", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Hq2KZaE/Uj/paNzirKIsyA==": { "id": "Hq2KZaE/Uj/paNzirKIsyA==", "updater": "debian/updater", "name": "CVE-2025-68972", "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68972", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "HuLcwroM1rTmCRiMq0xq/A==": { "id": "HuLcwroM1rTmCRiMq0xq/A==", "updater": "debian/updater", "name": "CVE-2026-42497", "description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42497", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I/QRd9kPIn5zI7Mx9M0CGg==": { "id": "I/QRd9kPIn5zI7Mx9M0CGg==", "updater": "debian/updater", "name": "CVE-2026-68147", "description": "In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() When a blk_crypto_key starts being used or is evicted, fs/crypto/ calls fscrypt_get_devices() to get the filesystem's list of block devices, then iterates over them and calls blk_crypto_config_supported(), blk_crypto_start_using_key(), or blk_crypto_evict_key() on each one. Currently, the block device pointers are placed in a dynamically allocated array. This dynamic allocation is problematic because: - It can fail, especially at the fscrypt_destroy_inline_crypt_key() call site when it's invoked for inode eviction under direct reclaim. - fscrypt_destroy_inline_crypt_key() doesn't handle the failure. It just zeroizes and frees the blk_crypto_key without calling blk_crypto_evict_key(). That causes a use-after-free. For now, let's fix this in the straightforward and easily-backportable way by switching to an on-stack array. Currently the fscrypt multi-device functionality is used only by f2fs, which has a hardcoded limit of 8 block devices. An on-stack array works fine for that. (Of course, this solution won't scale up to large number of block devices. For that we'd need a different solution, like moving the block device iteration into the filesystem. Or in the case of btrfs, which will only support blk-crypto-fallback, we should make it just call blk-crypto-fallback directly, so the block devices won't be needed.)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68147", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I1DkQsTuELtTHEgBqr+BVg==": { "id": "I1DkQsTuELtTHEgBqr+BVg==", "updater": "debian/updater", "name": "CVE-2026-64392", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file unlink and the ADS xattr removal consequently run with the ksmbd worker credentials and can bypass filesystem permission checks. Run both operations with the credentials captured in struct file when the handle was opened. This preserves the authenticated user's fsuid, fsgid, supplementary groups and capability restrictions at final close.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64392", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I2QYqEV869V5y9popmkhNg==": { "id": "I2QYqEV869V5y9popmkhNg==", "updater": "debian/updater", "name": "CVE-2026-31724", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_eem: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -\u003e /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31724", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I5rQJEau/vCfHOUKEwAKEA==": { "id": "I5rQJEau/vCfHOUKEwAKEA==", "updater": "debian/updater", "name": "CVE-2025-22104", "description": "In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Use kernel helpers for hex dumps Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of 8 then a read buffer overflow was possible. Therefore, create a new ibmvnic function that loops over a buffer and calls hex_dump_to_buffer instead. This patch address KASAN reports like the one below: ibmvnic 30000003 env3: Login Buffer: ibmvnic 30000003 env3: 01000000af000000 \u003c...\u003e ibmvnic 30000003 env3: 2e6d62692e736261 ibmvnic 30000003 env3: 65050003006d6f63 ================================================================== BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic] Read of size 8 at addr c0000001331a9aa8 by task ip/17681 \u003c...\u003e Allocated by task 17681: \u003c...\u003e ibmvnic_login+0x2f0/0xffc [ibmvnic] ibmvnic_open+0x148/0x308 [ibmvnic] __dev_open+0x1ac/0x304 \u003c...\u003e The buggy address is located 168 bytes inside of allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf) \u003c...\u003e ================================================================= ibmvnic 30000003 env3: 000000000033766e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22104", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I7Gt+2KyC1KdZkKZ23jpSA==": { "id": "I7Gt+2KyC1KdZkKZ23jpSA==", "updater": "debian/updater", "name": "CVE-2026-68197", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc-\u003ebcn_ht_cap being present, but then dereferences a different pointer, bss_desc-\u003ebcn_ht_oper: \tif (ISSUPP_CHANWIDTH40(priv-\u003eadapter-\u003ehw_dot_11n_dev_cap) \u0026\u0026 \t bss_desc-\u003ebcn_ht_cap \u0026\u0026 \t ISALLOWED_CHANWIDTH40(bss_desc-\u003ebcn_ht_oper-\u003eht_param)) bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first. Guard on the pointer that is actually dereferenced. Found by 0sec automated security-research tooling (https://0sec.ai).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68197", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "I9owf7FzH3E77Ei9S343oA==": { "id": "I9owf7FzH3E77Ei9S343oA==", "updater": "debian/updater", "name": "CVE-2025-71313", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_workqueue() alloc_workqueue() can return NULL on memory allocation failure. Without proper error checking, this may lead to a NULL pointer dereference when queue_work() is later called with the NULL workqueue pointer in epf_ntb_epc_init(). Add a NULL check immediately after alloc_workqueue() and return -ENOMEM on failure to prevent the driver from loading with an invalid workqueue pointer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71313", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IAC/C79xmpc7WEKnnXFbpg==": { "id": "IAC/C79xmpc7WEKnnXFbpg==", "updater": "debian/updater", "name": "CVE-2025-38264", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38264", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IFNW9YBko8LrXi4D/GCQ9A==": { "id": "IFNW9YBko8LrXi4D/GCQ9A==", "updater": "debian/updater", "name": "CVE-2018-1000021", "description": "GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-1000021", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "git", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IHXe4WyflrmOusIwp8d5Nw==": { "id": "IHXe4WyflrmOusIwp8d5Nw==", "updater": "debian/updater", "name": "CVE-2024-41045", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Defer work in bpf_timer_cancel_and_free Currently, the same case as previous patch (two timer callbacks trying to cancel each other) can be invoked through bpf_map_update_elem as well, or more precisely, freeing map elements containing timers. Since this relies on hrtimer_cancel as well, it is prone to the same deadlock situation as the previous patch. It would be sufficient to use hrtimer_try_to_cancel to fix this problem, as the timer cannot be enqueued after async_cancel_and_free. Once async_cancel_and_free has been done, the timer must be reinitialized before it can be armed again. The callback running in parallel trying to arm the timer will fail, and freeing bpf_hrtimer without waiting is sufficient (given kfree_rcu), and bpf_timer_cb will return HRTIMER_NORESTART, preventing the timer from being rearmed again. However, there exists a UAF scenario where the callback arms the timer before entering this function, such that if cancellation fails (due to timer callback invoking this routine, or the target timer callback running concurrently). In such a case, if the timer expiration is significantly far in the future, the RCU grace period expiration happening before it will free the bpf_hrtimer state and along with it the struct hrtimer, that is enqueued. Hence, it is clear cancellation needs to occur after async_cancel_and_free, and yet it cannot be done inline due to deadlock issues. We thus modify bpf_timer_cancel_and_free to defer work to the global workqueue, adding a work_struct alongside rcu_head (both used at _different_ points of time, so can share space). Update existing code comments to reflect the new state of affairs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41045", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IJDoATEPeUuA9XUXGUVO/g==": { "id": "IJDoATEPeUuA9XUXGUVO/g==", "updater": "debian/updater", "name": "CVE-2026-43126", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: mixer: oss: Add card disconnect checkpoints ALSA OSS mixer layer calls the kcontrol ops rather individually, and pending calls might be not always caught at disconnecting the device. For avoiding the potential UAF scenarios, add sanity checks of the card disconnection at each entry point of OSS mixer accesses. The rwsem is taken just before that check, hence the rest context should be covered by that properly.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43126", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IL1jRXwy2114/T7QtgavEQ==": { "id": "IL1jRXwy2114/T7QtgavEQ==", "updater": "debian/updater", "name": "CVE-2024-58006", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar() In commit 4284c88fff0e (\"PCI: designware-ep: Allow pci_epc_set_bar() update inbound map address\") set_bar() was modified to support dynamically changing the backing physical address of a BAR that was already configured. This means that set_bar() can be called twice, without ever calling clear_bar() (as calling clear_bar() would clear the BAR's PCI address assigned by the host). This can only be done if the new BAR size/flags does not differ from the existing BAR configuration. Add these missing checks. If we allow set_bar() to set e.g. a new BAR size that differs from the existing BAR size, the new address translation range will be smaller than the BAR size already determined by the host, which would mean that a read past the new BAR size would pass the iATU untranslated, which could allow the host to read memory not belonging to the new struct pci_epf_bar. While at it, add comments which clarifies the support for dynamically changing the physical address of a BAR. (Which was also missing.)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58006", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ILz/vDgVPgLngI8Xhmb//g==": { "id": "ILz/vDgVPgLngI8Xhmb//g==", "updater": "debian/updater", "name": "CVE-2026-68447", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU checkpoint copies the MQD control stack using cp_hqd_cntl_stack_size from hardware without bounding it to the allocated BO region. If the HW field is larger than the queue's control stack allocation, memcpy reads past the BO into adjacent GTT memory and can leak kernel data to userspace. Store the page-aligned control stack BO size in mqd_manager and clamp checkpoint copies and reported checkpoint sizes to min(cp_hqd_cntl_stack_size, mm-\u003ectl_stack_size). Apply the same bound for multi-XCC v9.4.3 checkpoint layout. (cherry picked from commit 6c2abd0ec09e86c6323010673766f76050e28aa3)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68447", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "INNgEif+mrTP5jbRcGV3pQ==": { "id": "INNgEif+mrTP5jbRcGV3pQ==", "updater": "debian/updater", "name": "CVE-2026-68131", "description": "In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object map update path In a reply message to an RBD request, a positive result code indicates a data payload, which is not allowed for writes. While rbd_osd_req_callback() already resets a positive result code for writes to zero, rbd_object_map_callback() does not. This allows a corrupted reply to an object map update to trigger the rbd_assert(*result \u003c 0) in __rbd_obj_handle_request(). This happens, because rbd_object_map_callback() calls rbd_obj_handle_request() -\u003e __rbd_obj_handle_request() and passes this positive result code. From __rbd_obj_handle_request(), rbd_obj_advance_write() is called, which leaves the positive result code unchanged and returns true. Therefore, the if(done \u0026\u0026 *result) branch is executed in __rbd_obj_handle_request() and the assertion triggers. This patch fixes the issue by adjusting the logic in the rbd_object_map_callback() path. A positive result code for an object map update is now reset to zero (similar to rbd_osd_req_callback()), and the message is subsequently handled the same way as if the result code was zero from the beginning. Additionally, a WARN_ON_ONCE() is added for this case.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68131", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IOSxX+ObQIo5oS9dnmmDoA==": { "id": "IOSxX+ObQIo5oS9dnmmDoA==", "updater": "debian/updater", "name": "CVE-2024-53089", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard interrupt context Like commit 2c0d278f3293f (\"KVM: LAPIC: Mark hrtimer to expire in hard interrupt context\") and commit 9090825fa9974 (\"KVM: arm/arm64: Let the timer expire in hardirq context on RT\"), On PREEMPT_RT enabled kernels unmarked hrtimers are moved into soft interrupt expiry mode by default. Then the timers are canceled from an preempt-notifier which is invoked with disabled preemption which is not allowed on PREEMPT_RT. The timer callback is short so in could be invoked in hard-IRQ context. So let the timer expire on hard-IRQ context even on -RT. This fix a \"scheduling while atomic\" bug for PREEMPT_RT enabled kernels: BUG: scheduling while atomic: qemu-system-loo/1011/0x00000002 Modules linked in: amdgpu rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ns CPU: 1 UID: 0 PID: 1011 Comm: qemu-system-loo Tainted: G W 6.12.0-rc2+ #1774 Tainted: [W]=WARN Hardware name: Loongson Loongson-3A5000-7A1000-1w-CRB/Loongson-LS3A5000-7A1000-1w-CRB, BIOS vUDK2018-LoongArch-V2.0.0-prebeta9 10/21/2022 Stack : ffffffffffffffff 0000000000000000 9000000004e3ea38 9000000116744000 90000001167475a0 0000000000000000 90000001167475a8 9000000005644830 90000000058dc000 90000000058dbff8 9000000116747420 0000000000000001 0000000000000001 6a613fc938313980 000000000790c000 90000001001c1140 00000000000003fe 0000000000000001 000000000000000d 0000000000000003 0000000000000030 00000000000003f3 000000000790c000 9000000116747830 90000000057ef000 0000000000000000 9000000005644830 0000000000000004 0000000000000000 90000000057f4b58 0000000000000001 9000000116747868 900000000451b600 9000000005644830 9000000003a13998 0000000010000020 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1d ... Call Trace: [\u003c9000000003a13998\u003e] show_stack+0x38/0x180 [\u003c9000000004e3ea34\u003e] dump_stack_lvl+0x84/0xc0 [\u003c9000000003a71708\u003e] __schedule_bug+0x48/0x60 [\u003c9000000004e45734\u003e] __schedule+0x1114/0x1660 [\u003c9000000004e46040\u003e] schedule_rtlock+0x20/0x60 [\u003c9000000004e4e330\u003e] rtlock_slowlock_locked+0x3f0/0x10a0 [\u003c9000000004e4f038\u003e] rt_spin_lock+0x58/0x80 [\u003c9000000003b02d68\u003e] hrtimer_cancel_wait_running+0x68/0xc0 [\u003c9000000003b02e30\u003e] hrtimer_cancel+0x70/0x80 [\u003cffff80000235eb70\u003e] kvm_restore_timer+0x50/0x1a0 [kvm] [\u003cffff8000023616c8\u003e] kvm_arch_vcpu_load+0x68/0x2a0 [kvm] [\u003cffff80000234c2d4\u003e] kvm_sched_in+0x34/0x60 [kvm] [\u003c9000000003a749a0\u003e] finish_task_switch.isra.0+0x140/0x2e0 [\u003c9000000004e44a70\u003e] __schedule+0x450/0x1660 [\u003c9000000004e45cb0\u003e] schedule+0x30/0x180 [\u003cffff800002354c70\u003e] kvm_vcpu_block+0x70/0x120 [kvm] [\u003cffff800002354d80\u003e] kvm_vcpu_halt+0x60/0x3e0 [kvm] [\u003cffff80000235b194\u003e] kvm_handle_gspr+0x3f4/0x4e0 [kvm] [\u003cffff80000235f548\u003e] kvm_handle_exit+0x1c8/0x260 [kvm]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53089", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IRuMvMA8Fi6mQgkH9s634w==": { "id": "IRuMvMA8Fi6mQgkH9s634w==", "updater": "debian/updater", "name": "CVE-2026-43250", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke() The ChipIdea UDC driver can encounter \"not page aligned sg buffer\" errors when a USB device is reconnected after being disconnected during an active transfer. This occurs because _ep_nuke() returns requests to the gadget layer without properly unmapping DMA buffers or cleaning up scatter-gather bounce buffers. Root cause: When a disconnect happens during a multi-segment DMA transfer, the request's num_mapped_sgs field and sgt.sgl pointer remain set with stale values. The request is returned to the gadget driver with status -ESHUTDOWN but still has active DMA state. If the gadget driver reuses this request on reconnect without reinitializing it, the stale DMA state causes _hardware_enqueue() to skip DMA mapping (seeing non-zero num_mapped_sgs) and attempt to use freed/invalid DMA addresses, leading to alignment errors and potential memory corruption. The normal completion path via _hardware_dequeue() properly calls usb_gadget_unmap_request_by_dev() and sglist_do_debounce() before returning the request. The _ep_nuke() path must do the same cleanup to ensure requests are returned in a clean, reusable state. Fix: Add DMA unmapping and bounce buffer cleanup to _ep_nuke() to mirror the cleanup sequence in _hardware_dequeue(): - Call usb_gadget_unmap_request_by_dev() if num_mapped_sgs is set - Call sglist_do_debounce() with copy=false if bounce buffer exists This ensures that when requests are returned due to endpoint shutdown, they don't retain stale DMA mappings. The 'false' parameter to sglist_do_debounce() prevents copying data back (appropriate for shutdown path where transfer was aborted).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43250", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IVCa8wAzO7odLR515cEXxw==": { "id": "IVCa8wAzO7odLR515cEXxw==", "updater": "debian/updater", "name": "CVE-2024-38608", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix netif state handling mlx5e_suspend cleans resources only if netif_device_present() returns true. However, mlx5e_resume changes the state of netif, via mlx5e_nic_enable, only if reg_state == NETREG_REGISTERED. In the below case, the above leads to NULL-ptr Oops[1] and memory leaks: mlx5e_probe _mlx5e_resume mlx5e_attach_netdev mlx5e_nic_enable \u003c-- netdev not reg, not calling netif_device_attach() register_netdev \u003c-- failed for some reason. ERROR_FLOW: _mlx5e_suspend \u003c-- netif_device_present return false, resources aren't freed :( Hence, clean resources in this case as well. [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0010 [#1] SMP CPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:0x0 Code: Unable to access opcode bytes at0xffffffffffffffd6. RSP: 0018:ffff888178aaf758 EFLAGS: 00010246 Call Trace: \u003cTASK\u003e ? __die+0x20/0x60 ? page_fault_oops+0x14c/0x3c0 ? exc_page_fault+0x75/0x140 ? asm_exc_page_fault+0x22/0x30 notifier_call_chain+0x35/0xb0 blocking_notifier_call_chain+0x3d/0x60 mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core] mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core] mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib] mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib] __mlx5_ib_add+0x34/0xd0 [mlx5_ib] mlx5r_probe+0xe1/0x210 [mlx5_ib] ? auxiliary_match_id+0x6a/0x90 auxiliary_bus_probe+0x38/0x80 ? driver_sysfs_add+0x51/0x80 really_probe+0xc9/0x3e0 ? driver_probe_device+0x90/0x90 __driver_probe_device+0x80/0x160 driver_probe_device+0x1e/0x90 __device_attach_driver+0x7d/0x100 bus_for_each_drv+0x80/0xd0 __device_attach+0xbc/0x1f0 bus_probe_device+0x86/0xa0 device_add+0x637/0x840 __auxiliary_device_add+0x3b/0xa0 add_adev+0xc9/0x140 [mlx5_core] mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core] mlx5_register_device+0x53/0xa0 [mlx5_core] mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core] mlx5_init_one+0x3b/0x60 [mlx5_core] probe_one+0x44c/0x730 [mlx5_core] local_pci_probe+0x3e/0x90 pci_device_probe+0xbf/0x210 ? kernfs_create_link+0x5d/0xa0 ? sysfs_do_create_link_sd+0x60/0xc0 really_probe+0xc9/0x3e0 ? driver_probe_device+0x90/0x90 __driver_probe_device+0x80/0x160 driver_probe_device+0x1e/0x90 __device_attach_driver+0x7d/0x100 bus_for_each_drv+0x80/0xd0 __device_attach+0xbc/0x1f0 pci_bus_add_device+0x54/0x80 pci_iov_add_virtfn+0x2e6/0x320 sriov_enable+0x208/0x420 mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core] sriov_numvfs_store+0xae/0x1a0 kernfs_fop_write_iter+0x10c/0x1a0 vfs_write+0x291/0x3c0 ksys_write+0x5f/0xe0 do_syscall_64+0x3d/0x90 entry_SYSCALL_64_after_hwframe+0x46/0xb0 CR2: 0000000000000000 ---[ end trace 0000000000000000 ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38608", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IYakbfCoZsMxgfjVJB5OPQ==": { "id": "IYakbfCoZsMxgfjVJB5OPQ==", "updater": "debian/updater", "name": "CVE-2026-8286", "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8286", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IckWa2ni3hDgKetUO6msAg==": { "id": "IckWa2ni3hDgKetUO6msAg==", "updater": "debian/updater", "name": "CVE-2022-24975", "description": "The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-24975", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "git", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IeoitvM9lwggrk3KXJzR/A==": { "id": "IeoitvM9lwggrk3KXJzR/A==", "updater": "debian/updater", "name": "CVE-2019-1010023", "description": "GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-1010023", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IhzBtHWmglxBKo+mcln/Dw==": { "id": "IhzBtHWmglxBKo+mcln/Dw==", "updater": "debian/updater", "name": "CVE-2025-40146", "description": "In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix potential deadlock while nr_requests grown Allocate and free sched_tags while queue is freezed can deadlock[1], this is a long term problem, hence allocate memory before freezing queue and free memory after queue is unfreezed. [1] https://lore.kernel.org/all/0659ea8d-a463-47c8-9180-43c719e106eb@linux.ibm.com/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40146", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IiHIqbVmvG4EG9wLjhDnjQ==": { "id": "IiHIqbVmvG4EG9wLjhDnjQ==", "updater": "debian/updater", "name": "CVE-2023-31437", "description": "An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31437", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IiNBd3UzYec5KOagj4deCg==": { "id": "IiNBd3UzYec5KOagj4deCg==", "updater": "debian/updater", "name": "CVE-2024-47703", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf, lsm: Add check for BPF LSM return value A bpf prog returning a positive number attached to file_alloc_security hook makes kernel panic. This happens because file system can not filter out the positive number returned by the LSM prog using IS_ERR, and misinterprets this positive number as a file pointer. Given that hook file_alloc_security never returned positive number before the introduction of BPF LSM, and other BPF LSM hooks may encounter similar issues, this patch adds LSM return value check in verifier, to ensure no unexpected value is returned.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47703", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IkSL3kbr93i9k/D1z8DQOw==": { "id": "IkSL3kbr93i9k/D1z8DQOw==", "updater": "debian/updater", "name": "CVE-2024-56592", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Call free_htab_elem() after htab_unlock_bucket() For htab of maps, when the map is removed from the htab, it may hold the last reference of the map. bpf_map_fd_put_ptr() will invoke bpf_map_free_id() to free the id of the removed map element. However, bpf_map_fd_put_ptr() is invoked while holding a bucket lock (raw_spin_lock_t), and bpf_map_free_id() attempts to acquire map_idr_lock (spinlock_t), triggering the following lockdep warning: ============================= [ BUG: Invalid wait context ] 6.11.0-rc4+ #49 Not tainted ----------------------------- test_maps/4881 is trying to lock: ffffffff84884578 (map_idr_lock){+...}-{3:3}, at: bpf_map_free_id.part.0+0x21/0x70 other info that might help us debug this: context-{5:5} 2 locks held by test_maps/4881: #0: ffffffff846caf60 (rcu_read_lock){....}-{1:3}, at: bpf_fd_htab_map_update_elem+0xf9/0x270 #1: ffff888149ced148 (\u0026htab-\u003elockdep_key#2){....}-{2:2}, at: htab_map_update_elem+0x178/0xa80 stack backtrace: CPU: 0 UID: 0 PID: 4881 Comm: test_maps Not tainted 6.11.0-rc4+ #49 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), ... Call Trace: \u003cTASK\u003e dump_stack_lvl+0x6e/0xb0 dump_stack+0x10/0x20 __lock_acquire+0x73e/0x36c0 lock_acquire+0x182/0x450 _raw_spin_lock_irqsave+0x43/0x70 bpf_map_free_id.part.0+0x21/0x70 bpf_map_put+0xcf/0x110 bpf_map_fd_put_ptr+0x9a/0xb0 free_htab_elem+0x69/0xe0 htab_map_update_elem+0x50f/0xa80 bpf_fd_htab_map_update_elem+0x131/0x270 htab_map_update_elem+0x50f/0xa80 bpf_fd_htab_map_update_elem+0x131/0x270 bpf_map_update_value+0x266/0x380 __sys_bpf+0x21bb/0x36b0 __x64_sys_bpf+0x45/0x60 x64_sys_call+0x1b2a/0x20d0 do_syscall_64+0x5d/0x100 entry_SYSCALL_64_after_hwframe+0x76/0x7e One way to fix the lockdep warning is using raw_spinlock_t for map_idr_lock as well. However, bpf_map_alloc_id() invokes idr_alloc_cyclic() after acquiring map_idr_lock, it will trigger a similar lockdep warning because the slab's lock (s-\u003ecpu_slab-\u003elock) is still a spinlock. Instead of changing map_idr_lock's type, fix the issue by invoking htab_put_fd_value() after htab_unlock_bucket(). However, only deferring the invocation of htab_put_fd_value() is not enough, because the old map pointers in htab of maps can not be saved during batched deletion. Therefore, also defer the invocation of free_htab_elem(), so these to-be-freed elements could be linked together similar to lru map. There are four callers for -\u003emap_fd_put_ptr: (1) alloc_htab_elem() (through htab_put_fd_value()) It invokes -\u003emap_fd_put_ptr() under a raw_spinlock_t. The invocation of htab_put_fd_value() can not simply move after htab_unlock_bucket(), because the old element has already been stashed in htab-\u003eextra_elems. It may be reused immediately after htab_unlock_bucket() and the invocation of htab_put_fd_value() after htab_unlock_bucket() may release the newly-added element incorrectly. Therefore, saving the map pointer of the old element for htab of maps before unlocking the bucket and releasing the map_ptr after unlock. Beside the map pointer in the old element, should do the same thing for the special fields in the old element as well. (2) free_htab_elem() (through htab_put_fd_value()) Its caller includes __htab_map_lookup_and_delete_elem(), htab_map_delete_elem() and __htab_map_lookup_and_delete_batch(). For htab_map_delete_elem(), simply invoke free_htab_elem() after htab_unlock_bucket(). For __htab_map_lookup_and_delete_batch(), just like lru map, linking the to-be-freed element into node_to_free list and invoking free_htab_elem() for these element after unlock. It is safe to reuse batch_flink as the link for node_to_free, because these elements have been removed from the hash llist. Because htab of maps doesn't support lookup_and_delete operation, __htab_map_lookup_and_delete_elem() doesn't have the problem, so kept it as ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56592", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ImTupm53kNU++C083mygDw==": { "id": "ImTupm53kNU++C083mygDw==", "updater": "debian/updater", "name": "CVE-2026-64272", "description": "In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and MMS136 The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes. When __mms114_read_reg() reads the touch data packet from the device into the touch buffer, the events are packed tightly at 6-byte intervals. However, the driver iterates through the events using standard C array indexing (touch[index]), where each element is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any touch events beyond the first one are read from incorrect offsets and parsed improperly. Fix this by explicitly calculating the byte offset for each touch event based on the device's specific event size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64272", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IpfbTVt+g1kooJABwZClSw==": { "id": "IpfbTVt+g1kooJABwZClSw==", "updater": "debian/updater", "name": "CVE-2025-8534", "description": "A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that \"[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. \"rD\") option is used.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8534", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IuRLsRsG56+n47x1CeHN2g==": { "id": "IuRLsRsG56+n47x1CeHN2g==", "updater": "debian/updater", "name": "CVE-2026-53115", "description": "In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53115", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IvNyA4RScflkfrHyoUsbww==": { "id": "IvNyA4RScflkfrHyoUsbww==", "updater": "debian/updater", "name": "TEMP-0000000-F7A20F", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0000000-F7A20F", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "IvtNhBs9EBdfQJVcaS8g/Q==": { "id": "IvtNhBs9EBdfQJVcaS8g/Q==", "updater": "debian/updater", "name": "CVE-2025-39767", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Optimize module load time by optimizing PLT/GOT counting When enabling CONFIG_KASAN, CONFIG_PREEMPT_VOLUNTARY_BUILD and CONFIG_PREEMPT_VOLUNTARY at the same time, there will be soft deadlock, the relevant logs are as follows: rcu: INFO: rcu_sched self-detected stall on CPU ... Call Trace: [\u003c900000000024f9e4\u003e] show_stack+0x5c/0x180 [\u003c90000000002482f4\u003e] dump_stack_lvl+0x94/0xbc [\u003c9000000000224544\u003e] rcu_dump_cpu_stacks+0x1fc/0x280 [\u003c900000000037ac80\u003e] rcu_sched_clock_irq+0x720/0xf88 [\u003c9000000000396c34\u003e] update_process_times+0xb4/0x150 [\u003c90000000003b2474\u003e] tick_nohz_handler+0xf4/0x250 [\u003c9000000000397e28\u003e] __hrtimer_run_queues+0x1d0/0x428 [\u003c9000000000399b2c\u003e] hrtimer_interrupt+0x214/0x538 [\u003c9000000000253634\u003e] constant_timer_interrupt+0x64/0x80 [\u003c9000000000349938\u003e] __handle_irq_event_percpu+0x78/0x1a0 [\u003c9000000000349a78\u003e] handle_irq_event_percpu+0x18/0x88 [\u003c9000000000354c00\u003e] handle_percpu_irq+0x90/0xf0 [\u003c9000000000348c74\u003e] handle_irq_desc+0x94/0xb8 [\u003c9000000001012b28\u003e] handle_cpu_irq+0x68/0xa0 [\u003c9000000001def8c0\u003e] handle_loongarch_irq+0x30/0x48 [\u003c9000000001def958\u003e] do_vint+0x80/0xd0 [\u003c9000000000268a0c\u003e] kasan_mem_to_shadow.part.0+0x2c/0x2a0 [\u003c90000000006344f4\u003e] __asan_load8+0x4c/0x120 [\u003c900000000025c0d0\u003e] module_frob_arch_sections+0x5c8/0x6b8 [\u003c90000000003895f0\u003e] load_module+0x9e0/0x2958 [\u003c900000000038b770\u003e] __do_sys_init_module+0x208/0x2d0 [\u003c9000000001df0c34\u003e] do_syscall+0x94/0x190 [\u003c900000000024d6fc\u003e] handle_syscall+0xbc/0x158 After analysis, this is because the slow speed of loading the amdgpu module leads to the long time occupation of the cpu and then the soft deadlock. When loading a module, module_frob_arch_sections() tries to figure out the number of PLTs/GOTs that will be needed to handle all the RELAs. It will call the count_max_entries() to find in an out-of-order date which counting algorithm has O(n^2) complexity. To make it faster, we sort the relocation list by info and addend. That way, to check for a duplicate relocation, it just needs to compare with the previous entry. This reduces the complexity of the algorithm to O(n log n), as done in commit d4e0340919fb (\"arm64/module: Optimize module load time by optimizing PLT counting\"). This gives sinificant reduction in module load time for modules with large number of relocations. After applying this patch, the soft deadlock problem has been solved, and the kernel starts normally without \"Call Trace\". Using the default configuration to test some modules, the results are as follows: Module Size ip_tables 36K fat 143K radeon 2.5MB amdgpu 16MB Without this patch: Module Module load time (ms)\tCount(PLTs/GOTs) ip_tables 18\t\t\t\t59/6 fat 0\t\t\t\t162/14 radeon 54\t\t\t\t1221/84 amdgpu 1411\t\t\t4525/1098 With this patch: Module Module load time (ms)\tCount(PLTs/GOTs) ip_tables 18\t\t\t\t59/6 fat 0\t\t\t\t162/14 radeon 22\t\t\t\t1221/84 amdgpu 45\t\t\t\t4525/1098", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39767", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Iyl2+BN5OE2iopIsMT0Wsg==": { "id": "Iyl2+BN5OE2iopIsMT0Wsg==", "updater": "debian/updater", "name": "CVE-2025-38006", "description": "In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In mctp_dump_addrinfo, ifa_index can be used to filter interfaces, but only when the struct ifaddrmsg is provided. Otherwise it will be comparing to uninitialised memory - reproducible in the syzkaller case from dhcpd, or busybox \"ip addr show\". The kernel MCTP implementation has always filtered by ifa_index, so existing userspace programs expecting to dump MCTP addresses must already be passing a valid ifa_index value (either 0 or a real index). BUG: KMSAN: uninit-value in mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128 mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128 rtnl_dump_all+0x3ec/0x5b0 net/core/rtnetlink.c:4380 rtnl_dumpit+0xd5/0x2f0 net/core/rtnetlink.c:6824 netlink_dump+0x97b/0x1690 net/netlink/af_netlink.c:2309", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38006", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J+BMNtoyQOWexo7hrmq3rA==": { "id": "J+BMNtoyQOWexo7hrmq3rA==", "updater": "debian/updater", "name": "CVE-2026-4647", "description": "A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-4647", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J2eGA05DEwryfnUENIziAw==": { "id": "J2eGA05DEwryfnUENIziAw==", "updater": "debian/updater", "name": "CVE-2025-69720", "description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69720", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J8jkPCTciB9Y+QEeYk9/ZA==": { "id": "J8jkPCTciB9Y+QEeYk9/ZA==", "updater": "debian/updater", "name": "CVE-2026-63826", "description": "In the Linux kernel, the following vulnerability has been resolved: fbdev: fix use-after-free in store_modes() store_modes() replaces a framebuffer's modelist with modes from userspace. On success it frees the old modelist with fb_destroy_modelist(). Two fields still point into that freed list. One pointer is fb_display[i].mode, the mode a console is using. fbcon_new_modelist() moves these pointers to the new list. It only does so for consoles still mapped to the framebuffer. An unmapped console is skipped and keeps its stale pointer. Unbinding fbcon, for example, sets con2fb_map[i] to -1 but leaves fb_display[i].mode set. An FBIOPUT_VSCREENINFO ioctl with FB_ACTIVATE_INV_MODE later reaches fbcon_mode_deleted(). That function reads the stale fb_display[i].mode through fb_mode_is_equal(). The read is a use-after-free. The other pointer is fb_info-\u003emode, the current mode. It is set through the mode sysfs attribute. store_modes() does not update fb_info-\u003emode, so it is left pointing into the freed list. show_mode(), the attribute's read handler, dereferences the stale fb_info-\u003emode through mode_string(). The read is a use-after-free. Clear both pointers before freeing the list. Commit a1f305893074 (\"fbcon: Set fb_display[i]-\u003emode to NULL when the mode is released\") added the helper fbcon_delete_modelist(). It clears every fb_display[i].mode that points into a given list. So far it is called only from the unregister path. Call it from store_modes() too, and set fb_info-\u003emode to NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63826", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "J98qdwAtIlFmuTWiWH2dZA==": { "id": "J98qdwAtIlFmuTWiWH2dZA==", "updater": "debian/updater", "name": "CVE-2024-53187", "description": "In the Linux kernel, the following vulnerability has been resolved: io_uring: check for overflows in io_pin_pages WARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144 CPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0 Call Trace: \u003cTASK\u003e __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183 io_rings_map io_uring/io_uring.c:2611 [inline] io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470 io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692 io_uring_setup io_uring/io_uring.c:3781 [inline] ... \u003c/TASK\u003e io_pin_pages()'s uaddr parameter came directly from the user and can be garbage. Don't just add size to it as it can overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53187", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JCBjk0sch/mgIqnyRjXsZw==": { "id": "JCBjk0sch/mgIqnyRjXsZw==", "updater": "debian/updater", "name": "TEMP-1142906-2C6C79", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-1142906-2C6C79", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "unzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JDTAxWidVWpCaBoteYh51g==": { "id": "JDTAxWidVWpCaBoteYh51g==", "updater": "debian/updater", "name": "CVE-2026-68113", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit f952076f76d62f783e8ba4995a7c400d39354ccf)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68113", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JENS6w0/SSPbnjHI5uhkLg==": { "id": "JENS6w0/SSPbnjHI5uhkLg==", "updater": "debian/updater", "name": "CVE-2025-50422", "description": "Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled-\u003eface == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-50422", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "cairo", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JF+sYH11Tbao/uQQ3R4oJQ==": { "id": "JF+sYH11Tbao/uQQ3R4oJQ==", "updater": "debian/updater", "name": "CVE-2026-57062", "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-57062", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JQ1E3FLXucARkh38lJeV9g==": { "id": "JQ1E3FLXucARkh38lJeV9g==", "updater": "debian/updater", "name": "CVE-2025-10911", "description": "A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-10911", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libxslt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JUvDbSDk41M9/2isiLVsVA==": { "id": "JUvDbSDk41M9/2isiLVsVA==", "updater": "debian/updater", "name": "CVE-2026-68151", "description": "In the Linux kernel, the following vulnerability has been resolved: binfmt_elf_fdpic: only honour the first PT_INTERP The program header scan handles PT_INTERP from a switch nested in the scan loop, so its break leaves the switch and not the loop. A binary carrying more than one PT_INTERP runs the case again and overwrites both interpreter_name and interpreter. The previous name allocation leaks and so does the previous interpreter reference, along with the write denial open_exec() took on it. The denial is never released, so the file stays unwritable for as long as the system runs. An unprivileged caller reaches this with a crafted binary and repeats it at will. binfmt_elf stops at the first PT_INTERP. Do the same here. The flaw dates back to the driver's introduction in the pre-git history tree introduced in v2.6.11 by 91808d6ebe39 (\"[PATCH] FRV: Add FDPIC ELF binary format driver\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68151", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JVCst7rPc5C+mXRLD/3i7A==": { "id": "JVCst7rPc5C+mXRLD/3i7A==", "updater": "debian/updater", "name": "CVE-2025-69650", "description": "GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69650", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JVgYJrtjksiu+imyHUIFaQ==": { "id": "JVgYJrtjksiu+imyHUIFaQ==", "updater": "debian/updater", "name": "CVE-2026-45957", "description": "In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to softirq Commit 5f5fa7ea89dc (\"rcu: Don't use negative nesting depth in __rcu_read_unlock()\") removes the recursion-protection code from __rcu_read_unlock(). Therefore, we could invoke the deadloop in raise_softirq_irqoff() with ftrace enabled as follows: WARNING: CPU: 0 PID: 0 at kernel/trace/trace.c:3021 __ftrace_trace_stack.constprop.0+0x172/0x180 Modules linked in: my_irq_work(O) CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Tainted: G O 6.18.0-rc7-dirty #23 PREEMPT(full) Tainted: [O]=OOT_MODULE Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:__ftrace_trace_stack.constprop.0+0x172/0x180 RSP: 0018:ffffc900000034a8 EFLAGS: 00010002 RAX: 0000000000000000 RBX: 0000000000000004 RCX: 0000000000000000 RDX: 0000000000000003 RSI: ffffffff826d7b87 RDI: ffffffff826e9329 RBP: 0000000000090009 R08: 0000000000000005 R09: ffffffff82afbc4c R10: 0000000000000008 R11: 0000000000011d7a R12: 0000000000000000 R13: ffff888003874100 R14: 0000000000000003 R15: ffff8880038c1054 FS: 0000000000000000(0000) GS:ffff8880fa8ea000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055b31fa7f540 CR3: 00000000078f4005 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace: \u003cIRQ\u003e trace_buffer_unlock_commit_regs+0x6d/0x220 trace_event_buffer_commit+0x5c/0x260 trace_event_raw_event_softirq+0x47/0x80 raise_softirq_irqoff+0x6e/0xa0 rcu_read_unlock_special+0xb1/0x160 unwind_next_frame+0x203/0x9b0 __unwind_start+0x15d/0x1c0 arch_stack_walk+0x62/0xf0 stack_trace_save+0x48/0x70 __ftrace_trace_stack.constprop.0+0x144/0x180 trace_buffer_unlock_commit_regs+0x6d/0x220 trace_event_buffer_commit+0x5c/0x260 trace_event_raw_event_softirq+0x47/0x80 raise_softirq_irqoff+0x6e/0xa0 rcu_read_unlock_special+0xb1/0x160 unwind_next_frame+0x203/0x9b0 __unwind_start+0x15d/0x1c0 arch_stack_walk+0x62/0xf0 stack_trace_save+0x48/0x70 __ftrace_trace_stack.constprop.0+0x144/0x180 trace_buffer_unlock_commit_regs+0x6d/0x220 trace_event_buffer_commit+0x5c/0x260 trace_event_raw_event_softirq+0x47/0x80 raise_softirq_irqoff+0x6e/0xa0 rcu_read_unlock_special+0xb1/0x160 unwind_next_frame+0x203/0x9b0 __unwind_start+0x15d/0x1c0 arch_stack_walk+0x62/0xf0 stack_trace_save+0x48/0x70 __ftrace_trace_stack.constprop.0+0x144/0x180 trace_buffer_unlock_commit_regs+0x6d/0x220 trace_event_buffer_commit+0x5c/0x260 trace_event_raw_event_softirq+0x47/0x80 raise_softirq_irqoff+0x6e/0xa0 rcu_read_unlock_special+0xb1/0x160 __is_insn_slot_addr+0x54/0x70 kernel_text_address+0x48/0xc0 __kernel_text_address+0xd/0x40 unwind_get_return_address+0x1e/0x40 arch_stack_walk+0x9c/0xf0 stack_trace_save+0x48/0x70 __ftrace_trace_stack.constprop.0+0x144/0x180 trace_buffer_unlock_commit_regs+0x6d/0x220 trace_event_buffer_commit+0x5c/0x260 trace_event_raw_event_softirq+0x47/0x80 __raise_softirq_irqoff+0x61/0x80 __flush_smp_call_function_queue+0x115/0x420 __sysvec_call_function_single+0x17/0xb0 sysvec_call_function_single+0x8c/0xc0 \u003c/IRQ\u003e Commit b41642c87716 (\"rcu: Fix rcu_read_unlock() deadloop due to IRQ work\") fixed the infinite loop in rcu_read_unlock_special() for IRQ work by setting a flag before calling irq_work_queue_on(). We fix this issue by setting the same flag before calling raise_softirq_irqoff() and rename the flag to defer_qs_pending for more common.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45957", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JbzslWZ8XhHtjGeJPRHhkA==": { "id": "JbzslWZ8XhHtjGeJPRHhkA==", "updater": "debian/updater", "name": "CVE-2026-23000", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash on profile change rollback failure mlx5e_netdev_change_profile can fail to attach a new profile and can fail to rollback to old profile, in such case, we could end up with a dangling netdev with a fully reset netdev_priv. A retry to change profile, e.g. another attempt to call mlx5e_netdev_change_profile via switchdev mode change, will crash trying to access the now NULL priv-\u003emdev. This fix allows mlx5e_netdev_change_profile() to handle previous failures and an empty priv, by not assuming priv is valid. Pass netdev and mdev to all flows requiring mlx5e_netdev_change_profile() and avoid passing priv. In mlx5e_netdev_change_profile() check if current priv is valid, and if not, just attach the new profile without trying to access the old one. This fixes the following oops, when enabling switchdev mode for the 2nd time after first time failure: ## Enabling switchdev mode first time: mlx5_core 0012:03:00.1: E-Switch: Supported tc chains and prios offload workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12 ^^^^^^^^ mlx5_core 0000:00:03.0: E-Switch: Disable: mode(LEGACY), nvfs(0), necvfs(0), active vports(0) ## retry: Enabling switchdev mode 2nd time: mlx5_core 0000:00:03.0: E-Switch: Supported tc chains and prios offload BUG: kernel NULL pointer dereference, address: 0000000000000038 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 13 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc4+ #91 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_detach_netdev+0x3c/0x90 Code: 50 00 00 f0 80 4f 78 02 48 8b bf e8 07 00 00 48 85 ff 74 16 48 8b 73 78 48 d1 ee 83 e6 01 83 f6 01 40 0f b6 f6 e8 c4 42 00 00 \u003c48\u003e 8b 45 38 48 85 c0 74 08 48 89 df e8 cc 47 40 1e 48 8b bb f0 07 RSP: 0018:ffffc90000673890 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff8881036a89c0 RCX: 0000000000000000 RDX: ffff888113f63800 RSI: ffffffff822fe720 RDI: 0000000000000000 RBP: 0000000000000000 R08: 0000000000002dcd R09: 0000000000000000 R10: ffffc900006738e8 R11: 00000000ffffffff R12: 0000000000000000 R13: 0000000000000000 R14: ffff8881036a89c0 R15: 0000000000000000 FS: 00007fdfb8384740(0000) GS:ffff88856a9d6000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000038 CR3: 0000000112ae0005 CR4: 0000000000370ef0 Call Trace: \u003cTASK\u003e mlx5e_netdev_change_profile+0x45/0xb0 mlx5e_vport_rep_load+0x27b/0x2d0 mlx5_esw_offloads_rep_load+0x72/0xf0 esw_offloads_enable+0x5d0/0x970 mlx5_eswitch_enable_locked+0x349/0x430 ? is_mp_supported+0x57/0xb0 mlx5_devlink_eswitch_mode_set+0x26b/0x430 devlink_nl_eswitch_set_doit+0x6f/0xf0 genl_family_rcv_msg_doit+0xe8/0x140 genl_rcv_msg+0x18b/0x290 ? __pfx_devlink_nl_pre_doit+0x10/0x10 ? __pfx_devlink_nl_eswitch_set_doit+0x10/0x10 ? __pfx_devlink_nl_post_doit+0x10/0x10 ? __pfx_genl_rcv_msg+0x10/0x10 netlink_rcv_skb+0x52/0x100 genl_rcv+0x28/0x40 netlink_unicast+0x282/0x3e0 ? __alloc_skb+0xd6/0x190 netlink_sendmsg+0x1f7/0x430 __sys_sendto+0x213/0x220 ? __sys_recvmsg+0x6a/0xd0 __x64_sys_sendto+0x24/0x30 do_syscall_64+0x50/0x1f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7fdfb8495047", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23000", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JcUD7/ApkvlfO47KVpD1zw==": { "id": "JcUD7/ApkvlfO47KVpD1zw==", "updater": "debian/updater", "name": "CVE-2025-5244", "description": "A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-5244", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JeKSqOKLpwhp1P0VSS+TJA==": { "id": "JeKSqOKLpwhp1P0VSS+TJA==", "updater": "debian/updater", "name": "CVE-2025-68324", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI host adapter is detached through imm_detach(), the imm_struct device instance is deallocated. However, the delayed work might still be pending or executing when imm_detach() is called, leading to use-after-free bugs when the work function imm_interrupt() accesses the already freed imm_struct memory. The race condition can occur as follows: CPU 0(detach thread) | CPU 1 | imm_queuecommand() | imm_queuecommand_lck() imm_detach() | schedule_delayed_work() kfree(dev) //FREE | imm_interrupt() | dev = container_of(...) //USE dev-\u003e //USE Add disable_delayed_work_sync() in imm_detach() to guarantee proper cancellation of the delayed work item before imm_struct is deallocated.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68324", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Jg7YPBhdd2Y1YRc1lg9K/g==": { "id": "Jg7YPBhdd2Y1YRc1lg9K/g==", "updater": "debian/updater", "name": "CVE-2026-64077", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: move to two-stage removal scheme Like previous patches for x_tables, follow same pattern in ebtables. We can't reuse xt helpers: ebt_table struct layout is incompatible. table-\u003eops assignment is now done while still holding the ebt mutex to make sure we never expose partially-filled table struct.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64077", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JkDUeWM85AYU2EUC6YsyXw==": { "id": "JkDUeWM85AYU2EUC6YsyXw==", "updater": "debian/updater", "name": "CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2010-4756", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JoQXSLz122fLIwbOi3oENA==": { "id": "JoQXSLz122fLIwbOi3oENA==", "updater": "debian/updater", "name": "CVE-2026-56209", "description": "An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56209", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JqBYA9g+3NYa6CczOXQGhQ==": { "id": "JqBYA9g+3NYa6CczOXQGhQ==", "updater": "debian/updater", "name": "CVE-2026-68218", "description": "In the Linux kernel, the following vulnerability has been resolved: media: pci: dm1105: Free allocated workqueue Destroy allocated workqueue in remove() callback to free its resources, thus fixing memory leak.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68218", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JqM0nqzbtdEgcyvoIyzloQ==": { "id": "JqM0nqzbtdEgcyvoIyzloQ==", "updater": "debian/updater", "name": "CVE-2026-45877", "description": "In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients During a warm reset flow, the cl-\u003edevice pointer may be NULL if the reset occurs while clients are still being enumerated. Accessing cl-\u003edevice-\u003ereference_count without a NULL check leads to a kernel panic. This issue was identified during multi-unit warm reboot stress clycles. Add a defensive NULL check for cl-\u003edevice to ensure stability under such intensive testing conditions. KASAN: null-ptr-deref in range [0000000000000000-0000000000000007] Workqueue: ish_fw_update_wq fw_reset_work_fn Call Trace: ishtp_bus_remove_all_clients+0xbe/0x130 [intel_ishtp] ishtp_reset_handler+0x85/0x1a0 [intel_ishtp] fw_reset_work_fn+0x8a/0xc0 [intel_ish_ipc]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45877", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Jr8LE9YgqhUL/qPVlyGCkw==": { "id": "Jr8LE9YgqhUL/qPVlyGCkw==", "updater": "debian/updater", "name": "CVE-2026-3479", "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3479", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JtMhEzdWDI1puPD9shAVng==": { "id": "JtMhEzdWDI1puPD9shAVng==", "updater": "debian/updater", "name": "CVE-2025-39932", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: let smbd_destroy() call disable_work_sync(\u0026info-\u003epost_send_credits_work) In smbd_destroy() we may destroy the memory so we better wait until post_send_credits_work is no longer pending and will never be started again. I actually just hit the case using rxe: WARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe] ... [ 5305.686979] [ T138] smbd_post_recv+0x445/0xc10 [cifs] [ 5305.687135] [ T138] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687149] [ T138] ? __kasan_check_write+0x14/0x30 [ 5305.687185] [ T138] ? __pfx_smbd_post_recv+0x10/0x10 [cifs] [ 5305.687329] [ T138] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 5305.687356] [ T138] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687368] [ T138] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687378] [ T138] ? _raw_spin_unlock_irqrestore+0x11/0x60 [ 5305.687389] [ T138] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687399] [ T138] ? get_receive_buffer+0x168/0x210 [cifs] [ 5305.687555] [ T138] smbd_post_send_credits+0x382/0x4b0 [cifs] [ 5305.687701] [ T138] ? __pfx_smbd_post_send_credits+0x10/0x10 [cifs] [ 5305.687855] [ T138] ? __pfx___schedule+0x10/0x10 [ 5305.687865] [ T138] ? __pfx__raw_spin_lock_irq+0x10/0x10 [ 5305.687875] [ T138] ? queue_delayed_work_on+0x8e/0xa0 [ 5305.687889] [ T138] process_one_work+0x629/0xf80 [ 5305.687908] [ T138] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687917] [ T138] ? __kasan_check_write+0x14/0x30 [ 5305.687933] [ T138] worker_thread+0x87f/0x1570 ... It means rxe_post_recv was called after rdma_destroy_qp(). This happened because put_receive_buffer() was triggered by ib_drain_qp() and called: queue_work(info-\u003eworkqueue, \u0026info-\u003epost_send_credits_work);", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39932", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "JyMCBwsAlUJ+0nV0dZZ1Vw==": { "id": "JyMCBwsAlUJ+0nV0dZZ1Vw==", "updater": "debian/updater", "name": "CVE-2026-34544", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34544", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K0pvLWS3Bi17A0Aw8q10eg==": { "id": "K0pvLWS3Bi17A0Aw8q10eg==", "updater": "debian/updater", "name": "CVE-2026-68146", "description": "In the Linux kernel, the following vulnerability has been resolved: ftrace: Add global mutex to serialize trace_parser access In ftrace, the trace_parser structure is allocated and initialized when a trace file is opened, and is subsequently used across write and release handlers to parse user input. The affected handler paths and their specific functions are: - Open paths: ftrace_regex_open(), ftrace_graph_open() - Write paths: ftrace_regex_write(), ftrace_graph_write() - Release paths: ftrace_regex_release(), ftrace_graph_release() If userspace opens a trace file descriptor and shares it across multiple threads, concurrent write calls will race on the parser's internal state, specifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted input or undefined behavior. Fix this by adding a global mutex, parser_lock, to serialize all access to trace_parser across write and release paths, preventing concurrent corruption of parser state.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68146", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K9+A/YujZbKHptbKzfLGDw==": { "id": "K9+A/YujZbKHptbKzfLGDw==", "updater": "debian/updater", "name": "CVE-2024-40918", "description": "In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more stable. Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems. The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc. My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy. 1) PA-RISC caches have a mind of their own and they can speculatively load data and instructions for a page as long as there is a entry in the TLB for the page which allows move-in. TLBs are local to each CPU. Thus, the TLB entry for a page must be purged before flushing the page. This is particularly important on SMP systems. In some of the flush routines, the flush routine would be called and then the TLB entry would be purged. This was because the flush routine needed the TLB entry to do the flush. 2) My initial approach to trying the fix the random faults was to try and use flush_cache_page_if_present for all flush operations. This actually made things worse and led to a couple of hardware lockups. It finally dawned on me that some lines weren't being flushed because the pte check code was racy. This resulted in random inequivalent mappings to physical pages. The __flush_cache_page tmpalias flush sets up its own TLB entry and it doesn't need the existing TLB entry. As long as we can find the pte pointer for the vm page, we can get the pfn and physical address of the page. We can also purge the TLB entry for the page before doing the flush. Further, __flush_cache_page uses a special TLB entry that inhibits cache move-in. When switching page mappings, we need to ensure that lines are removed from the cache. It is not sufficient to just flush the lines to memory as they may come back. This made it clear that we needed to implement all the required flush operations using tmpalias routines. This includes flushes for user and kernel pages. After modifying the code to use tmpalias flushes, it became clear that the random segmentation faults were not fully resolved. The frequency of faults was worse on systems with a 64 MB L2 (PA8900) and systems with more CPUs (rp4440). The warning that I added to flush_cache_page_if_present to detect pages that couldn't be flushed triggered frequently on some systems. Helge and I looked at the pages that couldn't be flushed and found that the PTE was either cleared or for a swap page. Ignoring pages that were swapped out seemed okay but pages with cleared PTEs seemed problematic. I looked at routines related to pte_clear and noticed ptep_clear_flush. The default implementation just flushes the TLB entry. However, it was obvious that on parisc we need to flush the cache page as well. If we don't flush the cache page, stale lines will be left in the cache and cause random corruption. Once a PTE is cleared, there is no way to find the physical address associated with the PTE and flush the associated page at a later time. I implemented an updated change with a parisc specific version of ptep_clear_flush. It fixed the random data corruption on Helge's rp4440 and rp3440, as well as on my c8000. At this point, I realized that I could restore the code where we only flush in flush_cache_page_if_present if the page has been accessed. However, for this, we also need to flush the cache when the accessed bit is cleared in ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40918", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K9HJuYuqoA0oSln39+ncyg==": { "id": "K9HJuYuqoA0oSln39+ncyg==", "updater": "debian/updater", "name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for Perl does not properly handle symlinks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-4116", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "K9Vsb61vzm4QbCVaTbr4Ag==": { "id": "K9Vsb61vzm4QbCVaTbr4Ag==", "updater": "debian/updater", "name": "CVE-2026-46000", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix conn-level packet handling to unshare RESPONSE packets The security operations that verify the RESPONSE packets decrypt bits of it in place - however, the sk_buff may be shared with a packet sniffer, which would lead to the sniffer seeing an apparently corrupt packet (actually decrypted). Fix this by handing a copy of the packet off to the specific security handler if the packet was cloned.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46000", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KCR+OKWAEK8jxDXW1fyJcg==": { "id": "KCR+OKWAEK8jxDXW1fyJcg==", "updater": "debian/updater", "name": "CVE-2026-46090", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved the peer lookup under cable-\u003elock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable-\u003estreams[] and detach or free its runtime while the playback trigger path still holds a stale peer substream pointer. Keep a per-cable count of in-flight peer stops before dropping cable-\u003elock, and make free_cable() wait for those stops before detaching the runtime. This preserves the existing behavior while making the peer runtime lifetime explicit.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46090", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KD6Eqcfq8aH0K5cooWIvRA==": { "id": "KD6Eqcfq8aH0K5cooWIvRA==", "updater": "debian/updater", "name": "CVE-2026-68402", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem-\u003edata[0]) to look it up in an extension non-inheritance list. It does so after testing elem-\u003eid, but without verifying that the element actually has a data octet. A zero-length extension element (WLAN_EID_EXTENSION with length 0) therefore makes it read one octet past the end of the element. _ieee802_11_parse_elems_full() runs this check for every element of a frame once a non-inheritance context exists -- e.g. while parsing a per-STA profile of a Multi-Link element in a (re)association response, or a non-transmitted BSS profile -- so a crafted frame from an AP can trigger a one-octet slab-out-of-bounds read during element parsing: BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited Read of size 1 ... in net/wireless/scan.c Return early (treat the element as inherited) when an extension element carries no data, mirroring the existing handling of empty ID lists. The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68402", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KGtQEHShm+Nh11YMiqlHfQ==": { "id": "KGtQEHShm+Nh11YMiqlHfQ==", "updater": "debian/updater", "name": "CVE-2026-68450", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allocates a mapping_node before inserting it into rc-\u003ereloc_root_tree. If rb_simple_insert() finds an existing entry, it returns the existing rb_node and leaves the newly allocated node unlinked. The error path then returns -EEXIST without freeing the new node. Since the node was never inserted into reloc_root_tree, the later cleanup in put_reloc_control() cannot find it either. Free the newly allocated node before returning -EEXIST. The callers currently assert that -EEXIST should not happen, so this is a defensive cleanup for an unexpected duplicate insert path. If the path is ever reached, the local allocation should still be released.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68450", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KIWTfqGvHChaaQEfN6qJjA==": { "id": "KIWTfqGvHChaaQEfN6qJjA==", "updater": "debian/updater", "name": "CVE-2023-52797", "description": "In the Linux kernel, the following vulnerability has been resolved: drivers: perf: Check find_first_bit() return value We must check the return value of find_first_bit() before using the return value as an index array since it happens to overflow the array and then panic: [ 107.318430] Kernel BUG [#1] [ 107.319434] CPU: 3 PID: 1238 Comm: kill Tainted: G E 6.6.0-rc6ubuntu-defconfig #2 [ 107.319465] Hardware name: riscv-virtio,qemu (DT) [ 107.319551] epc : pmu_sbi_ovf_handler+0x3a4/0x3ae [ 107.319840] ra : pmu_sbi_ovf_handler+0x52/0x3ae [ 107.319868] epc : ffffffff80a0a77c ra : ffffffff80a0a42a sp : ffffaf83fecda350 [ 107.319884] gp : ffffffff823961a8 tp : ffffaf8083db1dc0 t0 : ffffaf83fecda480 [ 107.319899] t1 : ffffffff80cafe62 t2 : 000000000000ff00 s0 : ffffaf83fecda520 [ 107.319921] s1 : ffffaf83fecda380 a0 : 00000018fca29df0 a1 : ffffffffffffffff [ 107.319936] a2 : 0000000001073734 a3 : 0000000000000004 a4 : 0000000000000000 [ 107.319951] a5 : 0000000000000040 a6 : 000000001d1c8774 a7 : 0000000000504d55 [ 107.319965] s2 : ffffffff82451f10 s3 : ffffffff82724e70 s4 : 000000000000003f [ 107.319980] s5 : 0000000000000011 s6 : ffffaf8083db27c0 s7 : 0000000000000000 [ 107.319995] s8 : 0000000000000001 s9 : 00007fffb45d6558 s10: 00007fffb45d81a0 [ 107.320009] s11: ffffaf7ffff60000 t3 : 0000000000000004 t4 : 0000000000000000 [ 107.320023] t5 : ffffaf7f80000000 t6 : ffffaf8000000000 [ 107.320037] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003 [ 107.320081] [\u003cffffffff80a0a77c\u003e] pmu_sbi_ovf_handler+0x3a4/0x3ae [ 107.320112] [\u003cffffffff800b42d0\u003e] handle_percpu_devid_irq+0x9e/0x1a0 [ 107.320131] [\u003cffffffff800ad92c\u003e] generic_handle_domain_irq+0x28/0x36 [ 107.320148] [\u003cffffffff8065f9f8\u003e] riscv_intc_irq+0x36/0x4e [ 107.320166] [\u003cffffffff80caf4a0\u003e] handle_riscv_irq+0x54/0x86 [ 107.320189] [\u003cffffffff80cb0036\u003e] do_irq+0x64/0x96 [ 107.320271] Code: 85a6 855e b097 ff7f 80e7 9220 b709 9002 4501 bbd9 (9002) 6097 [ 107.320585] ---[ end trace 0000000000000000 ]--- [ 107.320704] Kernel panic - not syncing: Fatal exception in interrupt [ 107.320775] SMP: stopping secondary CPUs [ 107.321219] Kernel Offset: 0x0 from 0xffffffff80000000 [ 107.333051] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52797", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KJIdfpTdRKWkCMfxbS/mUg==": { "id": "KJIdfpTdRKWkCMfxbS/mUg==", "updater": "debian/updater", "name": "CVE-2025-61144", "description": "libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-61144", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KLJBylkG3Wsrc5iZ+g9zLw==": { "id": "KLJBylkG3Wsrc5iZ+g9zLw==", "updater": "debian/updater", "name": "CVE-2026-34588", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34588", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KNBnL8x4YgVUk9a3l4+5tw==": { "id": "KNBnL8x4YgVUk9a3l4+5tw==", "updater": "debian/updater", "name": "CVE-2025-38507", "description": "In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: avoid bluetooth suspend/resume stalls Ensure we don't stall or panic the kernel when using bluetooth-connected controllers. This was reported as an issue on android devices using kernel 6.6 due to the resume hook which had been added for usb joycons. First, set a new state value to JOYCON_CTLR_STATE_SUSPENDED in a newly-added nintendo_hid_suspend. This makes sure we will not stall out the kernel waiting for input reports during led classdev suspend. The stalls could happen if connectivity is unreliable or lost to the controller prior to suspend. Second, since we lose connectivity during suspend, do not try joycon_init() for bluetooth controllers in the nintendo_hid_resume path. Tested via multiple suspend/resume flows when using the controller both in USB and bluetooth modes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38507", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KPnqRHuP399EH8xpAsppRQ==": { "id": "KPnqRHuP399EH8xpAsppRQ==", "updater": "debian/updater", "name": "CVE-2026-43172", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using \"fwrt-\u003esmem_cfg.lmac[2]\" is an overrun of the array. Reject such and use IWL_FW_CHECK instead of WARN_ON in this function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43172", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KT/XSjqNnGmyUjZ4EXYXeA==": { "id": "KT/XSjqNnGmyUjZ4EXYXeA==", "updater": "debian/updater", "name": "CVE-2026-3442", "description": "A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3442", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Kalz8nPy29l3XQTjNg1oTw==": { "id": "Kalz8nPy29l3XQTjNg1oTw==", "updater": "debian/updater", "name": "CVE-2024-28757", "description": "libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-28757", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KbVdO3g9TpKrFW6unwJ3eA==": { "id": "KbVdO3g9TpKrFW6unwJ3eA==", "updater": "debian/updater", "name": "CVE-2023-52485", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a command [Why] We can hang in place trying to send commands when the DMCUB isn't powered on. [How] For functions that execute within a DC context or DC lock we can wrap the direct calls to dm_execute_dmub_cmd/list with code that exits idle power optimizations and reallows once we're done with the command submission on success. For DM direct submissions the DM will need to manage the enter/exit sequencing manually. We cannot invoke a DMCUB command directly within the DM execution helper or we can deadlock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52485", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ko56RywS/QY4DPnvHjCF8w==": { "id": "Ko56RywS/QY4DPnvHjCF8w==", "updater": "debian/updater", "name": "CVE-2026-45963", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: nau8821: Cancel delayed work on component remove Attempting to unload the driver while a jack detection work is pending would likely crash the kernel when it is eventually scheduled for execution: [ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20 [...] [ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024 [ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821] [ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0 [...] [ 1984.896504] Call Trace: [ 1984.896511] \u003cTASK\u003e [ 1984.896524] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896572] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896596] snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896622] nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821] [ 1984.896636] process_one_work+0x211/0x590 [ 1984.896649] ? srso_return_thunk+0x5/0x5f [ 1984.896670] worker_thread+0x1cd/0x3a0 Cancel unscheduled jdet_work or wait for its execution to finish before the component driver gets removed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45963", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KsWYpAXrfuC7trSFJnEVxQ==": { "id": "KsWYpAXrfuC7trSFJnEVxQ==", "updater": "debian/updater", "name": "CVE-2022-44033", "description": "An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cm4040_open() and reader_detach().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-44033", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Kw0EaPoYj535/n7O8wuTLQ==": { "id": "Kw0EaPoYj535/n7O8wuTLQ==", "updater": "debian/updater", "name": "CVE-2026-23138", "description": "In the Linux kernel, the following vulnerability has been resolved: tracing: Add recursion protection in kernel stack trace recording A bug was reported about an infinite recursion caused by tracing the rcu events with the kernel stack trace trigger enabled. The stack trace code called back into RCU which then called the stack trace again. Expand the ftrace recursion protection to add a set of bits to protect events from recursion. Each bit represents the context that the event is in (normal, softirq, interrupt and NMI). Have the stack trace code use the interrupt context to protect against recursion. Note, the bug showed an issue in both the RCU code as well as the tracing stacktrace code. This only handles the tracing stack trace side of the bug. The RCU fix will be handled separately.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23138", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "KxKTzhkAQv+z2VKOGo/8bA==": { "id": "KxKTzhkAQv+z2VKOGo/8bA==", "updater": "debian/updater", "name": "CVE-2026-58469", "description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58469", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L24+fTbM1h+Y5XH0k90XrQ==": { "id": "L24+fTbM1h+Y5XH0k90XrQ==", "updater": "debian/updater", "name": "CVE-2025-3198", "description": "A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-3198", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L2i68tImyqS0x0XbBigK9A==": { "id": "L2i68tImyqS0x0XbBigK9A==", "updater": "debian/updater", "name": "CVE-2026-45981", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() `css_alloc_subchannel()` calls `device_initialize()` before setting up the DMA masks. If `dma_set_coherent_mask()` or `dma_set_mask()` fails, the error path frees the subchannel structure directly, bypassing the device model reference counting. Once `device_initialize()` has been called, the embedded struct device must be released via `put_device()`, allowing the release callback to free the container structure. Fix the error path by dropping the initial device reference with `put_device()` instead of calling `kfree()` directly. This ensures correct device lifetime handling and avoids potential use-after-free or double-free issues.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45981", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L6mHELyLIvOeppCFbTEiYA==": { "id": "L6mHELyLIvOeppCFbTEiYA==", "updater": "debian/updater", "name": "CVE-2026-68114", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit e4d99e04b2e9b13b97d3b17804c735f62689db23)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68114", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L6sfUnRyu2lAMh3ROdPlag==": { "id": "L6sfUnRyu2lAMh3ROdPlag==", "updater": "debian/updater", "name": "CVE-2026-31420", "description": "In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM panic br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied interval value from netlink without validation. When interval is 0, usecs_to_jiffies(0) yields 0, causing the delayed work (br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule itself with zero delay. This creates a tight loop on system_percpu_wq that allocates and transmits MRP test frames at maximum rate, exhausting all system memory and causing a kernel panic via OOM deadlock. The same zero-interval issue applies to br_mrp_start_in_test_parse() for interconnect test frames. Use NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both IFLA_BRIDGE_MRP_START_TEST_INTERVAL and IFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the netlink attribute parsing layer before the value ever reaches the workqueue scheduling code. This is consistent with how other bridge subsystems (br_fdb, br_mst) enforce range constraints on netlink attributes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31420", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "L8aIsY3YbUYD/sR0L1FHbA==": { "id": "L8aIsY3YbUYD/sR0L1FHbA==", "updater": "debian/updater", "name": "CVE-2026-31458", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts-\u003enr before accessing contexts_arr[0] Multiple sysfs command paths dereference contexts_arr[0] without first verifying that kdamond-\u003econtexts-\u003enr == 1. A user can set nr_contexts to 0 via sysfs while DAMON is running, causing NULL pointer dereferences. In more detail, the issue can be triggered by privileged users like below. First, start DAMON and make contexts directory empty (kdamond-\u003econtexts-\u003enr == 0). # damo start # cd /sys/kernel/mm/damon/admin/kdamonds/0 # echo 0 \u003e contexts/nr_contexts Then, each of below commands will cause the NULL pointer dereference. # echo update_schemes_stats \u003e state # echo update_schemes_tried_regions \u003e state # echo update_schemes_tried_bytes \u003e state # echo update_schemes_effective_quotas \u003e state # echo update_tuned_intervals \u003e state Guard all commands (except OFF) at the entry point of damon_sysfs_handle_cmd().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31458", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LA1kH936Pv8VoSzyI8d3Tg==": { "id": "LA1kH936Pv8VoSzyI8d3Tg==", "updater": "debian/updater", "name": "CVE-2026-42496", "description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42496", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LJsYhUYv1jp57lU5SMRltg==": { "id": "LJsYhUYv1jp57lU5SMRltg==", "updater": "debian/updater", "name": "CVE-2026-15588", "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15588", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LQ+t6bZl9RlU5H2tsWen1A==": { "id": "LQ+t6bZl9RlU5H2tsWen1A==", "updater": "debian/updater", "name": "CVE-2026-23088", "description": "In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash on synthetic stacktrace field usage When creating a synthetic event based on an existing synthetic event that had a stacktrace field and the new synthetic event used that field a kernel crash occurred: ~# cd /sys/kernel/tracing ~# echo 's:stack unsigned long stack[];' \u003e dynamic_events ~# echo 'hist:keys=prev_pid:s0=common_stacktrace if prev_state \u0026 3' \u003e\u003e events/sched/sched_switch/trigger ~# echo 'hist:keys=next_pid:s1=$s0:onmatch(sched.sched_switch).trace(stack,$s1)' \u003e\u003e events/sched/sched_switch/trigger The above creates a synthetic event that takes a stacktrace when a task schedules out in a non-running state and passes that stacktrace to the sched_switch event when that task schedules back in. It triggers the \"stack\" synthetic event that has a stacktrace as its field (called \"stack\"). ~# echo 's:syscall_stack s64 id; unsigned long stack[];' \u003e\u003e dynamic_events ~# echo 'hist:keys=common_pid:s2=stack' \u003e\u003e events/synthetic/stack/trigger ~# echo 'hist:keys=common_pid:s3=$s2,i0=id:onmatch(synthetic.stack).trace(syscall_stack,$i0,$s3)' \u003e\u003e events/raw_syscalls/sys_exit/trigger The above makes another synthetic event called \"syscall_stack\" that attaches the first synthetic event (stack) to the sys_exit trace event and records the stacktrace from the stack event with the id of the system call that is exiting. When enabling this event (or using it in a historgram): ~# echo 1 \u003e events/synthetic/syscall_stack/enable Produces a kernel crash! BUG: unable to handle page fault for address: 0000000000400010 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP PTI CPU: 6 UID: 0 PID: 1257 Comm: bash Not tainted 6.16.3+deb14-amd64 #1 PREEMPT(lazy) Debian 6.16.3-1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 RIP: 0010:trace_event_raw_event_synth+0x90/0x380 Code: c5 00 00 00 00 85 d2 0f 84 e1 00 00 00 31 db eb 34 0f 1f 00 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 \u003c49\u003e 8b 04 24 48 83 c3 01 8d 0c c5 08 00 00 00 01 cd 41 3b 5d 40 0f RSP: 0018:ffffd2670388f958 EFLAGS: 00010202 RAX: ffff8ba1065cc100 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000001 RSI: fffff266ffda7b90 RDI: ffffd2670388f9b0 RBP: 0000000000000010 R08: ffff8ba104e76000 R09: ffffd2670388fa50 R10: ffff8ba102dd42e0 R11: ffffffff9a908970 R12: 0000000000400010 R13: ffff8ba10a246400 R14: ffff8ba10a710220 R15: fffff266ffda7b90 FS: 00007fa3bc63f740(0000) GS:ffff8ba2e0f48000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000400010 CR3: 0000000107f9e003 CR4: 0000000000172ef0 Call Trace: \u003cTASK\u003e ? __tracing_map_insert+0x208/0x3a0 action_trace+0x67/0x70 event_hist_trigger+0x633/0x6d0 event_triggers_call+0x82/0x130 trace_event_buffer_commit+0x19d/0x250 trace_event_raw_event_sys_exit+0x62/0xb0 syscall_exit_work+0x9d/0x140 do_syscall_64+0x20a/0x2f0 ? trace_event_raw_event_sched_switch+0x12b/0x170 ? save_fpregs_to_fpstate+0x3e/0x90 ? _raw_spin_unlock+0xe/0x30 ? finish_task_switch.isra.0+0x97/0x2c0 ? __rseq_handle_notify_resume+0xad/0x4c0 ? __schedule+0x4b8/0xd00 ? restore_fpregs_from_fpstate+0x3c/0x90 ? switch_fpu_return+0x5b/0xe0 ? do_syscall_64+0x1ef/0x2f0 ? do_fault+0x2e9/0x540 ? __handle_mm_fault+0x7d1/0xf70 ? count_memcg_events+0x167/0x1d0 ? handle_mm_fault+0x1d7/0x2e0 ? do_user_addr_fault+0x2c3/0x7f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The reason is that the stacktrace field is not labeled as such, and is treated as a normal field and not as a dynamic event that it is. In trace_event_raw_event_synth() the event is field is still treated as a dynamic array, but the retrieval of the data is considered a normal field, and the reference is just the meta data: // Meta data is retrieved instead of a dynamic array ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23088", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LQUZVuqaFm5FS1tle9bVrA==": { "id": "LQUZVuqaFm5FS1tle9bVrA==", "updater": "debian/updater", "name": "CVE-2007-3719", "description": "The process scheduler in the Linux kernel 2.6.16 gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-3719", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LR53RfBcaLruNmVIjJlLPg==": { "id": "LR53RfBcaLruNmVIjJlLPg==", "updater": "debian/updater", "name": "CVE-2023-52426", "description": "libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52426", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LRmZme+MFDTrTqd0tt9LgA==": { "id": "LRmZme+MFDTrTqd0tt9LgA==", "updater": "debian/updater", "name": "CVE-2025-38531", "description": "In the Linux kernel, the following vulnerability has been resolved: iio: common: st_sensors: Fix use of uninitialize device structs Throughout the various probe functions \u0026indio_dev-\u003edev is used before it is initialized. This caused a kernel panic in st_sensors_power_enable() when the call to devm_regulator_bulk_get_enable() fails and then calls dev_err_probe() with the uninitialized device. This seems to only cause a panic with dev_err_probe(), dev_err(), dev_warn() and dev_info() don't seem to cause a panic, but are fixed as well. The issue is reported and traced here: [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38531", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LSj8enWZZsQGSoQTpJsNLQ==": { "id": "LSj8enWZZsQGSoQTpJsNLQ==", "updater": "debian/updater", "name": "CVE-2026-63847", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 3216a7f4e2642bda5fd14f57586e835ae9202587)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63847", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LUOZZKY4oeyvXegiWO6Yhg==": { "id": "LUOZZKY4oeyvXegiWO6Yhg==", "updater": "debian/updater", "name": "CVE-2025-1376", "description": "A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1376", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LV6LIlj72s5e2jnkTg5TsA==": { "id": "LV6LIlj72s5e2jnkTg5TsA==", "updater": "debian/updater", "name": "CVE-2025-27587", "description": "OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-27587", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LWHMtlh7noa7WaBqmptSKA==": { "id": "LWHMtlh7noa7WaBqmptSKA==", "updater": "debian/updater", "name": "CVE-2024-46870", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout for DCN35 [Why] DMCUB can intermittently take longer than expected to process commands. Old ASIC policy was to continue while logging a diagnostic error - which works fine for ASIC without IPS, but with IPS this could lead to a race condition where we attempt to access DCN state while it's inaccessible, leading to a system hang when the NIU port is not disabled or register accesses that timeout and the display configuration in an undefined state. [How] We need to investigate why these accesses take longer than expected, but for now we should disable the timeout on DCN35 to avoid this race condition. Since the waits happen only at lower interrupt levels the risk of taking too long at higher IRQ and causing a system watchdog timeout are minimal.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46870", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LWL/yb4swqiUg65uYn6G/w==": { "id": "LWL/yb4swqiUg65uYn6G/w==", "updater": "debian/updater", "name": "CVE-2026-68388", "description": "In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC. The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset. For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200): Request: [100, 400) Server range: [ 0, 200) allocated Correct: [100, 200) allocated data, skip [200, 400) hole, zero-fill Current: [100, 300) skipped [300, 400) zero-filled afterwards The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled. Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset. Ignore ranges that end before the current offset and reject ranges whose end offset overflows. This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68388", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LWdYqSSWB1E7q9rwDYTSew==": { "id": "LWdYqSSWB1E7q9rwDYTSew==", "updater": "debian/updater", "name": "CVE-2026-36849", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-36849", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lc3Tll/o9JPam+3IT/DrKQ==": { "id": "Lc3Tll/o9JPam+3IT/DrKQ==", "updater": "debian/updater", "name": "CVE-2026-54411", "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54411", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "pam", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LeJ94r+TvuBTyjiQvoh/+A==": { "id": "LeJ94r+TvuBTyjiQvoh/+A==", "updater": "debian/updater", "name": "CVE-2024-58100", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension programs When processing calls to global sub-programs, verifier decides whether to invalidate all packet pointers in current state depending on the changes_pkt_data property of the global sub-program. Because of this, an extension program replacing a global sub-program must be compatible with changes_pkt_data property of the sub-program being replaced. This commit: - adds changes_pkt_data flag to struct bpf_prog_aux: - this flag is set in check_cfg() for main sub-program; - in jit_subprogs() for other sub-programs; - modifies bpf_check_attach_btf_id() to check changes_pkt_data flag; - moves call to check_attach_btf_id() after the call to check_cfg(), because it needs changes_pkt_data flag to be set: bpf_check: ... ... - check_attach_btf_id resolve_pseudo_ldimm64 resolve_pseudo_ldimm64 --\u003e bpf_prog_is_offloaded bpf_prog_is_offloaded check_cfg check_cfg + check_attach_btf_id ... ... The following fields are set by check_attach_btf_id(): - env-\u003eops - prog-\u003eaux-\u003eattach_btf_trace - prog-\u003eaux-\u003eattach_func_name - prog-\u003eaux-\u003eattach_func_proto - prog-\u003eaux-\u003edst_trampoline - prog-\u003eaux-\u003emod - prog-\u003eaux-\u003esaved_dst_attach_type - prog-\u003eaux-\u003esaved_dst_prog_type - prog-\u003eexpected_attach_type Neither of these fields are used by resolve_pseudo_ldimm64() or bpf_prog_offload_verifier_prep() (for netronome and netdevsim drivers), so the reordering is safe.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58100", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lf0gWAt8cyrMV+1lxEIWlg==": { "id": "Lf0gWAt8cyrMV+1lxEIWlg==", "updater": "debian/updater", "name": "CVE-2026-68406", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range. Reject out-of-range values before using them in the parser capability bit test using the policy. [drop unnecessary check]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68406", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LgJ7oWqdNk4cJQzVzTFMRQ==": { "id": "LgJ7oWqdNk4cJQzVzTFMRQ==", "updater": "debian/updater", "name": "CVE-2016-9117", "description": "NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9117", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LicXfFw+HaekF+CWm0dH9A==": { "id": "LicXfFw+HaekF+CWm0dH9A==", "updater": "debian/updater", "name": "CVE-2026-68426", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb-\u003eprev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with -\u003eprev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it sets its tail pointer (tail = skb-\u003eprev). When validate_xmit_xfrm() walks a GSO list and some segments are stolen by async crypto (-\u003exmit() returns -EINPROGRESS), those segments are unlinked from the list but the head -\u003eprev is never updated. If the last segment is the one stolen, the returned head still has -\u003eprev pointing at it, even though it is now owned by the crypto engine and may be freed. validate_xmit_skb_list() later does tail-\u003enext = skb, writing through that stale pointer -- a use-after-free. Repoint skb-\u003eprev at the last retained segment before returning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68426", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LjSRKao8rTYjhGOoAVtUog==": { "id": "LjSRKao8rTYjhGOoAVtUog==", "updater": "debian/updater", "name": "CVE-2026-56412", "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56412", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lo3/+u57vnFiy3iLkojwsg==": { "id": "Lo3/+u57vnFiy3iLkojwsg==", "updater": "debian/updater", "name": "CVE-2025-71273", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() Simplify the code by using device managed memory allocations. This also fixes a memory leak in rtw_register_hw(). The supported bands were not freed in the error path. Copied from commit 145df52a8671 (\"wifi: rtw89: Convert rtw89_core_set_supported_band to use devm_*\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71273", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LoNrKFr+U3cMzjwTDABwMg==": { "id": "LoNrKFr+U3cMzjwTDABwMg==", "updater": "debian/updater", "name": "CVE-2026-43248", "description": "In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43248", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LrXhgDkb+00pghFQVX0J/w==": { "id": "LrXhgDkb+00pghFQVX0J/w==", "updater": "debian/updater", "name": "CVE-2023-4134", "description": "A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-4134", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LsID8egvR6MllXOxUPXkwQ==": { "id": "LsID8egvR6MllXOxUPXkwQ==", "updater": "debian/updater", "name": "CVE-2025-71160", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if possible Hamza Mahfooz reports cpu soft lock-ups in nft_chain_validate(): watchdog: BUG: soft lockup - CPU#1 stuck for 27s! [iptables-nft-re:37547] [..] RIP: 0010:nft_chain_validate+0xcb/0x110 [nf_tables] [..] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_immediate_validate+0x36/0x50 [nf_tables] nft_chain_validate+0xc9/0x110 [nf_tables] nft_table_validate+0x6b/0xb0 [nf_tables] nf_tables_validate+0x8b/0xa0 [nf_tables] nf_tables_commit+0x1df/0x1eb0 [nf_tables] [..] Currently nf_tables will traverse the entire table (chain graph), starting from the entry points (base chains), exploring all possible paths (chain jumps). But there are cases where we could avoid revalidation. Consider: 1 input -\u003e j2 -\u003e j3 2 input -\u003e j2 -\u003e j3 3 input -\u003e j1 -\u003e j2 -\u003e j3 Then the second rule does not need to revalidate j2, and, by extension j3, because this was already checked during validation of the first rule. We need to validate it only for rule 3. This is needed because chain loop detection also ensures we do not exceed the jump stack: Just because we know that j2 is cycle free, its last jump might now exceed the allowed stack size. We also need to update all reachable chains with the new largest observed call depth. Care has to be taken to revalidate even if the chain depth won't be an issue: chain validation also ensures that expressions are not called from invalid base chains. For example, the masquerade expression can only be called from NAT postrouting base chains. Therefore we also need to keep record of the base chain context (type, hooknum) and revalidate if the chain becomes reachable from a different hook location.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71160", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lt5HHPW4BE0rSRDcZNrHlQ==": { "id": "Lt5HHPW4BE0rSRDcZNrHlQ==", "updater": "debian/updater", "name": "CVE-2026-68252", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68252", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "LvYuTk+G9PGeT3CX8knLKQ==": { "id": "LvYuTk+G9PGeT3CX8knLKQ==", "updater": "debian/updater", "name": "CVE-2026-45383", "description": "libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45383", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Lx+kSp9vjsGhL+UyYXuS7A==": { "id": "Lx+kSp9vjsGhL+UyYXuS7A==", "updater": "debian/updater", "name": "CVE-2025-40337", "description": "In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload errors The stmmac_rx function would previously set skb-\u003eip_summed to CHECKSUM_UNNECESSARY if hardware checksum offload (CoE) was enabled and the packet was of a known IP ethertype. However, this logic failed to check if the hardware had actually reported a checksum error. The hardware status, indicating a header or payload checksum failure, was being ignored at this stage. This could cause corrupt packets to be passed up the network stack as valid. This patch corrects the logic by checking the `csum_none` status flag, which is set when the hardware reports a checksum error. If this flag is set, skb-\u003eip_summed is now correctly set to CHECKSUM_NONE, ensuring the kernel's network stack will perform its own validation and properly handle the corrupt packet.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40337", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M0jbZmBvyRuYzBNrvmqEbA==": { "id": "M0jbZmBvyRuYzBNrvmqEbA==", "updater": "debian/updater", "name": "CVE-2026-6470", "description": "Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6470", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M4tbiBn7IwzJ1ZmsEQrp+A==": { "id": "M4tbiBn7IwzJ1ZmsEQrp+A==", "updater": "debian/updater", "name": "CVE-2025-11081", "description": "A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11081", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "M784aJgm2VrqBMgf0VR0JA==": { "id": "M784aJgm2VrqBMgf0VR0JA==", "updater": "debian/updater", "name": "CVE-2026-68363", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev: \tdev_info(\u0026hif_dev-\u003eudev-\u003edev, \"ath9k_htc: Firmware %s requested\\n\", \t\t hif_dev-\u003efw_name); The re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\" workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -\u003e complete_all(\u0026hif_dev-\u003efw_done). That releases the wait_for_completion(\u0026hif_dev-\u003efw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev-\u003eudev, the first field of struct hif_device_usb): BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware Read of size 8 ... by task kworker/... ath9k_hif_request_firmware ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247 request_firmware_work_func Allocated by ...: ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c Freed by ...: ath9k_hif_usb_disconnect -\u003e kfree drivers/net/wireless/ath/ath9k/hif_usb.c The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the request and keeps touching hif_dev afterwards. Drop the post-request dev_info(): it is the only use of hif_dev after the async request is armed, and it is purely informational (the dev_err() on the failure path runs only when request_firmware_nowait() did not arm a callback, so hif_dev is still alive there). This was first reported by syzbot as a single, non-reproduced crash that was later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer, which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc device whose firmware download fails). The vulnerable code is unchanged and still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN once the (sub-microsecond) race window is widened.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68363", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MCePqVkLQnwVpeYNDE+rBg==": { "id": "MCePqVkLQnwVpeYNDE+rBg==", "updater": "debian/updater", "name": "CVE-2026-18408", "description": "Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \\restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \\restrict and \\unrestrict to block this attack, but \\unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \\restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18408", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MGrbbNsTtAJ91AysbDgiPw==": { "id": "MGrbbNsTtAJ91AysbDgiPw==", "updater": "debian/updater", "name": "CVE-2017-7475", "description": "Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-7475", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "cairo", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MISSvrkhRBXMQUwT3M+KUQ==": { "id": "MISSvrkhRBXMQUwT3M+KUQ==", "updater": "debian/updater", "name": "CVE-2025-1352", "description": "A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1352", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MIdBsN6uGjXn5hPMPX7Kzw==": { "id": "MIdBsN6uGjXn5hPMPX7Kzw==", "updater": "debian/updater", "name": "CVE-2025-37957", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit ed129ec9057f (\"KVM: x86: forcibly leave nested mode on vCPU reset\") addressed an issue where a triple fault occurring in nested mode could lead to use-after-free scenarios. However, the commit did not handle the analogous situation for System Management Mode (SMM). This omission results in triggering a WARN when KVM forces a vCPU INIT after SHUTDOWN interception while the vCPU is in SMM. This situation was reprodused using Syzkaller by: 1) Creating a KVM VM and vCPU 2) Sending a KVM_SMI ioctl to explicitly enter SMM 3) Executing invalid instructions causing consecutive exceptions and eventually a triple fault The issue manifests as follows: WARNING: CPU: 0 PID: 25506 at arch/x86/kvm/x86.c:12112 kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112 Modules linked in: CPU: 0 PID: 25506 Comm: syz-executor.0 Not tainted 6.1.130-syzkaller-00157-g164fe5dde9b6 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112 Call Trace: \u003cTASK\u003e shutdown_interception+0x66/0xb0 arch/x86/kvm/svm/svm.c:2136 svm_invoke_exit_handler+0x110/0x530 arch/x86/kvm/svm/svm.c:3395 svm_handle_exit+0x424/0x920 arch/x86/kvm/svm/svm.c:3457 vcpu_enter_guest arch/x86/kvm/x86.c:10959 [inline] vcpu_run+0x2c43/0x5a90 arch/x86/kvm/x86.c:11062 kvm_arch_vcpu_ioctl_run+0x50f/0x1cf0 arch/x86/kvm/x86.c:11283 kvm_vcpu_ioctl+0x570/0xf00 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4122 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x19a/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Architecturally, INIT is blocked when the CPU is in SMM, hence KVM's WARN() in kvm_vcpu_reset() to guard against KVM bugs, e.g. to detect improper emulation of INIT. SHUTDOWN on SVM is a weird edge case where KVM needs to do _something_ sane with the VMCB, since it's technically undefined, and INIT is the least awful choice given KVM's ABI. So, double down on stuffing INIT on SHUTDOWN, and force the vCPU out of SMM to avoid any weirdness (and the WARN). Found by Linux Verification Center (linuxtesting.org) with Syzkaller. [sean: massage changelog, make it clear this isn't architectural behavior]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37957", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MIkTRAv/IGPjw1oKbjib+g==": { "id": "MIkTRAv/IGPjw1oKbjib+g==", "updater": "debian/updater", "name": "CVE-2024-47141", "description": "In the Linux kernel, the following vulnerability has been resolved: pinmux: Use sequential access to access desc-\u003epinmux data When two client of the same gpio call pinctrl_select_state() for the same functionality, we are seeing NULL pointer issue while accessing desc-\u003emux_owner. Let's say two processes A, B executing in pin_request() for the same pin and process A updates the desc-\u003emux_usecount but not yet updated the desc-\u003emux_owner while process B see the desc-\u003emux_usecount which got updated by A path and further executes strcmp and while accessing desc-\u003emux_owner it crashes with NULL pointer. Serialize the access to mux related setting with a mutex lock. \tcpu0 (process A)\t\t\tcpu1(process B) pinctrl_select_state() {\t\t pinctrl_select_state() { pin_request() {\t\t\t\tpin_request() { ... \t\t\t\t\t\t .... } else { desc-\u003emux_usecount++; \t\t\t\t\t\tdesc-\u003emux_usecount \u0026\u0026 strcmp(desc-\u003emux_owner, owner)) { if (desc-\u003emux_usecount \u003e 1) return 0; desc-\u003emux_owner = owner; }\t\t\t\t\t\t}", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47141", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MJ0OFjy8U2e/bsG70rEfYw==": { "id": "MJ0OFjy8U2e/bsG70rEfYw==", "updater": "debian/updater", "name": "CVE-2026-68169", "description": "In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: userspace: fix use-after-free in get_local_id In mptcp_pm_userspace_get_local_id(), the address entry is looked up under spinlock, but its id is read after dropping the lock. A concurrent deletion can free the entry between the unlock and the read, leading to UAF. The race window is narrow. It was reproduced only with a locally constructed stress test that repeatedly overlaps an MP_JOIN SYN with a MPTCP_PM_CMD_SUBFLOW_DESTROY request. However, the KASAN report below confirms that the race is reachable: [ 666.319376] BUG: KASAN: slab-use-after-free in mptcp_userspace_pm_get_local_id+0x1dc/0x1f0 [ 666.319386] Read of size 1 at addr ffff888124845610 by task swapper/0/0 ... [ 666.319401] Call Trace: [ 666.319405] \u003cIRQ\u003e [ 666.319408] dump_stack_lvl+0x53/0x70 [ 666.319412] print_address_description.constprop.0+0x2c/0x3b0 [ 666.319418] print_report+0xbe/0x2b0 [ 666.319421] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0 [ 666.319423] kasan_report+0xce/0x100 [ 666.319426] ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0 [ 666.319429] mptcp_userspace_pm_get_local_id+0x1dc/0x1f0 [ 666.319433] mptcp_pm_get_local_id+0x371/0x440 ... [ 666.319821] Allocated by task 45539: [ 666.319844] kasan_save_stack+0x33/0x60 [ 666.319855] kasan_save_track+0x14/0x30 [ 666.319858] __kasan_kmalloc+0x8f/0xa0 [ 666.319863] __kmalloc_noprof+0x1e7/0x520 [ 666.319867] sock_kmalloc+0xdf/0x130 [ 666.319885] sock_kmemdup+0x1b/0x40 [ 666.319888] mptcp_userspace_pm_append_new_local_addr+0x261/0x500 [ 666.319910] mptcp_pm_nl_announce_doit+0x16a/0x610 ... [ 666.319967] Freed by task 45560: [ 666.319988] kasan_save_stack+0x33/0x60 [ 666.319991] kasan_save_track+0x14/0x30 [ 666.319994] kasan_save_free_info+0x3b/0x60 [ 666.319998] __kasan_slab_free+0x43/0x70 [ 666.320000] kfree+0x166/0x440 [ 666.320003] sock_kfree_s+0x1d/0x50 [ 666.320007] mptcp_userspace_pm_delete_local_addr.isra.0+0x157/0x200 [ 666.320011] mptcp_pm_nl_subflow_destroy_doit+0x51d/0xea0 Fix by copying the id into a local variable while still holding the lock, and use -1 as a \"not found\" sentinel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68169", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MKbNqtVKIsB4Skin5vwLuw==": { "id": "MKbNqtVKIsB4Skin5vwLuw==", "updater": "debian/updater", "name": "CVE-2024-56565", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to drop all discards after creating snapshot on lvm device Piergiorgio reported a bug in bugzilla as below: ------------[ cut here ]------------ WARNING: CPU: 2 PID: 969 at fs/f2fs/segment.c:1330 RIP: 0010:__submit_discard_cmd+0x27d/0x400 [f2fs] Call Trace: __issue_discard_cmd+0x1ca/0x350 [f2fs] issue_discard_thread+0x191/0x480 [f2fs] kthread+0xcf/0x100 ret_from_fork+0x31/0x50 ret_from_fork_asm+0x1a/0x30 w/ below testcase, it can reproduce this bug quickly: - pvcreate /dev/vdb - vgcreate myvg1 /dev/vdb - lvcreate -L 1024m -n mylv1 myvg1 - mount /dev/myvg1/mylv1 /mnt/f2fs - dd if=/dev/zero of=/mnt/f2fs/file bs=1M count=20 - sync - rm /mnt/f2fs/file - sync - lvcreate -L 1024m -s -n mylv1-snapshot /dev/myvg1/mylv1 - umount /mnt/f2fs The root cause is: it will update discard_max_bytes of mounted lvm device to zero after creating snapshot on this lvm device, then, __submit_discard_cmd() will pass parameter @nr_sects w/ zero value to __blkdev_issue_discard(), it returns a NULL bio pointer, result in panic. This patch changes as below for fixing: 1. Let's drop all remained discards in f2fs_unfreeze() if snapshot of lvm device is created. 2. Checking discard_max_bytes before submitting discard during __submit_discard_cmd().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56565", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ML4iV/fRl+h1v0CFzdyy1A==": { "id": "ML4iV/fRl+h1v0CFzdyy1A==", "updater": "debian/updater", "name": "CVE-2026-53132", "description": "In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() checks vvs-\u003erx_bytes + len \u003e vvs-\u003ebuf_alloc. virtio_transport_recv_enqueue() skips coalescing for packets with VIRTIO_VSOCK_SEQ_EOM. If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs-\u003erx_bytes stays at 0. Fix this by estimating the skb metadata size: \t(Number of skbs in the queue) * SKB_TRUESIZE(0)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53132", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MTPA2fuSLOyzUIakkBHnzA==": { "id": "MTPA2fuSLOyzUIakkBHnzA==", "updater": "debian/updater", "name": "CVE-2025-64181", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-64181", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MVI9YH7/7TuqWPhRsSRp2A==": { "id": "MVI9YH7/7TuqWPhRsSRp2A==", "updater": "debian/updater", "name": "CVE-2026-59998", "description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-59998", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MWwgjsOk1ofNsK1d5IdecA==": { "id": "MWwgjsOk1ofNsK1d5IdecA==", "updater": "debian/updater", "name": "CVE-2025-39797", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in charon.conf : spi_min = 0x10000000 spi_max = 0x10000002 This limits the system to only 2 usable SPI values. Next, create more than 2 Child SA. each using unique pair of src/dst address. As soon as the 3rd Child SA is initiated, it will be assigned a duplicate SPI, since the SPI pool is already exhausted. With a narrow SPI range, the issue is consistently reproducible. With a broader/default range, it becomes rare and unpredictable. Current implementation: xfrm_spi_hash() lookup function computes hash using daddr, proto, and family. So if two SAs have the same SPI but different destination addresses, then they will: a. Hash into different buckets b. Be stored in different linked lists (byspi + h) c. Not be seen in the same hlist_for_each_entry_rcu() iteration. As a result, the lookup will result in NULL and kernel allows that Duplicate SPI Proposed Change: xfrm_state_lookup_spi_proto() does a truly global search - across all states, regardless of hash bucket and matches SPI and proto.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39797", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Mc/PcK7PUGXHVZGur/JxKQ==": { "id": "Mc/PcK7PUGXHVZGur/JxKQ==", "updater": "debian/updater", "name": "CVE-2016-9116", "description": "NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9116", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Mgm9HKdYPJAe2Mp7mvmEcA==": { "id": "Mgm9HKdYPJAe2Mp7mvmEcA==", "updater": "debian/updater", "name": "CVE-2025-68219", "description": "In the Linux kernel, the following vulnerability has been resolved: cifs: fix memory leak in smb3_fs_context_parse_param error path Add proper cleanup of ctx-\u003esource and fc-\u003esource to the cifs_parse_mount_err error handler. This ensures that memory allocated for the source strings is correctly freed on all error paths, matching the cleanup already performed in the success path by smb3_cleanup_fs_context_contents(). Pointers are also set to NULL after freeing to prevent potential double-free issues. This change fixes a memory leak originally detected by syzbot. The leak occurred when processing Opt_source mount options if an error happened after ctx-\u003esource and fc-\u003esource were successfully allocated but before the function completed. The specific leak sequence was: 1. ctx-\u003esource = smb3_fs_context_fullpath(ctx, '/') allocates memory 2. fc-\u003esource = kstrdup(ctx-\u003esource, GFP_KERNEL) allocates more memory 3. A subsequent error jumps to cifs_parse_mount_err 4. The old error handler freed passwords but not the source strings, causing the memory to leak. This issue was not addressed by commit e8c73eb7db0a (\"cifs: client: fix memory leak in smb3_fs_context_parse_param\"), which only fixed leaks from repeated fsconfig() calls but not this error path. Patch updated with minor change suggested by kernel test robot", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68219", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MkiM9LdBRncPwjGfHTMgxQ==": { "id": "MkiM9LdBRncPwjGfHTMgxQ==", "updater": "debian/updater", "name": "CVE-2026-68205", "description": "In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() The v4l2 helper v4l2_async_register_subdev_sensor() calls v4l2_async_register_subdev(), which is a macro that expands to __v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module rather than the sensor driver module that originally set sd-\u003eowner. When v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then overwrites the sensor driver's owner with NULL. This causes the problem that the sensor module's reference count is never incremented during async registration, so the module can be removed while the subdevice is still in use by a notifier (e.g., a CSI-2 receiver bridge driver). Fix this by renaming v4l2_async_register_subdev_sensor() to __v4l2_async_register_subdev_sensor() with an added explicit module argument and introducing a wrapper macro: #define v4l2_async_register_subdev_sensor(sd) \\ __v4l2_async_register_subdev_sensor(sd, THIS_MODULE) This ensures the sensor driver module is properly referenced even when the sensor driver does not init the owner field before calling v4l2_async_register_subdev_sensor() and prevents premature module removal.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68205", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MmgZ4Cd3XBWQk/ZvGoOd/g==": { "id": "MmgZ4Cd3XBWQk/ZvGoOd/g==", "updater": "debian/updater", "name": "CVE-2024-57976", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when cow_file_range() failed [BUG] When testing with COW fixup marked as BUG_ON() (this is involved with the new pin_user_pages*() change, which should not result new out-of-band dirty pages), I hit a crash triggered by the BUG_ON() from hitting COW fixup path. This BUG_ON() happens just after a failed btrfs_run_delalloc_range(): BTRFS error (device dm-2): failed to run delalloc range, root 348 ino 405 folio 65536 submit_bitmap 6-15 start 90112 len 106496: -28 ------------[ cut here ]------------ kernel BUG at fs/btrfs/extent_io.c:1444! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP CPU: 0 UID: 0 PID: 434621 Comm: kworker/u24:8 Tainted: G OE 6.12.0-rc7-custom+ #86 Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022 Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs] pc : extent_writepage_io+0x2d4/0x308 [btrfs] lr : extent_writepage_io+0x2d4/0x308 [btrfs] Call trace: extent_writepage_io+0x2d4/0x308 [btrfs] extent_writepage+0x218/0x330 [btrfs] extent_write_cache_pages+0x1d4/0x4b0 [btrfs] btrfs_writepages+0x94/0x150 [btrfs] do_writepages+0x74/0x190 filemap_fdatawrite_wbc+0x88/0xc8 start_delalloc_inodes+0x180/0x3b0 [btrfs] btrfs_start_delalloc_roots+0x174/0x280 [btrfs] shrink_delalloc+0x114/0x280 [btrfs] flush_space+0x250/0x2f8 [btrfs] btrfs_async_reclaim_data_space+0x180/0x228 [btrfs] process_one_work+0x164/0x408 worker_thread+0x25c/0x388 kthread+0x100/0x118 ret_from_fork+0x10/0x20 Code: aa1403e1 9402f3ef aa1403e0 9402f36f (d4210000) ---[ end trace 0000000000000000 ]--- [CAUSE] That failure is mostly from cow_file_range(), where we can hit -ENOSPC. Although the -ENOSPC is already a bug related to our space reservation code, let's just focus on the error handling. For example, we have the following dirty range [0, 64K) of an inode, with 4K sector size and 4K page size: 0 16K 32K 48K 64K |///////////////////////////////////////| |#######################################| Where |///| means page are still dirty, and |###| means the extent io tree has EXTENT_DELALLOC flag. - Enter extent_writepage() for page 0 - Enter btrfs_run_delalloc_range() for range [0, 64K) - Enter cow_file_range() for range [0, 64K) - Function btrfs_reserve_extent() only reserved one 16K extent So we created extent map and ordered extent for range [0, 16K) 0 16K 32K 48K 64K |////////|//////////////////////////////| |\u003c- OE -\u003e|##############################| And range [0, 16K) has its delalloc flag cleared. But since we haven't yet submit any bio, involved 4 pages are still dirty. - Function btrfs_reserve_extent() returns with -ENOSPC Now we have to run error cleanup, which will clear all EXTENT_DELALLOC* flags and clear the dirty flags for the remaining ranges: 0 16K 32K 48K 64K |////////| | | | | Note that range [0, 16K) still has its pages dirty. - Some time later, writeback is triggered again for the range [0, 16K) since the page range still has dirty flags. - btrfs_run_delalloc_range() will do nothing because there is no EXTENT_DELALLOC flag. - extent_writepage_io() finds page 0 has no ordered flag Which falls into the COW fixup path, triggering the BUG_ON(). Unfortunately this error handling bug dates back to the introduction of btrfs. Thankfully with the abuse of COW fixup, at least it won't crash the kernel. [FIX] Instead of immediately unlocking the extent and folios, we keep the extent and folios locked until either erroring out or the whole delalloc range finished. When the whole delalloc range finished without error, we just unlock the whole range with PAGE_SET_ORDERED (and PAGE_UNLOCK for !keep_locked cases) ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57976", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MsAjOQqU9HBRH1IUou6UlA==": { "id": "MsAjOQqU9HBRH1IUou6UlA==", "updater": "debian/updater", "name": "CVE-2017-16232", "description": "LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-16232", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MsQlQGzt9E1GQg3tm6Z6Xg==": { "id": "MsQlQGzt9E1GQg3tm6Z6Xg==", "updater": "debian/updater", "name": "CVE-2023-53627", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list When freeing slots in function slot_complete_v3_hw(), it is possible that sas_dev.list is being traversed elsewhere, and it may trigger a NULL pointer exception, such as follows: ==\u003ecq thread ==\u003escsi_eh_6 ==\u003escsi_error_handler() \t\t\t\t ==\u003esas_eh_handle_sas_errors() \t\t\t\t ==\u003esas_scsi_find_task() \t\t\t\t ==\u003elldd_abort_task() ==\u003eslot_complete_v3_hw() ==\u003ehisi_sas_abort_task() ==\u003ehisi_sas_slot_task_free()\t ==\u003edereg_device_v3_hw() ==\u003elist_del_init() \t\t ==\u003elist_for_each_entry_safe() [ 7165.434918] sas: Enter sas_scsi_recover_host busy: 32 failed: 32 [ 7165.434926] sas: trying to find task 0x00000000769b5ba5 [ 7165.434927] sas: sas_scsi_find_task: aborting task 0x00000000769b5ba5 [ 7165.434940] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000769b5ba5) aborted [ 7165.434964] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000c9f7aa07) ignored [ 7165.434965] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000e2a1cf01) ignored [ 7165.434968] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 7165.434972] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000022d52d93) ignored [ 7165.434975] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000066a7516c) ignored [ 7165.434976] Mem abort info: [ 7165.434982] ESR = 0x96000004 [ 7165.434991] Exception class = DABT (current EL), IL = 32 bits [ 7165.434992] SET = 0, FnV = 0 [ 7165.434993] EA = 0, S1PTW = 0 [ 7165.434994] Data abort info: [ 7165.434994] ISV = 0, ISS = 0x00000004 [ 7165.434995] CM = 0, WnR = 0 [ 7165.434997] user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000f29543f2 [ 7165.434998] [0000000000000000] pgd=0000000000000000 [ 7165.435003] Internal error: Oops: 96000004 [#1] SMP [ 7165.439863] Process scsi_eh_6 (pid: 4109, stack limit = 0x00000000c43818d5) [ 7165.468862] pstate: 00c00009 (nzcv daif +PAN +UAO) [ 7165.473637] pc : dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw] [ 7165.479443] lr : dereg_device_v3_hw+0x2c/0xa8 [hisi_sas_v3_hw] [ 7165.485247] sp : ffff00001d623bc0 [ 7165.488546] x29: ffff00001d623bc0 x28: ffffa027d03b9508 [ 7165.493835] x27: ffff80278ed50af0 x26: ffffa027dd31e0a8 [ 7165.499123] x25: ffffa027d9b27f88 x24: ffffa027d9b209f8 [ 7165.504411] x23: ffffa027c45b0d60 x22: ffff80278ec07c00 [ 7165.509700] x21: 0000000000000008 x20: ffffa027d9b209f8 [ 7165.514988] x19: ffffa027d9b27f88 x18: ffffffffffffffff [ 7165.520276] x17: 0000000000000000 x16: 0000000000000000 [ 7165.525564] x15: ffff0000091d9708 x14: ffff0000093b7dc8 [ 7165.530852] x13: ffff0000093b7a23 x12: 6e7265746e692067 [ 7165.536140] x11: 0000000000000000 x10: 0000000000000bb0 [ 7165.541429] x9 : ffff00001d6238f0 x8 : ffffa027d877af00 [ 7165.546718] x7 : ffffa027d6329600 x6 : ffff7e809f58ca00 [ 7165.552006] x5 : 0000000000001f8a x4 : 000000000000088e [ 7165.557295] x3 : ffffa027d9b27fa8 x2 : 0000000000000000 [ 7165.562583] x1 : 0000000000000000 x0 : 000000003000188e [ 7165.567872] Call trace: [ 7165.570309] dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw] [ 7165.575775] hisi_sas_abort_task+0x248/0x358 [hisi_sas_main] [ 7165.581415] sas_eh_handle_sas_errors+0x258/0x8e0 [libsas] [ 7165.586876] sas_scsi_recover_host+0x134/0x458 [libsas] [ 7165.592082] scsi_error_handler+0xb4/0x488 [ 7165.596163] kthread+0x134/0x138 [ 7165.599380] ret_from_fork+0x10/0x18 [ 7165.602940] Code: d5033e9f b9000040 aa0103e2 eb03003f (f9400021) [ 7165.609004] kernel fault(0x1) notification starting on CPU 75 [ 7165.700728] ---[ end trace fc042cbbea224efc ]--- [ 7165.705326] Kernel panic - not syncing: Fatal exception To fix the issue, grab sas_dev lock when traversing the members of sas_dev.list in dereg_device_v3_hw() and hisi_sas_release_tasks() to avoid concurrency of adding and deleting member. When ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53627", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "MsbFZkmfoWEAxb2Qnj1CHw==": { "id": "MsbFZkmfoWEAxb2Qnj1CHw==", "updater": "debian/updater", "name": "CVE-2019-16089", "description": "An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16089", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Mu99OY+ZuIj2ySoksh3ThQ==": { "id": "Mu99OY+ZuIj2ySoksh3ThQ==", "updater": "debian/updater", "name": "CVE-2026-53122", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit When using the flushoncommit mount option, we can have a deadlock between a transaction commit and a reflink operation that copied an inline extent to an offset beyond the current i_size of the destination node. The deadlock happens like this: 1) Task A clones an inline extent from inode X to an offset of inode Y that is beyond Y's current i_size. This means we copied the inline extent's data to a folio of inode Y that is beyond its EOF, using a call to copy_inline_to_page(); 2) Task B starts a transaction commit and calls btrfs_start_delalloc_flush() to flush delalloc; 3) The delalloc flushing sees the new dirty folio of inode Y and when it attempts to flush it, it ends up at extent_writepage() and sees that the offset of the folio is beyond the i_size of inode Y, so it attempts to invalidate the folio by calling folio_invalidate(), which ends up at btrfs' folio invalidate callback - btrfs_invalidate_folio(). There it tries to lock the folio's range in inode Y's extent io tree, but it blocks since it's currently locked by task A - during a reflink we lock the inodes and the source and destination ranges after flushing all delalloc and waiting for ordered extent completion - after that we don't expect to have dirty folios in the ranges, the exception is if we have to copy an inline extent's data (because the destination offset is not zero); 4) Task A then attempts to start a transaction to update the inode item, and then it's blocked since the current transaction is in the TRANS_STATE_COMMIT_START state. Therefore task A has to wait for the current transaction to become unblocked (its state \u003e= TRANS_STATE_UNBLOCKED). So task A is waiting for the transaction commit done by task B, and the later waiting on the extent lock of inode Y that is currently held by task A. Syzbot recently reported this with the following stack traces: INFO: task kworker/u8:7:1053 blocked for more than 143 seconds. Not tainted syzkaller #0 \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:kworker/u8:7 state:D stack:23520 pid:1053 tgid:1053 ppid:2 task_flags:0x4208060 flags:0x00080000 Workqueue: writeback wb_workfn (flush-btrfs-46) Call Trace: \u003cTASK\u003e context_switch kernel/sched/core.c:5298 [inline] __schedule+0x1553/0x5240 kernel/sched/core.c:6911 __schedule_loop kernel/sched/core.c:6993 [inline] schedule+0x164/0x360 kernel/sched/core.c:7008 wait_extent_bit fs/btrfs/extent-io-tree.c:811 [inline] btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:1914 btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline] btrfs_invalidate_folio+0x43d/0xc40 fs/btrfs/inode.c:7704 extent_writepage fs/btrfs/extent_io.c:1852 [inline] extent_write_cache_pages fs/btrfs/extent_io.c:2580 [inline] btrfs_writepages+0x12ff/0x2440 fs/btrfs/extent_io.c:2713 do_writepages+0x32e/0x550 mm/page-writeback.c:2554 __writeback_single_inode+0x133/0x11a0 fs/fs-writeback.c:1750 writeback_sb_inodes+0x995/0x19d0 fs/fs-writeback.c:2042 wb_writeback+0x456/0xb70 fs/fs-writeback.c:2227 wb_do_writeback fs/fs-writeback.c:2374 [inline] wb_workfn+0x41a/0xf60 fs/fs-writeback.c:2414 process_one_work kernel/workqueue.c:3276 [inline] process_scheduled_works+0xb6e/0x18c0 kernel/workqueue.c:3359 worker_thread+0xa53/0xfc0 kernel/workqueue.c:3440 kthread+0x388/0x470 kernel/kthread.c:436 ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 \u003c/TASK\u003e INFO: task syz.4.64:6910 blocked for more than 143 seconds. Not tainted syzkaller #0 \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:syz.4.64 state:D stack:22752 pid:6910 tgid: ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53122", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Mw989Y2kuFloF3u0zyM2qw==": { "id": "Mw989Y2kuFloF3u0zyM2qw==", "updater": "debian/updater", "name": "CVE-2026-23247", "description": "In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 (\"secure_seq: downgrade to per-host timestamp offsets\") tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways. One of them is to bring back TCP ports in TS offset randomization. As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23247", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "N+fzYkC09CSzgvWTQBy8Aw==": { "id": "N+fzYkC09CSzgvWTQBy8Aw==", "updater": "debian/updater", "name": "CVE-2026-15146", "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15146", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "N0pXiwLCavo/09vFe/8Y+Q==": { "id": "N0pXiwLCavo/09vFe/8Y+Q==", "updater": "debian/updater", "name": "CVE-2026-53226", "description": "In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: fix generic IRQ chip leak on remove The driver allocates domain generic chips using irq_alloc_domain_generic_chips() during probe. However, on driver remove/teardown, the generic chips are not automatically freed when the IRQ domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC. This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global gc_list and may later be visited by generic IRQ chip suspend, resume, or shutdown callbacks after the GPIO bank has been removed, potentially resulting in a use-after-free and kernel crash. Fix the resource leak by explicitly calling irq_domain_remove_generic_chips() before removing the IRQ domain in rockchip_gpio_remove().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53226", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "N473F11M/P9rXXVHcdmElg==": { "id": "N473F11M/P9rXXVHcdmElg==", "updater": "debian/updater", "name": "CVE-2026-72522", "description": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-72522", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "N6KFD0gQnZqGoV2GULM/7A==": { "id": "N6KFD0gQnZqGoV2GULM/7A==", "updater": "debian/updater", "name": "CVE-2026-8927", "description": "When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8927", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NAl3wEfkqVbijYPDBkjnSA==": { "id": "NAl3wEfkqVbijYPDBkjnSA==", "updater": "debian/updater", "name": "CVE-2021-4214", "description": "A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-4214", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libpng1.6", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NAsisJpfKjN1bhnqwGO/dg==": { "id": "NAsisJpfKjN1bhnqwGO/dg==", "updater": "debian/updater", "name": "CVE-2026-68206", "description": "In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC active reference counts HEVC slice parameters are shared stateless V4L2 controls, but the common validation path does not verify the active L0/L1 reference counts before driver-specific code consumes them. The original report came from Cedrus, but the active count bounds are not Cedrus-specific. Validate them in the common HEVC slice control path so stateless HEVC drivers get the same basic guarantees as soon as the control is queued. Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may use out-of-range sentinel values such as 0xff for missing references, and some hardware can use that information for concealment. Keep this common check limited to the active reference counts.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68206", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NK0hpvWCXi1qKWF+3Jh4KQ==": { "id": "NK0hpvWCXi1qKWF+3Jh4KQ==", "updater": "debian/updater", "name": "CVE-2025-71152", "description": "In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference Problem description ------------------- DSA has a mumbo-jumbo of reference handling of the conduit net device and its kobject which, sadly, is just wrong and doesn't make sense. There are two distinct problems. 1. The OF path, which uses of_find_net_device_by_node(), never releases the elevated refcount on the conduit's kobject. Nominally, the OF and non-OF paths should result in objects having identical reference counts taken, and it is already suspicious that dsa_dev_to_net_device() has a put_device() call which is missing in dsa_port_parse_of(), but we can actually even verify that an issue exists. With CONFIG_DEBUG_KOBJECT_RELEASE=y, if we run this command \"before\" and \"after\" applying this patch: (unbind the conduit driver for net device eno2) echo 0000:00:00.2 \u003e /sys/bus/pci/drivers/fsl_enetc/unbind we see these lines in the output diff which appear only with the patch applied: kobject: 'eno2' (ffff002009a3a6b8): kobject_release, parent 0000000000000000 (delayed 1000) kobject: '109' (ffff0020099d59a0): kobject_release, parent 0000000000000000 (delayed 1000) 2. After we find the conduit interface one way (OF) or another (non-OF), it can get unregistered at any time, and DSA remains with a long-lived, but in this case stale, cpu_dp-\u003econduit pointer. Holding the net device's underlying kobject isn't actually of much help, it just prevents it from being freed (but we never need that kobject directly). What helps us to prevent the net device from being unregistered is the parallel netdev reference mechanism (dev_hold() and dev_put()). Actually we actually use that netdev tracker mechanism implicitly on user ports since commit 2f1e8ea726e9 (\"net: dsa: link interfaces with the DSA master to get rid of lockdep warnings\"), via netdev_upper_dev_link(). But time still passes at DSA switch probe time between the initial of_find_net_device_by_node() code and the user port creation time, time during which the conduit could unregister itself and DSA wouldn't know about it. So we have to run of_find_net_device_by_node() under rtnl_lock() to prevent that from happening, and release the lock only with the netdev tracker having acquired the reference. Do we need to keep the reference until dsa_unregister_switch() / dsa_switch_shutdown()? 1: Maybe yes. A switch device will still be registered even if all user ports failed to probe, see commit 86f8b1c01a0a (\"net: dsa: Do not make user port errors fatal\"), and the cpu_dp-\u003econduit pointers remain valid. I haven't audited all call paths to see whether they will actually use the conduit in lack of any user port, but if they do, it seems safer to not rely on user ports for that reference. 2. Definitely yes. We support changing the conduit which a user port is associated to, and we can get into a situation where we've moved all user ports away from a conduit, thus no longer hold any reference to it via the net device tracker. But we shouldn't let it go nonetheless - see the next change in relation to dsa_tree_find_first_conduit() and LAG conduits which disappear. We have to be prepared to return to the physical conduit, so the CPU port must explicitly keep another reference to it. This is also to say: the user ports and their CPU ports may not always keep a reference to the same conduit net device, and both are needed. As for the conduit's kobject for the /sys/class/net/ entry, we don't care about it, we can release it as soon as we hold the net device object itself. History and blame attribution ----------------------------- The code has been refactored so many times, it is very difficult to follow and properly attribute a blame, but I'll try to make a short history which I hope to be correct. We have two distinct probing paths: - one for OF, introduced in 2016 i ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71152", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NK1kWadbZSLwkY1aoYnx4w==": { "id": "NK1kWadbZSLwkY1aoYnx4w==", "updater": "debian/updater", "name": "CVE-2026-68435", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec command line lookup When searching the loaded segments for the \"kexec\" command line marker, the kexec_load(2) path (file_mode == 0) passes the user-space segment buffer straight to strncmp() through a bogus (char __user *) cast. This dereferences a user pointer in kernel context, which is wrong and is flagged by sparse: arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in argument 2 (different address spaces) @@ expected char const * @@ got char [noderef] __user * Here copy the marker-sized prefix of each segment into a small on-stack buffer with copy_from_user() before comparing, and skip segments that fault. The subsequent copy_from_user() that stages the full command line into the safe area is left unchanged.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68435", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NLzrvdj29R1KWzyuO7vGrw==": { "id": "NLzrvdj29R1KWzyuO7vGrw==", "updater": "debian/updater", "name": "CVE-2026-46071", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 svm_copy_lbrs() always marks VMCB_LBR dirty in the destination VMCB. However, nested_svm_vmexit() uses it to copy LBRs to vmcb12, and clearing clean bits in vmcb12 is not architecturally defined. Move vmcb_mark_dirty() to callers and drop it for vmcb12. This also facilitates incoming refactoring that does not pass the entire VMCB to svm_copy_lbrs().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46071", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NNeGSUp8UIMc5elm+qOY6g==": { "id": "NNeGSUp8UIMc5elm+qOY6g==", "updater": "debian/updater", "name": "CVE-2026-3949", "description": "A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3949", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NPKsnmhsUE2/wNe5Pb3DLQ==": { "id": "NPKsnmhsUE2/wNe5Pb3DLQ==", "updater": "debian/updater", "name": "CVE-2026-68433", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply() uses msg-\u003efront_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read. Use msg-\u003efront.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68433", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NQ2dAoiyDdaP6k9PNV2Zmg==": { "id": "NQ2dAoiyDdaP6k9PNV2Zmg==", "updater": "debian/updater", "name": "CVE-2018-9996", "description": "An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-9996", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NXu+dXN5KBvsm9u13e7YlA==": { "id": "NXu+dXN5KBvsm9u13e7YlA==", "updater": "debian/updater", "name": "CVE-2026-7017", "description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-7017", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NZI2pa2BKL40u6kulzTybA==": { "id": "NZI2pa2BKL40u6kulzTybA==", "updater": "debian/updater", "name": "CVE-2025-1371", "description": "A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1371", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NZV9KIcDUlVYcEXxu9twfg==": { "id": "NZV9KIcDUlVYcEXxu9twfg==", "updater": "debian/updater", "name": "CVE-2026-6253", "description": "curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow a redirect to a URL using another scheme (say `https://`), accessed using a second, different, proxy", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6253", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NcOCxDESPibyfzi9bB8MWQ==": { "id": "NcOCxDESPibyfzi9bB8MWQ==", "updater": "debian/updater", "name": "CVE-2025-40307", "description": "In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created an exfat image with cluster bits not set for the allocation bitmap. exfat-fs reads and uses the allocation bitmap without checking this. The problem is that if the start cluster of the allocation bitmap is 6, cluster 6 can be allocated when creating a directory with mkdir. exfat zeros out this cluster in exfat_mkdir, which can delete existing entries. This can reallocate the allocated entries. In addition, the allocation bitmap is also zeroed out, so cluster 6 can be reallocated. This patch adds exfat_test_bitmap_range to validate that clusters used for the allocation bitmap are correctly marked as in-use.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40307", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NgS+u6TtkDzJT8fQO9+/4g==": { "id": "NgS+u6TtkDzJT8fQO9+/4g==", "updater": "debian/updater", "name": "CVE-2026-62946", "description": "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-62946", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NhLMD1ecB2U1wdghzQvPSA==": { "id": "NhLMD1ecB2U1wdghzQvPSA==", "updater": "debian/updater", "name": "CVE-2025-21888", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix a WARN during dereg_mr for DM type Memory regions (MR) of type DM (device memory) do not have an associated umem. In the __mlx5_ib_dereg_mr() -\u003e mlx5_free_priv_descs() flow, the code incorrectly takes the wrong branch, attempting to call dma_unmap_single() on a DMA address that is not mapped. This results in a WARN [1], as shown below. The issue is resolved by properly accounting for the DM type and ensuring the correct branch is selected in mlx5_free_priv_descs(). [1] WARNING: CPU: 12 PID: 1346 at drivers/iommu/dma-iommu.c:1230 iommu_dma_unmap_page+0x79/0x90 Modules linked in: ip6table_mangle ip6table_nat ip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry ovelay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core CPU: 12 UID: 0 PID: 1346 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1631 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:iommu_dma_unmap_page+0x79/0x90 Code: 2b 49 3b 29 72 26 49 3b 69 08 73 20 4d 89 f0 44 89 e9 4c 89 e2 48 89 ee 48 89 df 5b 5d 41 5c 41 5d 41 5e 41 5f e9 07 b8 88 ff \u003c0f\u003e 0b 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 66 0f 1f 44 00 RSP: 0018:ffffc90001913a10 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff88810194b0a8 RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001 RBP: ffff88810194b0a8 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000 R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000 FS: 00007f537abdd740(0000) GS:ffff88885fb00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f537aeb8000 CR3: 000000010c248001 CR4: 0000000000372eb0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: \u003cTASK\u003e ? __warn+0x84/0x190 ? iommu_dma_unmap_page+0x79/0x90 ? report_bug+0xf8/0x1c0 ? handle_bug+0x55/0x90 ? exc_invalid_op+0x13/0x60 ? asm_exc_invalid_op+0x16/0x20 ? iommu_dma_unmap_page+0x79/0x90 dma_unmap_page_attrs+0xe6/0x290 mlx5_free_priv_descs+0xb0/0xe0 [mlx5_ib] __mlx5_ib_dereg_mr+0x37e/0x520 [mlx5_ib] ? _raw_spin_unlock_irq+0x24/0x40 ? wait_for_completion+0xfe/0x130 ? rdma_restrack_put+0x63/0xe0 [ib_core] ib_dereg_mr_user+0x5f/0x120 [ib_core] ? lock_release+0xc6/0x280 destroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs] uverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs] uobj_destroy+0x3f/0x70 [ib_uverbs] ib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs] ? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs] ? lock_acquire+0xc1/0x2f0 ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0x116/0x170 [ib_uverbs] ? lock_release+0xc6/0x280 ib_uverbs_ioctl+0xe7/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] __x64_sys_ioctl+0x1b0/0xa70 do_syscall_64+0x6b/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f537adaf17b Code: 0f 1e fa 48 8b 05 1d ad 0c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 8b 0d ed ac 0c 00 f7 d8 64 89 01 48 RSP: 002b:00007ffff218f0b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ffff218f1d8 RCX: 00007f537adaf17b RDX: 00007ffff218f1c0 RSI: 00000000c0181b01 RDI: 0000000000000003 RBP: 00007ffff218f1a0 R08: 00007f537aa8d010 R09: 0000561ee2e4f270 R10: 00007f537aace3a8 R11: 0000000000000246 R12: 00007ffff218f190 R13: 000000000000001c R14: 0000561ee2e4d7c0 R15: 00007ffff218f450 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21888", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Nkn4Lx7wFGCCYyHykJcx5Q==": { "id": "Nkn4Lx7wFGCCYyHykJcx5Q==", "updater": "debian/updater", "name": "CVE-2019-9192", "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-9192", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NnyA5h91xhCGj/V12bkyNQ==": { "id": "NnyA5h91xhCGj/V12bkyNQ==", "updater": "debian/updater", "name": "CVE-2025-40003", "description": "In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work The origin code calls cancel_delayed_work() in ocelot_stats_deinit() to cancel the cyclic delayed work item ocelot-\u003estats_work. However, cancel_delayed_work() may fail to cancel the work item if it is already executing. While destroy_workqueue() does wait for all pending work items in the work queue to complete before destroying the work queue, it cannot prevent the delayed work item from being rescheduled within the ocelot_check_stats_work() function. This limitation exists because the delayed work item is only enqueued into the work queue after its timer expires. Before the timer expiration, destroy_workqueue() has no visibility of this pending work item. Once the work queue appears empty, destroy_workqueue() proceeds with destruction. When the timer eventually expires, the delayed work item gets queued again, leading to the following warning: workqueue: cannot queue ocelot_check_stats_work on wq ocelot-switch-stats WARNING: CPU: 2 PID: 0 at kernel/workqueue.c:2255 __queue_work+0x875/0xaf0 ... RIP: 0010:__queue_work+0x875/0xaf0 ... RSP: 0018:ffff88806d108b10 EFLAGS: 00010086 RAX: 0000000000000000 RBX: 0000000000000101 RCX: 0000000000000027 RDX: 0000000000000027 RSI: 0000000000000004 RDI: ffff88806d123e88 RBP: ffffffff813c3170 R08: 0000000000000000 R09: ffffed100da247d2 R10: ffffed100da247d1 R11: ffff88806d123e8b R12: ffff88800c00f000 R13: ffff88800d7285c0 R14: ffff88806d0a5580 R15: ffff88800d7285a0 FS: 0000000000000000(0000) GS:ffff8880e5725000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe18e45ea10 CR3: 0000000005e6c000 CR4: 00000000000006f0 Call Trace: \u003cIRQ\u003e ? kasan_report+0xc6/0xf0 ? __pfx_delayed_work_timer_fn+0x10/0x10 ? __pfx_delayed_work_timer_fn+0x10/0x10 call_timer_fn+0x25/0x1c0 __run_timer_base.part.0+0x3be/0x8c0 ? __pfx_delayed_work_timer_fn+0x10/0x10 ? rcu_sched_clock_irq+0xb06/0x27d0 ? __pfx___run_timer_base.part.0+0x10/0x10 ? try_to_wake_up+0xb15/0x1960 ? _raw_spin_lock_irq+0x80/0xe0 ? __pfx__raw_spin_lock_irq+0x10/0x10 tmigr_handle_remote_up+0x603/0x7e0 ? __pfx_tmigr_handle_remote_up+0x10/0x10 ? sched_balance_trigger+0x1c0/0x9f0 ? sched_tick+0x221/0x5a0 ? _raw_spin_lock_irq+0x80/0xe0 ? __pfx__raw_spin_lock_irq+0x10/0x10 ? tick_nohz_handler+0x339/0x440 ? __pfx_tmigr_handle_remote_up+0x10/0x10 __walk_groups.isra.0+0x42/0x150 tmigr_handle_remote+0x1f4/0x2e0 ? __pfx_tmigr_handle_remote+0x10/0x10 ? ktime_get+0x60/0x140 ? lapic_next_event+0x11/0x20 ? clockevents_program_event+0x1d4/0x2a0 ? hrtimer_interrupt+0x322/0x780 handle_softirqs+0x16a/0x550 irq_exit_rcu+0xaf/0xe0 sysvec_apic_timer_interrupt+0x70/0x80 \u003c/IRQ\u003e ... The following diagram reveals the cause of the above warning: CPU 0 (remove) | CPU 1 (delayed work callback) mscc_ocelot_remove() | ocelot_deinit() | ocelot_check_stats_work() ocelot_stats_deinit() | cancel_delayed_work()| ... | queue_delayed_work() destroy_workqueue() | (wait a time) | __queue_work() //UAF The above scenario actually constitutes a UAF vulnerability. The ocelot_stats_deinit() is only invoked when initialization failure or resource destruction, so we must ensure that any delayed work items cannot be rescheduled. Replace cancel_delayed_work() with disable_delayed_work_sync() to guarantee proper cancellation of the delayed work item and ensure completion of any currently executing work before the workqueue is deallocated. A deadlock concern was considered: ocelot_stats_deinit() is called in a process context and is not holding any locks that the delayed work item might also need. Therefore, the use of the _sync() variant is safe here. This bug was identified through static analysis. To reproduce the issue and validate the fix, I simulated ocelot-swit ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40003", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "NuQaIdTAWjK8WtwsvClXbg==": { "id": "NuQaIdTAWjK8WtwsvClXbg==", "updater": "debian/updater", "name": "CVE-2026-46181", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() Sashiko points out the radix_tree itself is RCU safe, but nothing ever frees the mlx4_srq struct with RCU, and it isn't even accessed within the RCU critical section. It also will crash if an event is delivered before the srq object is finished initializing. Use the spinlock since it isn't easy to make RCU work, use refcount_inc_not_zero() to protect against partially initialized objects, and order the refcount_set() to be after the srq is fully initialized.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46181", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Nvv3pdW1HxIo+5qMwgrR5g==": { "id": "Nvv3pdW1HxIo+5qMwgrR5g==", "updater": "debian/updater", "name": "CVE-2026-23276", "description": "In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functions Tunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own recursion limit. When a bond device in broadcast mode has GRE tap interfaces as slaves, and those GRE tunnels route back through the bond, multicast/broadcast traffic triggers infinite recursion between bond_xmit_broadcast() and ip_tunnel_xmit()/ip6_tnl_xmit(), causing kernel stack overflow. The existing XMIT_RECURSION_LIMIT (8) in the no-qdisc path is not sufficient because tunnel recursion involves route lookups and full IP output, consuming much more stack per level. Use a lower limit of 4 (IP_TUNNEL_RECURSION_LIMIT) to prevent overflow. Add recursion detection using dev_xmit_recursion helpers directly in iptunnel_xmit() and ip6tunnel_xmit() to cover all IPv4/IPv6 tunnel paths including UDP encapsulated tunnels (VXLAN, Geneve, etc.). Move dev_xmit_recursion helpers from net/core/dev.h to public header include/linux/netdevice.h so they can be used by tunnel code. BUG: KASAN: stack-out-of-bounds in blake2s.constprop.0+0xe7/0x160 Write of size 32 at addr ffff88810033fed0 by task kworker/0:1/11 Workqueue: mld mld_ifc_work Call Trace: \u003cTASK\u003e __build_flow_key.constprop.0 (net/ipv4/route.c:515) ip_rt_update_pmtu (net/ipv4/route.c:1073) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:84) ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) ip_finish_output2 (net/ipv4/ip_output.c:237) ip_output (net/ipv4/ip_output.c:438) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) ip_finish_output2 (net/ipv4/ip_output.c:237) ip_output (net/ipv4/ip_output.c:438) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86) ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) mld_sendpack mld_ifc_work process_one_work worker_thread \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23276", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O+eHWF1ryUlCFVMNqM1DDQ==": { "id": "O+eHWF1ryUlCFVMNqM1DDQ==", "updater": "debian/updater", "name": "CVE-2017-14988", "description": "Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmImf/ImfCRgbaFile.cpp. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-14988", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O+l1d8VG6t1aH2SBfORAMQ==": { "id": "O+l1d8VG6t1aH2SBfORAMQ==", "updater": "debian/updater", "name": "CVE-2026-68430", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's no need to crash the kernel for this case. (cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68430", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O3Czql5c0ZzfDAtbZXKSfA==": { "id": "O3Czql5c0ZzfDAtbZXKSfA==", "updater": "debian/updater", "name": "CVE-2025-21649", "description": "In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is sent on HIP08 devices Currently, HIP08 devices does not register the ptp devices, so the hdev-\u003eptp is NULL. But the tx process would still try to set hardware time stamp info with SKBTX_HW_TSTAMP flag and cause a kernel crash. [ 128.087798] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018 ... [ 128.280251] pc : hclge_ptp_set_tx_info+0x2c/0x140 [hclge] [ 128.286600] lr : hclge_ptp_set_tx_info+0x20/0x140 [hclge] [ 128.292938] sp : ffff800059b93140 [ 128.297200] x29: ffff800059b93140 x28: 0000000000003280 [ 128.303455] x27: ffff800020d48280 x26: ffff0cb9dc814080 [ 128.309715] x25: ffff0cb9cde93fa0 x24: 0000000000000001 [ 128.315969] x23: 0000000000000000 x22: 0000000000000194 [ 128.322219] x21: ffff0cd94f986000 x20: 0000000000000000 [ 128.328462] x19: ffff0cb9d2a166c0 x18: 0000000000000000 [ 128.334698] x17: 0000000000000000 x16: ffffcf1fc523ed24 [ 128.340934] x15: 0000ffffd530a518 x14: 0000000000000000 [ 128.347162] x13: ffff0cd6bdb31310 x12: 0000000000000368 [ 128.353388] x11: ffff0cb9cfbc7070 x10: ffff2cf55dd11e02 [ 128.359606] x9 : ffffcf1f85a212b4 x8 : ffff0cd7cf27dab0 [ 128.365831] x7 : 0000000000000a20 x6 : ffff0cd7cf27d000 [ 128.372040] x5 : 0000000000000000 x4 : 000000000000ffff [ 128.378243] x3 : 0000000000000400 x2 : ffffcf1f85a21294 [ 128.384437] x1 : ffff0cb9db520080 x0 : ffff0cb9db500080 [ 128.390626] Call trace: [ 128.393964] hclge_ptp_set_tx_info+0x2c/0x140 [hclge] [ 128.399893] hns3_nic_net_xmit+0x39c/0x4c4 [hns3] [ 128.405468] xmit_one.constprop.0+0xc4/0x200 [ 128.410600] dev_hard_start_xmit+0x54/0xf0 [ 128.415556] sch_direct_xmit+0xe8/0x634 [ 128.420246] __dev_queue_xmit+0x224/0xc70 [ 128.425101] dev_queue_xmit+0x1c/0x40 [ 128.429608] ovs_vport_send+0xac/0x1a0 [openvswitch] [ 128.435409] do_output+0x60/0x17c [openvswitch] [ 128.440770] do_execute_actions+0x898/0x8c4 [openvswitch] [ 128.446993] ovs_execute_actions+0x64/0xf0 [openvswitch] [ 128.453129] ovs_dp_process_packet+0xa0/0x224 [openvswitch] [ 128.459530] ovs_vport_receive+0x7c/0xfc [openvswitch] [ 128.465497] internal_dev_xmit+0x34/0xb0 [openvswitch] [ 128.471460] xmit_one.constprop.0+0xc4/0x200 [ 128.476561] dev_hard_start_xmit+0x54/0xf0 [ 128.481489] __dev_queue_xmit+0x968/0xc70 [ 128.486330] dev_queue_xmit+0x1c/0x40 [ 128.490856] ip_finish_output2+0x250/0x570 [ 128.495810] __ip_finish_output+0x170/0x1e0 [ 128.500832] ip_finish_output+0x3c/0xf0 [ 128.505504] ip_output+0xbc/0x160 [ 128.509654] ip_send_skb+0x58/0xd4 [ 128.513892] udp_send_skb+0x12c/0x354 [ 128.518387] udp_sendmsg+0x7a8/0x9c0 [ 128.522793] inet_sendmsg+0x4c/0x8c [ 128.527116] __sock_sendmsg+0x48/0x80 [ 128.531609] __sys_sendto+0x124/0x164 [ 128.536099] __arm64_sys_sendto+0x30/0x5c [ 128.540935] invoke_syscall+0x50/0x130 [ 128.545508] el0_svc_common.constprop.0+0x10c/0x124 [ 128.551205] do_el0_svc+0x34/0xdc [ 128.555347] el0_svc+0x20/0x30 [ 128.559227] el0_sync_handler+0xb8/0xc0 [ 128.563883] el0_sync+0x160/0x180", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21649", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O3dORpbcud/0vqRs7HyGhQ==": { "id": "O3dORpbcud/0vqRs7HyGhQ==", "updater": "debian/updater", "name": "CVE-2026-68125", "description": "In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_decrypt_auth() computes the associated-data length for the AEAD request as \tassoclen += datalen - authlen; where datalen is the number of bytes after the MAC header and authlen (4, 8 or 16) is the length of the authentication tag. Nothing verifies that the frame actually carries at least authlen payload bytes. A secured frame whose payload is shorter than the tag makes datalen - authlen negative; assoclen is then passed to aead_request_set_ad() as an unsigned value close to 4 GiB, so crypto_aead_decrypt() walks far off the end of the scatterlist that only spans the real frame. The frame is fully attacker-controlled and reaches this path from any IEEE 802.15.4 peer in radio range. Reject frames whose payload is shorter than the authentication tag before the subtraction. Dynamically reproduced on a KASAN kernel as a general-protection-fault in the AEAD scatterwalk, and the fix confirmed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68125", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O4I5OUkDRdIqJ5Q9vidfxA==": { "id": "O4I5OUkDRdIqJ5Q9vidfxA==", "updater": "debian/updater", "name": "CVE-2026-73281", "description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-73281", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O5i6HOYABXcKKK82h0iOYA==": { "id": "O5i6HOYABXcKKK82h0iOYA==", "updater": "debian/updater", "name": "CVE-2026-18024", "description": "Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18024", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O6rYT5lpJicjJDJhxGauhQ==": { "id": "O6rYT5lpJicjJDJhxGauhQ==", "updater": "debian/updater", "name": "CVE-2026-41071", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz-\u003eget_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41071", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "O7qzhTPmuAniGdn3z0AkdQ==": { "id": "O7qzhTPmuAniGdn3z0AkdQ==", "updater": "debian/updater", "name": "CVE-2023-52590", "description": "In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be locking moved directory if its parent does not change. Change ocfs2 rename code to avoid touching renamed directory if its parent does not change as without locking that can corrupt the filesystem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52590", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OER9o99pdjlfsp56JzoqNg==": { "id": "OER9o99pdjlfsp56JzoqNg==", "updater": "debian/updater", "name": "CVE-2025-37853", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: debugfs hang_hws skip GPU with MES debugfs hang_hws is used by GPU reset test with HWS, for MES this crash the kernel with NULL pointer access because dqm-\u003epacket_mgr is not setup for MES path. Skip GPU with MES for now, MES hang_hws debugfs interface will be supported later.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37853", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OGb2T1usqCHtg55ESExGbA==": { "id": "OGb2T1usqCHtg55ESExGbA==", "updater": "debian/updater", "name": "CVE-2019-12378", "description": "An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This has been disputed as not an issue", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12378", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ONPAYP/p9d2gYGt/OPIPqw==": { "id": "ONPAYP/p9d2gYGt/OPIPqw==", "updater": "debian/updater", "name": "CVE-2024-46806", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the warning division or modulo by zero Checks the partition mode and returns an error for an invalid mode.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46806", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ORg9zjoAVr2V+FF+1/aIzg==": { "id": "ORg9zjoAVr2V+FF+1/aIzg==", "updater": "debian/updater", "name": "CVE-2024-50029", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following trace: BUG: KASAN: slab-use-after-free in hci_enhanced_setup_sync+0x91b/0xa60 Read of size 1 at addr ffff888002328ffd by task kworker/u5:2/37 CPU: 0 UID: 0 PID: 37 Comm: kworker/u5:2 Not tainted 6.11.0-rc6-01300-g810be445d8d6 #7099 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace: \u003cTASK\u003e dump_stack_lvl+0x5d/0x80 ? hci_enhanced_setup_sync+0x91b/0xa60 print_report+0x152/0x4c0 ? hci_enhanced_setup_sync+0x91b/0xa60 ? __virt_addr_valid+0x1fa/0x420 ? hci_enhanced_setup_sync+0x91b/0xa60 kasan_report+0xda/0x1b0 ? hci_enhanced_setup_sync+0x91b/0xa60 hci_enhanced_setup_sync+0x91b/0xa60 ? __pfx_hci_enhanced_setup_sync+0x10/0x10 ? __pfx___mutex_lock+0x10/0x10 hci_cmd_sync_work+0x1c2/0x330 process_one_work+0x7d9/0x1360 ? __pfx_lock_acquire+0x10/0x10 ? __pfx_process_one_work+0x10/0x10 ? assign_work+0x167/0x240 worker_thread+0x5b7/0xf60 ? __kthread_parkme+0xac/0x1c0 ? __pfx_worker_thread+0x10/0x10 ? __pfx_worker_thread+0x10/0x10 kthread+0x293/0x360 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x2f/0x70 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e Allocated by task 34: kasan_save_stack+0x30/0x50 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __hci_conn_add+0x187/0x17d0 hci_connect_sco+0x2e1/0xb90 sco_sock_connect+0x2a2/0xb80 __sys_connect+0x227/0x2a0 __x64_sys_connect+0x6d/0xb0 do_syscall_64+0x71/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 37: kasan_save_stack+0x30/0x50 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x101/0x160 kfree+0xd0/0x250 device_release+0x9a/0x210 kobject_put+0x151/0x280 hci_conn_del+0x448/0xbf0 hci_abort_conn_sync+0x46f/0x980 hci_cmd_sync_work+0x1c2/0x330 process_one_work+0x7d9/0x1360 worker_thread+0x5b7/0xf60 kthread+0x293/0x360 ret_from_fork+0x2f/0x70 ret_from_fork_asm+0x1a/0x30", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50029", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OTrExOT2ykXeHWl52M9Mcg==": { "id": "OTrExOT2ykXeHWl52M9Mcg==", "updater": "debian/updater", "name": "CVE-2025-21836", "description": "In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21836", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OWJa3duCz1A5SfiSYrzr3Q==": { "id": "OWJa3duCz1A5SfiSYrzr3Q==", "updater": "debian/updater", "name": "CVE-2023-4016", "description": "Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-4016", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "procps", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OWtN2QRRD7xZ6IJXy9oe/w==": { "id": "OWtN2QRRD7xZ6IJXy9oe/w==", "updater": "debian/updater", "name": "CVE-2026-43344", "description": "In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix die ID init and look up bugs In snbep_pci2phy_map_init(), in the nr_node_ids \u003e 8 path, uncore_device_to_die() may return -1 when all CPUs associated with the UBOX device are offline. Remove the WARN_ON_ONCE(die_id == -1) check for two reasons: - The current code breaks out of the loop. This is incorrect because pci_get_device() does not guarantee iteration in domain or bus order, so additional UBOX devices may be skipped during the scan. - Returning -EINVAL is incorrect, since marking offline buses with die_id == -1 is expected and should not be treated as an error. Separately, when NUMA is disabled on a NUMA-capable platform, pcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die() to return -1 for all PCI devices. As a result, spr_update_device_location(), used on Intel SPR and EMR, ignores the corresponding PMON units and does not add them to the RB tree. Fix this by using uncore_pcibus_to_dieid(), which retrieves topology from the UBOX GIDNIDMAP register and works regardless of whether NUMA is enabled in Linux. This requires snbep_pci2phy_map_init() to be added in spr_uncore_pci_init(). Keep uncore_device_to_die() only for the nr_node_ids \u003e 8 case, where NUMA is expected to be enabled.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43344", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OYZS0g53R8lKkEyzqhKAaw==": { "id": "OYZS0g53R8lKkEyzqhKAaw==", "updater": "debian/updater", "name": "CVE-2026-31677", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX scatterlist extraction to the remaining receive buffer budget. af_alg_get_rsgl() currently uses af_alg_readable() only as a gate before extracting data into the RX scatterlist. Limit each extraction to the remaining af_alg_rcvbuf(sk) budget so that receive-side accounting matches the amount of data attached to the request. If skcipher cannot obtain enough RX space for at least one chunk while more data remains to be processed, reject the recvmsg call instead of rounding the request length down to zero.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31677", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OaLlKdp4dalc9B0bAvjr/w==": { "id": "OaLlKdp4dalc9B0bAvjr/w==", "updater": "debian/updater", "name": "CVE-2026-46012", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix memory leaks in rxkad_verify_response() Fix rxkad_verify_response() to free the ticket and the server key under all circumstances by initialising the ticket pointer to NULL and then making all paths through the function after the first allocation has been done go through a single common epilogue that just releases everything - where all the releases skip on a NULL pointer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46012", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OdUQ3B3TaB6Z7yh9Y747EQ==": { "id": "OdUQ3B3TaB6Z7yh9Y747EQ==", "updater": "debian/updater", "name": "CVE-2023-52625", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Refactor DMCUB enter/exit idle interface [Why] We can hang in place trying to send commands when the DMCUB isn't powered on. [How] We need to exit out of the idle state prior to sending a command, but the process that performs the exit also invokes a command itself. Fixing this issue involves the following: 1. Using a software state to track whether or not we need to start the process to exit idle or notify idle. It's possible for the hardware to have exited an idle state without driver knowledge, but entering one is always restricted to a driver allow - which makes the SW state vs HW state mismatch issue purely one of optimization, which should seldomly be hit, if at all. 2. Refactor any instances of exit/notify idle to use a single wrapper that maintains this SW state. This works simialr to dc_allow_idle_optimizations, but works at the DMCUB level and makes sure the state is marked prior to any notify/exit idle so we don't enter an infinite loop. 3. Make sure we exit out of idle prior to sending any commands or waiting for DMCUB idle. This patch takes care of 1/2. A future patch will take care of wrapping DMCUB command submission with calls to this new interface.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52625", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ofi0/2sjxB8nnRkMGdfgiA==": { "id": "Ofi0/2sjxB8nnRkMGdfgiA==", "updater": "debian/updater", "name": "CVE-2026-14677", "description": "Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14677", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OiYs2+zugavnJ0RPGp7q3g==": { "id": "OiYs2+zugavnJ0RPGp7q3g==", "updater": "debian/updater", "name": "CVE-2026-66034", "description": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-66034", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OmC3nNLL/7/oGa15psUdDQ==": { "id": "OmC3nNLL/7/oGa15psUdDQ==", "updater": "debian/updater", "name": "CVE-2025-1179", "description": "A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1179", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Opk4oLLMvcTmHz8OjJT6ig==": { "id": "Opk4oLLMvcTmHz8OjJT6ig==", "updater": "debian/updater", "name": "CVE-2026-64685", "description": "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64685", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ot2ALFiZ3eowUTEjMJWYNg==": { "id": "Ot2ALFiZ3eowUTEjMJWYNg==", "updater": "debian/updater", "name": "CVE-2025-38722", "description": "In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix UAF in export_dmabuf() As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it). However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its -\u003erelease()), we have a UAF. dma_buf_fd() is a combination of reserving a descriptor and fd_install(). habanalabs export_dmabuf() calls it and then proceeds to access the objects destroyed on close. In particular, it grabs an extra reference to another struct file that will be dropped as part of -\u003erelease() for ours; that \"will be\" is actually \"might have already been\". Fix that by reserving descriptor before anything else and do fd_install() only when everything had been set up. As a side benefit, we no longer have the failure exit with file already created, but reference to underlying file (as well as -\u003edmabuf_export_cnt, etc.) not grabbed yet; unlike dma_buf_fd(), fd_install() can't fail.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38722", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OudWGxMkT04EAPUlATCyKw==": { "id": "OudWGxMkT04EAPUlATCyKw==", "updater": "debian/updater", "name": "CVE-2026-68279", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, \u0026raw-\u003emsg[idx], num_bytes); without checking that idx + num_bytes \u003c= raw-\u003ecurlen. raw-\u003emsg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw-\u003emsg[]. drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced). Fix both functions by using a single combined check (idx + num_bytes \u003e curlen) before each memcpy. Since num_bytes is u8, it is always \u003e= 0, so this strictly subsumes the simpler idx \u003e curlen form and no separate step is needed. [added missing fixes tag]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68279", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ovas4KEKa7VAli51+uaUcg==": { "id": "Ovas4KEKa7VAli51+uaUcg==", "updater": "debian/updater", "name": "CVE-2026-11822", "description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11822", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ovox+LFKTyPfDw/8TYho6A==": { "id": "Ovox+LFKTyPfDw/8TYho6A==", "updater": "debian/updater", "name": "CVE-2025-29088", "description": "In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-29088", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "OyZClLDMbQRE/2KgCJrplA==": { "id": "OyZClLDMbQRE/2KgCJrplA==", "updater": "debian/updater", "name": "CVE-2024-43899", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null pointer deref in dcn20_resource.c Fixes a hang thats triggered when MPV is run on a DCN401 dGPU: mpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all and then enabling fullscreen playback (double click on the video) The following calltrace will be seen: [ 181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 181.843997] #PF: supervisor instruction fetch in kernel mode [ 181.844003] #PF: error_code(0x0010) - not-present page [ 181.844009] PGD 0 P4D 0 [ 181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI [ 181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G W OE 6.5.0-41-generic #41~22.04.2-Ubuntu [ 181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018 [ 181.844044] RIP: 0010:0x0 [ 181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6. [ 181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246 [ 181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004 [ 181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400 [ 181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c [ 181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8 [ 181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005 [ 181.844121] FS: 00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000 [ 181.844128] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0 [ 181.844141] Call Trace: [ 181.844146] \u003cTASK\u003e [ 181.844153] ? show_regs+0x6d/0x80 [ 181.844167] ? __die+0x24/0x80 [ 181.844179] ? page_fault_oops+0x99/0x1b0 [ 181.844192] ? do_user_addr_fault+0x31d/0x6b0 [ 181.844204] ? exc_page_fault+0x83/0x1b0 [ 181.844216] ? asm_exc_page_fault+0x27/0x30 [ 181.844237] dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu] [ 181.845115] amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu] [ 181.845985] amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu] [ 181.846848] fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu] [ 181.847734] fill_dc_plane_attributes+0x162/0x350 [amdgpu] [ 181.848748] dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu] [ 181.849791] ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu] [ 181.850840] amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43899", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P2+GI7i9vikUEShC4ve81Q==": { "id": "P2+GI7i9vikUEShC4ve81Q==", "updater": "debian/updater", "name": "CVE-2024-49916", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL check for clk_mgr and clk_mgr-\u003efuncs in dcn401_init_hw This commit addresses a potential null pointer dereference issue in the `dcn401_init_hw` function. The issue could occur when `dc-\u003eclk_mgr` or `dc-\u003eclk_mgr-\u003efuncs` is null. The fix adds a check to ensure `dc-\u003eclk_mgr` and `dc-\u003eclk_mgr-\u003efuncs` is not null before accessing its functions. This prevents a potential null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn401/dcn401_hwseq.c:416 dcn401_init_hw() error: we previously assumed 'dc-\u003eclk_mgr' could be null (see line 225)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49916", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P2lxsKJKPIWm7qQRXm3vKA==": { "id": "P2lxsKJKPIWm7qQRXm3vKA==", "updater": "debian/updater", "name": "CVE-2025-22053", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ibmveth: make veth_pool_store stop hanging v2: - Created a single error handling unlock and exit in veth_pool_store - Greatly expanded commit message with previous explanatory-only text Summary: Use rtnl_mutex to synchronize veth_pool_store with itself, ibmveth_close and ibmveth_open, preventing multiple calls in a row to napi_disable. Background: Two (or more) threads could call veth_pool_store through writing to /sys/devices/vio/30000002/pool*/*. You can do this easily with a little shell script. This causes a hang. I configured LOCKDEP, compiled ibmveth.c with DEBUG, and built a new kernel. I ran this test again and saw: Setting pool0/active to 0 Setting pool1/active to 1 [ 73.911067][ T4365] ibmveth 30000002 eth0: close starting Setting pool1/active to 1 Setting pool1/active to 0 [ 73.911367][ T4366] ibmveth 30000002 eth0: close starting [ 73.916056][ T4365] ibmveth 30000002 eth0: close complete [ 73.916064][ T4365] ibmveth 30000002 eth0: open starting [ 110.808564][ T712] systemd-journald[712]: Sent WATCHDOG=1 notification. [ 230.808495][ T712] systemd-journald[712]: Sent WATCHDOG=1 notification. [ 243.683786][ T123] INFO: task stress.sh:4365 blocked for more than 122 seconds. [ 243.683827][ T123] Not tainted 6.14.0-01103-g2df0c02dab82-dirty #8 [ 243.683833][ T123] \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message. [ 243.683838][ T123] task:stress.sh state:D stack:28096 pid:4365 tgid:4365 ppid:4364 task_flags:0x400040 flags:0x00042000 [ 243.683852][ T123] Call Trace: [ 243.683857][ T123] [c00000000c38f690] [0000000000000001] 0x1 (unreliable) [ 243.683868][ T123] [c00000000c38f840] [c00000000001f908] __switch_to+0x318/0x4e0 [ 243.683878][ T123] [c00000000c38f8a0] [c000000001549a70] __schedule+0x500/0x12a0 [ 243.683888][ T123] [c00000000c38f9a0] [c00000000154a878] schedule+0x68/0x210 [ 243.683896][ T123] [c00000000c38f9d0] [c00000000154ac80] schedule_preempt_disabled+0x30/0x50 [ 243.683904][ T123] [c00000000c38fa00] [c00000000154dbb0] __mutex_lock+0x730/0x10f0 [ 243.683913][ T123] [c00000000c38fb10] [c000000001154d40] napi_enable+0x30/0x60 [ 243.683921][ T123] [c00000000c38fb40] [c000000000f4ae94] ibmveth_open+0x68/0x5dc [ 243.683928][ T123] [c00000000c38fbe0] [c000000000f4aa20] veth_pool_store+0x220/0x270 [ 243.683936][ T123] [c00000000c38fc70] [c000000000826278] sysfs_kf_write+0x68/0xb0 [ 243.683944][ T123] [c00000000c38fcb0] [c0000000008240b8] kernfs_fop_write_iter+0x198/0x2d0 [ 243.683951][ T123] [c00000000c38fd00] [c00000000071b9ac] vfs_write+0x34c/0x650 [ 243.683958][ T123] [c00000000c38fdc0] [c00000000071bea8] ksys_write+0x88/0x150 [ 243.683966][ T123] [c00000000c38fe10] [c0000000000317f4] system_call_exception+0x124/0x340 [ 243.683973][ T123] [c00000000c38fe50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec ... [ 243.684087][ T123] Showing all locks held in the system: [ 243.684095][ T123] 1 lock held by khungtaskd/123: [ 243.684099][ T123] #0: c00000000278e370 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x50/0x248 [ 243.684114][ T123] 4 locks held by stress.sh/4365: [ 243.684119][ T123] #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150 [ 243.684132][ T123] #1: c000000041aea888 (\u0026of-\u003emutex#2){+.+.}-{3:3}, at: kernfs_fop_write_iter+0x154/0x2d0 [ 243.684143][ T123] #2: c0000000366fb9a8 (kn-\u003eactive#64){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x160/0x2d0 [ 243.684155][ T123] #3: c000000035ff4cb8 (\u0026dev-\u003elock){+.+.}-{3:3}, at: napi_enable+0x30/0x60 [ 243.684166][ T123] 5 locks held by stress.sh/4366: [ 243.684170][ T123] #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150 [ 243. ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22053", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P3dCGUpIbpcPhfTgvL/rYA==": { "id": "P3dCGUpIbpcPhfTgvL/rYA==", "updater": "debian/updater", "name": "CVE-2024-49910", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func This commit adds a null check for the set_output_gamma function pointer in the dcn401_set_output_transfer_func function. Previously, set_output_gamma was being checked for null, but then it was being dereferenced without any null check. This could lead to a null pointer dereference if set_output_gamma is null. To fix this, we now ensure that set_output_gamma is not null before dereferencing it. We do this by adding a null check for set_output_gamma before the call to set_output_gamma.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49910", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P8sDnbg5LMrjsP/4Z+0szw==": { "id": "P8sDnbg5LMrjsP/4Z+0szw==", "updater": "debian/updater", "name": "CVE-2024-42239", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fail bpf_timer_cancel when callback is being cancelled Given a schedule: timer1 cb\t\t\ttimer2 cb bpf_timer_cancel(timer2);\tbpf_timer_cancel(timer1); Both bpf_timer_cancel calls would wait for the other callback to finish executing, introducing a lockup. Add an atomic_t count named 'cancelling' in bpf_hrtimer. This keeps track of all in-flight cancellation requests for a given BPF timer. Whenever cancelling a BPF timer, we must check if we have outstanding cancellation requests, and if so, we must fail the operation with an error (-EDEADLK) since cancellation is synchronous and waits for the callback to finish executing. This implies that we can enter a deadlock situation involving two or more timer callbacks executing in parallel and attempting to cancel one another. Note that we avoid incrementing the cancelling counter for the target timer (the one being cancelled) if bpf_timer_cancel is not invoked from a callback, to avoid spurious errors. The whole point of detecting cur-\u003ecancelling and returning -EDEADLK is to not enter a busy wait loop (which may or may not lead to a lockup). This does not apply in case the caller is in a non-callback context, the other side can continue to cancel as it sees fit without running into errors. Background on prior attempts: Earlier versions of this patch used a bool 'cancelling' bit and used the following pattern under timer-\u003elock to publish cancellation status. lock(t-\u003elock); t-\u003ecancelling = true; mb(); if (cur-\u003ecancelling) \treturn -EDEADLK; unlock(t-\u003elock); hrtimer_cancel(t-\u003etimer); t-\u003ecancelling = false; The store outside the critical section could overwrite a parallel requests t-\u003ecancelling assignment to true, to ensure the parallely executing callback observes its cancellation status. It would be necessary to clear this cancelling bit once hrtimer_cancel is done, but lack of serialization introduced races. Another option was explored where bpf_timer_start would clear the bit when (re)starting the timer under timer-\u003elock. This would ensure serialized access to the cancelling bit, but may allow it to be cleared before in-flight hrtimer_cancel has finished executing, such that lockups can occur again. Thus, we choose an atomic counter to keep track of all outstanding cancellation requests and use it to prevent lockups in case callbacks attempt to cancel each other while executing in parallel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42239", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "P91CMsaALOlJiJxLpiVGpw==": { "id": "P91CMsaALOlJiJxLpiVGpw==", "updater": "debian/updater", "name": "CVE-2026-68377", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: act_tunnel_key: Defer dst_release to RCU callback Fix a race-condition use-after-free in tunnel_key_release_params(). The function releases the metadata_dst of the old params synchronously via dst_release() while deferring the params struct free with kfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may still hold the old params pointer (under rcu_read_lock_bh) and proceed to call dst_clone(\u0026params-\u003etcft_enc_metadata-\u003edst) after the writer's dst_release has already pushed the dst's rcuref to RCUREF_DEAD. zdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified that KASAN reports: ================================================================== BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 BUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326 BUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109 BUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173 BUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168 Write of size 4 at addr ffff88806158de40 by task poc/9388 CPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G W 7.1.0-rc7 #7 PREEMPT(lazy) Tainted: [W]=WARN Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:94 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 print_report+0x139/0x4ad mm/kasan/report.c:482 kasan_report+0xe4/0x1d0 mm/kasan/report.c:595 check_region_inline mm/kasan/generic.c:186 kasan_check_range+0x125/0x200 mm/kasan/generic.c:200 instrument_atomic_read_write include/linux/instrumented.h:112 atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326 __rcuref_put include/linux/rcuref.h:109 rcuref_put include/linux/rcuref.h:173 dst_release+0x5b/0x370 net/core/dst.c:168 refdst_drop include/net/dst.h:272 skb_dst_drop include/net/dst.h:284 skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163 skb_release_all net/core/skbuff.c:1187 [..] Allocated by task 9391: kasan_save_stack+0x30/0x50 mm/kasan/common.c:57 kasan_save_track+0x14/0x30 mm/kasan/common.c:78 poison_kmalloc_redzone mm/kasan/common.c:398 __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415 kasan_kmalloc include/linux/kasan.h:263 __do_kmalloc_node mm/slub.c:5296 __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308 kmalloc_noprof include/linux/slab.h:954 kzalloc_noprof include/linux/slab.h:1188 offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35 tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258 tcf_action_offload_add net/sched/act_api.c:293 tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547 tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101 [..] Freed by task 9391: kasan_save_stack+0x30/0x50 mm/kasan/common.c:57 kasan_save_track+0x14/0x30 mm/kasan/common.c:78 kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 slab_free_hook mm/slub.c:2689 slab_free mm/slub.c:6251 kfree+0x21f/0x6b0 mm/slub.c:6566 tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284 tcf_action_offload_add net/sched/act_api.c:293 tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547 tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101 The buggy address belongs to the object at ffff88806158de00 which belongs to the cache kmalloc-256 of size 256 The buggy address is located 64 bytes inside of freed 256-byte region [ffff88806158de00, ffff88806158df00) The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c head: order:1 mapcount:0 entire_map ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68377", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PA589Yx2mGOwxMg1sXMN0w==": { "id": "PA589Yx2mGOwxMg1sXMN0w==", "updater": "debian/updater", "name": "CVE-2026-68374", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: core: sysfs: add lock to bos_descriptors_read() Add a lock to the function bos_descriptors_read(). This function accesses udev-\u003ebos, which could be simultaneously freed in usb_reset_and_verify_device(), a function that is commonly called in drivers all over the kernel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68374", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PASB9dYrqWcXbuomz7pV0Q==": { "id": "PASB9dYrqWcXbuomz7pV0Q==", "updater": "debian/updater", "name": "CVE-2025-40102", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before init Another day, another syzkaller bug. KVM erroneously allows userspace to pend vCPU events for a vCPU that hasn't been initialized yet, leading to KVM interpreting a bunch of uninitialized garbage for routing / injecting the exception. In one case the injection code and the hyp disagree on whether the vCPU has a 32bit EL1 and put the vCPU into an illegal mode for AArch64, tripping the BUG() in exception_target_el() during the next injection: kernel BUG at arch/arm64/kvm/inject_fault.c:40! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT Hardware name: linux,dummy-virt (DT) pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) pc : exception_target_el+0x88/0x8c lr : pend_serror_exception+0x18/0x13c sp : ffff800082f03a10 x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000 x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000 x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004 x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0 x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000 x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000 x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20 Call trace: exception_target_el+0x88/0x8c (P) kvm_inject_serror_esr+0x40/0x3b4 __kvm_arm_vcpu_set_events+0xf0/0x100 kvm_arch_vcpu_ioctl+0x180/0x9d4 kvm_vcpu_ioctl+0x60c/0x9f4 __arm64_sys_ioctl+0xac/0x104 invoke_syscall+0x48/0x110 el0_svc_common.constprop.0+0x40/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x34/0xf0 el0t_64_sync_handler+0xa0/0xe4 el0t_64_sync+0x198/0x19c Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000) Reject the ioctls outright as no sane VMM would call these before KVM_ARM_VCPU_INIT anyway. Even if it did the exception would've been thrown away by the eventual reset of the vCPU's state.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40102", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PF8BPDtAFqhzfwgGoGNhcQ==": { "id": "PF8BPDtAFqhzfwgGoGNhcQ==", "updater": "debian/updater", "name": "CVE-2024-49908", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2) This commit adds a null check for the 'afb' variable in the amdgpu_dm_update_cursor function. Previously, 'afb' was assumed to be null at line 8388, but was used later in the code without a null check. This could potentially lead to a null pointer dereference. Changes since v1: - Moved the null check for 'afb' to the line where 'afb' is used. (Alex) Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm.c:8433 amdgpu_dm_update_cursor() \terror: we previously assumed 'afb' could be null (see line 8388)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49908", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PJlk6OySat9b8dMsND5mBg==": { "id": "PJlk6OySat9b8dMsND5mBg==", "updater": "debian/updater", "name": "CVE-2026-68182", "description": "In the Linux kernel, the following vulnerability has been resolved: comedi: comedi_parport: deal with premature interrupt Syzbot reported a general protection fault in `comedi_get_is_subdevice_running()`, which was called from the interrupt handler `parport_interrupt()` in the \"comedi_parport\" driver, but it does not currently have a C reproducer for the problem. It's probably due to a premature interrupt for one of two reasons: 1. The driver sets up the interrupt handler before the comedi subdevices used by the interrupt handler have been allocated, but does not disable the interrupt in the parallel port's CTRL register first. 2. The driver uses a user-supplied I/O port base address which Syzbot would have supplied, but it might not be backed by real parallel port hardware. Change the initialization order in the driver's comedi \"attach\" handler (`parport_attach()`) so that the hardware registers are initialized before the interrupt handler is requested. This should prevent premature interrupts occurring for real hardware. Also add a test to the interrupt handler to ensure the comedi device is fully attached and return early if it isn't.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68182", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PK1vYjWaZ1mf1KuZmjERPA==": { "id": "PK1vYjWaZ1mf1KuZmjERPA==", "updater": "debian/updater", "name": "CVE-2023-53574", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: delete timer and free skb queue when unloading Fix possible crash and memory leak on driver unload by deleting TX purge timer and freeing C2H queue in 'rtw_core_deinit()', shrink critical section in the latter by freeing COEX queue out of TX report lock scope.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53574", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PKaiUOTn/Mfy5YjfqxZM9A==": { "id": "PKaiUOTn/Mfy5YjfqxZM9A==", "updater": "debian/updater", "name": "CVE-2026-68432", "description": "In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan-\u003enet. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan-\u003enet can rewrite a vxlan device whose underlay lives in vxlan-\u003enet. vxlan_changelink() validates and applies the new configuration against vxlan-\u003enet (vxlan_config_validate(vxlan-\u003enet, ...)) and can reopen the underlay socket in that netns, so the same reasoning as the tunnel changelink series applies here. Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the \"require CAP_NET_ADMIN in the device netns for changelink\" series. Found by 0sec automated security-research tooling (https://0sec.ai).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68432", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PNM3dlozFto46zHKLLUEnQ==": { "id": "PNM3dlozFto46zHKLLUEnQ==", "updater": "debian/updater", "name": "CVE-2024-0564", "description": "A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is \"max page sharing=256\", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's \"max page share\". Through these operations, the attacker can leak the victim's page.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-0564", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PSkg4cwA46LL8z/Lgyf8sg==": { "id": "PSkg4cwA46LL8z/Lgyf8sg==", "updater": "debian/updater", "name": "CVE-2026-15534", "description": "Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it. A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15534", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PYhpLJ9RKZfyoD9gRqTXHw==": { "id": "PYhpLJ9RKZfyoD9gRqTXHw==", "updater": "debian/updater", "name": "CVE-2024-47794", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tailcall infinite loop caused by freplace There is a potential infinite loop issue that can occur when using a combination of tail calls and freplace. In an upcoming selftest, the attach target for entry_freplace of tailcall_freplace.c is subprog_tc of tc_bpf2bpf.c, while the tail call in entry_freplace leads to entry_tc. This results in an infinite loop: entry_tc -\u003e subprog_tc -\u003e entry_freplace --tailcall-\u003e entry_tc. The problem arises because the tail_call_cnt in entry_freplace resets to zero each time entry_freplace is executed, causing the tail call mechanism to never terminate, eventually leading to a kernel panic. To fix this issue, the solution is twofold: 1. Prevent updating a program extended by an freplace program to a prog_array map. 2. Prevent extending a program that is already part of a prog_array map with an freplace program. This ensures that: * If a program or its subprogram has been extended by an freplace program, it can no longer be updated to a prog_array map. * If a program has been added to a prog_array map, neither it nor its subprograms can be extended by an freplace program. Moreover, an extension program should not be tailcalled. As such, return -EINVAL if the program has a type of BPF_PROG_TYPE_EXT when adding it to a prog_array map. Additionally, fix a minor code style issue by replacing eight spaces with a tab for proper formatting.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47794", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PfhjREk4GtBBWbLt/M6Dlw==": { "id": "PfhjREk4GtBBWbLt/M6Dlw==", "updater": "debian/updater", "name": "CVE-2026-32776", "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32776", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PgZ2lGBOPfLgmdY25m/o0w==": { "id": "PgZ2lGBOPfLgmdY25m/o0w==", "updater": "debian/updater", "name": "CVE-2025-68794", "description": "In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-aligned. This is not always the case however, as shown in the syzbot generated case for erofs. This causes too many bytes to be skipped for uptodate blocks, which results in returning the incorrect position and length to read in. If all the blocks are uptodate, this underflows length and returns a position beyond the folio. Fix the calculation to also take into account the block offset when calculating how many bytes can be skipped for uptodate blocks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68794", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Phm8YvjUIERay7fC4vhmgA==": { "id": "Phm8YvjUIERay7fC4vhmgA==", "updater": "debian/updater", "name": "CVE-2025-40137", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to truncate first page in error path of f2fs_truncate() syzbot reports a bug as below: loop0: detected capacity change from 0 to 40427 F2FS-fs (loop0): Wrong SSA boundary, start(3584) end(4096) blocks(3072) F2FS-fs (loop0): Can't find valid F2FS filesystem in 1th superblock F2FS-fs (loop0): invalid crc value F2FS-fs (loop0): f2fs_convert_inline_folio: corrupted inline inode ino=3, i_addr[0]:0x1601, run fsck to fix. ------------[ cut here ]------------ kernel BUG at fs/inode.c:753! RIP: 0010:clear_inode+0x169/0x190 fs/inode.c:753 Call Trace: \u003cTASK\u003e evict+0x504/0x9c0 fs/inode.c:810 f2fs_fill_super+0x5612/0x6fa0 fs/f2fs/super.c:5047 get_tree_bdev_flags+0x40e/0x4d0 fs/super.c:1692 vfs_get_tree+0x8f/0x2b0 fs/super.c:1815 do_new_mount+0x2a2/0x9e0 fs/namespace.c:3808 do_mount fs/namespace.c:4136 [inline] __do_sys_mount fs/namespace.c:4347 [inline] __se_sys_mount+0x317/0x410 fs/namespace.c:4324 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f During f2fs_evict_inode(), clear_inode() detects that we missed to truncate all page cache before destorying inode, that is because in below path, we will create page #0 in cache, but missed to drop it in error path, let's fix it. - evict - f2fs_evict_inode - f2fs_truncate - f2fs_convert_inline_inode - f2fs_grab_cache_folio : create page #0 in cache - f2fs_convert_inline_folio : sanity check failed, return -EFSCORRUPTED - clear_inode detects that inode-\u003ei_data.nrpages is not zero", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40137", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Pi59oKxtylAGg/MHtN0qBA==": { "id": "Pi59oKxtylAGg/MHtN0qBA==", "updater": "debian/updater", "name": "CVE-2026-31568", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add missing secure storage access fixups for donated memory There are special cases where secure storage access exceptions happen in a kernel context for pages that don't have the PG_arch_1 bit set. That bit is set for non-exported guest secure storage (memory) but is absent on storage donated to the Ultravisor since the kernel isn't allowed to export donated pages. Prior to this patch we would try to export the page by calling arch_make_folio_accessible() which would instantly return since the arch bit is absent signifying that the page was already exported and no further action is necessary. This leads to secure storage access exception loops which can never be resolved. With this patch we unconditionally try to export and if that fails we fixup.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31568", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PmbS8KA5GseS80O/YimnuQ==": { "id": "PmbS8KA5GseS80O/YimnuQ==", "updater": "debian/updater", "name": "CVE-2024-35784", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock with fiemap and extent locking While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock. This deadlock exists with our normal code, we just don't have lockdep annotations with the extent locking so we've never noticed it. Since we're copying the fiemap extent to user space on every iteration we have the chance of pagefaulting. Because we hold the extent lock for the entire range we could mkwrite into a range in the file that we have mmap'ed. This would deadlock with the following stack trace [\u003c0\u003e] lock_extent+0x28d/0x2f0 [\u003c0\u003e] btrfs_page_mkwrite+0x273/0x8a0 [\u003c0\u003e] do_page_mkwrite+0x50/0xb0 [\u003c0\u003e] do_fault+0xc1/0x7b0 [\u003c0\u003e] __handle_mm_fault+0x2fa/0x460 [\u003c0\u003e] handle_mm_fault+0xa4/0x330 [\u003c0\u003e] do_user_addr_fault+0x1f4/0x800 [\u003c0\u003e] exc_page_fault+0x7c/0x1e0 [\u003c0\u003e] asm_exc_page_fault+0x26/0x30 [\u003c0\u003e] rep_movs_alternative+0x33/0x70 [\u003c0\u003e] _copy_to_user+0x49/0x70 [\u003c0\u003e] fiemap_fill_next_extent+0xc8/0x120 [\u003c0\u003e] emit_fiemap_extent+0x4d/0xa0 [\u003c0\u003e] extent_fiemap+0x7f8/0xad0 [\u003c0\u003e] btrfs_fiemap+0x49/0x80 [\u003c0\u003e] __x64_sys_ioctl+0x3e1/0xb50 [\u003c0\u003e] do_syscall_64+0x94/0x1a0 [\u003c0\u003e] entry_SYSCALL_64_after_hwframe+0x6e/0x76 I wrote an fstest to reproduce this deadlock without my replacement lock and verified that the deadlock exists with our existing locking. To fix this simply don't take the extent lock for the entire duration of the fiemap. This is safe in general because we keep track of where we are when we're searching the tree, so if an ordered extent updates in the middle of our fiemap call we'll still emit the correct extents because we know what offset we were on before. The only place we maintain the lock is searching delalloc. Since the delalloc stuff can change during writeback we want to lock the extent range so we have a consistent view of delalloc at the time we're checking to see if we need to set the delalloc flag. With this patch applied we no longer deadlock with my testcase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35784", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Po/Ca1qA1mJ+o8NRmnbxbg==": { "id": "Po/Ca1qA1mJ+o8NRmnbxbg==", "updater": "debian/updater", "name": "CVE-2025-39940", "description": "In the Linux kernel, the following vulnerability has been resolved: dm-stripe: fix a possible integer overflow There's a possible integer overflow in stripe_io_hints if we have too large chunk size. Test if the overflow happened, and if it did, don't set limits-\u003eio_min and limits-\u003eio_opt;", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39940", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PoujEHCHWEnkSxht3LvodA==": { "id": "PoujEHCHWEnkSxht3LvodA==", "updater": "debian/updater", "name": "CVE-2024-36024", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable idle reallow as part of command/gpint execution [Why] Workaroud for a race condition where DMCUB is in the process of committing to IPS1 during the handshake causing us to miss the transition into IPS2 and touch the INBOX1 RPTR causing a HW hang. [How] Disable the reallow to ensure that we have enough of a gap between entry and exit and we're not seeing back-to-back wake_and_executes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36024", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PqUWqiKg/hRVx15iUfBtvg==": { "id": "PqUWqiKg/hRVx15iUfBtvg==", "updater": "debian/updater", "name": "CVE-2025-1182", "description": "A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1182", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PqqxmFVRtD8Y5XIsEOgprQ==": { "id": "PqqxmFVRtD8Y5XIsEOgprQ==", "updater": "debian/updater", "name": "CVE-2019-16231", "description": "drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16231", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ps5MCo5QpzgrRW8/KZMYuA==": { "id": "Ps5MCo5QpzgrRW8/KZMYuA==", "updater": "debian/updater", "name": "CVE-2026-8458", "description": "libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8458", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PtVDQvqAWTWjVkSW56jMZw==": { "id": "PtVDQvqAWTWjVkSW56jMZw==", "updater": "debian/updater", "name": "CVE-2024-42107", "description": "In the Linux kernel, the following vulnerability has been resolved: ice: Don't process extts if PTP is disabled The ice_ptp_extts_event() function can race with ice_ptp_release() and result in a NULL pointer dereference which leads to a kernel panic. Panic occurs because the ice_ptp_extts_event() function calls ptp_clock_event() with a NULL pointer. The ice driver has already released the PTP clock by the time the interrupt for the next external timestamp event occurs. To fix this, modify the ice_ptp_extts_event() function to check the PTP state and bail early if PTP is not ready.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42107", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PtYB7j3KiYHvNfT+z2TDRw==": { "id": "PtYB7j3KiYHvNfT+z2TDRw==", "updater": "debian/updater", "name": "CVE-2024-42158", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42158", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PtgAAlJUo6Q894aXIicfNw==": { "id": "PtgAAlJUo6Q894aXIicfNw==", "updater": "debian/updater", "name": "CVE-2017-17740", "description": "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-17740", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PvPOVXZOs5mWfRHbAqRK9Q==": { "id": "PvPOVXZOs5mWfRHbAqRK9Q==", "updater": "debian/updater", "name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2015-9019", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libxslt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "PxZNCkfZQaCYwxe14mPXGA==": { "id": "PxZNCkfZQaCYwxe14mPXGA==", "updater": "debian/updater", "name": "CVE-2024-35931", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Skip do PCI error slot reset during RAS recovery Why: The PCI error slot reset maybe triggered after inject ue to UMC multi times, this caused system hang. [ 557.371857] amdgpu 0000:af:00.0: amdgpu: GPU reset succeeded, trying to resume [ 557.373718] [drm] PCIE GART of 512M enabled. [ 557.373722] [drm] PTB located at 0x0000031FED700000 [ 557.373788] [drm] VRAM is lost due to GPU reset! [ 557.373789] [drm] PSP is resuming... [ 557.547012] mlx5_core 0000:55:00.0: mlx5_pci_err_detected Device state = 1 pci_status: 0. Exit, result = 3, need reset [ 557.547067] [drm] PCI error: detected callback, state(1)!! [ 557.547069] [drm] No support for XGMI hive yet... [ 557.548125] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 0. Enter [ 557.607763] mlx5_core 0000:55:00.0: wait vital counter value 0x16b5b after 1 iterations [ 557.607777] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 1. Exit, err = 0, result = 5, recovered [ 557.610492] [drm] PCI error: slot reset callback!! ... [ 560.689382] amdgpu 0000:3f:00.0: amdgpu: GPU reset(2) succeeded! [ 560.689546] amdgpu 0000:5a:00.0: amdgpu: GPU reset(2) succeeded! [ 560.689562] general protection fault, probably for non-canonical address 0x5f080b54534f611f: 0000 [#1] SMP NOPTI [ 560.701008] CPU: 16 PID: 2361 Comm: kworker/u448:9 Tainted: G OE 5.15.0-91-generic #101-Ubuntu [ 560.712057] Hardware name: Microsoft C278A/C278A, BIOS C2789.5.BS.1C11.AG.1 11/08/2023 [ 560.720959] Workqueue: amdgpu-reset-hive amdgpu_ras_do_recovery [amdgpu] [ 560.728887] RIP: 0010:amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu] [ 560.736891] Code: ff 41 89 c6 e9 1b ff ff ff 44 0f b6 45 b0 e9 4f ff ff ff be 01 00 00 00 4c 89 e7 e8 76 c9 8b ff 44 0f b6 45 b0 e9 3c fd ff ff \u003c48\u003e 83 ba 18 02 00 00 00 0f 84 6a f8 ff ff 48 8d 7a 78 be 01 00 00 [ 560.757967] RSP: 0018:ffa0000032e53d80 EFLAGS: 00010202 [ 560.763848] RAX: ffa00000001dfd10 RBX: ffa0000000197090 RCX: ffa0000032e53db0 [ 560.771856] RDX: 5f080b54534f5f07 RSI: 0000000000000000 RDI: ff11000128100010 [ 560.779867] RBP: ffa0000032e53df0 R08: 0000000000000000 R09: ffffffffffe77f08 [ 560.787879] R10: 0000000000ffff0a R11: 0000000000000001 R12: 0000000000000000 [ 560.795889] R13: ffa0000032e53e00 R14: 0000000000000000 R15: 0000000000000000 [ 560.803889] FS: 0000000000000000(0000) GS:ff11007e7e800000(0000) knlGS:0000000000000000 [ 560.812973] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 560.819422] CR2: 000055a04c118e68 CR3: 0000000007410005 CR4: 0000000000771ee0 [ 560.827433] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 560.835433] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 560.843444] PKRU: 55555554 [ 560.846480] Call Trace: [ 560.849225] \u003cTASK\u003e [ 560.851580] ? show_trace_log_lvl+0x1d6/0x2ea [ 560.856488] ? show_trace_log_lvl+0x1d6/0x2ea [ 560.861379] ? amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu] [ 560.867778] ? show_regs.part.0+0x23/0x29 [ 560.872293] ? __die_body.cold+0x8/0xd [ 560.876502] ? die_addr+0x3e/0x60 [ 560.880238] ? exc_general_protection+0x1c5/0x410 [ 560.885532] ? asm_exc_general_protection+0x27/0x30 [ 560.891025] ? amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu] [ 560.898323] amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu] [ 560.904520] process_one_work+0x228/0x3d0 How: In RAS recovery, mode-1 reset is issued from RAS fatal error handling and expected all the nodes in a hive to be reset. no need to issue another mode-1 during this procedure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35931", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Q29O4Bg/VvfVqS3UXQeb5w==": { "id": "Q29O4Bg/VvfVqS3UXQeb5w==", "updater": "debian/updater", "name": "CVE-2019-15213", "description": "An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-15213", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Q2V4OQGLyygD4mA4BeUHwg==": { "id": "Q2V4OQGLyygD4mA4BeUHwg==", "updater": "debian/updater", "name": "CVE-2026-68396", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: core: wake eh reliably when using scsi_schedule_eh Drivers which use the scsi_schedule_eh function to run the error handler currently risk the error handler thread never waking once all commands are timed out or inactive. There is no enforced memory order between setting the host into error recovery state and counting busy commands. This can result in a race with scsi_dec_host_busy where neither CPU sees both conditions of all commands inactive and the host error state to request waking the error handler. To fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item which will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will occur after the error state is globally visible and will be seen by any current scsi_dec_host_busy callers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68396", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QBFhf4GHFlHTR/5pa1CHXg==": { "id": "QBFhf4GHFlHTR/5pa1CHXg==", "updater": "debian/updater", "name": "TEMP-0628843-DBAD28", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0628843-DBAD28", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "shadow", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QDHl1wjJ/hhM0L8lwX+C3Q==": { "id": "QDHl1wjJ/hhM0L8lwX+C3Q==", "updater": "debian/updater", "name": "CVE-2026-52936", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock with mutex jent_kcapi_random() serializes the shared jitterentropy state, but it currently holds a spinlock across the jent_read_entropy() call. That path performs expensive jitter collection and SHA3 conditioning, so parallel readers can trigger stalls as contending waiters spin for the same lock. To prevent non-preemptible lock hold, replace rng-\u003ejent_lock with a mutex so contended readers sleep instead of spinning on a shared lock held across expensive entropy generation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52936", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QFJEvbxzg3ctxMvbnApYkA==": { "id": "QFJEvbxzg3ctxMvbnApYkA==", "updater": "debian/updater", "name": "CVE-2026-53091", "description": "In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb-\u003ehead. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb-\u003edata, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53091", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QGrcmtKnV84PkEVV4mmlmg==": { "id": "QGrcmtKnV84PkEVV4mmlmg==", "updater": "debian/updater", "name": "CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-20796", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QMKDT35jYGAcqqClVStulQ==": { "id": "QMKDT35jYGAcqqClVStulQ==", "updater": "debian/updater", "name": "CVE-2026-68451", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68451", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QOBrzNFBTPjlxOPHaS2UrA==": { "id": "QOBrzNFBTPjlxOPHaS2UrA==", "updater": "debian/updater", "name": "CVE-2026-43491", "description": "In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added per node. A malicious client can flood NEW_SERVER messages and exhaust memory. Fix this issue by limiting the maximum number of server registrations to 256 per node. If the NEW_SERVER message is received for an old port, then don't restrict it as it will get replaced. While at it, also rate limit the error messages in the failure path of qrtr_ns_worker(). Note that the limit of 256 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43491", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QP+4ZaPTGK0vJoGz0t342Q==": { "id": "QP+4ZaPTGK0vJoGz0t342Q==", "updater": "debian/updater", "name": "CVE-2026-31606", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: don't call cdev_init while cdev in use When calling unbind, then bind again, cdev_init reinitialized the cdev, even though there may still be references to it. That's the case when the /dev/hidg* device is still opened. This obviously unsafe behavior like oopes. This fixes this by using cdev_alloc to put the cdev on the heap. That way, we can simply allocate a new one in hidg_bind.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31606", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QRArYIgl58N8Ovzgvjnhbg==": { "id": "QRArYIgl58N8Ovzgvjnhbg==", "updater": "debian/updater", "name": "CVE-2025-39833", "description": "In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat: [ 250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0 [ 250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0 [ 250.218775] Modules linked in: hfcpci(-) mISDN_core [ 250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary) [ 250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0 [ 250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d [ 250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286 [ 250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95 [ 250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0 [ 250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39 [ 250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001 [ 250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8 [ 250.232454] FS: 00007f3208f01540(0000) GS:ffff8880caf5a000(0000) knlGS:0000000000000000 [ 250.233851] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 250.234856] CR2: 00007f32090a7421 CR3: 0000000004d63000 CR4: 00000000000006f0 [ 250.236117] Call Trace: [ 250.236599] \u003cTASK\u003e [ 250.236967] ? trace_irq_enable.constprop.0+0xd4/0x130 [ 250.237920] debug_object_assert_init+0x1f6/0x310 [ 250.238762] ? __pfx_debug_object_assert_init+0x10/0x10 [ 250.239658] ? __lock_acquire+0xdea/0x1c70 [ 250.240369] __try_to_del_timer_sync+0x69/0x140 [ 250.241172] ? __pfx___try_to_del_timer_sync+0x10/0x10 [ 250.242058] ? __timer_delete_sync+0xc6/0x120 [ 250.242842] ? lock_acquire+0x30/0x80 [ 250.243474] ? __timer_delete_sync+0xc6/0x120 [ 250.244262] __timer_delete_sync+0x98/0x120 [ 250.245015] HFC_cleanup+0x10/0x20 [hfcpci] [ 250.245704] __do_sys_delete_module+0x348/0x510 [ 250.246461] ? __pfx___do_sys_delete_module+0x10/0x10 [ 250.247338] do_syscall_64+0xc1/0x360 [ 250.247924] entry_SYSCALL_64_after_hwframe+0x77/0x7f Fix this by initializing hfc_tl timer with DEFINE_TIMER macro. Also, use mod_timer instead of manual timeout update.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39833", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QYc6DpX2RSeSt/RKd6dG5A==": { "id": "QYc6DpX2RSeSt/RKd6dG5A==", "updater": "debian/updater", "name": "CVE-2025-68736", "description": "In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories Disconnected files or directories can appear when they are visible and opened from a bind mount, but have been renamed or moved from the source of the bind mount in a way that makes them inaccessible from the mount point (i.e. out of scope). Previously, access rights tied to files or directories opened through a disconnected directory were collected by walking the related hierarchy down to the root of the filesystem, without taking into account the mount point because it couldn't be found. This could lead to inconsistent access results, potential access right widening, and hard-to-debug renames, especially since such paths cannot be printed. For a sandboxed task to create a disconnected directory, it needs to have write access (i.e. FS_MAKE_REG, FS_REMOVE_FILE, and FS_REFER) to the underlying source of the bind mount, and read access to the related mount point. Because a sandboxed task cannot acquire more access rights than those defined by its Landlock domain, this could lead to inconsistent access rights due to missing permissions that should be inherited from the mount point hierarchy, while inheriting permissions from the filesystem hierarchy hidden by this mount point instead. Landlock now handles files and directories opened from disconnected directories by taking into account the filesystem hierarchy when the mount point is not found in the hierarchy walk, and also always taking into account the mount point from which these disconnected directories were opened. This ensures that a rename is not allowed if it would widen access rights [1]. The rationale is that, even if disconnected hierarchies might not be visible or accessible to a sandboxed task, relying on the collected access rights from them improves the guarantee that access rights will not be widened during a rename because of the access right comparison between the source and the destination (see LANDLOCK_ACCESS_FS_REFER). It may look like this would grant more access on disconnected files and directories, but the security policies are always enforced for all the evaluated hierarchies. This new behavior should be less surprising to users and safer from an access control perspective. Remove a wrong WARN_ON_ONCE() canary in collect_domain_accesses() and fix the related comment. Because opened files have their access rights stored in the related file security properties, there is no impact for disconnected or unlinked files.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68736", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QdbJOXOx0QoCor7uxoMzVQ==": { "id": "QdbJOXOx0QoCor7uxoMzVQ==", "updater": "debian/updater", "name": "CVE-2026-63963", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers Properly validate the count passed from a device when calling svdm_consume_identity() or svdm_consume_identity_sop_prime() as the device-controlled value could index off of the static arrays, which could leak data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63963", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QlXZcP/gBAx3ErJ13BXquw==": { "id": "QlXZcP/gBAx3ErJ13BXquw==", "updater": "debian/updater", "name": "CVE-2023-3397", "description": "A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different threads. This flaw allows a local attacker with normal user privileges to crash the system or leak internal kernel information.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-3397", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QmJiluo6MJGfZS7D1EaJ/Q==": { "id": "QmJiluo6MJGfZS7D1EaJ/Q==", "updater": "debian/updater", "name": "CVE-2026-68135", "description": "In the Linux kernel, the following vulnerability has been resolved: net: hip04: fix RX buffer leak on build_skb failure When build_skb() fails in hip04_rx_poll(), the driver jumps to the refill path without releasing the current RX buffer and its DMA mapping. Installing a replacement buffer then overwrites the slot references and leaks both resources. Keep the current slot intact and return budget so NAPI retries the same buffer. Also free a newly allocated RX fragment when dma_map_single() fails. This issue was found by an in-house static analysis tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68135", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "QmzF0n9xqyFZOW62FA1/qQ==": { "id": "QmzF0n9xqyFZOW62FA1/qQ==", "updater": "debian/updater", "name": "CVE-2023-39329", "description": "A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-39329", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qq49by++IUkNs52HRvz21w==": { "id": "Qq49by++IUkNs52HRvz21w==", "updater": "debian/updater", "name": "CVE-2025-39910", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc() kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and always allocate memory using the hardcoded GFP_KERNEL flag. This makes them inconsistent with vmalloc(), which was recently extended to support GFP_NOFS and GFP_NOIO allocations. Page table allocations performed during shadow population also ignore the external gfp_mask. To preserve the intended semantics of GFP_NOFS and GFP_NOIO, wrap the apply_to_page_range() calls into the appropriate memalloc scope. xfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock. There was a report here https://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com This patch: - Extends kasan_populate_vmalloc() and helpers to take gfp_mask; - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page(); - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore() around apply_to_page_range(); - Updates vmalloc.c and percpu allocator call sites accordingly.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39910", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Qv2Wv+TjxG5okt+jr01G3g==": { "id": "Qv2Wv+TjxG5okt+jr01G3g==", "updater": "debian/updater", "name": "CVE-2025-40180", "description": "In the Linux kernel, the following vulnerability has been resolved: mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop The cleanup loop was starting at the wrong array index, causing out-of-bounds access. Start the loop at the correct index for zero-indexed arrays to prevent accessing memory beyond the allocated array bounds.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40180", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R/mDXHIDlEeq362SxYMlhg==": { "id": "R/mDXHIDlEeq362SxYMlhg==", "updater": "debian/updater", "name": "CVE-2026-11824", "description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11824", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R1MAm+57BqKjyvlSiGGjrw==": { "id": "R1MAm+57BqKjyvlSiGGjrw==", "updater": "debian/updater", "name": "CVE-2024-46765", "description": "In the Linux kernel, the following vulnerability has been resolved: ice: protect XDP configuration with a mutex The main threat to data consistency in ice_xdp() is a possible asynchronous PF reset. It can be triggered by a user or by TX timeout handler. XDP setup and PF reset code access the same resources in the following sections: * ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked * ice_vsi_rebuild() for the PF VSI - not protected * ice_vsi_open() - already rtnl-locked With an unfortunate timing, such accesses can result in a crash such as the one below: [ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14 [ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18 [Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms [ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001 [ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14 [ +0.394718] ice 0000:b1:00.0: PTP reset successful [ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098 [ +0.000045] #PF: supervisor read access in kernel mode [ +0.000023] #PF: error_code(0x0000) - not-present page [ +0.000023] PGD 0 P4D 0 [ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI [ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1 [ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021 [ +0.000036] Workqueue: ice ice_service_task [ice] [ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice] [...] [ +0.000013] Call Trace: [ +0.000016] \u003cTASK\u003e [ +0.000014] ? __die+0x1f/0x70 [ +0.000029] ? page_fault_oops+0x171/0x4f0 [ +0.000029] ? schedule+0x3b/0xd0 [ +0.000027] ? exc_page_fault+0x7b/0x180 [ +0.000022] ? asm_exc_page_fault+0x22/0x30 [ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice] [ +0.000194] ice_free_tx_ring+0xe/0x60 [ice] [ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice] [ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice] [ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice] [ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice] [ +0.000145] ice_rebuild+0x18c/0x840 [ice] [ +0.000145] ? delay_tsc+0x4a/0xc0 [ +0.000022] ? delay_tsc+0x92/0xc0 [ +0.000020] ice_do_reset+0x140/0x180 [ice] [ +0.000886] ice_service_task+0x404/0x1030 [ice] [ +0.000824] process_one_work+0x171/0x340 [ +0.000685] worker_thread+0x277/0x3a0 [ +0.000675] ? preempt_count_add+0x6a/0xa0 [ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50 [ +0.000679] ? __pfx_worker_thread+0x10/0x10 [ +0.000653] kthread+0xf0/0x120 [ +0.000635] ? __pfx_kthread+0x10/0x10 [ +0.000616] ret_from_fork+0x2d/0x50 [ +0.000612] ? __pfx_kthread+0x10/0x10 [ +0.000604] ret_from_fork_asm+0x1b/0x30 [ +0.000604] \u003c/TASK\u003e The previous way of handling this through returning -EBUSY is not viable, particularly when destroying AF_XDP socket, because the kernel proceeds with removal anyway. There is plenty of code between those calls and there is no need to create a large critical section that covers all of them, same as there is no need to protect ice_vsi_rebuild() with rtnl_lock(). Add xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp(). Leaving unprotected sections in between would result in two states that have to be considered: 1. when the VSI is closed, but not yet rebuild 2. when VSI is already rebuild, but not yet open The latter case is actually already handled through !netif_running() case, we just need to adjust flag checking a little. The former one is not as trivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of hardware interaction happens, this can make adding/deleting rings exit with an error. Luckily, VSI rebuild is pending and can apply new configuration for us in a managed fashion. Therefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to indicate that ice_x ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46765", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R2d8BwjTnNG4x5x8DC2N1A==": { "id": "R2d8BwjTnNG4x5x8DC2N1A==", "updater": "debian/updater", "name": "CVE-2019-16233", "description": "drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16233", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R3jTuLGdWUQtcXVXN/W1fw==": { "id": "R3jTuLGdWUQtcXVXN/W1fw==", "updater": "debian/updater", "name": "CVE-2026-43022", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43022", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R5eHMXQhuB92WB0MreSz4A==": { "id": "R5eHMXQhuB92WB0MreSz4A==", "updater": "debian/updater", "name": "CVE-2026-46148", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: control built-in cs manually The coreQSPI IP supports only a single chip select, which is automagically operated by the hardware - set low when the transmit buffer first gets written to and set high when the number of bytes written to the TOTALBYTES field of the FRAMES register have been sent on the bus. Additional devices must use GPIOs for their chip selects. It was reported to me that if there are two devices attached to this QSPI controller that the in-built chip select is set low while linux tries to access the device attached to the GPIO. This went undetected as the boards that connected multiple devices to the SPI controller all exclusively used GPIOs for chip selects, not relying on the built-in chip select at all. It turns out that this was because the built-in chip select, when controlled automagically, is set low when active and high when inactive, thereby ruling out its use for active-high devices or devices that need to transmit with the chip select disabled. Modify the driver so that it controls chip select directly, retaining the behaviour for mem_ops of setting the chip select active for the entire duration of the transfer in the exec_op callback. For regular transfers, implement the set_cs callback for the core to use. As part of this, the existing setup callback, mchp_coreqspi_setup_op(), is removed. Modifying the CLKIDLE field is not safe to do during operation when there are multiple devices, so this code is removed entirely. Setting the MASTER and ENABLE fields is something that can be done once at probe, it doesn't need to be re-run for each device. Instead the new setup callback sets the built-in chip select to its inactive state for active-low devices, as the reset value of the chip select in software controlled mode is low.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46148", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R6AHXq9kIXOTM2VjUoYfdQ==": { "id": "R6AHXq9kIXOTM2VjUoYfdQ==", "updater": "debian/updater", "name": "CVE-2019-1010022", "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "R9EvNzu5a78IhkYE+ovVXg==": { "id": "R9EvNzu5a78IhkYE+ovVXg==", "updater": "debian/updater", "name": "CVE-2025-1178", "description": "A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1178", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RBYBjfXBVxQdpYBUYaRE9Q==": { "id": "RBYBjfXBVxQdpYBUYaRE9Q==", "updater": "debian/updater", "name": "CVE-2023-52888", "description": "In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Only free buffer VA that is not NULL In the MediaTek vcodec driver, while mtk_vcodec_mem_free() is mostly called only when the buffer to free exists, there are some instances that didn't do the check and triggered warnings in practice. We believe those checks were forgotten unintentionally. Add the checks back to fix the warnings.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52888", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RCPRH8WEB/73FUqeKHr/tA==": { "id": "RCPRH8WEB/73FUqeKHr/tA==", "updater": "debian/updater", "name": "CVE-2024-58237", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet pointers Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates packet pointers. Making the change in bpf_helper_changes_pkt_data() automatically makes use of check_cfg() logic that computes 'changes_pkt_data' effect for global sub-programs, such that the following program could be rejected: int tail_call(struct __sk_buff *sk) { \tbpf_tail_call_static(sk, \u0026jmp_table, 0); \treturn 0; } SEC(\"tc\") int not_safe(struct __sk_buff *sk) { \tint *p = (void *)(long)sk-\u003edata; \t... make p valid ... \ttail_call(sk); \t*p = 42; /* this is unsafe */ \t... } The tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that can invalidate packet pointers. Otherwise, it can't be freplaced with tailcall_freplace.c:entry_freplace() that does a tail call.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58237", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RCTFNcTWXhvQB4avl+clNw==": { "id": "RCTFNcTWXhvQB4avl+clNw==", "updater": "debian/updater", "name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry-\u003en_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-5709", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RHM3pRxZLojreeoTqHcLWA==": { "id": "RHM3pRxZLojreeoTqHcLWA==", "updater": "debian/updater", "name": "CVE-2021-3864", "description": "A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-3864", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RHXquoov8J1zuTpnk4gIEQ==": { "id": "RHXquoov8J1zuTpnk4gIEQ==", "updater": "debian/updater", "name": "CVE-2024-56566", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/slub: Avoid list corruption when removing a slab from the full list Boot with slub_debug=UFPZ. If allocated object failed in alloc_consistency_checks, all objects of the slab will be marked as used, and then the slab will be removed from the partial list. When an object belonging to the slab got freed later, the remove_full() function is called. Because the slab is neither on the partial list nor on the full list, it eventually lead to a list corruption (actually a list poison being detected). So we need to mark and isolate the slab page with metadata corruption, do not put it back in circulation. Because the debug caches avoid all the fastpaths, reusing the frozen bit to mark slab page with metadata corruption seems to be fine. [ 4277.385669] list_del corruption, ffffea00044b3e50-\u003enext is LIST_POISON1 (dead000000000100) [ 4277.387023] ------------[ cut here ]------------ [ 4277.387880] kernel BUG at lib/list_debug.c:56! [ 4277.388680] invalid opcode: 0000 [#1] PREEMPT SMP PTI [ 4277.389562] CPU: 5 PID: 90 Comm: kworker/5:1 Kdump: loaded Tainted: G OE 6.6.1-1 #1 [ 4277.392113] Workqueue: xfs-inodegc/vda1 xfs_inodegc_worker [xfs] [ 4277.393551] RIP: 0010:__list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.394518] Code: 48 91 82 e8 37 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 28 49 91 82 e8 26 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 58 49 91 [ 4277.397292] RSP: 0018:ffffc90000333b38 EFLAGS: 00010082 [ 4277.398202] RAX: 000000000000004e RBX: ffffea00044b3e50 RCX: 0000000000000000 [ 4277.399340] RDX: 0000000000000002 RSI: ffffffff828f8715 RDI: 00000000ffffffff [ 4277.400545] RBP: ffffea00044b3e40 R08: 0000000000000000 R09: ffffc900003339f0 [ 4277.401710] R10: 0000000000000003 R11: ffffffff82d44088 R12: ffff888112cf9910 [ 4277.402887] R13: 0000000000000001 R14: 0000000000000001 R15: ffff8881000424c0 [ 4277.404049] FS: 0000000000000000(0000) GS:ffff88842fd40000(0000) knlGS:0000000000000000 [ 4277.405357] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4277.406389] CR2: 00007f2ad0b24000 CR3: 0000000102a3a006 CR4: 00000000007706e0 [ 4277.407589] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4277.408780] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4277.410000] PKRU: 55555554 [ 4277.410645] Call Trace: [ 4277.411234] \u003cTASK\u003e [ 4277.411777] ? die+0x32/0x80 [ 4277.412439] ? do_trap+0xd6/0x100 [ 4277.413150] ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.414158] ? do_error_trap+0x6a/0x90 [ 4277.414948] ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.415915] ? exc_invalid_op+0x4c/0x60 [ 4277.416710] ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.417675] ? asm_exc_invalid_op+0x16/0x20 [ 4277.418482] ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.419466] ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.420410] free_to_partial_list+0x515/0x5e0 [ 4277.421242] ? xfs_iext_remove+0x41a/0xa10 [xfs] [ 4277.422298] xfs_iext_remove+0x41a/0xa10 [xfs] [ 4277.423316] ? xfs_inodegc_worker+0xb4/0x1a0 [xfs] [ 4277.424383] xfs_bmap_del_extent_delay+0x4fe/0x7d0 [xfs] [ 4277.425490] __xfs_bunmapi+0x50d/0x840 [xfs] [ 4277.426445] xfs_itruncate_extents_flags+0x13a/0x490 [xfs] [ 4277.427553] xfs_inactive_truncate+0xa3/0x120 [xfs] [ 4277.428567] xfs_inactive+0x22d/0x290 [xfs] [ 4277.429500] xfs_inodegc_worker+0xb4/0x1a0 [xfs] [ 4277.430479] process_one_work+0x171/0x340 [ 4277.431227] worker_thread+0x277/0x390 [ 4277.431962] ? __pfx_worker_thread+0x10/0x10 [ 4277.432752] kthread+0xf0/0x120 [ 4277.433382] ? __pfx_kthread+0x10/0x10 [ 4277.434134] ret_from_fork+0x2d/0x50 [ 4277.434837] ? __pfx_kthread+0x10/0x10 [ 4277.435566] ret_from_fork_asm+0x1b/0x30 [ 4277.436280] \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56566", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RHmrG4Tsyn4HRk0mAfBmIg==": { "id": "RHmrG4Tsyn4HRk0mAfBmIg==", "updater": "debian/updater", "name": "CVE-2025-11731", "description": "A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT \u003cfunc:result\u003e elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11731", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libxslt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RKjK5hvAP1fD81G9qknIXQ==": { "id": "RKjK5hvAP1fD81G9qknIXQ==", "updater": "debian/updater", "name": "CVE-2026-64581", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -\u003e sk_dst_check -\u003e sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64581", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RROy+89qj73l90OV1VglGg==": { "id": "RROy+89qj73l90OV1VglGg==", "updater": "debian/updater", "name": "CVE-2016-9114", "description": "There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image-\u003ecomps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9114", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RSK1xJaKXQINWZhrI1wtbg==": { "id": "RSK1xJaKXQINWZhrI1wtbg==", "updater": "debian/updater", "name": "CVE-2024-46678", "description": "In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond-\u003eipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, \"scheduling while atomic\" will be triggered when changing bond's active slave. [ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [ 101.055726] Modules linked in: [ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [ 101.058760] Hardware name: [ 101.059434] Call Trace: [ 101.059436] \u003cTASK\u003e [ 101.060873] dump_stack_lvl+0x51/0x60 [ 101.061275] __schedule_bug+0x4e/0x60 [ 101.061682] __schedule+0x612/0x7c0 [ 101.062078] ? __mod_timer+0x25c/0x370 [ 101.062486] schedule+0x25/0xd0 [ 101.062845] schedule_timeout+0x77/0xf0 [ 101.063265] ? asm_common_interrupt+0x22/0x40 [ 101.063724] ? __bpf_trace_itimer_state+0x10/0x10 [ 101.064215] __wait_for_common+0x87/0x190 [ 101.064648] ? usleep_range_state+0x90/0x90 [ 101.065091] cmd_exec+0x437/0xb20 [mlx5_core] [ 101.065569] mlx5_cmd_do+0x1e/0x40 [mlx5_core] [ 101.066051] mlx5_cmd_exec+0x18/0x30 [mlx5_core] [ 101.066552] mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core] [ 101.067163] ? bonding_sysfs_store_option+0x4d/0x80 [bonding] [ 101.067738] ? kmalloc_trace+0x4d/0x350 [ 101.068156] mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core] [ 101.068747] mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core] [ 101.069312] bond_change_active_slave+0x392/0x900 [bonding] [ 101.069868] bond_option_active_slave_set+0x1c2/0x240 [bonding] [ 101.070454] __bond_opt_set+0xa6/0x430 [bonding] [ 101.070935] __bond_opt_set_notify+0x2f/0x90 [bonding] [ 101.071453] bond_opt_tryset_rtnl+0x72/0xb0 [bonding] [ 101.071965] bonding_sysfs_store_option+0x4d/0x80 [bonding] [ 101.072567] kernfs_fop_write_iter+0x10c/0x1a0 [ 101.073033] vfs_write+0x2d8/0x400 [ 101.073416] ? alloc_fd+0x48/0x180 [ 101.073798] ksys_write+0x5f/0xe0 [ 101.074175] do_syscall_64+0x52/0x110 [ 101.074576] entry_SYSCALL_64_after_hwframe+0x4b/0x53 As bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called from bond_change_active_slave, which requires holding the RTNL lock. And bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state xdo_dev_state_add and xdo_dev_state_delete APIs, which are in user context. So ipsec_lock doesn't have to be spin lock, change it to mutex, and thus the above issue can be resolved.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46678", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RW7pMUOuapy77fLYrIg6pw==": { "id": "RW7pMUOuapy77fLYrIg6pw==", "updater": "debian/updater", "name": "CVE-2026-68405", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock ieee80211_do_stop() removes AP_VLAN packets from the parent AP ps-\u003ebc_buf while holding ps-\u003ebc_buf.lock with IRQs disabled. It then calls ieee80211_free_txskb() before dropping the lock. ieee80211_free_txskb() is not just a passive SKB release. For SKBs with TX status state it can report a dropped frame through cfg80211/nl80211, and that path can reach netlink tap transmit. This is the same reason the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs under the queue lock and frees them after IRQ state is restored. The buggy scenario involves two paths, with each column showing the order within that path: AP_VLAN management TX: AP_VLAN stop: 1. attach ACK-status state 1. clear the running state 2. queue a multicast SKB on 2. take ps-\u003ebc_buf.lock with IRQs parent ps-\u003ebc_buf disabled 3. unlink the AP_VLAN SKB 4. call ieee80211_free_txskb() Unlink matching AP_VLAN SKBs from ps-\u003ebc_buf under the existing lock, but move them to a local free queue. Drop the lock and restore IRQ state before calling ieee80211_free_txskb(). WARNING: kernel/softirq.c:430 at __local_bh_enable_ip", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68405", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RXvg9/2lKym73IdTnr8C7w==": { "id": "RXvg9/2lKym73IdTnr8C7w==", "updater": "debian/updater", "name": "CVE-2026-64583", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns. devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -\u003e bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -\u003e bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc-\u003esrr.sr_bds) and kfree()s bdc-\u003ebdc_ep_array. Both happen while the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED) remains deliverable in the window up to the post-remove devm free_irq(). On receipt of a shared interrupt in that window, bdc_udc_interrupt() dereferences bdc-\u003esrr.sr_bds[bdc-\u003esrr.dqp_index] (NULL or freed DMA) and dispatches sr_handler callbacks that index into bdc_ep_array, causing a NULL-deref or use-after-free. The same window affects the delayed_work bdc-\u003efunc_wake_notify, which is armed from the IRQ handler via bdc_sr_uspc() -\u003e handle_link_state_change() -\u003e schedule_delayed_work() and may self-rearm from its own callback bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a queued work item that fires after bdc_remove() returns and the bdc structure is devm-freed dereferences freed memory. Replace devm_request_irq() with request_irq() and add an explicit free_irq(bdc-\u003eirq, bdc) in bdc_remove(). Clear BDC_GIE before free_irq() to stop the device from asserting interrupts, then free_irq() drains any in-flight handler, then cancel_delayed_work_sync() drains the func_wake_notify delayed work. This ordering ensures the IRQ handler and delayed work cannot interfere with the subsequent endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the matching free_irq() into the bdc_udc_init() error path so the IRQ is released on probe failure, and route the bdc_init_ep() failure through err0 instead of returning directly. This issue was found by an in-house static analysis tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64583", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RZbwexafVJIj0fYiHghpiA==": { "id": "RZbwexafVJIj0fYiHghpiA==", "updater": "debian/updater", "name": "CVE-2025-71285", "description": "In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels MHI stack offers the 'auto_queue' feature, which allows the MHI stack to auto queue the buffers for the RX path (DL channel). Though this feature simplifies the client driver design, it introduces race between the client drivers and the MHI stack. For instance, with auto_queue, the 'dl_callback' for the DL channel may get called before the client driver is fully probed. This means, by the time the dl_callback gets called, the client driver's structures might not be initialized, leading to NULL ptr dereference. Currently, the drivers have to workaround this issue by initializing the internal structures before calling mhi_prepare_for_transfer_autoqueue(). But even so, there is a chance that the client driver's internal code path may call the MHI queue APIs before mhi_prepare_for_transfer_autoqueue() is called, leading to similar NULL ptr dereference. This issue has been reported on the Qcom X1E80100 CRD machines affecting boot. So to properly fix all these races, drop the MHI 'auto_queue' feature altogether and let the client driver (QRTR) manage the RX buffers manually. In the QRTR driver, queue the RX buffers based on the ring length during probe and recycle the buffers in 'dl_callback' once they are consumed. This also warrants removing the setting of 'auto_queue' flag from controller drivers. Currently, this 'auto_queue' feature is only enabled for IPCR DL channel. So only the QRTR client driver requires the modification.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71285", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rf60dR/Fk4GWivBblGX5uQ==": { "id": "Rf60dR/Fk4GWivBblGX5uQ==", "updater": "debian/updater", "name": "CVE-2026-68410", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix memory leak in helper_firmware_cb() helper_firmware_cb() neglects to free the single-stage firmware image after a successful async load, leading to a memory leak in the USB firmware-download path. Fix this memory leak by calling release_firmware() immediately after lbs_fw_loaded() returns. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in the current wireless tree. An x86_64 allyesconfig build showed no new warnings. As we do not have compatible Libertas USB hardware for exercising this firmware-download path, no runtime testing was able to be performed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68410", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RfsugNWfNkQkkeZRRmj6OA==": { "id": "RfsugNWfNkQkkeZRRmj6OA==", "updater": "debian/updater", "name": "CVE-2026-43101", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43101", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rj9IqPmKRJYSLzoR0SyLLw==": { "id": "Rj9IqPmKRJYSLzoR0SyLLw==", "updater": "debian/updater", "name": "CVE-2026-32814", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32814", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rp9OSGQipDOR4a9bA2FuVw==": { "id": "Rp9OSGQipDOR4a9bA2FuVw==", "updater": "debian/updater", "name": "CVE-2019-19449", "description": "In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-19449", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Rqd9TLIcblEe/+yGz2R3dA==": { "id": "Rqd9TLIcblEe/+yGz2R3dA==", "updater": "debian/updater", "name": "CVE-2012-4542", "description": "block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2012-4542", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RrvaRGc6kM93o5B4pizuKg==": { "id": "RrvaRGc6kM93o5B4pizuKg==", "updater": "debian/updater", "name": "CVE-2026-68233", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Shut down BO cache timer before teardown The BO cache timer callback schedules time_work, and time_work can rearm the timer through vc4_bo_cache_free_old(). vc4_bo_cache_destroy() deletes the timer and then cancels the work, which does not break that cycle: the work being cancelled can rearm the timer, and the timer then queues work again after teardown. Use timer_shutdown_sync() instead, so the timer cannot be rearmed and the cycle ends with cancel_work_sync().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68233", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RvZnPU2cIYuGeiv/rD1odw==": { "id": "RvZnPU2cIYuGeiv/rD1odw==", "updater": "debian/updater", "name": "CVE-2026-19385", "description": "Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-19385", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RxrW7ydW11PIaDYyAYKVTg==": { "id": "RxrW7ydW11PIaDYyAYKVTg==", "updater": "debian/updater", "name": "CVE-2025-1150", "description": "A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1150", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RySRoRIa3as132RYPgaQ+Q==": { "id": "RySRoRIa3as132RYPgaQ+Q==", "updater": "debian/updater", "name": "CVE-2025-38041", "description": "In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h616: Reparent GPU clock during frequency changes The H616 manual does not state that the GPU PLL supports dynamic frequency configuration, so we must take extra care when changing the frequency. Currently any attempt to do device DVFS on the GPU lead to panfrost various ooops, and GPU hangs. The manual describes the algorithm for changing the PLL frequency, which the CPU PLL notifier code already support, so we reuse that to reparent the GPU clock to GPU1 clock during frequency changes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38041", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "RyaU8EhxqdcTWh8ybWTskw==": { "id": "RyaU8EhxqdcTWh8ybWTskw==", "updater": "debian/updater", "name": "CVE-2026-54370", "description": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54370", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "acl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S1WPfRkh+Ptiwz9FBz1fLw==": { "id": "S1WPfRkh+Ptiwz9FBz1fLw==", "updater": "debian/updater", "name": "CVE-2007-3996", "description": "Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-3996", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libwmf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S3qfKrj3et4RUCaKB10piw==": { "id": "S3qfKrj3et4RUCaKB10piw==", "updater": "debian/updater", "name": "CVE-2026-3441", "description": "A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3441", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S4UDJEN31Y9gXebwQEZXnw==": { "id": "S4UDJEN31Y9gXebwQEZXnw==", "updater": "debian/updater", "name": "CVE-2025-39933", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39933", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S4XcHs/PjEW7QI+5zc1r6Q==": { "id": "S4XcHs/PjEW7QI+5zc1r6Q==", "updater": "debian/updater", "name": "CVE-2025-68809", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd maintains delete-on-close and pending-delete state in ksmbd_inode-\u003em_flags. In vfs_cache.c this field is accessed under inconsistent locking: some paths read and modify m_flags under ci-\u003em_lock while others do so without taking the lock at all. Examples: - ksmbd_query_inode_status() and __ksmbd_inode_close() use ci-\u003em_lock when checking or updating m_flags. - ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(), ksmbd_clear_inode_pending_delete() and ksmbd_fd_set_delete_on_close() used to read and modify m_flags without ci-\u003em_lock. This creates a potential data race on m_flags when multiple threads open, close and delete the same file concurrently. In the worst case delete-on-close and pending-delete bits can be lost or observed in an inconsistent state, leading to confusing delete semantics (files that stay on disk after delete-on-close, or files that disappear while still in use). Fix it by: - Making ksmbd_query_inode_status() look at m_flags under ci-\u003em_lock after dropping inode_hash_lock. - Adding ci-\u003em_lock protection to all helpers that read or modify m_flags (ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(), ksmbd_clear_inode_pending_delete(), ksmbd_fd_set_delete_on_close()). - Keeping the existing ci-\u003em_lock protection in __ksmbd_inode_close(), and moving the actual unlink/xattr removal outside the lock. This unifies the locking around m_flags and removes the data race while preserving the existing delete-on-close behaviour.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68809", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S5XbWbaEYS26ORNQqOThVg==": { "id": "S5XbWbaEYS26ORNQqOThVg==", "updater": "debian/updater", "name": "CVE-2023-52770", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: split initial and dynamic conditions for extent_cache Let's allocate the extent_cache tree without dynamic conditions to avoid a missing condition causing a panic as below. # create a file w/ a compressed flag # disable the compression # panic while updating extent_cache F2FS-fs (dm-64): Swapfile: last extent is not aligned to section F2FS-fs (dm-64): Swapfile (3) is not align to section: 1) creat(), 2) ioctl(F2FS_IOC_SET_PIN_FILE), 3) fallocate(2097152 * N) Adding 124996k swap on ./swap-file. Priority:0 extents:2 across:17179494468k ================================================================== BUG: KASAN: null-ptr-deref in instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline] BUG: KASAN: null-ptr-deref in atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline] BUG: KASAN: null-ptr-deref in queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline] BUG: KASAN: null-ptr-deref in __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline] BUG: KASAN: null-ptr-deref in _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295 Write of size 4 at addr 0000000000000030 by task syz-executor154/3327 CPU: 0 PID: 3327 Comm: syz-executor154 Tainted: G O 5.10.185 #1 Hardware name: emulation qemu-x86/qemu-x86, BIOS 2023.01-21885-gb3cc1cd24d 01/01/2023 Call Trace: __dump_stack out/common/lib/dump_stack.c:77 [inline] dump_stack_lvl+0x17e/0x1c4 out/common/lib/dump_stack.c:118 __kasan_report+0x16c/0x260 out/common/mm/kasan/report.c:415 kasan_report+0x51/0x70 out/common/mm/kasan/report.c:428 kasan_check_range+0x2f3/0x340 out/common/mm/kasan/generic.c:186 __kasan_check_write+0x14/0x20 out/common/mm/kasan/shadow.c:37 instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline] atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline] queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline] __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline] _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295 __drop_extent_tree+0xdf/0x2f0 out/common/fs/f2fs/extent_cache.c:1155 f2fs_drop_extent_tree+0x17/0x30 out/common/fs/f2fs/extent_cache.c:1172 f2fs_insert_range out/common/fs/f2fs/file.c:1600 [inline] f2fs_fallocate+0x19fd/0x1f40 out/common/fs/f2fs/file.c:1764 vfs_fallocate+0x514/0x9b0 out/common/fs/open.c:310 ksys_fallocate out/common/fs/open.c:333 [inline] __do_sys_fallocate out/common/fs/open.c:341 [inline] __se_sys_fallocate out/common/fs/open.c:339 [inline] __x64_sys_fallocate+0xb8/0x100 out/common/fs/open.c:339 do_syscall_64+0x35/0x50 out/common/arch/x86/entry/common.c:46", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52770", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S7ffVdT0arMe7/C4MSXpWQ==": { "id": "S7ffVdT0arMe7/C4MSXpWQ==", "updater": "debian/updater", "name": "CVE-2025-5245", "description": "A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-5245", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "S9khA+AWY8JaldQC0uvPGg==": { "id": "S9khA+AWY8JaldQC0uvPGg==", "updater": "debian/updater", "name": "CVE-2024-42162", "description": "In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact that the NIC might send us stats for a subset of queues. Without this change, gve_get_ethtool_stats might make an invalid access on the priv-\u003estats_report-\u003estats array.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42162", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SAarmoZzBAYwwO6Nw/ABww==": { "id": "SAarmoZzBAYwwO6Nw/ABww==", "updater": "debian/updater", "name": "CVE-2026-9547", "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-9547", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SDLk5L+DIAztqW2bxjrZsA==": { "id": "SDLk5L+DIAztqW2bxjrZsA==", "updater": "debian/updater", "name": "CVE-2026-31706", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() trusts the on-disk num_aces value from the parent directory's DACL xattr and uses it to size a heap allocation: aces_base = kmalloc(sizeof(struct smb_ace) * num_aces * 2, ...); num_aces is a u16 read from le16_to_cpu(parent_pdacl-\u003enum_aces) without checking that it is consistent with the declared pdacl_size. An authenticated client whose parent directory's security.NTACL is tampered (e.g. via offline xattr corruption or a concurrent path that bypasses parse_dacl()) can present num_aces = 65535 with minimal actual ACE data. This causes a ~8 MB allocation (not kzalloc, so uninitialized) that the subsequent loop only partially populates, and may also overflow the three-way size_t multiply on 32-bit kernels. Additionally, the ACE walk loop uses the weaker offsetof(struct smb_ace, access_req) minimum size check rather than the minimum valid on-wire ACE size, and does not reject ACEs whose declared size is below the minimum. Reproduced on UML + KASAN + LOCKDEP against the real ksmbd code path. A legitimate mount.cifs client creates a parent directory over SMB (ksmbd writes a valid security.NTACL xattr), then the NTACL blob on the backing filesystem is rewritten to set num_aces = 0xFFFF while keeping the posix_acl_hash bytes intact so ksmbd_vfs_get_sd_xattr()'s hash check still passes. A subsequent SMB2 CREATE of a child under that parent drives smb2_open() into smb_inherit_dacl() (share has \"vfs objects = acl_xattr\" set), which fails the page allocator: WARNING: mm/page_alloc.c:5226 at __alloc_frozen_pages_noprof+0x46c/0x9c0 Workqueue: ksmbd-io handle_ksmbd_work __alloc_frozen_pages_noprof+0x46c/0x9c0 ___kmalloc_large_node+0x68/0x130 __kmalloc_large_node_noprof+0x24/0x70 __kmalloc_noprof+0x4c9/0x690 smb_inherit_dacl+0x394/0x2430 smb2_open+0x595d/0xabe0 handle_ksmbd_work+0x3d3/0x1140 With the patch applied the added guard rejects the tampered value with -EINVAL before any large allocation runs, smb2_open() falls back to smb2_create_sd_buffer(), and the child is created with a default SD. No warning, no splat. Fix by: 1. Validating num_aces against pdacl_size using the same formula applied in parse_dacl(). 2. Replacing the raw kmalloc(sizeof * num_aces * 2) with kmalloc_array(num_aces * 2, sizeof(...)) for overflow-safe allocation. 3. Tightening the per-ACE loop guard to require the minimum valid ACE size (offsetof(smb_ace, sid) + CIFS_SID_BASE_SIZE) and rejecting under-sized ACEs, matching the hardening in smb_check_perm_dacl() and parse_dacl(). v1 -\u003e v2: - Replace the synthetic test-module splat in the changelog with a real-path UML + KASAN reproduction driven through mount.cifs and SMB2 CREATE; Namjae flagged the kcifs3_test_inherit_dacl_old name in v1 since it does not exist in ksmbd. - Drop the commit-hash citation from the code comment per Namjae's review; keep the parse_dacl() pointer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31706", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SEepFiQnAZsWEFzEFPs56w==": { "id": "SEepFiQnAZsWEFzEFPs56w==", "updater": "debian/updater", "name": "CVE-2026-43213", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate sequence number of TX release report Hardware rarely reports abnormal sequence number in TX release report, which will access out-of-bounds of wd_ring-\u003epages array, causing NULL pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S U 6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1) Call Trace: \u003cIRQ\u003e rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)] rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)] net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759 handle_softirqs+0xbe/0x290 kernel/softirq.c:601 ? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)] __local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423 \u003c/IRQ\u003e \u003cTASK\u003e rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)] ? irq_thread+0xa7/0x340 kernel/irq/manage.c:0 irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314 ? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202 ? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220 kthread+0xea/0x110 kernel/kthread.c:376 ? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287 ? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295 \u003c/TASK\u003e To prevent crash, validate rpp_info.seq before using.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43213", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SEvHJqkvVkwfeRKpQlBP3g==": { "id": "SEvHJqkvVkwfeRKpQlBP3g==", "updater": "debian/updater", "name": "CVE-2026-68361", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within corsairpsu_probe(). If the probe operation fails after \"io start\" has been initiated, this race condition will result in a uaf vulnerability [1]. CPU0\t\t\t\tCPU1 ====\t\t\t\t==== corsairpsu_probe() hid_device_io_start() ... unlock driver_input_lock hid_hw_stop() kfree(hidraw)\t\t\t__hid_input_report() \t\t\t\t ... acquire driver_input_lock \t\t\t\t hid_report_raw_event() \t\t\t\t hidraw_report_event() \t\t\t\t ... access hidraw's list_lock // trigger uaf Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to be executed, the io_started flag is first cleared while holding the driver_input_lock to prevent potential race conditions involving input reports. [1] BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56 Call Trace: hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577 hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076 __hid_input_report drivers/hid/hid-core.c:2152 [inline] hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174 hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286 __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657 dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005 Allocated by task 10: hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606 hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277 hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387 corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782 Freed by task 10: hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662 hid_disconnect drivers/hid/hid-core.c:2362 [inline] hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407 corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826 Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop(). [groeck: Updated subject and description; call hid_device_io_stop() only if IO has been started]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68361", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SLBj1tyoPWEZAMUQgU6Bxw==": { "id": "SLBj1tyoPWEZAMUQgU6Bxw==", "updater": "debian/updater", "name": "CVE-2024-25743", "description": "In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-25743", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SM7H0rz5ObYMAIw/TQYRpQ==": { "id": "SM7H0rz5ObYMAIw/TQYRpQ==", "updater": "debian/updater", "name": "CVE-2026-23050", "description": "In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix a deadlock when returning a delegation during open() Ben Coddington reports seeing a hang in the following stack trace: 0 [ffffd0b50e1774e0] __schedule at ffffffff9ca05415 1 [ffffd0b50e177548] schedule at ffffffff9ca05717 2 [ffffd0b50e177558] bit_wait at ffffffff9ca061e1 3 [ffffd0b50e177568] __wait_on_bit at ffffffff9ca05cfb 4 [ffffd0b50e1775c8] out_of_line_wait_on_bit at ffffffff9ca05ea5 5 [ffffd0b50e177618] pnfs_roc at ffffffffc154207b [nfsv4] 6 [ffffd0b50e1776b8] _nfs4_proc_delegreturn at ffffffffc1506586 [nfsv4] 7 [ffffd0b50e177788] nfs4_proc_delegreturn at ffffffffc1507480 [nfsv4] 8 [ffffd0b50e1777f8] nfs_do_return_delegation at ffffffffc1523e41 [nfsv4] 9 [ffffd0b50e177838] nfs_inode_set_delegation at ffffffffc1524a75 [nfsv4] 10 [ffffd0b50e177888] nfs4_process_delegation at ffffffffc14f41dd [nfsv4] 11 [ffffd0b50e1778a0] _nfs4_opendata_to_nfs4_state at ffffffffc1503edf [nfsv4] 12 [ffffd0b50e1778c0] _nfs4_open_and_get_state at ffffffffc1504e56 [nfsv4] 13 [ffffd0b50e177978] _nfs4_do_open at ffffffffc15051b8 [nfsv4] 14 [ffffd0b50e1779f8] nfs4_do_open at ffffffffc150559c [nfsv4] 15 [ffffd0b50e177a80] nfs4_atomic_open at ffffffffc15057fb [nfsv4] 16 [ffffd0b50e177ad0] nfs4_file_open at ffffffffc15219be [nfsv4] 17 [ffffd0b50e177b78] do_dentry_open at ffffffff9c09e6ea 18 [ffffd0b50e177ba8] vfs_open at ffffffff9c0a082e 19 [ffffd0b50e177bd0] dentry_open at ffffffff9c0a0935 The issue is that the delegreturn is being asked to wait for a layout return that cannot complete because a state recovery was initiated. The state recovery cannot complete until the open() finishes processing the delegations it was given. The solution is to propagate the existing flags that indicate a non-blocking call to the function pnfs_roc(), so that it knows not to wait in this situation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23050", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SNKDZDO5r13pfUGn0GISlA==": { "id": "SNKDZDO5r13pfUGn0GISlA==", "updater": "debian/updater", "name": "CVE-2019-12455", "description": "An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is an unchecked kstrndup of derived_name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This id is disputed as not being an issue because “The memory allocation that was not checked is part of a code that only runs at boot time, before user processes are started. Therefore, there is no possibility for an unprivileged user to control it, and no denial of service.”", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12455", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SOZasT93ZTk1r15AlKIQHw==": { "id": "SOZasT93ZTk1r15AlKIQHw==", "updater": "debian/updater", "name": "CVE-2026-5450", "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-5450", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SQFW+PQ31vzHzDdxXe8f8g==": { "id": "SQFW+PQ31vzHzDdxXe8f8g==", "updater": "debian/updater", "name": "CVE-2026-64112", "description": "In the Linux kernel, the following vulnerability has been resolved: rbd: eliminate a race in lock_dwork draining on unmap Given how rbd_lock_add_request() and rbd_img_exclusive_lock() are written, lock_dwork may be (re)queued more than it's actually needed: for example in case a new I/O request comes in while we are in the middle of rbd_acquire_lock() on behalf of another I/O request. This is expected and with rbd_release_lock() preemptively canceling lock_dwork is benign under normal operation. A more problematic example is maybe_kick_acquire(): if (have_requests || delayed_work_pending(\u0026rbd_dev-\u003elock_dwork)) { dout(\"%s rbd_dev %p kicking lock_dwork\\n\", __func__, rbd_dev); mod_delayed_work(rbd_dev-\u003etask_wq, \u0026rbd_dev-\u003elock_dwork, 0); } It's not unrealistic for lock_dwork to get canceled right after delayed_work_pending() returns true and for mod_delayed_work() to requeue it right there anyway. This is a classic TOCTOU race. When it comes to unmapping the image, there is an implicit assumption of no self-initiated exclusive lock activity past the point of return from rbd_dev_image_unlock() which unlocks the lock if it happens to be held. This unlock is assumed to be final and lock_dwork (as well as all other exclusive lock tasks, really) isn't expected to get queued again. However, lock_dwork is canceled only in cancel_tasks_sync() (i.e. later in the unmap sequence) and on top of that the cancellation can get in effect nullified by maybe_kick_acquire(). This may result in rbd_acquire_lock() executing after rbd_dev_device_release() and rbd_dev_image_release() run and free and/or reset a bunch of things. One of the possible failure modes then is a violated rbd_assert(rbd_image_format_valid(rbd_dev-\u003eimage_format)); in rbd_dev_header_info() which is called via rbd_dev_refresh() from rbd_post_acquire_action(). Redo exclusive lock task draining to provide saner semantics and try to meet the assumptions around rbd_dev_image_unlock().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64112", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SSVSuTL0VIq15KhNLh5h8Q==": { "id": "SSVSuTL0VIq15KhNLh5h8Q==", "updater": "debian/updater", "name": "CVE-2025-40168", "description": "In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL. Using sk_dst_get(sk)-\u003edev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the returned value of smc_clc_prfx_match() is not used in the caller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40168", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SWBAXBdd/KEOaPZs2gye7A==": { "id": "SWBAXBdd/KEOaPZs2gye7A==", "updater": "debian/updater", "name": "CVE-2025-5278", "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-5278", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SWPowIEYYudHKp5flT9zvA==": { "id": "SWPowIEYYudHKp5flT9zvA==", "updater": "debian/updater", "name": "CVE-2025-39851", "description": "In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD when refreshing an FDB entry with a nexthop object VXLAN FDB entries can point to either a remote destination or an FDB nexthop group. The latter is usually used in EVPN deployments where learning is disabled. However, when learning is enabled, an incoming packet might try to refresh an FDB entry that points to an FDB nexthop group and therefore does not have a remote. Such packets should be dropped, but they are only dropped after dereferencing the non-existent remote, resulting in a NPD [1] which can be reproduced using [2]. Fix by dropping such packets earlier. Remove the misleading comment from first_remote_rcu(). [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 13 UID: 0 PID: 361 Comm: mausezahn Not tainted 6.17.0-rc1-virtme-g9f6b606b6b37 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 RIP: 0010:vxlan_snoop+0x98/0x1e0 [...] Call Trace: \u003cTASK\u003e vxlan_encap_bypass+0x209/0x240 encap_bypass_if_local+0xb1/0x100 vxlan_xmit_one+0x1375/0x17e0 vxlan_xmit+0x6b4/0x15f0 dev_hard_start_xmit+0x5d/0x1c0 __dev_queue_xmit+0x246/0xfd0 packet_sendmsg+0x113a/0x1850 __sock_sendmsg+0x38/0x70 __sys_sendto+0x126/0x180 __x64_sys_sendto+0x24/0x30 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x4b/0x53 [2] #!/bin/bash ip address add 192.0.2.1/32 dev lo ip address add 192.0.2.2/32 dev lo ip nexthop add id 1 via 192.0.2.3 fdb ip nexthop add id 10 group 1 fdb ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 12345 localbypass ip link add name vx1 up type vxlan id 10020 local 192.0.2.2 dstport 54321 learning bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 192.0.2.2 port 54321 vni 10020 bridge fdb add 00:aa:bb:cc:dd:ee dev vx1 self static nhid 10 mausezahn vx0 -a 00:aa:bb:cc:dd:ee -b 00:11:22:33:44:55 -c 1 -q", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39851", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SXstzXJo3ARVPRHH1XkipQ==": { "id": "SXstzXJo3ARVPRHH1XkipQ==", "updater": "debian/updater", "name": "CVE-2025-38234", "description": "In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======== When a CPU chooses to call push_rt_task and picks a task to push to another CPU's runqueue then it will call find_lock_lowest_rq method which would take a double lock on both CPUs' runqueues. If one of the locks aren't readily available, it may lead to dropping the current runqueue lock and reacquiring both the locks at once. During this window it is possible that the task is already migrated and is running on some other CPU. These cases are already handled. However, if the task is migrated and has already been executed and another CPU is now trying to wake it up (ttwu) such that it is queued again on the runqeue (on_rq is 1) and also if the task was run by the same CPU, then the current checks will pass even though the task was migrated out and is no longer in the pushable tasks list. Crashes ======= This bug resulted in quite a few flavors of crashes triggering kernel panics with various crash signatures such as assert failures, page faults, null pointer dereferences, and queue corruption errors all coming from scheduler itself. Some of the crashes: -\u003e kernel BUG at kernel/sched/rt.c:1616! BUG_ON(idx \u003e= MAX_RT_PRIO) Call Trace: ? __die_body+0x1a/0x60 ? die+0x2a/0x50 ? do_trap+0x85/0x100 ? pick_next_task_rt+0x6e/0x1d0 ? do_error_trap+0x64/0xa0 ? pick_next_task_rt+0x6e/0x1d0 ? exc_invalid_op+0x4c/0x60 ? pick_next_task_rt+0x6e/0x1d0 ? asm_exc_invalid_op+0x12/0x20 ? pick_next_task_rt+0x6e/0x1d0 __schedule+0x5cb/0x790 ? update_ts_time_stats+0x55/0x70 schedule_idle+0x1e/0x40 do_idle+0x15e/0x200 cpu_startup_entry+0x19/0x20 start_secondary+0x117/0x160 secondary_startup_64_no_verify+0xb0/0xbb -\u003e BUG: kernel NULL pointer dereference, address: 00000000000000c0 Call Trace: ? __die_body+0x1a/0x60 ? no_context+0x183/0x350 ? __warn+0x8a/0xe0 ? exc_page_fault+0x3d6/0x520 ? asm_exc_page_fault+0x1e/0x30 ? pick_next_task_rt+0xb5/0x1d0 ? pick_next_task_rt+0x8c/0x1d0 __schedule+0x583/0x7e0 ? update_ts_time_stats+0x55/0x70 schedule_idle+0x1e/0x40 do_idle+0x15e/0x200 cpu_startup_entry+0x19/0x20 start_secondary+0x117/0x160 secondary_startup_64_no_verify+0xb0/0xbb -\u003e BUG: unable to handle page fault for address: ffff9464daea5900 kernel BUG at kernel/sched/rt.c:1861! BUG_ON(rq-\u003ecpu != task_cpu(p)) -\u003e kernel BUG at kernel/sched/rt.c:1055! BUG_ON(!rq-\u003enr_running) Call Trace: ? __die_body+0x1a/0x60 ? die+0x2a/0x50 ? do_trap+0x85/0x100 ? dequeue_top_rt_rq+0xa2/0xb0 ? do_error_trap+0x64/0xa0 ? dequeue_top_rt_rq+0xa2/0xb0 ? exc_invalid_op+0x4c/0x60 ? dequeue_top_rt_rq+0xa2/0xb0 ? asm_exc_invalid_op+0x12/0x20 ? dequeue_top_rt_rq+0xa2/0xb0 dequeue_rt_entity+0x1f/0x70 dequeue_task_rt+0x2d/0x70 __schedule+0x1a8/0x7e0 ? blk_finish_plug+0x25/0x40 schedule+0x3c/0xb0 futex_wait_queue_me+0xb6/0x120 futex_wait+0xd9/0x240 do_futex+0x344/0xa90 ? get_mm_exe_file+0x30/0x60 ? audit_exe_compare+0x58/0x70 ? audit_filter_rules.constprop.26+0x65e/0x1220 __x64_sys_futex+0x148/0x1f0 do_syscall_64+0x30/0x80 entry_SYSCALL_64_after_hwframe+0x62/0xc7 -\u003e BUG: unable to handle page fault for address: ffff8cf3608bc2c0 Call Trace: ? __die_body+0x1a/0x60 ? no_context+0x183/0x350 ? spurious_kernel_fault+0x171/0x1c0 ? exc_page_fault+0x3b6/0x520 ? plist_check_list+0x15/0x40 ? plist_check_list+0x2e/0x40 ? asm_exc_page_fault+0x1e/0x30 ? _cond_resched+0x15/0x30 ? futex_wait_queue_me+0xc8/0x120 ? futex_wait+0xd9/0x240 ? try_to_wake_up+0x1b8/0x490 ? futex_wake+0x78/0x160 ? do_futex+0xcd/0xa90 ? plist_check_list+0x15/0x40 ? plist_check_list+0x2e/0x40 ? plist_del+0x6a/0xd0 ? plist_check_list+0x15/0x40 ? plist_check_list+0x2e/0x40 ? dequeue_pushable_task+0x20/0x70 ? __schedule+0x382/0x7e0 ? asm_sysvec_reschedule_i ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38234", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SZAMdkdOi2w2C22zR27Q3g==": { "id": "SZAMdkdOi2w2C22zR27Q3g==", "updater": "debian/updater", "name": "CVE-2025-38616", "description": "In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was installed, or uses some non-standard read API (eg. zerocopy ones). Replace the WARN_ON() and a buggy early exit (which leaves anchor pointing to a freed skb) with real error handling. Wipe the parsing state and tell the reader to retry. We already reload the anchor every time we (re)acquire the socket lock, so the only condition we need to avoid is an out of bounds read (not having enough bytes in the socket for previously parsed record len). If some data was read from under TLS but there's enough in the queue we'll reload and decrypt what is most likely not a valid TLS record. Leading to some undefined behavior from TLS perspective (corrupting a stream? missing an alert? missing an attack?) but no kernel crash should take place.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38616", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Sg9xJ1gba62NLkd95QOh4A==": { "id": "Sg9xJ1gba62NLkd95QOh4A==", "updater": "debian/updater", "name": "CVE-2026-63805", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: nx - fix nx_crypto_ctx_exit argument nx_crypto_ctx_shash_exit calls nx_crypto_ctx_exit with crypto_shash_ctx(...) but crypto_shash_ctx gives a nx_crypto_ctx *, not a crypto_tfm *. Fix the type in nx_crypto_ctx_exit and drop the bogus crypto_tfm_ctx call. This fixes the following oops: BUG: Unable to handle kernel data access at 0xc0403effffffffc8 Faulting instruction address: 0xc000000000396cb4 Oops: Kernel access of bad area, sig: 11 [#15] Call Trace: nx_crypto_ctx_shash_exit+0x24/0x60 crypto_shash_exit_tfm+0x28/0x40 crypto_destroy_tfm+0x98/0x140 crypto_exit_ahash_using_shash+0x20/0x40 crypto_destroy_tfm+0x98/0x140 hash_release+0x1c/0x30 alg_sock_destruct+0x38/0x60 __sk_destruct+0x48/0x2b0 af_alg_release+0x58/0xb0 __sock_release+0x68/0x150 sock_close+0x20/0x40 __fput+0x110/0x3a0 sys_close+0x48/0xa0 system_call_exception+0x140/0x2d0 system_call_common+0xf4/0x258 .. which came from hardlink(1) opportunistically using AF_ALG. The same problem exists with nx_crypto_ctx_skcipher_exit getting a context it wasn't expecting, but apparently nobody hit that for years.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63805", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SisGfjGX/TPw7kokQ3wHtQ==": { "id": "SisGfjGX/TPw7kokQ3wHtQ==", "updater": "debian/updater", "name": "CVE-2025-39947", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Harden uplink netdev access against device unbind The function mlx5_uplink_netdev_get() gets the uplink netdevice pointer from mdev-\u003emlx5e_res.uplink_netdev. However, the netdevice can be removed and its pointer cleared when unbound from the mlx5_core.eth driver. This results in a NULL pointer, causing a kernel panic. BUG: unable to handle page fault for address: 0000000000001300 at RIP: 0010:mlx5e_vport_rep_load+0x22a/0x270 [mlx5_core] Call Trace: \u003cTASK\u003e mlx5_esw_offloads_rep_load+0x68/0xe0 [mlx5_core] esw_offloads_enable+0x593/0x910 [mlx5_core] mlx5_eswitch_enable_locked+0x341/0x420 [mlx5_core] mlx5_devlink_eswitch_mode_set+0x17e/0x3a0 [mlx5_core] devlink_nl_eswitch_set_doit+0x60/0xd0 genl_family_rcv_msg_doit+0xe0/0x130 genl_rcv_msg+0x183/0x290 netlink_rcv_skb+0x4b/0xf0 genl_rcv+0x24/0x40 netlink_unicast+0x255/0x380 netlink_sendmsg+0x1f3/0x420 __sock_sendmsg+0x38/0x60 __sys_sendto+0x119/0x180 do_syscall_64+0x53/0x1d0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Ensure the pointer is valid before use by checking it for NULL. If it is valid, immediately call netdev_hold() to take a reference, and preventing the netdevice from being freed while it is in use.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39947", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SjOLMJaPaetNB7CJwZwaWA==": { "id": "SjOLMJaPaetNB7CJwZwaWA==", "updater": "debian/updater", "name": "CVE-2024-52559", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit() The \"submit-\u003ecmd[i].size\" and \"submit-\u003ecmd[i].offset\" variables are u32 values that come from the user via the submit_lookup_cmds() function. This addition could lead to an integer wrapping bug so use size_add() to prevent that. Patchwork: https://patchwork.freedesktop.org/patch/624696/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-52559", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SjxxlwRlBvhzJ+EIPQg+2A==": { "id": "SjxxlwRlBvhzJ+EIPQg+2A==", "updater": "debian/updater", "name": "CVE-2021-3714", "description": "A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-3714", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SldwWsd7f71t2sTT4le4NA==": { "id": "SldwWsd7f71t2sTT4le4NA==", "updater": "debian/updater", "name": "CVE-2023-54280", "description": "In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54280", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SmDyXYC0yd+JAF28cyzlyQ==": { "id": "SmDyXYC0yd+JAF28cyzlyQ==", "updater": "debian/updater", "name": "CVE-2025-38597", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port Each window of a vop2 is usable by a specific set of video ports, so while binding the vop2, we look through the list of available windows trying to find one designated as primary-plane and usable by that specific port. The code later wants to use drm_crtc_init_with_planes with that found primary plane, but nothing has checked so far if a primary plane was actually found. For whatever reason, the rk3576 vp2 does not have a usable primary window (if vp0 is also in use) which brought the issue to light and ended in a null-pointer dereference further down. As we expect a primary-plane to exist for a video-port, add a check at the end of the window-iteration and fail probing if none was found.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38597", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SmqMtlvlVJyhJeSdEeHrGw==": { "id": "SmqMtlvlVJyhJeSdEeHrGw==", "updater": "debian/updater", "name": "CVE-2026-58470", "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58470", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SnaDJIBcaepGlEY5l0YiZQ==": { "id": "SnaDJIBcaepGlEY5l0YiZQ==", "updater": "debian/updater", "name": "CVE-2026-48961", "description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine \u0026main::unpackValueQ' and the script exits with status 255. Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-48961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "SqunC8KQn/zUdd4jPxGV8g==": { "id": "SqunC8KQn/zUdd4jPxGV8g==", "updater": "debian/updater", "name": "CVE-2026-53353", "description": "In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is simply wrong. hsr-\u003eself_node is cleared in hsr_del_self_node(), which is called from hsr_dellink(). Since dev-\u003ertnl_link_ops-\u003edellink() is called before unregister_netdevice_many(), there is a window when user can find the device but without hsr-\u003eself_node. Let's remove WARN_ONCE() in hsr_addr_is_self(). [0]: HSR: No self node WARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220 Modules linked in: CPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)} Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 RIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39 Code: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 \u003c67\u003e 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96 RSP: 0018:ffffc900041c70e0 EFLAGS: 00010283 RAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000 RDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000 R13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000 FS: 00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0 DR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002 DR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400 Call Trace: \u003cTASK\u003e check_local_dest net/hsr/hsr_forward.c:592 [inline] fill_frame_info net/hsr/hsr_forward.c:728 [inline] hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739 hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236 __netdev_start_xmit include/linux/netdevice.h:5368 [inline] netdev_start_xmit include/linux/netdevice.h:5377 [inline] xmit_one net/core/dev.c:3888 [inline] dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904 __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870 neigh_output include/net/neighbour.h:556 [inline] ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237 ip_send_skb net/ipv4/ip_output.c:1510 [inline] ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530 raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659 sock_sendmsg_nosec net/socket.c:787 [inline] __sock_sendmsg net/socket.c:802 [inline] ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752 __sys_sendmsg net/socket.c:2784 [inline] __do_sys_sendmsg net/socket.c:2789 [inline] __se_sys_sendmsg net/socket.c:2787 [inline] __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6feb62ce59 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59 RDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004 RBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53353", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T4DqnulOMrKXYCngPGMyDg==": { "id": "T4DqnulOMrKXYCngPGMyDg==", "updater": "debian/updater", "name": "CVE-2026-68323", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: serialize udp bearer replicast list updates tipc_udp_rcast_add() and cleanup_bearer() both update ub-\u003ercast.list with list_add_rcu() / list_del_rcu(), but nothing serializes them. The add runs from the encap receive softirq (via tipc_udp_rcast_disc()) without rtnl_lock(), so it can race the cleanup delete and corrupt the list: list_del corruption. prev-\u003enext should be ffff8880298d7ab8, but was ffff88802449ad38. (prev=ffff888027e3ec98) kernel BUG at lib/list_debug.c:62! RIP: __list_del_entry_valid_or_report+0x17a/0x200 Workqueue: events cleanup_bearer Call Trace: cleanup_bearer (net/tipc/udp_media.c:811) process_one_work (kernel/workqueue.c:3302) worker_thread (kernel/workqueue.c:3466) The bearer can be enabled from an unprivileged user namespace, as the TIPCv2 generic-netlink ops carry no GENL_ADMIN_PERM. Add a spinlock to struct udp_bearer and take it around the list_add_rcu() in tipc_udp_rcast_add() and the list_del_rcu() loop in cleanup_bearer() so the two writers can no longer corrupt the list. Reject a duplicate peer under the same lock before allocating, and remove tipc_udp_is_known_peer(). The old lockless pre-check in tipc_udp_rcast_disc() was racy: two softirqs discovering the same peer could both find it absent and add it twice. cleanup_bearer() runs from a workqueue after tipc_udp_disable() clears the bearer's up bit, so an encap softirq can still reach tipc_udp_rcast_add() and add a peer after cleanup_bearer() has already emptied the list, leaking that entry when the bearer is freed. Mark the bearer disabled under rcast_lock once the list is emptied and refuse further additions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68323", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T5ISGm5LbVeRDQDfUYF1oA==": { "id": "T5ISGm5LbVeRDQDfUYF1oA==", "updater": "debian/updater", "name": "CVE-2026-34545", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34545", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T6jUkybzEGhntULjAsvqfA==": { "id": "T6jUkybzEGhntULjAsvqfA==", "updater": "debian/updater", "name": "CVE-2025-21732", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error This patch addresses a race condition for an ODP MR that can result in a CQE with an error on the UMR QP. During the __mlx5_ib_dereg_mr() flow, the following sequence of calls occurs: mlx5_revoke_mr() mlx5r_umr_revoke_mr() mlx5r_umr_post_send_wait() At this point, the lkey is freed from the hardware's perspective. However, concurrently, mlx5_ib_invalidate_range() might be triggered by another task attempting to invalidate a range for the same freed lkey. This task will: - Acquire the umem_odp-\u003eumem_mutex lock. - Call mlx5r_umr_update_xlt() on the UMR QP. - Since the lkey has already been freed, this can lead to a CQE error, causing the UMR QP to enter an error state [1]. To resolve this race condition, the umem_odp-\u003eumem_mutex lock is now also acquired as part of the mlx5_revoke_mr() scope. Upon successful revoke, we set umem_odp-\u003eprivate which points to that MR to NULL, preventing any further invalidation attempts on its lkey. [1] From dmesg: infiniband rocep8s0f0: dump_cqe:277:(pid 0): WC error: 6, Message: memory bind operation error cqe_dump: 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cqe_dump: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cqe_dump: 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cqe_dump: 00000030: 00 00 00 00 08 00 78 06 25 00 11 b9 00 0e dd d2 WARNING: CPU: 15 PID: 1506 at drivers/infiniband/hw/mlx5/umr.c:394 mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib] Modules linked in: ip6table_mangle ip6table_natip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_umad ib_ipoib ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core CPU: 15 UID: 0 PID: 1506 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1626 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib] [..] Call Trace: \u003cTASK\u003e mlx5r_umr_update_xlt+0x23c/0x3e0 [mlx5_ib] mlx5_ib_invalidate_range+0x2e1/0x330 [mlx5_ib] __mmu_notifier_invalidate_range_start+0x1e1/0x240 zap_page_range_single+0xf1/0x1a0 madvise_vma_behavior+0x677/0x6e0 do_madvise+0x1a2/0x4b0 __x64_sys_madvise+0x25/0x30 do_syscall_64+0x6b/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21732", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T7H5goqWimRhJ6/lmz/14A==": { "id": "T7H5goqWimRhJ6/lmz/14A==", "updater": "debian/updater", "name": "CVE-2025-66866", "description": "An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66866", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T8SIyFnp0mpbb+kcuicFvw==": { "id": "T8SIyFnp0mpbb+kcuicFvw==", "updater": "debian/updater", "name": "CVE-2026-68273", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context initialization time. Both are due amdgpu_ctx_init() not holding the adev-\u003epm.stable_pstate_ctx_lock, which is otherwise used from both sysfs and the context code itself for modifying and clearing the stored context pointer. Second issue is that context fini can trample over the pstate configuration set via sysfs. This is due the restore state (ctx-\u003estable_pstate) being saved at context init time, and not if, or when the context actually changes the pstate. As the context exits it will therefore incorrectly restore to what was set before the sysfs override was requested. The simplest fix is to drastically simplify how the state is tracked, by clearly defining the points at which pstate ownership is taken and released, and to handle all transitions under the correct lock. Instead of at context init time, the previous state is saved only at the point the context overrides the current state, and is restored on context exit only if the context is still the owner of the current override state. (cherry picked from commit 1b5e413713c0a93bc1818394d0ce49aaad21bd27)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68273", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "T9d7eiSCgaG9+XuCv6U0qg==": { "id": "T9d7eiSCgaG9+XuCv6U0qg==", "updater": "debian/updater", "name": "CVE-2025-38203", "description": "In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkaller Report ] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000087: 0000 [#1 KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f] CPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted 6.13.0-rc6-gfbfd64d25c7a-dirty #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Sched_ext: serialise (enabled+all), task: runnable_at=-30ms RIP: 0010:jfs_ioc_trim+0x34b/0x8f0 Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93 90 82 fe ff 4c 89 ff 31 f6 RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206 RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001 RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000 R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438 FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: \u003cTASK\u003e ? __die_body+0x61/0xb0 ? die_addr+0xb1/0xe0 ? exc_general_protection+0x333/0x510 ? asm_exc_general_protection+0x26/0x30 ? jfs_ioc_trim+0x34b/0x8f0 jfs_ioctl+0x3c8/0x4f0 ? __pfx_jfs_ioctl+0x10/0x10 ? __pfx_jfs_ioctl+0x10/0x10 __se_sys_ioctl+0x269/0x350 ? __pfx___se_sys_ioctl+0x10/0x10 ? do_syscall_64+0xfb/0x210 do_syscall_64+0xee/0x210 ? syscall_exit_to_user_mode+0x1e0/0x330 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe51f4903ad Code: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d RSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad RDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640 R13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000 \u003c/TASK\u003e Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:jfs_ioc_trim+0x34b/0x8f0 Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93 90 82 fe ff 4c 89 ff 31 f6 RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206 RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001 RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000 R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438 FS: 00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Kernel panic - not syncing: Fatal exception [ Analysis ] We believe that we have found a concurrency bug in the `fs/jfs` module that results in a null pointer dereference. There is a closely related issue which has been fixed: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234 ... but, unfortunately, the accepted patch appears to still be susceptible to a null pointer dereference under some interleavings. To trigger the bug, we think that `JFS_SBI(ipbmap-\u003ei_sb)-\u003ebmap` is set to NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This bug manifests quite rarely under normal circumstances, but is triggereable from a syz-program.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38203", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TCd9g35j6XmK96Itj5MuqA==": { "id": "TCd9g35j6XmK96Itj5MuqA==", "updater": "debian/updater", "name": "CVE-2025-61145", "description": "libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-61145", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TGiO4b3FHe8JhZ/HfsRRTQ==": { "id": "TGiO4b3FHe8JhZ/HfsRRTQ==", "updater": "debian/updater", "name": "CVE-2026-68222", "description": "In the Linux kernel, the following vulnerability has been resolved: media: msi2500: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. msi2500_start_streaming() had five error paths that all hit this trap and were further tangled by ret-overwriting between calls: - -ENODEV when the USB device was already disconnected - -ERESTARTSYS when mutex_lock_interruptible() was interrupted - msi2500_set_usb_adc() failure: ret was silently overwritten by the next call (msi2500_isoc_init), so the error was lost entirely - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but the function then fell through to msi2500_ctrl_msg() and again masked the original error by overwriting ret - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all, leaving isoc URBs submitted with no way for the driver to consume them Consolidate the error paths into a small goto chain. Every failure now stops the function, drains the queued-buffer list, and returns the real error code. The ctrl_msg failure path also rolls back the preceding msi2500_isoc_init() via msi2500_isoc_cleanup() before unlocking and draining. The cleanup helper takes a vb2_buffer_state argument so that the start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as expected by userspace on start_streaming failure) while stop_streaming keeps its existing VB2_BUF_STATE_ERROR semantics. This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68222", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TGoRkI+VuLFVYEHzjLAL2g==": { "id": "TGoRkI+VuLFVYEHzjLAL2g==", "updater": "debian/updater", "name": "CVE-2026-52937", "description": "In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR In the SIOCGIFHWADDR path, tap_ioctl() copies 16 bytes of an uninitialised on-stack struct sockaddr_storage to userspace via ifr_hwaddr, but netif_get_mac_address() only writes sa_family and dev-\u003eaddr_len (6 for Ethernet) bytes, leaving sa_data[6..13] uninitialised. Those 8 trailing bytes leak kernel stack contents; SIOCGIFHWADDR on a macvtap chardev returns kernel .text and direct-map pointers, defeating KASLR. Initialise ss at declaration.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52937", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TKbTlc4iN8EYX5qKd3EbZA==": { "id": "TKbTlc4iN8EYX5qKd3EbZA==", "updater": "debian/updater", "name": "CVE-2023-34152", "description": "A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-34152", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TPyZYIBowqrU6+m4nrBEHQ==": { "id": "TPyZYIBowqrU6+m4nrBEHQ==", "updater": "debian/updater", "name": "CVE-2024-40975", "description": "In the Linux kernel, the following vulnerability has been resolved: platform/x86: x86-android-tablets: Unregister devices in reverse order Not all subsystems support a device getting removed while there are still consumers of the device with a reference to the device. One example of this is the regulator subsystem. If a regulator gets unregistered while there are still drivers holding a reference a WARN() at drivers/regulator/core.c:5829 triggers, e.g.: WARNING: CPU: 1 PID: 1587 at drivers/regulator/core.c:5829 regulator_unregister Hardware name: Intel Corp. VALLEYVIEW C0 PLATFORM/BYT-T FFD8, BIOS BLADE_21.X64.0005.R00.1504101516 FFD8_X64_R_2015_04_10_1516 04/10/2015 RIP: 0010:regulator_unregister Call Trace: \u003cTASK\u003e regulator_unregister devres_release_group i2c_device_remove device_release_driver_internal bus_remove_device device_del device_unregister x86_android_tablet_remove On the Lenovo Yoga Tablet 2 series the bq24190 charger chip also provides a 5V boost converter output for powering USB devices connected to the micro USB port, the bq24190-charger driver exports this as a Vbus regulator. On the 830 (8\") and 1050 (\"10\") models this regulator is controlled by a platform_device and x86_android_tablet_remove() removes platform_device-s before i2c_clients so the consumer gets removed first. But on the 1380 (13\") model there is a lc824206xa micro-USB switch connected over I2C and the extcon driver for that controls the regulator. The bq24190 i2c-client *must* be registered first, because that creates the regulator with the lc824206xa listed as its consumer. If the regulator has not been registered yet the lc824206xa driver will end up getting a dummy regulator. Since in this case both the regulator provider and consumer are I2C devices, the only way to ensure that the consumer is unregistered first is to unregister the I2C devices in reverse order of in which they were created. For consistency and to avoid similar problems in the future change x86_android_tablet_remove() to unregister all device types in reverse order.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40975", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TRgfVy4kI8aktXR88Au/ng==": { "id": "TRgfVy4kI8aktXR88Au/ng==", "updater": "debian/updater", "name": "CVE-2026-63855", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit efc9dd5590894109bce9a0bfe1fa5592dd6b20b1)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63855", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TTAW99m397pPNBpmG2HcRw==": { "id": "TTAW99m397pPNBpmG2HcRw==", "updater": "debian/updater", "name": "CVE-2026-68217", "description": "In the Linux kernel, the following vulnerability has been resolved: media: pwc: Drain fill_buf on start_streaming() failure pwc_isoc_init() submits its isochronous URBs with usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is submitted, its completion handler pwc_isoc_handler() can run on another CPU before the loop finishes: start_streaming() pwc_isoc_init() usb_submit_urb(urbs[0], GFP_KERNEL) pwc_isoc_handler(urbs[0]) pdev-\u003efill_buf = pwc_get_next_fill_buf(pdev) usb_submit_urb(urbs[i\u003e0], ..) -\u003e fails pwc_isoc_cleanup(pdev) /* kills URBs */ return ret; pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED) pwc_get_next_fill_buf() detaches a buffer from pdev-\u003equeued_bufs and stores it in pdev-\u003efill_buf. The error path in start_streaming() only drains pdev-\u003equeued_bufs, so the buffer parked in pdev-\u003efill_buf is leaked. vb2_start_streaming() then triggers WARN_ON(owned_by_drv_count). stop_streaming() already handles this since commit 80b0963e1698 (\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the teardown path but not in the start_streaming() error path. Mirror that handling on failure so start_streaming() returns with no buffer owned by the driver. Issue identified by automated review of the INV-003 series at https://sashiko.dev/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68217", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TUuFbo4isqcI/XbM1gY5Rg==": { "id": "TUuFbo4isqcI/XbM1gY5Rg==", "updater": "debian/updater", "name": "CVE-2026-53178", "description": "In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer underflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53178", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TXaAGqaslxw3rNhoiJkiZw==": { "id": "TXaAGqaslxw3rNhoiJkiZw==", "updater": "debian/updater", "name": "CVE-2026-41992", "description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41992", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TZ6L6I3Cd7+hJR4BXHfHTw==": { "id": "TZ6L6I3Cd7+hJR4BXHfHTw==", "updater": "debian/updater", "name": "CVE-2023-52676", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding together a 64-bit register with a int offset. The register was checked to be below 1\u003c\u003c29 when it was variable, but not when it was fixed. The offset either comes from an instruction (in which case it is 16 bit), from another register (in which case the caller checked it to be below 1\u003c\u003c29 [1]), or from the size of an argument to a kfunc (in which case it can be a u32 [2]). Between the register being inconsistently checked to be below 1\u003c\u003c29, and the offset being up to an u32, it appears that we were open to overflowing the `int`s which were currently used for arithmetic. [1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498 [2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52676", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TaiMhQEJ3Q6BZYv48dLzKA==": { "id": "TaiMhQEJ3Q6BZYv48dLzKA==", "updater": "debian/updater", "name": "CVE-2026-53297", "description": "In the Linux kernel, the following vulnerability has been resolved: net: mana: Guard mana_remove against double invocation If PM resume fails (e.g., mana_attach() returns an error), mana_probe() calls mana_remove(), which tears down the device and sets gd-\u003egdma_context = NULL and gd-\u003edriver_data = NULL. However, a failed resume callback does not automatically unbind the driver. When the device is eventually unbound, mana_remove() is invoked a second time. Without a NULL check, it dereferences gc-\u003edev with gc == NULL, causing a kernel panic. Add an early return if gdma_context or driver_data is NULL so the second invocation is harmless. Move the dev = gc-\u003edev assignment after the guard so it cannot dereference NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53297", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Tc7Jjf4+kp5gWgBaBH6IHQ==": { "id": "Tc7Jjf4+kp5gWgBaBH6IHQ==", "updater": "debian/updater", "name": "CVE-2026-31663", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reaches transport_finish. The skb-\u003edev pointer is then used inside NF_HOOK and its okfn, which can race with device teardown. Remove the dev_put from the async resumption entry and instead drop the reference after the NF_HOOK call in transport_finish, using a saved device pointer since NF_HOOK may consume the skb. This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip the okfn. For non-transport exits (decaps, gro, drop) and secondary async return points, release the reference inline when async is set.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31663", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Tdhosk8QDFrBzFw1O505sQ==": { "id": "Tdhosk8QDFrBzFw1O505sQ==", "updater": "debian/updater", "name": "CVE-2026-68320", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep-\u003eauth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc-\u003ec.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes. Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68320", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Te4WUvO8GpV/xKQSiWprnQ==": { "id": "Te4WUvO8GpV/xKQSiWprnQ==", "updater": "debian/updater", "name": "CVE-2025-11413", "description": "A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11413", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TiBB3rhbLcdx2WE3ADGWag==": { "id": "TiBB3rhbLcdx2WE3ADGWag==", "updater": "debian/updater", "name": "CVE-2025-21656", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur scsi_execute_cmd() function can return both negative (linux codes) and positive (scsi_cmnd result field) error codes. Currently the driver just passes error codes of scsi_execute_cmd() to hwmon core, which is incorrect because hwmon only checks for negative error codes. This leads to hwmon reporting uninitialized data to userspace in case of SCSI errors (for example if the disk drive was disconnected). This patch checks scsi_execute_cmd() output and returns -EIO if it's error code is positive. [groeck: Avoid inline variable declaration for portability]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21656", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TnHi5HWbIX9944L/44v7lw==": { "id": "TnHi5HWbIX9944L/44v7lw==", "updater": "debian/updater", "name": "CVE-2023-54263", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP Fixes OOPS on boards with ANX9805 DP encoders.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54263", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Tp5o/4SbPLzIMMSn6dmLAw==": { "id": "Tp5o/4SbPLzIMMSn6dmLAw==", "updater": "debian/updater", "name": "CVE-2026-14680", "description": "Type confusion with PostgreSQL \"internal\" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type \"internal\" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14680", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TqWd5ZUl5sVkYMkHIsu40Q==": { "id": "TqWd5ZUl5sVkYMkHIsu40Q==", "updater": "debian/updater", "name": "CVE-2025-15366", "description": "The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15366", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TqzX5XqesrQCHwYXN5ag3g==": { "id": "TqzX5XqesrQCHwYXN5ag3g==", "updater": "debian/updater", "name": "CVE-2019-20794", "description": "An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-20794", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TtPAUJEPt4ox78QA8ZcSgw==": { "id": "TtPAUJEPt4ox78QA8ZcSgw==", "updater": "debian/updater", "name": "CVE-2025-21759", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: extend RCU protection in igmp6_send() igmp6_send() can be called without RTNL or RCU being held. Extend RCU protection so that we can safely fetch the net pointer and avoid a potential UAF. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net-\u003eipv6.igmp_sk socket under RCU protection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21759", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "TwSGWkGdJQxHand5kiwizg==": { "id": "TwSGWkGdJQxHand5kiwizg==", "updater": "debian/updater", "name": "CVE-2026-34380", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. The expression (uint64_t)(w * 3) computes w * 3 as a signed 32-bit integer before casting to uint64_t. When w is large, this multiplication constitutes undefined behavior under the C standard. On tested builds (clang/gcc without sanitizers), two's-complement wraparound commonly occurs, and for specific values of w the wrapped result is a small positive integer, which may allow the subsequent bounds check to pass incorrectly. If the check is bypassed, the decoding loop proceeds to write pixel data through dout, potentially extending far beyond the allocated output buffer. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34380", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Ty07MJmxlxMtrmptnF2X2A==": { "id": "Ty07MJmxlxMtrmptnF2X2A==", "updater": "debian/updater", "name": "CVE-2017-14159", "description": "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U+wbm6D+bKmC0YerxjSEqQ==": { "id": "U+wbm6D+bKmC0YerxjSEqQ==", "updater": "debian/updater", "name": "CVE-2026-64078", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: add and use xtables_unregister_table_exit Previous change added xtables_unregister_table_pre_exit to detach the table from the packetpath and to unlink it from the active table list. In case of rmmod, userspace that is doing set/getsockopt for this table will not be able to re-instantiate the table: 1. The larval table has been removed already 2. existing instantiated table is no longer on the xt pernet table list. This adds the second stage helper: unlink the table from the dying list, free the hook ops (if any) and do the audit notification. It replaces xt_unregister_table().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64078", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U+y6NfYK1BUAIqPDEbxONA==": { "id": "U+y6NfYK1BUAIqPDEbxONA==", "updater": "debian/updater", "name": "CVE-2025-8225", "description": "A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8225", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U0DvYYTZagIO6ldE+WrquQ==": { "id": "U0DvYYTZagIO6ldE+WrquQ==", "updater": "debian/updater", "name": "CVE-2026-31505", "description": "In the Linux kernel, the following vulnerability has been resolved: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() iavf incorrectly uses real_num_tx_queues for ETH_SS_STATS. Since the value could change in runtime, we should use num_tx_queues instead. Moreover iavf_get_ethtool_stats() uses num_active_queues while iavf_get_sset_count() and iavf_get_stat_strings() use real_num_tx_queues, which triggers out-of-bounds writes when we do \"ethtool -L\" and \"ethtool -S\" simultaneously [1]. For example when we change channels from 1 to 8, Thread 3 could be scheduled before Thread 2, and out-of-bounds writes could be triggered in Thread 3: Thread 1 (ethtool -L) Thread 2 (work) Thread 3 (ethtool -S) iavf_set_channels() ... iavf_alloc_queues() -\u003e num_active_queues = 8 iavf_schedule_finish_config() iavf_get_sset_count() real_num_tx_queues: 1 -\u003e buffer for 1 queue iavf_get_ethtool_stats() num_active_queues: 8 -\u003e out-of-bounds! iavf_finish_config() -\u003e real_num_tx_queues = 8 Use immutable num_tx_queues in all related functions to avoid the issue. [1] BUG: KASAN: vmalloc-out-of-bounds in iavf_add_one_ethtool_stat+0x200/0x270 Write of size 8 at addr ffffc900031c9080 by task ethtool/5800 CPU: 1 UID: 0 PID: 5800 Comm: ethtool Not tainted 6.19.0-enjuk-08403-g8137e3db7f1c #241 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x6f/0xb0 print_report+0x170/0x4f3 kasan_report+0xe1/0x180 iavf_add_one_ethtool_stat+0x200/0x270 iavf_get_ethtool_stats+0x14c/0x2e0 __dev_ethtool+0x3d0c/0x5830 dev_ethtool+0x12d/0x270 dev_ioctl+0x53c/0xe30 sock_do_ioctl+0x1a9/0x270 sock_ioctl+0x3d4/0x5e0 __x64_sys_ioctl+0x137/0x1c0 do_syscall_64+0xf3/0x690 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f7da0e6e36d ... \u003c/TASK\u003e The buggy address belongs to a 1-page vmalloc region starting at 0xffffc900031c9000 allocated at __dev_ethtool+0x3cc9/0x5830 The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88813a013de0 pfn:0x13a013 flags: 0x200000000000000(node=0|zone=2) raw: 0200000000000000 0000000000000000 dead000000000122 0000000000000000 raw: ffff88813a013de0 0000000000000000 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffffc900031c8f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ffffc900031c9000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 \u003effffc900031c9080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ^ ffffc900031c9100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ffffc900031c9180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31505", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "U2VEKQWR5OWfSqtkBGXqmA==": { "id": "U2VEKQWR5OWfSqtkBGXqmA==", "updater": "debian/updater", "name": "CVE-2026-23361", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry Endpoint drivers use dw_pcie_ep_raise_msix_irq() to raise an MSI-X interrupt to the host using a writel(), which generates a PCI posted write transaction. There's no completion for posted writes, so the writel() may return before the PCI write completes. dw_pcie_ep_raise_msix_irq() also unmaps the outbound ATU entry used for the PCI write, so the write races with the unmap. If the PCI write loses the race with the ATU unmap, the write may corrupt host memory or cause IOMMU errors, e.g., these when running fio with a larger queue depth against nvmet-pci-epf: arm-smmu-v3 fc900000.iommu: 0x0000010000000010 arm-smmu-v3 fc900000.iommu: 0x0000020000000000 arm-smmu-v3 fc900000.iommu: 0x000000090000f040 arm-smmu-v3 fc900000.iommu: 0x0000000000000000 arm-smmu-v3 fc900000.iommu: event: F_TRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0 arm-smmu-v3 fc900000.iommu: unpriv data write s1 \"Input address caused fault\" stag: 0x0 Flush the write by performing a readl() of the same address to ensure that the write has reached the destination before the ATU entry is unmapped. The same problem was solved for dw_pcie_ep_raise_msi_irq() in commit 8719c64e76bf (\"PCI: dwc: ep: Cache MSI outbound iATU mapping\"), but there it was solved by dedicating an outbound iATU only for MSI. We can't do the same for MSI-X because each vector can have a different msg_addr and the msg_addr may be changed while the vector is masked. [bhelgaas: commit log]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23361", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UAWZPxzzQwGwhDNr0CGk9g==": { "id": "UAWZPxzzQwGwhDNr0CGk9g==", "updater": "debian/updater", "name": "CVE-2026-73282", "description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-73282", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UCJ0Wb2hKTJ6hH+buyeBOQ==": { "id": "UCJ0Wb2hKTJ6hH+buyeBOQ==", "updater": "debian/updater", "name": "CVE-2026-62343", "description": "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-62343", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UJIAglRfS3rNJeKQfo5kOA==": { "id": "UJIAglRfS3rNJeKQfo5kOA==", "updater": "debian/updater", "name": "CVE-2024-53589", "description": "GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53589", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UPXbqUFGE1PJo7+PrKvZ+A==": { "id": "UPXbqUFGE1PJo7+PrKvZ+A==", "updater": "debian/updater", "name": "CVE-2026-68289", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern. Kernel panic - not syncing: kernel: panic_on_warn set ... RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521) Call Trace: __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402) skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534) tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934) io_recvmsg+0x47e/0xda0 Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always \u003c= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68289", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UQvyHOeI4QjGtZnm6T6ljg==": { "id": "UQvyHOeI4QjGtZnm6T6ljg==", "updater": "debian/updater", "name": "CVE-2024-42118", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not return negative stream id for array [WHY] resource_stream_to_stream_idx returns an array index and it return -1 when not found; however, -1 is not a valid array index number. [HOW] When this happens, call ASSERT(), and return a zero instead. This fixes an OVERRUN and an NEGATIVE_RETURNS issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "USv5GnXR+OJ5oCOuiw09/Q==": { "id": "USv5GnXR+OJ5oCOuiw09/Q==", "updater": "debian/updater", "name": "CVE-2025-1181", "description": "A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1181", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UUx3cOvsfM1yB1cxpmSDRA==": { "id": "UUx3cOvsfM1yB1cxpmSDRA==", "updater": "debian/updater", "name": "CVE-2026-53120", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53120", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UdaSmnTocU22kiF2dyT8xA==": { "id": "UdaSmnTocU22kiF2dyT8xA==", "updater": "debian/updater", "name": "CVE-2026-68324", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from \u0026lstat[type]. When type \u003e 0, this writes beyond the end of the allocated array, corrupting adjacent memory. Fix by using sizeof(*lstat) to clear only the target entry.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68324", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UeFIZtTayPvdOzvVB41/jA==": { "id": "UeFIZtTayPvdOzvVB41/jA==", "updater": "debian/updater", "name": "CVE-2025-39810", "description": "In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix memory corruption when FW resources change during ifdown bnxt_set_dflt_rings() assumes that it is always called before any TC has been created. So it doesn't take bp-\u003enum_tc into account and assumes that it is always 0 or 1. In the FW resource or capability change scenario, the FW will return flags in bnxt_hwrm_if_change() that will cause the driver to reinitialize and call bnxt_cancel_reservations(). This will lead to bnxt_init_dflt_ring_mode() calling bnxt_set_dflt_rings() and bp-\u003enum_tc may be greater than 1. This will cause bp-\u003etx_ring[] to be sized too small and cause memory corruption in bnxt_alloc_cp_rings(). Fix it by properly scaling the TX rings by bp-\u003enum_tc in the code paths mentioned above. Add 2 helper functions to determine bp-\u003etx_nr_rings and bp-\u003etx_nr_rings_per_tc.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39810", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UgYbawVYBKlWqMXTnMrkFQ==": { "id": "UgYbawVYBKlWqMXTnMrkFQ==", "updater": "debian/updater", "name": "CVE-2026-25210", "description": "In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-25210", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UgtteC8anOFnYyiPGfCwSQ==": { "id": "UgtteC8anOFnYyiPGfCwSQ==", "updater": "debian/updater", "name": "CVE-2026-7598", "description": "A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-7598", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UhU7m296KGnSD1zZRSq/jA==": { "id": "UhU7m296KGnSD1zZRSq/jA==", "updater": "debian/updater", "name": "CVE-2024-38620", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers. Since we no longer need to differentiate between AMP and Primary controllers, as only HCI_PRIMARY is left, this also remove hdev-\u003edev_type altogether.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38620", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UiVcHg1u39wxeAduIGVeVQ==": { "id": "UiVcHg1u39wxeAduIGVeVQ==", "updater": "debian/updater", "name": "CVE-2024-53195", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Get rid of userspace_irqchip_in_use Improper use of userspace_irqchip_in_use led to syzbot hitting the following WARN_ON() in kvm_timer_update_irq(): WARNING: CPU: 0 PID: 3281 at arch/arm64/kvm/arch_timer.c:459 kvm_timer_update_irq+0x21c/0x394 Call trace: kvm_timer_update_irq+0x21c/0x394 arch/arm64/kvm/arch_timer.c:459 kvm_timer_vcpu_reset+0x158/0x684 arch/arm64/kvm/arch_timer.c:968 kvm_reset_vcpu+0x3b4/0x560 arch/arm64/kvm/reset.c:264 kvm_vcpu_set_target arch/arm64/kvm/arm.c:1553 [inline] kvm_arch_vcpu_ioctl_vcpu_init arch/arm64/kvm/arm.c:1573 [inline] kvm_arch_vcpu_ioctl+0x112c/0x1b3c arch/arm64/kvm/arm.c:1695 kvm_vcpu_ioctl+0x4ec/0xf74 virt/kvm/kvm_main.c:4658 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:907 [inline] __se_sys_ioctl fs/ioctl.c:893 [inline] __arm64_sys_ioctl+0x108/0x184 fs/ioctl.c:893 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] invoke_syscall+0x78/0x1b8 arch/arm64/kernel/syscall.c:49 el0_svc_common+0xe8/0x1b0 arch/arm64/kernel/syscall.c:132 do_el0_svc+0x40/0x50 arch/arm64/kernel/syscall.c:151 el0_svc+0x54/0x14c arch/arm64/kernel/entry-common.c:712 el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598 The following sequence led to the scenario: - Userspace creates a VM and a vCPU. - The vCPU is initialized with KVM_ARM_VCPU_PMU_V3 during KVM_ARM_VCPU_INIT. - Without any other setup, such as vGIC or vPMU, userspace issues KVM_RUN on the vCPU. Since the vPMU is requested, but not setup, kvm_arm_pmu_v3_enable() fails in kvm_arch_vcpu_run_pid_change(). As a result, KVM_RUN returns after enabling the timer, but before incrementing 'userspace_irqchip_in_use': kvm_arch_vcpu_run_pid_change() ret = kvm_arm_pmu_v3_enable() if (!vcpu-\u003earch.pmu.created) return -EINVAL; if (ret) return ret; [...] if (!irqchip_in_kernel(kvm)) static_branch_inc(\u0026userspace_irqchip_in_use); - Userspace ignores the error and issues KVM_ARM_VCPU_INIT again. Since the timer is already enabled, control moves through the following flow, ultimately hitting the WARN_ON(): kvm_timer_vcpu_reset() if (timer-\u003eenabled) kvm_timer_update_irq() if (!userspace_irqchip()) ret = kvm_vgic_inject_irq() ret = vgic_lazy_init() if (unlikely(!vgic_initialized(kvm))) if (kvm-\u003earch.vgic.vgic_model != KVM_DEV_TYPE_ARM_VGIC_V2) return -EBUSY; WARN_ON(ret); Theoretically, since userspace_irqchip_in_use's functionality can be simply replaced by '!irqchip_in_kernel()', get rid of the static key to avoid the mismanagement, which also helps with the syzbot issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53195", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Um4hWKnCf0UxAt6EEhGwzQ==": { "id": "Um4hWKnCf0UxAt6EEhGwzQ==", "updater": "debian/updater", "name": "CVE-2025-38204", "description": "In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_missing_indices stbl is s8 but it must contain offsets into slot which can go from 0 to 127. Added a bound check for that error and return -EIO if the check fails. Also make jfs_readdir return with error if add_missing_indices returns with an error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38204", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UmInHmlKA0q8kxh6TUPiWQ==": { "id": "UmInHmlKA0q8kxh6TUPiWQ==", "updater": "debian/updater", "name": "CVE-2026-56409", "description": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56409", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UnZ1Z5jaCJ5t0Ylihj7qQw==": { "id": "UnZ1Z5jaCJ5t0Ylihj7qQw==", "updater": "debian/updater", "name": "CVE-2026-53118", "description": "In the Linux kernel, the following vulnerability has been resolved: vdpa: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UqlXj97FrNpj1p9MIGdxxw==": { "id": "UqlXj97FrNpj1p9MIGdxxw==", "updater": "debian/updater", "name": "CVE-2026-15308", "description": "The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-15308", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "UrZKzZ/sKVqQmTDnQ47I9g==": { "id": "UrZKzZ/sKVqQmTDnQ47I9g==", "updater": "debian/updater", "name": "CVE-2023-31438", "description": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31438", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Uyt1KDdT5GAgyMiaZiypKA==": { "id": "Uyt1KDdT5GAgyMiaZiypKA==", "updater": "debian/updater", "name": "CVE-2026-53272", "description": "In the Linux kernel, the following vulnerability has been resolved: erofs: fix use-after-free on sbi-\u003esync_decompress z_erofs_decompress_kickoff() can race with filesystem unmount, causing a use-after-free on sbi-\u003esync_decompress. When I/O completes, z_erofs_endio() calls z_erofs_decompress_kickoff() to queue z_erofs_decompressqueue_work() asynchronously. Then, after all folios are unlocked, unmount workflow can proceed and sbi will be freed before accessing to sbi-\u003esync_decompress. Thread (unmount) I/O completion kworker queue_work z_erofs_decompressqueue_work (all folios are unlocked) cleanup_mnt .. erofs_kill_sb erofs_sb_free kfree(sbi) access sbi-\u003esync_decompress // UAF!!", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53272", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "V+U5FRF3lAEjle3LkhTGnQ==": { "id": "V+U5FRF3lAEjle3LkhTGnQ==", "updater": "debian/updater", "name": "CVE-2026-68140", "description": "In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path af_iucv queues not-yet-received message notifications on iucv-\u003emessage_q, each holding a raw pointer to the connection's iucv_path. When the peer severs the connection, iucv_sever_path() frees that path with iucv_path_free() but leaves the notifications queued. A later recvmsg() drains message_q via iucv_process_message_q() and hands the stale path to message_receive() -- a use-after-free of the freed iucv_path. Drop the queued notifications when the path is severed; once the path is gone they can no longer be received. This also frees the notifications leaked when a socket is closed with messages still queued.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68140", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "V8iS57FCTRiSUW3SJu20mw==": { "id": "V8iS57FCTRiSUW3SJu20mw==", "updater": "debian/updater", "name": "CVE-2025-38081", "description": "In the Linux kernel, the following vulnerability has been resolved: spi-rockchip: Fix register out of bounds access Do not write native chip select stuff for GPIO chip selects. GPIOs can be numbered much higher than native CS. Also, it makes no sense.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38081", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "V8kRDFippjKvrzP8VaHSbw==": { "id": "V8kRDFippjKvrzP8VaHSbw==", "updater": "debian/updater", "name": "CVE-2023-52751", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in smb2_query_info_compound() The following UAF was triggered when running fstests generic/072 with KASAN enabled against Windows Server 2022 and mount options 'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm' BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [cifs] Read of size 8 at addr ffff888014941048 by task xfs_io/27534 CPU: 0 PID: 27534 Comm: xfs_io Not tainted 6.6.0-rc7 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014 Call Trace: dump_stack_lvl+0x4a/0x80 print_report+0xcf/0x650 ? srso_alias_return_thunk+0x5/0x7f ? srso_alias_return_thunk+0x5/0x7f ? __phys_addr+0x46/0x90 kasan_report+0xda/0x110 ? smb2_query_info_compound+0x423/0x6d0 [cifs] ? smb2_query_info_compound+0x423/0x6d0 [cifs] smb2_query_info_compound+0x423/0x6d0 [cifs] ? __pfx_smb2_query_info_compound+0x10/0x10 [cifs] ? srso_alias_return_thunk+0x5/0x7f ? __stack_depot_save+0x39/0x480 ? kasan_save_stack+0x33/0x60 ? kasan_set_track+0x25/0x30 ? ____kasan_slab_free+0x126/0x170 smb2_queryfs+0xc2/0x2c0 [cifs] ? __pfx_smb2_queryfs+0x10/0x10 [cifs] ? __pfx___lock_acquire+0x10/0x10 smb311_queryfs+0x210/0x220 [cifs] ? __pfx_smb311_queryfs+0x10/0x10 [cifs] ? srso_alias_return_thunk+0x5/0x7f ? __lock_acquire+0x480/0x26c0 ? lock_release+0x1ed/0x640 ? srso_alias_return_thunk+0x5/0x7f ? do_raw_spin_unlock+0x9b/0x100 cifs_statfs+0x18c/0x4b0 [cifs] statfs_by_dentry+0x9b/0xf0 fd_statfs+0x4e/0xb0 __do_sys_fstatfs+0x7f/0xe0 ? __pfx___do_sys_fstatfs+0x10/0x10 ? srso_alias_return_thunk+0x5/0x7f ? lockdep_hardirqs_on_prepare+0x136/0x200 ? srso_alias_return_thunk+0x5/0x7f do_syscall_64+0x3f/0x90 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Allocated by task 27534: kasan_save_stack+0x33/0x60 kasan_set_track+0x25/0x30 __kasan_kmalloc+0x8f/0xa0 open_cached_dir+0x71b/0x1240 [cifs] smb2_query_info_compound+0x5c3/0x6d0 [cifs] smb2_queryfs+0xc2/0x2c0 [cifs] smb311_queryfs+0x210/0x220 [cifs] cifs_statfs+0x18c/0x4b0 [cifs] statfs_by_dentry+0x9b/0xf0 fd_statfs+0x4e/0xb0 __do_sys_fstatfs+0x7f/0xe0 do_syscall_64+0x3f/0x90 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Freed by task 27534: kasan_save_stack+0x33/0x60 kasan_set_track+0x25/0x30 kasan_save_free_info+0x2b/0x50 ____kasan_slab_free+0x126/0x170 slab_free_freelist_hook+0xd0/0x1e0 __kmem_cache_free+0x9d/0x1b0 open_cached_dir+0xff5/0x1240 [cifs] smb2_query_info_compound+0x5c3/0x6d0 [cifs] smb2_queryfs+0xc2/0x2c0 [cifs] This is a race between open_cached_dir() and cached_dir_lease_break() where the cache entry for the open directory handle receives a lease break while creating it. And before returning from open_cached_dir(), we put the last reference of the new @cfid because of !@cfid-\u003ehas_lease. Besides the UAF, while running xfstests a lot of missed lease breaks have been noticed in tests that run several concurrent statfs(2) calls on those cached fids CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame... CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1... CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 00000000715bfe83 len 108 CIFS: VFS: Dump pending requests: CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame... CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1... CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 000000005aa7316e len 108 ... To fix both, in open_cached_dir() ensure that @cfid-\u003ehas_lease is set right before sending out compounded request so that any potential lease break will be get processed by demultiplex thread while we're still caching @cfid. And, if open failed for some reason, re-check @cfid-\u003ehas_lease to decide whether or not put lease reference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52751", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "V9t26J6ZUHangNhaOQv5KQ==": { "id": "V9t26J6ZUHangNhaOQv5KQ==", "updater": "debian/updater", "name": "CVE-2026-31707", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fields from the daemon response to a fixed struct size in unsigned int arithmetic. Three cases can overflow: KSMBD_EVENT_RPC_REQUEST: msg_sz = sizeof(struct ksmbd_rpc_command) + resp-\u003epayload_sz; KSMBD_EVENT_SHARE_CONFIG_REQUEST: msg_sz = sizeof(struct ksmbd_share_config_response) + resp-\u003epayload_sz; KSMBD_EVENT_LOGIN_REQUEST_EXT: msg_sz = sizeof(struct ksmbd_login_response_ext) + resp-\u003engroups * sizeof(gid_t); resp-\u003epayload_sz is __u32 and resp-\u003engroups is __s32. Each addition can wrap in unsigned int; the multiplication by sizeof(gid_t) mixes signed and size_t, so a negative ngroups is converted to SIZE_MAX before the multiply. A wrapped value of msg_sz that happens to equal entry-\u003emsg_sz bypasses the size check on the next line, and downstream consumers (smb2pdu.c:6742 memcpy using rpc_resp-\u003epayload_sz, kmemdup in ksmbd_alloc_user using resp_ext-\u003engroups) then trust the unverified length. Use check_add_overflow() on the RPC_REQUEST and SHARE_CONFIG_REQUEST paths to detect integer overflow without constraining functional payload size; userspace ksmbd-tools grows NDR responses in 4096-byte chunks for calls like NetShareEnumAll, so a hard transport cap is unworkable on the response side. For LOGIN_REQUEST_EXT, reject resp-\u003engroups outside the signed [0, NGROUPS_MAX] range up front and report the error from ipc_validate_msg() so it fires at the IPC boundary; with that bound the subsequent multiplication and addition stay well below UINT_MAX. The now-redundant ngroups check and pr_err in ksmbd_alloc_user() are removed. This is the response-side analogue of aab98e2dbd64 (\"ksmbd: fix integer overflows on 32 bit systems\"), which hardened the request side.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31707", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VBhzdEYeRcywtNKzXlcEJw==": { "id": "VBhzdEYeRcywtNKzXlcEJw==", "updater": "debian/updater", "name": "CVE-2026-68300", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk-\u003eauth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68300", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VFI2YAPt+wwgNU00tRnLLA==": { "id": "VFI2YAPt+wwgNU00tRnLLA==", "updater": "debian/updater", "name": "CVE-2024-49893", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check stream_status before it is used [WHAT \u0026 HOW] dc_state_get_stream_status can return null, and therefore null must be checked before stream_status is used. This fixes 1 NULL_RETURNS issue reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49893", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VG2kMas1/Gt7kIoRyvIsOQ==": { "id": "VG2kMas1/Gt7kIoRyvIsOQ==", "updater": "debian/updater", "name": "CVE-2017-7275", "description": "The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows remote attackers to cause a denial of service (attempted large memory allocation and application crash) via a crafted file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862 and CVE-2016-8866.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-7275", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VIIHXNAx40tfWxKjUYoXug==": { "id": "VIIHXNAx40tfWxKjUYoXug==", "updater": "debian/updater", "name": "CVE-2008-2544", "description": "Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-2544", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VIauTgqjmmC3JrXtK9SoKA==": { "id": "VIauTgqjmmC3JrXtK9SoKA==", "updater": "debian/updater", "name": "CVE-2024-52005", "description": "Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-52005", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "git", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VJ3UbesVXW73e03bBBZDRg==": { "id": "VJ3UbesVXW73e03bBBZDRg==", "updater": "debian/updater", "name": "CVE-2022-4543", "description": "A flaw named \"EntryBleed\" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-4543", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VLHKht+kiKS6NMvy/MetxA==": { "id": "VLHKht+kiKS6NMvy/MetxA==", "updater": "debian/updater", "name": "CVE-2026-23004", "description": "In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1] Crash happens in list_del_init()/INIT_LIST_HEAD() while writing list-\u003eprev, while the prior write on list-\u003enext went well. static inline void INIT_LIST_HEAD(struct list_head *list) { \tWRITE_ONCE(list-\u003enext, list); // This went well \tWRITE_ONCE(list-\u003eprev, list); // Crash, @list has been freed. } Issue here is that rt6_uncached_list_del() did not attempt to lock ul-\u003elock, as list_empty(\u0026rt-\u003edst.rt_uncached) returned true because the WRITE_ONCE(list-\u003enext, list) happened on the other CPU. We might use list_del_init_careful() and list_empty_careful(), or make sure rt6_uncached_list_del() always grabs the spinlock whenever rt-\u003edst.rt_uncached_list has been set. A similar fix is neeed for IPv4. [1] BUG: KASAN: slab-use-after-free in INIT_LIST_HEAD include/linux/list.h:46 [inline] BUG: KASAN: slab-use-after-free in list_del_init include/linux/list.h:296 [inline] BUG: KASAN: slab-use-after-free in rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline] BUG: KASAN: slab-use-after-free in rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020 Write of size 8 at addr ffff8880294cfa78 by task kworker/u8:14/3450 CPU: 0 UID: 0 PID: 3450 Comm: kworker/u8:14 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)} Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 Workqueue: netns cleanup_net Call Trace: \u003cTASK\u003e dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 INIT_LIST_HEAD include/linux/list.h:46 [inline] list_del_init include/linux/list.h:296 [inline] rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline] rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020 addrconf_ifdown+0x143/0x18a0 net/ipv6/addrconf.c:3853 addrconf_notify+0x1bc/0x1050 net/ipv6/addrconf.c:-1 notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85 call_netdevice_notifiers_extack net/core/dev.c:2268 [inline] call_netdevice_notifiers net/core/dev.c:2282 [inline] netif_close_many+0x29c/0x410 net/core/dev.c:1785 unregister_netdevice_many_notify+0xb50/0x2330 net/core/dev.c:12353 ops_exit_rtnl_list net/core/net_namespace.c:187 [inline] ops_undo_list+0x3dc/0x990 net/core/net_namespace.c:248 cleanup_net+0x4de/0x7b0 net/core/net_namespace.c:696 process_one_work kernel/workqueue.c:3257 [inline] process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 \u003c/TASK\u003e Allocated by task 803: kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 unpoison_slab_object mm/kasan/common.c:340 [inline] __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366 kasan_slab_alloc include/linux/kasan.h:253 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5263 [inline] kmem_cache_alloc_noprof+0x18d/0x6c0 mm/slub.c:5270 dst_alloc+0x105/0x170 net/core/dst.c:89 ip6_dst_alloc net/ipv6/route.c:342 [inline] icmp6_dst_alloc+0x75/0x460 net/ipv6/route.c:3333 mld_sendpack+0x683/0xe60 net/ipv6/mcast.c:1844 mld_send_cr net/ipv6/mcast.c:2154 [inline] mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693 process_one_work kernel/workqueue.c:3257 [inline] process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23004", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VRBI4lPXeZDBh7vAlbseMw==": { "id": "VRBI4lPXeZDBh7vAlbseMw==", "updater": "debian/updater", "name": "CVE-2024-49945", "description": "In the Linux kernel, the following vulnerability has been resolved: net/ncsi: Disable the ncsi work before freeing the associated structure The work function can run after the ncsi device is freed, resulting in use-after-free bugs or kernel panic.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49945", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VUU74CujbBUJFROehJySAg==": { "id": "VUU74CujbBUJFROehJySAg==", "updater": "debian/updater", "name": "CVE-2026-56208", "description": "A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56208", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VUn+MKhO9qXlulJ0JJY/og==": { "id": "VUn+MKhO9qXlulJ0JJY/og==", "updater": "debian/updater", "name": "CVE-2026-42217", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42217", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VWpX5DzXUBXf2CZ3YPlpsw==": { "id": "VWpX5DzXUBXf2CZ3YPlpsw==", "updater": "debian/updater", "name": "CVE-2026-31462", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent immediate PASID reuse case PASID resue could cause interrupt issue when process immediately runs into hw state left by previous process exited with the same PASID, it's possible that page faults are still pending in the IH ring buffer when the process exits and frees up its PASID. To prevent the case, it uses idr cyclic allocator same as kernel pid's. (cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31462", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VYlkYCaZtG2x/9LY6YoOwQ==": { "id": "VYlkYCaZtG2x/9LY6YoOwQ==", "updater": "debian/updater", "name": "CVE-2026-43125", "description": "In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree(). Add length validation to prevent potential buffer overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43125", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VbYu/WOg75Vb8/1JanN0hA==": { "id": "VbYu/WOg75Vb8/1JanN0hA==", "updater": "debian/updater", "name": "CVE-2025-12495", "description": "Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-12495", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Vbe2XjswKKuAOoU341cwpQ==": { "id": "Vbe2XjswKKuAOoU341cwpQ==", "updater": "debian/updater", "name": "CVE-2025-38244", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential deadlock when reconnecting channels Fix cifs_signal_cifsd_for_reconnect() to take the correct lock order and prevent the following deadlock from happening ====================================================== WARNING: possible circular locking dependency detected 6.16.0-rc3-build2+ #1301 Tainted: G S W ------------------------------------------------------ cifsd/6055 is trying to acquire lock: ffff88810ad56038 (\u0026tcp_ses-\u003esrv_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x134/0x200 but task is already holding lock: ffff888119c64330 (\u0026ret_buf-\u003echan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -\u003e #2 (\u0026ret_buf-\u003echan_lock){+.+.}-{3:3}: validate_chain+0x1cf/0x270 __lock_acquire+0x60e/0x780 lock_acquire.part.0+0xb4/0x1f0 _raw_spin_lock+0x2f/0x40 cifs_setup_session+0x81/0x4b0 cifs_get_smb_ses+0x771/0x900 cifs_mount_get_session+0x7e/0x170 cifs_mount+0x92/0x2d0 cifs_smb3_do_mount+0x161/0x460 smb3_get_tree+0x55/0x90 vfs_get_tree+0x46/0x180 do_new_mount+0x1b0/0x2e0 path_mount+0x6ee/0x740 do_mount+0x98/0xe0 __do_sys_mount+0x148/0x180 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x76/0x7e -\u003e #1 (\u0026ret_buf-\u003eses_lock){+.+.}-{3:3}: validate_chain+0x1cf/0x270 __lock_acquire+0x60e/0x780 lock_acquire.part.0+0xb4/0x1f0 _raw_spin_lock+0x2f/0x40 cifs_match_super+0x101/0x320 sget+0xab/0x270 cifs_smb3_do_mount+0x1e0/0x460 smb3_get_tree+0x55/0x90 vfs_get_tree+0x46/0x180 do_new_mount+0x1b0/0x2e0 path_mount+0x6ee/0x740 do_mount+0x98/0xe0 __do_sys_mount+0x148/0x180 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x76/0x7e -\u003e #0 (\u0026tcp_ses-\u003esrv_lock){+.+.}-{3:3}: check_noncircular+0x95/0xc0 check_prev_add+0x115/0x2f0 validate_chain+0x1cf/0x270 __lock_acquire+0x60e/0x780 lock_acquire.part.0+0xb4/0x1f0 _raw_spin_lock+0x2f/0x40 cifs_signal_cifsd_for_reconnect+0x134/0x200 __cifs_reconnect+0x8f/0x500 cifs_handle_standard+0x112/0x280 cifs_demultiplex_thread+0x64d/0xbc0 kthread+0x2f7/0x310 ret_from_fork+0x2a/0x230 ret_from_fork_asm+0x1a/0x30 other info that might help us debug this: Chain exists of: \u0026tcp_ses-\u003esrv_lock --\u003e \u0026ret_buf-\u003eses_lock --\u003e \u0026ret_buf-\u003echan_lock Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(\u0026ret_buf-\u003echan_lock); lock(\u0026ret_buf-\u003eses_lock); lock(\u0026ret_buf-\u003echan_lock); lock(\u0026tcp_ses-\u003esrv_lock); *** DEADLOCK *** 3 locks held by cifsd/6055: #0: ffffffff857de398 (\u0026cifs_tcp_ses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x7b/0x200 #1: ffff888119c64060 (\u0026ret_buf-\u003eses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x9c/0x200 #2: ffff888119c64330 (\u0026ret_buf-\u003echan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38244", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Vd6ZTfdSpcn12KBePvRLWQ==": { "id": "Vd6ZTfdSpcn12KBePvRLWQ==", "updater": "debian/updater", "name": "CVE-2018-15607", "description": "In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-15607", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VgbIlYn/yGYWh6cVqQpddA==": { "id": "VgbIlYn/yGYWh6cVqQpddA==", "updater": "debian/updater", "name": "CVE-2026-63819", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on f2fs_get_node_folio_ra() kernel BUG at fs/f2fs/file.c:845! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:f2fs_do_truncate_blocks+0x1115/0x1140 fs/f2fs/file.c:845 Code: fc fc 90 0f 0b e8 8b 9d 9a fd 90 0f 0b e8 83 9d 9a fd 48 89 df 48 c7 c6 60 d1 1a 8c e8 54 f1 fc fc 90 0f 0b e8 6c 9d 9a fd 90 \u003c0f\u003e 0b e8 64 9d 9a fd 90 0f 0b 90 e9 93 fd ff ff e8 56 9d 9a fd 90 RSP: 0018:ffffc9000e4474c0 EFLAGS: 00010283 RAX: ffffffff842b1d34 RBX: 0000000000000003 RCX: 0000000000100000 RDX: ffffc9000f03a000 RSI: 0000000000035503 RDI: 0000000000035504 RBP: ffffc9000e447608 R08: ffff8880123b0000 R09: 0000000000000002 R10: 00000000fffffffe R11: 0000000000000002 R12: 0000000000000001 R13: 0000000000000000 R14: 1ffff92001c88ea0 R15: 00000000ffff039c FS: 00007f7e02ee36c0(0000) GS:ffff88808c887000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ff0305c4000 CR3: 0000000012d4c000 CR4: 0000000000352ef0 Call Trace: \u003cTASK\u003e f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:882 f2fs_truncate+0x471/0x7c0 fs/f2fs/file.c:940 f2fs_evict_inode+0xa3f/0x1ac0 fs/f2fs/inode.c:907 evict+0x61e/0xb10 fs/inode.c:841 f2fs_fill_super+0x5f43/0x78f0 fs/f2fs/super.c:5224 get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694 vfs_get_tree+0x92/0x2a0 fs/super.c:1754 fc_mount fs/namespace.c:1193 [inline] do_new_mount_fc fs/namespace.c:3758 [inline] do_new_mount+0x341/0xd30 fs/namespace.c:3834 do_mount fs/namespace.c:4167 [inline] __do_sys_mount fs/namespace.c:4383 [inline] __se_sys_mount+0x31d/0x420 fs/namespace.c:4360 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f \tcount = ADDRS_PER_PAGE(dn.node_folio, inode); \tcount -= dn.ofs_in_node; \tf2fs_bug_on(sbi, count \u003c 0); The fuzz test will trigger above bug_on in f2fs. The root cause should be: in the corrupted inode, there is a direct node which has the same ino and nid in its footer, so in f2fs_do_truncate_blocks(), after f2fs_get_dnode_of_data() finds such dnode: 1) ADDRS_PER_PAGE(dn.node_folio, inode) will return 923 2) once dn.ofs_in_node points to addr[923, 1017] Then it will trigger the system panic. Let's introduce NODE_TYPE_NON_IXNODE to indicate current node should not be an inode or xattr node, and then use it in below path to detect inconsistent node chain in inode mapping table: - f2fs_do_truncate_blocks - f2fs_get_dnode_of_data - f2fs_get_node_folio_ra - __get_node_folio - f2fs_sanity_check_node_footer - case NODE_TYPE_NON_IXNODE -\u003e check whether it is inode|xnode", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63819", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VgzyFJeiC9rkj6o3g1bF+Q==": { "id": "VgzyFJeiC9rkj6o3g1bF+Q==", "updater": "debian/updater", "name": "CVE-2024-47664", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware If the value of max_speed_hz is 0, it may cause a division by zero error in hisi_calc_effective_speed(). The value of max_speed_hz is provided by firmware. Firmware is generally considered as a trusted domain. However, as division by zero errors can cause system failure, for defense measure, the value of max_speed is validated here. So 0 is regarded as invalid and an error code is returned.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47664", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VhI3fCsM/ubhXhs9Rae4mQ==": { "id": "VhI3fCsM/ubhXhs9Rae4mQ==", "updater": "debian/updater", "name": "CVE-2026-64569", "description": "In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed attribute table itself instead of calling ip_valid_fib_dump_req(). The RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no RTA_OIF hits a NULL dereference. RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without CAP_NET_ADMIN, so an unprivileged user can trigger it. Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189) Call Trace: mpls_dump_routes (net/mpls/af_mpls.c:2236) netlink_dump (net/netlink/af_netlink.c:2331) __netlink_dump_start (net/netlink/af_netlink.c:2446) rtnetlink_rcv_msg (net/core/rtnetlink.c:7033) netlink_rcv_skb (net/netlink/af_netlink.c:2556) netlink_unicast (net/netlink/af_netlink.c:1345) netlink_sendmsg (net/netlink/af_netlink.c:1900) __sock_sendmsg (net/socket.c:790) ____sys_sendmsg (net/socket.c:2684) ___sys_sendmsg (net/socket.c:2738) __sys_sendmsg (net/socket.c:2770) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Skip unset attributes, as ip_valid_fib_dump_req() does.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64569", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VhutE6CSNp92DtQ53GCh4A==": { "id": "VhutE6CSNp92DtQ53GCh4A==", "updater": "debian/updater", "name": "CVE-2026-23371", "description": "In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting Running stress-ng --schedpolicy 0 on an RT kernel on a big machine might lead to the following WARNINGs (edited). sched: DL de-boosted task PID 22725: REPLENISH flag missing WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeue_task_dl+0x15c/0x1f8 ... (running_bw underflow) Call trace: dequeue_task_dl+0x15c/0x1f8 (P) dequeue_task+0x80/0x168 deactivate_task+0x24/0x50 push_dl_task+0x264/0x2e0 dl_task_timer+0x1b0/0x228 __hrtimer_run_queues+0x188/0x378 hrtimer_interrupt+0xfc/0x260 ... The problem is that when a SCHED_DEADLINE task (lock holder) is changed to a lower priority class via sched_setscheduler(), it may fail to properly inherit the parameters of potential DEADLINE donors if it didn't already inherit them in the past (shorter deadline than donor's at that time). This might lead to bandwidth accounting corruption, as enqueue_task_dl() won't recognize the lock holder as boosted. The scenario occurs when: 1. A DEADLINE task (donor) blocks on a PI mutex held by another DEADLINE task (holder), but the holder doesn't inherit parameters (e.g., it already has a shorter deadline) 2. sched_setscheduler() changes the holder from DEADLINE to a lower class while still holding the mutex 3. The holder should now inherit DEADLINE parameters from the donor and be enqueued with ENQUEUE_REPLENISH, but this doesn't happen Fix the issue by introducing __setscheduler_dl_pi(), which detects when a DEADLINE (proper or boosted) task gets setscheduled to a lower priority class. In case, the function makes the task inherit DEADLINE parameters of the donoer (pi_se) and sets ENQUEUE_REPLENISH flag to ensure proper bandwidth accounting during the next enqueue operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23371", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VmgWfo6cc7CWRKYng0D+LQ==": { "id": "VmgWfo6cc7CWRKYng0D+LQ==", "updater": "debian/updater", "name": "CVE-2018-6952", "description": "A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-6952", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VogRSV/2Imj9EVT5Y+ZWnQ==": { "id": "VogRSV/2Imj9EVT5Y+ZWnQ==", "updater": "debian/updater", "name": "CVE-2026-23171", "description": "In the Linux kernel, the following vulnerability has been resolved: bonding: fix use-after-free due to enslave fail after slave array update Fix a use-after-free which happens due to enslave failure after the new slave has been added to the array. Since the new slave can be used for Tx immediately, we can use it after it has been freed by the enslave error cleanup path which frees the allocated slave memory. Slave update array is supposed to be called last when further enslave failures are not expected. Move it after xdp setup to avoid any problems. It is very easy to reproduce the problem with a simple xdp_pass prog: ip l add bond1 type bond mode balance-xor ip l set bond1 up ip l set dev bond1 xdp object xdp_pass.o sec xdp_pass ip l add dumdum type dummy Then run in parallel: while :; do ip l set dumdum master bond1 1\u003e/dev/null 2\u003e\u00261; done; mausezahn bond1 -a own -b rand -A rand -B 1.1.1.1 -c 0 -t tcp \"dp=1-1023, flags=syn\" The crash happens almost immediately: [ 605.602850] Oops: general protection fault, probably for non-canonical address 0xe0e6fc2460000137: 0000 [#1] SMP KASAN NOPTI [ 605.602916] KASAN: maybe wild-memory-access in range [0x07380123000009b8-0x07380123000009bf] [ 605.602946] CPU: 0 UID: 0 PID: 2445 Comm: mausezahn Kdump: loaded Tainted: G B 6.19.0-rc6+ #21 PREEMPT(voluntary) [ 605.602979] Tainted: [B]=BAD_PAGE [ 605.602998] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 605.603032] RIP: 0010:netdev_core_pick_tx+0xcd/0x210 [ 605.603063] Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 3e 01 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 6b 08 49 8d 7d 30 48 89 fa 48 c1 ea 03 \u003c80\u003e 3c 02 00 0f 85 25 01 00 00 49 8b 45 30 4c 89 e2 48 89 ee 48 89 [ 605.603111] RSP: 0018:ffff88817b9af348 EFLAGS: 00010213 [ 605.603145] RAX: dffffc0000000000 RBX: ffff88817d28b420 RCX: 0000000000000000 [ 605.603172] RDX: 00e7002460000137 RSI: 0000000000000008 RDI: 07380123000009be [ 605.603199] RBP: ffff88817b541a00 R08: 0000000000000001 R09: fffffbfff3ed8c0c [ 605.603226] R10: ffffffff9f6c6067 R11: 0000000000000001 R12: 0000000000000000 [ 605.603253] R13: 073801230000098e R14: ffff88817d28b448 R15: ffff88817b541a84 [ 605.603286] FS: 00007f6570ef67c0(0000) GS:ffff888221dfa000(0000) knlGS:0000000000000000 [ 605.603319] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 605.603343] CR2: 00007f65712fae40 CR3: 000000011371b000 CR4: 0000000000350ef0 [ 605.603373] Call Trace: [ 605.603392] \u003cTASK\u003e [ 605.603410] __dev_queue_xmit+0x448/0x32a0 [ 605.603434] ? __pfx_vprintk_emit+0x10/0x10 [ 605.603461] ? __pfx_vprintk_emit+0x10/0x10 [ 605.603484] ? __pfx___dev_queue_xmit+0x10/0x10 [ 605.603507] ? bond_start_xmit+0xbfb/0xc20 [bonding] [ 605.603546] ? _printk+0xcb/0x100 [ 605.603566] ? __pfx__printk+0x10/0x10 [ 605.603589] ? bond_start_xmit+0xbfb/0xc20 [bonding] [ 605.603627] ? add_taint+0x5e/0x70 [ 605.603648] ? add_taint+0x2a/0x70 [ 605.603670] ? end_report.cold+0x51/0x75 [ 605.603693] ? bond_start_xmit+0xbfb/0xc20 [bonding] [ 605.603731] bond_start_xmit+0x623/0xc20 [bonding]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23171", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VtJFIoe4RZpuYfcXkn2FAQ==": { "id": "VtJFIoe4RZpuYfcXkn2FAQ==", "updater": "debian/updater", "name": "CVE-2020-35501", "description": "A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-35501", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Vv3PxPN9gE/EoER6vTtqlQ==": { "id": "Vv3PxPN9gE/EoER6vTtqlQ==", "updater": "debian/updater", "name": "CVE-2025-38615", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name fails The reproducer uses a file0 on a ntfs3 file system with a corrupted i_link. When renaming, the file0's inode is marked as a bad inode because the file name cannot be deleted. The underlying bug is that make_bad_inode() is called on a live inode. In some cases it's \"icache lookup finds a normal inode, d_splice_alias() is called to attach it to dentry, while another thread decides to call make_bad_inode() on it - that would evict it from icache, but we'd already found it there earlier\". In some it's outright \"we have an inode attached to dentry - that's how we got it in the first place; let's call make_bad_inode() on it just for shits and giggles\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38615", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VvK7VF34ghwBAlMiD4P5yg==": { "id": "VvK7VF34ghwBAlMiD4P5yg==", "updater": "debian/updater", "name": "CVE-2023-53538", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: insert tree mod log move in push_node_left There is a fairly unlikely race condition in tree mod log rewind that can result in a kernel panic which has the following trace: [530.569] BTRFS critical (device sda3): unable to find logical 0 length 4096 [530.585] BTRFS critical (device sda3): unable to find logical 0 length 4096 [530.602] BUG: kernel NULL pointer dereference, address: 0000000000000002 [530.618] #PF: supervisor read access in kernel mode [530.629] #PF: error_code(0x0000) - not-present page [530.641] PGD 0 P4D 0 [530.647] Oops: 0000 [#1] SMP [530.654] CPU: 30 PID: 398973 Comm: below Kdump: loaded Tainted: G S O K 5.12.0-0_fbk13_clang_7455_gb24de3bdb045 #1 [530.680] Hardware name: Quanta Mono Lake-M.2 SATA 1HY9U9Z001G/Mono Lake-M.2 SATA, BIOS F20_3A15 08/16/2017 [530.703] RIP: 0010:__btrfs_map_block+0xaa/0xd00 [530.755] RSP: 0018:ffffc9002c2f7600 EFLAGS: 00010246 [530.767] RAX: ffffffffffffffea RBX: ffff888292e41000 RCX: f2702d8b8be15100 [530.784] RDX: ffff88885fda6fb8 RSI: ffff88885fd973c8 RDI: ffff88885fd973c8 [530.800] RBP: ffff888292e410d0 R08: ffffffff82fd7fd0 R09: 00000000fffeffff [530.816] R10: ffffffff82e57fd0 R11: ffffffff82e57d70 R12: 0000000000000000 [530.832] R13: 0000000000001000 R14: 0000000000001000 R15: ffffc9002c2f76f0 [530.848] FS: 00007f38d64af000(0000) GS:ffff88885fd80000(0000) knlGS:0000000000000000 [530.866] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [530.880] CR2: 0000000000000002 CR3: 00000002b6770004 CR4: 00000000003706e0 [530.896] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [530.912] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [530.928] Call Trace: [530.934] ? btrfs_printk+0x13b/0x18c [530.943] ? btrfs_bio_counter_inc_blocked+0x3d/0x130 [530.955] btrfs_map_bio+0x75/0x330 [530.963] ? kmem_cache_alloc+0x12a/0x2d0 [530.973] ? btrfs_submit_metadata_bio+0x63/0x100 [530.984] btrfs_submit_metadata_bio+0xa4/0x100 [530.995] submit_extent_page+0x30f/0x360 [531.004] read_extent_buffer_pages+0x49e/0x6d0 [531.015] ? submit_extent_page+0x360/0x360 [531.025] btree_read_extent_buffer_pages+0x5f/0x150 [531.037] read_tree_block+0x37/0x60 [531.046] read_block_for_search+0x18b/0x410 [531.056] btrfs_search_old_slot+0x198/0x2f0 [531.066] resolve_indirect_ref+0xfe/0x6f0 [531.076] ? ulist_alloc+0x31/0x60 [531.084] ? kmem_cache_alloc_trace+0x12e/0x2b0 [531.095] find_parent_nodes+0x720/0x1830 [531.105] ? ulist_alloc+0x10/0x60 [531.113] iterate_extent_inodes+0xea/0x370 [531.123] ? btrfs_previous_extent_item+0x8f/0x110 [531.134] ? btrfs_search_path_in_tree+0x240/0x240 [531.146] iterate_inodes_from_logical+0x98/0xd0 [531.157] ? btrfs_search_path_in_tree+0x240/0x240 [531.168] btrfs_ioctl_logical_to_ino+0xd9/0x180 [531.179] btrfs_ioctl+0xe2/0x2eb0 This occurs when logical inode resolution takes a tree mod log sequence number, and then while backref walking hits a rewind on a busy node which has the following sequence of tree mod log operations (numbers filled in from a specific example, but they are somewhat arbitrary) REMOVE_WHILE_FREEING slot 532 REMOVE_WHILE_FREEING slot 531 REMOVE_WHILE_FREEING slot 530 ... REMOVE_WHILE_FREEING slot 0 REMOVE slot 455 REMOVE slot 454 REMOVE slot 453 ... REMOVE slot 0 ADD slot 455 ADD slot 454 ADD slot 453 ... ADD slot 0 MOVE src slot 0 -\u003e dst slot 456 nritems 533 REMOVE slot 455 REMOVE slot 454 REMOVE slot 453 ... REMOVE slot 0 When this sequence gets applied via btrfs_tree_mod_log_rewind, it allocates a fresh rewind eb, and first inserts the correct key info for the 533 elements, then overwrites the first 456 of them, then decrements the count by 456 via the add ops, then rewinds the move by doing a memmove from 456:988-\u003e0:532. We have never written anything past 532, ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53538", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "VyBNyzFVuqLQur70rY8brQ==": { "id": "VyBNyzFVuqLQur70rY8brQ==", "updater": "debian/updater", "name": "CVE-2026-68444", "description": "In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() ffa_partition_info_get() passes uuid_str directly to uuid_parse() without a NULL check. When a caller passes NULL, uuid_parse() -\u003e __uuid_parse() -\u003e uuid_is_valid() dereferences the pointer, causing a kernel panic: | Unable to handle kernel NULL pointer dereference at virtual address | 0000000000000040 | pc : uuid_parse+0x40/0xac | lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa] Add a NULL guard before uuid_parse() so a NULL argument returns -ENODEV instead of crashing. Callers are expected to always supply a valid partition UUID, so NULL is not a supported input.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68444", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W0WBVJpOgKZPh97Vdqea9w==": { "id": "W0WBVJpOgKZPh97Vdqea9w==", "updater": "debian/updater", "name": "CVE-2023-53218", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Make it so that a waiting process can be aborted When sendmsg() creates an rxrpc call, it queues it to wait for a connection and channel to be assigned and then waits before it can start shovelling data as the encrypted DATA packet content includes a summary of the connection parameters. However, sendmsg() may get interrupted before a connection gets assigned and further sendmsg() calls will fail with EBUSY until an assignment is made. Fix this so that the call can at least be aborted without failing on EBUSY. We have to be careful here as sendmsg() mustn't be allowed to start the call timer if the call doesn't yet have a connection assigned as an oops may follow shortly thereafter.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53218", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W14SH0dlFhsWPGHnK1aCZw==": { "id": "W14SH0dlFhsWPGHnK1aCZw==", "updater": "debian/updater", "name": "CVE-2025-40065", "description": "In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Write hgatp register with valid mode bits According to the RISC-V Privileged Architecture Spec, when MODE=Bare is selected,software must write zero to the remaining fields of hgatp. We have detected the valid mode supported by the HW before, So using a valid mode to detect how many vmid bits are supported.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40065", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W68w9FNf3fclCbjmzX4UBw==": { "id": "W68w9FNf3fclCbjmzX4UBw==", "updater": "debian/updater", "name": "CVE-2025-40338", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing 'name' directly, tearing down components may lead to use-after-free errors. Duplicate the name to avoid that. At the same time, update the order of operations - since commit cee28113db17 (\"ASoC: dmaengine_pcm: Allow passing component name via config\") the framework does not override component-\u003ename if set before invoking the initializer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40338", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W7Ne/UdSHmg7xt0DK0wdtg==": { "id": "W7Ne/UdSHmg7xt0DK0wdtg==", "updater": "debian/updater", "name": "CVE-2026-32738", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32738", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "W8Jcu+Pl8GU+xmEpyPS4Rg==": { "id": "W8Jcu+Pl8GU+xmEpyPS4Rg==", "updater": "debian/updater", "name": "CVE-2023-53823", "description": "In the Linux kernel, the following vulnerability has been resolved: block/rq_qos: protect rq_qos apis with a new lock commit 50e34d78815e (\"block: disable the elevator int del_gendisk\") move rq_qos_exit() from disk_release() to del_gendisk(), this will introduce some problems: 1) If rq_qos_add() is triggered by enabling iocost/iolatency through cgroupfs, then it can concurrent with del_gendisk(), it's not safe to write 'q-\u003erq_qos' concurrently. 2) Activate cgroup policy that is relied on rq_qos will call rq_qos_add() and blkcg_activate_policy(), and if rq_qos_exit() is called in the middle, null-ptr-dereference will be triggered in blkcg_activate_policy(). 3) blkg_conf_open_bdev() can call blkdev_get_no_open() first to find the disk, then if rq_qos_exit() from del_gendisk() is done before rq_qos_add(), then memory will be leaked. This patch add a new disk level mutex 'rq_qos_mutex': 1) The lock will protect rq_qos_exit() directly. 2) For wbt that doesn't relied on blk-cgroup, rq_qos_add() can only be called from disk initialization for now because wbt can't be destructed until rq_qos_exit(), so it's safe not to protect wbt for now. Hoever, in case that rq_qos dynamically destruction is supported in the furture, this patch also protect rq_qos_add() from wbt_init() directly, this is enough because blk-sysfs already synchronize writers with disk removal. 3) For iocost and iolatency, in order to synchronize disk removal and cgroup configuration, the lock is held after blkdev_get_no_open() from blkg_conf_open_bdev(), and is released in blkg_conf_exit(). In order to fix the above memory leak, disk_live() is checked after holding the new lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53823", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WBKwh4EgcLSoFYU6H4fS+Q==": { "id": "WBKwh4EgcLSoFYU6H4fS+Q==", "updater": "debian/updater", "name": "CVE-2026-68123", "description": "In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)-\u003ecutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb-\u003elen, underflowing the length passed to skb_zerocopy(). Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68123", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WBns/fFatdGns4nV2QuIEQ==": { "id": "WBns/fFatdGns4nV2QuIEQ==", "updater": "debian/updater", "name": "CVE-2026-68326", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs to the event buffer mwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the (re)association request IEs that the firmware copies into the event: \tsinfo-\u003eassoc_req_ies = \u0026event-\u003edata[len]; \tlen = (u8 *)sinfo-\u003eassoc_req_ies - (u8 *)\u0026event-\u003eframe_control; \tsinfo-\u003eassoc_req_ies_len = le16_to_cpu(event-\u003elen) - (u16)len; event-\u003elen is supplied by the device firmware and is never validated, and the subtraction is unchecked. assoc_req_ies points into adapter-\u003eevent_body[MAX_EVENT_SIZE], a fixed-size array embedded in the kmalloc()'d struct mwifiex_adapter. On the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with cfg80211_find_ie(), whose for_each_element() loop dereferences each element header. A firmware-reported event-\u003elen larger than the bytes actually received makes assoc_req_ies_len describe IEs that extend past event_body, so the walk reads out of the adapter slab object, a slab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie). An event-\u003elen smaller than the header instead makes the int subtraction negative, which wraps to a huge size_t when stored in assoc_req_ies_len. The same length is handed to cfg80211_new_sta(), so a more modest over-claim can also copy stale event_body bytes into the NL80211_CMD_NEW_STATION notification. A malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver such an event while the interface is in AP/uAP mode. Validate event-\u003elen before use: reject a length that underflows the header or that would place the IEs outside the event_body[] buffer the event was copied into. event-\u003elen here is struct mwifiex_assoc_event.len, a payload field internal to this event, not the transport frame length, so it is validated in this handler rather than at the generic MWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the transport frame length. The bound is against event_body[MAX_EVENT_SIZE] rather than the actually-received length because the transports store the event differently (USB and SDIO leave the 4-byte event header in event_skb, PCIe strips it via skb_pull), whereas event_body is the single fixed buffer all of them copy the event into. This is the event-path analogue of the receive-path bounds checks added in commit 119585281617 (\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68326", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WDdht+QZQ3xI6LngG1n+jA==": { "id": "WDdht+QZQ3xI6LngG1n+jA==", "updater": "debian/updater", "name": "CVE-2024-38570", "description": "In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace. This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released. To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks. As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38570", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WIR2HdumojMDCSS6nHR6mg==": { "id": "WIR2HdumojMDCSS6nHR6mg==", "updater": "debian/updater", "name": "CVE-2025-38524", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and process it. Once the thread has picked up the call off of the queue, further events will cause it to be requeued, and once the socket lock is dropped (recvmsg uses call-\u003euser_mutex to allow the socket to be used in parallel), a second thread can come in and its recvmsg can pop the call off the socket queue again. In such a case, the first thread will be receiving stuff from the call and the second thread will be blocked on call-\u003euser_mutex. The first thread can, at this point, process both the event that it picked call for and the event that the second thread picked the call for and may see the call terminate - in which case the call will be \"released\", decoupling the call from the user call ID assigned to it (RXRPC_USER_CALL_ID in the control message). The first thread will return okay, but then the second thread will wake up holding the user_mutex and, if it sees that the call has been released by the first thread, it will BUG thusly: \tkernel BUG at net/rxrpc/recvmsg.c:474! Fix this by just dequeuing the call and ignoring it if it is seen to be already released. We can't tell userspace about it anyway as the user call ID has become stale.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38524", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WLEJTIMl3R9U+oSWIgIMrw==": { "id": "WLEJTIMl3R9U+oSWIgIMrw==", "updater": "debian/updater", "name": "CVE-2025-21949", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Set hugetlb mmap base address aligned with pmd size With ltp test case \"testcases/bin/hugefork02\", there is a dmesg error report message such as: kernel BUG at mm/hugetlb.c:5550! Oops - BUG[#1]: CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241 Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022 pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940 a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000 a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000 t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000 t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001 t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280 s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10 s5 900000010edbfb00 s6 00007ffff3474000 s7 0000000000000406 s8 900000010edbfa08 ra: 9000000000485538 unmap_vmas+0x130/0x218 ERA: 90000000004eaf1c __unmap_hugepage_range+0x6f4/0x7d0 PRMD: 00000004 (PPLV0 +PIE -PWE) EUEN: 00000007 (+FPE +SXE +ASXE -BTE) ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7) ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0) PRID: 0014c010 (Loongson-64bit, Loongson-3A5000) Process hugefork02 (pid: 1517, threadinfo=00000000a670eaf4, task=000000007a95fc64) Call Trace: [\u003c90000000004eaf1c\u003e] __unmap_hugepage_range+0x6f4/0x7d0 [\u003c9000000000485534\u003e] unmap_vmas+0x12c/0x218 [\u003c9000000000494068\u003e] exit_mmap+0xe0/0x308 [\u003c900000000025fdc4\u003e] mmput+0x74/0x180 [\u003c900000000026a284\u003e] do_exit+0x294/0x898 [\u003c900000000026aa30\u003e] do_group_exit+0x30/0x98 [\u003c900000000027bed4\u003e] get_signal+0x83c/0x868 [\u003c90000000002457b4\u003e] arch_do_signal_or_restart+0x54/0xfa0 [\u003c90000000015795e8\u003e] irqentry_exit_to_user_mode+0xb8/0x138 [\u003c90000000002572d0\u003e] tlb_do_page_fault_1+0x114/0x1b4 The problem is that base address allocated from hugetlbfs is not aligned with pmd size. Here add a checking for hugetlbfs and align base address with pmd size. After this patch the test case \"testcases/bin/hugefork02\" passes to run. This is similar to the commit 7f24cbc9c4d42db8a3c8484d1 (\"mm/mmap: teach generic_get_unmapped_area{_topdown} to handle hugetlb mappings\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21949", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WLUVqWxLwr0GY5Xim112wA==": { "id": "WLUVqWxLwr0GY5Xim112wA==", "updater": "debian/updater", "name": "CVE-2025-68378", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check in __bpf_get_stackid() Syzkaller reported a KASAN slab-out-of-bounds write in __bpf_get_stackid() when copying stack trace data. The issue occurs when the perf trace contains more stack entries than the stack map bucket can hold, leading to an out-of-bounds write in the bucket's data array.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68378", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WLo5mNz+nRD5O8r0IuqS6A==": { "id": "WLo5mNz+nRD5O8r0IuqS6A==", "updater": "debian/updater", "name": "CVE-2026-52991", "description": "In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressure write and cgroup file release regarding the priv member of struct kernfs_open_file, which triggers the uaf reported in [1]. Consider the following scenario involving execution on two separate CPUs: CPU0\t\t\t\t\tCPU1 ====\t\t\t\t\t==== \t\t\t\t\tvfs_rmdir() \t\t\t\t\tkernfs_iop_rmdir() \t\t\t\t\tcgroup_rmdir() \t\t\t\t\tcgroup_kn_lock_live() \t\t\t\t\tcgroup_destroy_locked() \t\t\t\t\tcgroup_addrm_files() \t\t\t\t\tcgroup_rm_file() \t\t\t\t\tkernfs_remove_by_name() \t\t\t\t\tkernfs_remove_by_name_ns() vfs_write()\t\t\t\t__kernfs_remove() new_sync_write()\t\t\tkernfs_drain() kernfs_fop_write_iter()\t\tkernfs_drain_open_files() cgroup_file_write()\t\t\tkernfs_release_file() pressure_write()\t\t\tcgroup_file_release() ctx = of-\u003epriv; \t\t\t\t\tkfree(ctx); \t\t\t\t\tof-\u003epriv = NULL; \t\t\t\t\tcgroup_kn_unlock() cgroup_kn_lock_live() cgroup_get(cgrp) cgroup_kn_unlock() if (ctx-\u003epsi.trigger) // here, trigger uaf for ctx, that is of-\u003epriv The cgroup_rmdir() is protected by the cgroup_mutex, it also safeguards the memory deallocation of of-\u003epriv performed within cgroup_file_release(). However, the operations involving of-\u003epriv executed within pressure_write() are not entirely covered by the protection of cgroup_mutex. Consequently, if the code in pressure_write(), specifically the section handling the ctx variable executes after cgroup_file_release() has completed, a uaf vulnerability involving of-\u003epriv is triggered. Therefore, the issue can be resolved by extending the scope of the cgroup_mutex lock within pressure_write() to encompass all code paths involving of-\u003epriv, thereby properly synchronizing the race condition occurring between cgroup_file_release() and pressure_write(). And, if an live kn lock can be successfully acquired while executing the pressure write operation, it indicates that the cgroup deletion process has not yet reached its final stage; consequently, the priv pointer within open_file cannot be NULL. Therefore, the operation to retrieve the ctx value must be moved to a point *after* the live kn lock has been successfully acquired. In another situation, specifically after entering cgroup_kn_lock_live() but before acquiring cgroup_mutex, there exists a different class of race condition: CPU0: write memory.pressure CPU1: write cgroup.pressure=0 ===========================\t\t ============================= kernfs_fop_write_iter() kernfs_get_active_of(of) pressure_write() cgroup_kn_lock_live(memory.pressure) cgroup_tryget(cgrp) kernfs_break_active_protection(kn) ... blocks on cgroup_mutex \t cgroup_pressure_write() \t cgroup_kn_lock_live(cgroup.pressure) \t cgroup_file_show(memory.pressure, false) \t kernfs_show(false) \t kernfs_drain_open_files() \t cgroup_file_release(of) \t kfree(ctx) \t of-\u003epriv = NULL \t cgroup_kn_unlock() ... acquires cgroup_mutex ctx = of-\u003epriv; // may now be NULL if (ctx-\u003epsi.trigger) // NULL dereference Consequently, there is a possibility that of-\u003epriv is NULL, the pressure write needs to check for this. Now that the scope of the cgroup_mutex has been expanded, the original explicit cgroup_get/put operations are no longer necessary, this is because acquiring/releasing the live kn lock inherently executes a cgroup get/put operation. [1] BUG: KASAN: slab-use-after-free in pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011 Call Trace: pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011 cgroup_file_write+0x36f/0x790 kernel/cgroup/cgroup.c:43 ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52991", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WQgTTwn+g6RZhl4VVAGeqQ==": { "id": "WQgTTwn+g6RZhl4VVAGeqQ==", "updater": "debian/updater", "name": "CVE-2018-1121", "description": "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-1121", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WR/jw4xeHrK73fGOrvF1KA==": { "id": "WR/jw4xeHrK73fGOrvF1KA==", "updater": "debian/updater", "name": "CVE-2026-14664", "description": "Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14664", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WSHmH2/QOPqnJ/tYpBj0sA==": { "id": "WSHmH2/QOPqnJ/tYpBj0sA==", "updater": "debian/updater", "name": "CVE-2026-48029", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-48029", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wc+Cv0UbBgGLpFfKGy+CJQ==": { "id": "Wc+Cv0UbBgGLpFfKGy+CJQ==", "updater": "debian/updater", "name": "CVE-2026-43016", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: Fix use-after-free of sk-\u003esk_socket in sk_psock_verdict_data_ready(). syzbot reported use-after-free of AF_UNIX socket's sk-\u003esk_socket in sk_psock_verdict_data_ready(). [0] In unix_stream_sendmsg(), the peer socket's -\u003esk_data_ready() is called after dropping its unix_state_lock(). Although the sender socket holds the peer's refcount, it does not prevent the peer's sock_orphan(), and the peer's sk_socket might be freed after one RCU grace period. Let's fetch the peer's sk-\u003esk_socket and sk-\u003esk_socket-\u003eops under RCU in sk_psock_verdict_data_ready(). [0]: BUG: KASAN: slab-use-after-free in sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278 Read of size 8 at addr ffff8880594da860 by task syz.4.1842/11013 CPU: 1 UID: 0 PID: 11013 Comm: syz.4.1842 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026 Call Trace: \u003cTASK\u003e dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xba/0x230 mm/kasan/report.c:482 kasan_report+0x117/0x150 mm/kasan/report.c:595 sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278 unix_stream_sendmsg+0x8a3/0xe80 net/unix/af_unix.c:2482 sock_sendmsg_nosec net/socket.c:721 [inline] __sock_sendmsg net/socket.c:736 [inline] ____sys_sendmsg+0x972/0x9f0 net/socket.c:2585 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2639 __sys_sendmsg net/socket.c:2671 [inline] __do_sys_sendmsg net/socket.c:2676 [inline] __se_sys_sendmsg net/socket.c:2674 [inline] __x64_sys_sendmsg+0x1bd/0x2a0 net/socket.c:2674 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7facf899c819 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007facf9827028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007facf8c15fa0 RCX: 00007facf899c819 RDX: 0000000000000000 RSI: 0000200000000500 RDI: 0000000000000004 RBP: 00007facf8a32c91 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007facf8c16038 R14: 00007facf8c15fa0 R15: 00007ffd41b01c78 \u003c/TASK\u003e Allocated by task 11013: kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 unpoison_slab_object mm/kasan/common.c:340 [inline] __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366 kasan_slab_alloc include/linux/kasan.h:253 [inline] slab_post_alloc_hook mm/slub.c:4538 [inline] slab_alloc_node mm/slub.c:4866 [inline] kmem_cache_alloc_lru_noprof+0x2b8/0x640 mm/slub.c:4885 sock_alloc_inode+0x28/0xc0 net/socket.c:316 alloc_inode+0x6a/0x1b0 fs/inode.c:347 new_inode_pseudo include/linux/fs.h:3003 [inline] sock_alloc net/socket.c:631 [inline] __sock_create+0x12d/0x9d0 net/socket.c:1562 sock_create net/socket.c:1656 [inline] __sys_socketpair+0x1c4/0x560 net/socket.c:1803 __do_sys_socketpair net/socket.c:1856 [inline] __se_sys_socketpair net/socket.c:1853 [inline] __x64_sys_socketpair+0x9b/0xb0 net/socket.c:1853 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 15: kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 [inline] __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 [inline] slab_free_hook mm/slub.c:2685 [inline] slab_free mm/slub.c:6165 [inline] kmem_cache_free+0x187/0x630 mm/slub.c:6295 rcu_do_batch kernel/rcu/tree.c: ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43016", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wl81NablfKtwVAL4vOotQg==": { "id": "Wl81NablfKtwVAL4vOotQg==", "updater": "debian/updater", "name": "CVE-2024-25269", "description": "libheif \u003c= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-25269", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WmdYA4n7cWm+dw3CSnfVKw==": { "id": "WmdYA4n7cWm+dw3CSnfVKw==", "updater": "debian/updater", "name": "CVE-2026-23239", "description": "In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the espintcp_tx_work() worker may dereference a freed espintcp ctx or sk. The following is a simple race scenario: cpu0 cpu1 espintcp_close() cancel_work_sync(\u0026ctx-\u003ework); espintcp_write_space() schedule_work(\u0026ctx-\u003ework); To prevent this race condition, cancel_work_sync() is replaced with disable_work_sync().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23239", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WxIKMZNzfMhN/POQQ+P6fQ==": { "id": "WxIKMZNzfMhN/POQQ+P6fQ==", "updater": "debian/updater", "name": "CVE-2025-21972", "description": "In the Linux kernel, the following vulnerability has been resolved: net: mctp: unshare packets when reassembling Ensure that the frag_list used for reassembly isn't shared with other packets. This avoids incorrect reassembly when packets are cloned, and prevents a memory leak due to circular references between fragments and their skb_shared_info. The upcoming MCTP-over-USB driver uses skb_clone which can trigger the problem - other MCTP drivers don't share SKBs. A kunit test is added to reproduce the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21972", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Wytddh4/grdOMQGfYqgKuw==": { "id": "Wytddh4/grdOMQGfYqgKuw==", "updater": "debian/updater", "name": "CVE-2026-68188", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc-\u003esession without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session-\u003einitiator and session-\u003esock. Meanwhile, krfcommd can unlink the DLC and free the session while holding rfcomm_mutex. The race can proceed as follows: TTY ioctl task krfcommd -------------- -------- load dlc-\u003esession enter rfcomm_send_rpn() lock rfcomm_mutex clear dlc-\u003esession free session unlock rfcomm_mutex read session-\u003einitiator KASAN reported: BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0 Read of size 4 at addr ffff88810012a850 by task poc/92 Call Trace: rfcomm_send_rpn+0x297/0x2a0 rfcomm_tty_set_termios+0x50d/0x850 tty_set_termios+0x596/0x950 set_termios+0x46a/0x6e0 tty_mode_ioctl+0x152/0xbd0 tty_ioctl+0x915/0x1240 __x64_sys_ioctl+0x134/0x1c0 Allocated by task 92: rfcomm_session_add+0x9e/0x2e0 rfcomm_dlc_open+0x8b1/0xe00 rfcomm_dev_activate+0x85/0x1a0 rfcomm_tty_open+0x90/0x280 Freed by task 68: kfree+0x131/0x3c0 rfcomm_session_del+0x119/0x180 rfcomm_run+0x737/0x4710 Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies that the DLC is still attached and sends the RPN frame. Have the TTY path use the helper and drop its unlocked session check. This keeps the session valid through both the frame construction and socket send.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68188", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "WzuogyQu2dsLRYZjLeTWhA==": { "id": "WzuogyQu2dsLRYZjLeTWhA==", "updater": "debian/updater", "name": "CVE-2025-71202", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kernel address space Introduce a new IOMMU interface to flush IOTLB paging cache entries for the CPU kernel address space. This interface is invoked from the x86 architecture code that manages combined user and kernel page tables, specifically before any kernel page table page is freed and reused. This addresses the main issue with vfree() which is a common occurrence and can be triggered by unprivileged users. While this resolves the primary problem, it doesn't address some extremely rare case related to memory unplug of memory that was present as reserved memory at boot, which cannot be triggered by unprivileged users. The discussion can be found at the link below. Enable SVA on x86 architecture since the IOMMU can now receive notification to flush the paging cache before freeing the CPU kernel page table pages.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71202", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X+KWCuGLzTBeWttwniMBuA==": { "id": "X+KWCuGLzTBeWttwniMBuA==", "updater": "debian/updater", "name": "CVE-2024-24864", "description": "A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-24864", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X/bHAQhdCYw9YE9271HYiQ==": { "id": "X/bHAQhdCYw9YE9271HYiQ==", "updater": "debian/updater", "name": "CVE-2024-41031", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/filemap: skip to create PMD-sized page cache if needed On ARM64, HPAGE_PMD_ORDER is 13 when the base page size is 64KB. The PMD-sized page cache can't be supported by xarray as the following error messages indicate. ------------[ cut here ]------------ WARNING: CPU: 35 PID: 7484 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\ nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\ nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\ ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm \\ fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 \\ sha1_ce virtio_net net_failover virtio_console virtio_blk failover \\ dimlib virtio_mmio CPU: 35 PID: 7484 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xas_split_alloc+0xf8/0x128 lr : split_huge_page_to_list_to_order+0x1c4/0x720 sp : ffff800087a4f6c0 x29: ffff800087a4f6c0 x28: ffff800087a4f720 x27: 000000001fffffff x26: 0000000000000c40 x25: 000000000000000d x24: ffff00010625b858 x23: ffff800087a4f720 x22: ffffffdfc0780000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0780000 x18: 000000001ff40000 x17: 00000000ffffffff x16: 0000018000000000 x15: 51ec004000000000 x14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020 x11: 51ec000000000000 x10: 51ece1c0ffff8000 x9 : ffffbeb961a44d28 x8 : 0000000000000003 x7 : ffffffdfc0456420 x6 : ffff0000e1aa6eb8 x5 : 20bf08b4fe778fca x4 : ffffffdfc0456420 x3 : 0000000000000c40 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace: xas_split_alloc+0xf8/0x128 split_huge_page_to_list_to_order+0x1c4/0x720 truncate_inode_partial_folio+0xdc/0x160 truncate_inode_pages_range+0x1b4/0x4a8 truncate_pagecache_range+0x84/0xa0 xfs_flush_unmap_range+0x70/0x90 [xfs] xfs_file_fallocate+0xfc/0x4d8 [xfs] vfs_fallocate+0x124/0x2e8 ksys_fallocate+0x4c/0xa0 __arm64_sys_fallocate+0x24/0x38 invoke_syscall.constprop.0+0x7c/0xd8 do_el0_svc+0xb4/0xd0 el0_svc+0x44/0x1d8 el0t_64_sync_handler+0x134/0x150 el0t_64_sync+0x17c/0x180 Fix it by skipping to allocate PMD-sized page cache when its size is larger than MAX_PAGECACHE_ORDER. For this specific case, we will fall to regular path where the readahead window is determined by BDI's sysfs file (read_ahead_kb).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41031", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X2bZcXn+gYKr8UlsiAMsIQ==": { "id": "X2bZcXn+gYKr8UlsiAMsIQ==", "updater": "debian/updater", "name": "CVE-2025-40247", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix pgtable prealloc error path The following splat was reported: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=00000008d0fd8000 [0000000000000010] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000096000004 [#1] SMP CPU: 5 UID: 1000 PID: 149076 Comm: Xwayland Tainted: G S 6.16.0-rc2-00809-g0b6974bb4134-dirty #367 PREEMPT Tainted: [S]=CPU_OUT_OF_SPEC Hardware name: Qualcomm Technologies, Inc. SM8650 HDK (DT) pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : build_detached_freelist+0x28/0x224 lr : kmem_cache_free_bulk.part.0+0x38/0x244 sp : ffff000a508c7a20 x29: ffff000a508c7a20 x28: ffff000a508c7d50 x27: ffffc4e49d16f350 x26: 0000000000000058 x25: 00000000fffffffc x24: 0000000000000000 x23: ffff00098c4e1450 x22: 00000000fffffffc x21: 0000000000000000 x20: ffff000a508c7af8 x19: 0000000000000002 x18: 00000000000003e8 x17: ffff000809523850 x16: ffff000809523820 x15: 0000000000401640 x14: ffff000809371140 x13: 0000000000000130 x12: ffff0008b5711e30 x11: 00000000001058fa x10: 0000000000000a80 x9 : ffff000a508c7940 x8 : ffff000809371ba0 x7 : 781fffe033087fff x6 : 0000000000000000 x5 : ffff0008003cd000 x4 : 781fffe033083fff x3 : ffff000a508c7af8 x2 : fffffdffc0000000 x1 : 0001000000000000 x0 : ffff0008001a6a00 Call trace: build_detached_freelist+0x28/0x224 (P) kmem_cache_free_bulk.part.0+0x38/0x244 kmem_cache_free_bulk+0x10/0x1c msm_iommu_pagetable_prealloc_cleanup+0x3c/0xd0 msm_vma_job_free+0x30/0x240 msm_ioctl_vm_bind+0x1d0/0x9a0 drm_ioctl_kernel+0x84/0x104 drm_ioctl+0x358/0x4d4 __arm64_sys_ioctl+0x8c/0xe0 invoke_syscall+0x44/0x100 el0_svc_common.constprop.0+0x3c/0xe0 do_el0_svc+0x18/0x20 el0_svc+0x30/0x100 el0t_64_sync_handler+0x104/0x130 el0t_64_sync+0x170/0x174 Code: aa0203f5 b26287e2 f2dfbfe2 aa0303f4 (f8737ab6) ---[ end trace 0000000000000000 ]--- Since msm_vma_job_free() is called directly from the ioctl, this looks like an error path cleanup issue. Which I think results from prealloc_cleanup() called without a preceding successful prealloc_allocate() call. So handle that case better. Patchwork: https://patchwork.freedesktop.org/patch/678677/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40247", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X2d9l5X1xLpQwAiEXTTewg==": { "id": "X2d9l5X1xLpQwAiEXTTewg==", "updater": "debian/updater", "name": "CVE-2026-3276", "description": "unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3276", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X3TrrLKAzF8VT/gBWvF08A==": { "id": "X3TrrLKAzF8VT/gBWvF08A==", "updater": "debian/updater", "name": "CVE-2026-68403", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: initialize SDIO data work before cleanup brcmf_sdio_probe() stores the newly allocated bus in sdiodev-\u003ebus before allocating the ordered workqueue. If that allocation fails, the function jumps to fail and calls brcmf_sdio_remove(). brcmf_sdio_remove() unconditionally cancels bus-\u003edatawork. Initialize the work item before the first failure path that can reach brcmf_sdio_remove(), so the cleanup path always observes a valid work object. This issue was found by our static analysis tool and then confirmed by manual review of the probe error path and the remove-time work drain. The problem pattern is an early setup failure that reaches a cleanup helper which cancels an embedded work item before its initializer has run. A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in brcmf_sdio_probe(), before INIT_WORK(\u0026bus-\u003edatawork) is reached. The resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in the stack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68403", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X5btFWIXIO7Mm8lNAKiCFw==": { "id": "X5btFWIXIO7Mm8lNAKiCFw==", "updater": "debian/updater", "name": "CVE-2026-68192", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempotent brcmf_pcie_release_scratchbuffers() frees the shared.scratch and shared.ringupd DMA buffers with dma_free_coherent() but does not clear the pointers afterwards, unlike the sibling release_ringbuffers() which NULLs commonrings/flowrings/idxbuf on release. Both the bus_reset .reset callback (brcmf_pcie_reset) and brcmf_pcie_remove() call release_scratchbuffers. When reset teardown has run before removal, remove's own teardown would call dma_free_coherent() a second time on the already-freed DMA allocation. NULL the pointers after free, matching release_ringbuffers(), so a later release observes that the allocation has already been released. This patch makes repeated sequential release safe; the reset-work lifetime is handled separately by the following patch. This issue was found by an in-house static analysis tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68192", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "X8WzV6hUi6GZYWa/shwqXg==": { "id": "X8WzV6hUi6GZYWa/shwqXg==", "updater": "debian/updater", "name": "CVE-2025-1151", "description": "A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1151", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XEO2N+fKL88Nc+lWd2zGlQ==": { "id": "XEO2N+fKL88Nc+lWd2zGlQ==", "updater": "debian/updater", "name": "CVE-2026-46200", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix controller deregistration Make sure to deregister the controller before disabling and releasing underlying resources like interrupts and gpios during driver unbind.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46200", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XG93vQK96jZKCPLypcOiZQ==": { "id": "XG93vQK96jZKCPLypcOiZQ==", "updater": "debian/updater", "name": "CVE-2026-43198", "description": "In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet-\u003epinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43198", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XHFgJNEJIiIPE15DtoD2KQ==": { "id": "XHFgJNEJIiIPE15DtoD2KQ==", "updater": "debian/updater", "name": "CVE-2026-14673", "description": "Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14673", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XKgaiu1TTiF94OEf06hPHQ==": { "id": "XKgaiu1TTiF94OEf06hPHQ==", "updater": "debian/updater", "name": "CVE-2024-58053", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix handling of received connection abort Fix the handling of a connection abort that we've received. Though the abort is at the connection level, it needs propagating to the calls on that connection. Whilst the propagation bit is performed, the calls aren't then woken up to go and process their termination, and as no further input is forthcoming, they just hang. Also add some tracing for the logging of connection aborts.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58053", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XNkZz0xHBwW067x0zzkuWg==": { "id": "XNkZz0xHBwW067x0zzkuWg==", "updater": "debian/updater", "name": "CVE-2026-68417", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: publish QP after initialization siw_create_qp() currently calls siw_qp_add() before the queues, CQ pointers, state, completion, and device list entry are ready. A QPN lookup can therefore reach a QP that is still being constructed. Move siw_qp_add() to the end of siw_create_qp(), after QP initialization and before adding the QP to the siw device list.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68417", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XUbU+UOP9MU55829zWk52w==": { "id": "XUbU+UOP9MU55829zWk52w==", "updater": "debian/updater", "name": "CVE-2025-40266", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40266", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XUdSfenojPgi0C3JLdCmEg==": { "id": "XUdSfenojPgi0C3JLdCmEg==", "updater": "debian/updater", "name": "CVE-2024-35808", "description": "In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b (\"md: refactor idle/frozen_sync_thread() to fix deadlock\"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35808", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XVEm+2KqBXTjMkwVXx4JzQ==": { "id": "XVEm+2KqBXTjMkwVXx4JzQ==", "updater": "debian/updater", "name": "CVE-2024-35946", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix null pointer access when abort scan During cancel scan we might use vif that weren't scanning. Fix this by using the actual scanning vif.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35946", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XYrWNG/ZD9L4k6Jv7ONGBA==": { "id": "XYrWNG/ZD9L4k6Jv7ONGBA==", "updater": "debian/updater", "name": "CVE-2025-40325", "description": "In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning a discard bio which has REQ_NOWAIT. And there is no need to print warning calltrace if a discard bio has REQ_NOWAIT flag. Quality engineer usually checks dmesg and reports error if dmesg has warning/error calltrace.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40325", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XaThmJAaKtpx8Mjg3OXeEg==": { "id": "XaThmJAaKtpx8Mjg3OXeEg==", "updater": "debian/updater", "name": "CVE-2025-68745", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f (\"scsi: qla2xxx: target: Fix offline port handling and host reset handling\") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd-\u003esg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a (\"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert \"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\" and partially revert \"scsi: qla2xxx: target: Fix offline port handling and host reset handling\" at __qla2x00_abort_all_cmds.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68745", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Xe5HZ8wO+kGA+Q95DAIHAw==": { "id": "Xe5HZ8wO+kGA+Q95DAIHAw==", "updater": "debian/updater", "name": "CVE-2026-68412", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() If the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks. Use the existing error handling path to fix it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68412", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XeDhNbWrPP/57TKkZGU/9w==": { "id": "XeDhNbWrPP/57TKkZGU/9w==", "updater": "debian/updater", "name": "CVE-2026-68395", "description": "In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler. If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm. Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68395", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XiJI8JQ+WXVm0Ec9LMZ3JA==": { "id": "XiJI8JQ+WXVm0Ec9LMZ3JA==", "updater": "debian/updater", "name": "CVE-2025-38038", "description": "In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost set_boost is a per-policy function call, hence a driver wide lock is unnecessary. Also this mutex_acquire can collide with the mutex_acquire from the mode-switch path in status_store(), which can lead to a deadlock. So, remove it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38038", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XkqmUhavZ8Tr7Mrbp/rI0w==": { "id": "XkqmUhavZ8Tr7Mrbp/rI0w==", "updater": "debian/updater", "name": "CVE-2026-6429", "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6429", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XlpyvWfZ026/hB+1UCTGeA==": { "id": "XlpyvWfZ026/hB+1UCTGeA==", "updater": "debian/updater", "name": "CVE-2023-53762", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync Use-after-free can occur in hci_disconnect_all_sync if a connection is deleted by concurrent processing of a controller event. To prevent this the code now tries to iterate over the list backwards to ensure the links are cleanup before its parents, also it no longer relies on a cursor, instead it always uses the last element since hci_abort_conn_sync is guaranteed to call hci_conn_del. UAF crash log: ================================================================== BUG: KASAN: slab-use-after-free in hci_set_powered_sync (net/bluetooth/hci_sync.c:5424) [bluetooth] Read of size 8 at addr ffff888009d9c000 by task kworker/u9:0/124 CPU: 0 PID: 124 Comm: kworker/u9:0 Tainted: G W 6.5.0-rc1+ #10 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-1.fc38 04/01/2014 Workqueue: hci0 hci_cmd_sync_work [bluetooth] Call Trace: \u003cTASK\u003e dump_stack_lvl+0x5b/0x90 print_report+0xcf/0x670 ? __virt_addr_valid+0xdd/0x160 ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth] kasan_report+0xa6/0xe0 ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth] ? __pfx_set_powered_sync+0x10/0x10 [bluetooth] hci_set_powered_sync+0x2c9/0x4a0 [bluetooth] ? __pfx_hci_set_powered_sync+0x10/0x10 [bluetooth] ? __pfx_lock_release+0x10/0x10 ? __pfx_set_powered_sync+0x10/0x10 [bluetooth] hci_cmd_sync_work+0x137/0x220 [bluetooth] process_one_work+0x526/0x9d0 ? __pfx_process_one_work+0x10/0x10 ? __pfx_do_raw_spin_lock+0x10/0x10 ? mark_held_locks+0x1a/0x90 worker_thread+0x92/0x630 ? __pfx_worker_thread+0x10/0x10 kthread+0x196/0x1e0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x2c/0x50 \u003c/TASK\u003e Allocated by task 1782: kasan_save_stack+0x33/0x60 kasan_set_track+0x25/0x30 __kasan_kmalloc+0x8f/0xa0 hci_conn_add+0xa5/0xa80 [bluetooth] hci_bind_cis+0x881/0x9b0 [bluetooth] iso_connect_cis+0x121/0x520 [bluetooth] iso_sock_connect+0x3f6/0x790 [bluetooth] __sys_connect+0x109/0x130 __x64_sys_connect+0x40/0x50 do_syscall_64+0x60/0x90 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Freed by task 695: kasan_save_stack+0x33/0x60 kasan_set_track+0x25/0x30 kasan_save_free_info+0x2b/0x50 __kasan_slab_free+0x10a/0x180 __kmem_cache_free+0x14d/0x2e0 device_release+0x5d/0xf0 kobject_put+0xdf/0x270 hci_disconn_complete_evt+0x274/0x3a0 [bluetooth] hci_event_packet+0x579/0x7e0 [bluetooth] hci_rx_work+0x287/0xaa0 [bluetooth] process_one_work+0x526/0x9d0 worker_thread+0x92/0x630 kthread+0x196/0x1e0 ret_from_fork+0x2c/0x50 ==================================================================", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53762", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Xo30MVWPbFyt6A6zkqyXXw==": { "id": "Xo30MVWPbFyt6A6zkqyXXw==", "updater": "debian/updater", "name": "CVE-2026-12064", "description": "When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-12064", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XoEp9DT2Gi2ed605R4lXUQ==": { "id": "XoEp9DT2Gi2ed605R4lXUQ==", "updater": "debian/updater", "name": "CVE-2026-64109", "description": "In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail-\u003elen in unix_stream_data_wait() unix_stream_data_wait() does skb_peek_tail(\u0026sk-\u003esk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea (\"unix/stream: fix peeking with an offset larger than data in queue\"). The first consequence of this is that the pointer comparison `tail != last` can be false even if `last` semantically refers to an already-freed SKB while `tail` is a new SKB allocated at the same address; which can cause unix_stream_data_wait() to wrongly keep blocking after new data has arrived, but only in a weird scenario where a peeking recv() and a normal recv() on the same socket are racing, which is probably not a real problem. But since commit 2b514574f7e8 (\"net: af_unix: implement splice for stream af_unix sockets\"), `tail` is actually dereferenced, which can cause UAF in the following race scenario (where test_setup() runs single-threaded, and afterwards, test_thread1() and test_thread2() run concurrently in two threads: ``` static int socks[2]; void test_setup(void) { socketpair(AF_UNIX, SOCK_STREAM, 0, socks); send(socks[1], \"A\", 1, 0); int peekoff = 1; setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, \u0026peekoff, sizeof(peekoff)); } void test_thread1(void) { char dummy; recv(socks[0], \u0026dummy, 1, MSG_PEEK); } void test_thread2(void) { char dummy; recv(socks[0], \u0026dummy, 1, 0); shutdown(socks[1], SHUT_WR); } ``` when racing like this: ``` thread1 thread2 unix_stream_read_generic mutex_lock(\u0026u-\u003eiolock) skb_peek(\u0026sk-\u003esk_receive_queue) skb_peek_next(skb, \u0026sk-\u003esk_receive_queue) mutex_unlock(\u0026u-\u003eiolock) unix_stream_read_generic unix_state_lock(sk) skb_peek(\u0026sk-\u003esk_receive_queue) unix_state_unlock(sk) unix_stream_data_wait unix_state_lock(sk) tail = skb_peek_tail(\u0026sk-\u003esk_receive_queue) spin_lock(\u0026sk-\u003esk_receive_queue.lock) __skb_unlink(skb, \u0026sk-\u003esk_receive_queue) spin_unlock(\u0026sk-\u003esk_receive_queue.lock) consume_skb(skb) [frees the SKB] `tail != last`: false `tail`: true `tail-\u003elen != last_len` ***UAF*** ``` Fix the UAF by removing the read of tail-\u003elen; checking tail-\u003elen would only make sense if SKBs in the receive queue of a UNIX socket could grow, which can no longer happen. Kuniyuki explained: \u003e When commit 869e7c62486e (\"net: af_unix: implement stream sendpage \u003e support\") added sendpage() support, data could be appended to the last \u003e skb in the receiver's queue. \u003e \u003e That's why we needed to check if the length of the last skb was changed \u003e while waiting for new data in unix_stream_data_wait(). \u003e \u003e However, commit a0dbf5f818f9 (\"af_unix: Support MSG_SPLICE_PAGES\") and \u003e commit 57d44a354a43 (\"unix: Convert unix_stream_sendpage() to use \u003e MSG_SPLICE_PAGES\") refactored sendmsg(), and now data is always added \u003e to a new skb. That means this fix is not suitable for kernels before 6.5.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64109", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XvR107GSrc+xeR3HWE/qEg==": { "id": "XvR107GSrc+xeR3HWE/qEg==", "updater": "debian/updater", "name": "CVE-2025-21976", "description": "In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebuffer When a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to release the framebuffer forcefully. If this framebuffer is in use it produce the following WARN and hence this framebuffer is never released. [ 44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40 \u003c snip \u003e [ 44.111289] Call Trace: [ 44.111290] \u003cTASK\u003e [ 44.111291] ? show_regs+0x6c/0x80 [ 44.111295] ? __warn+0x8d/0x150 [ 44.111298] ? framebuffer_release+0x2c/0x40 [ 44.111300] ? report_bug+0x182/0x1b0 [ 44.111303] ? handle_bug+0x6e/0xb0 [ 44.111306] ? exc_invalid_op+0x18/0x80 [ 44.111308] ? asm_exc_invalid_op+0x1b/0x20 [ 44.111311] ? framebuffer_release+0x2c/0x40 [ 44.111313] ? hvfb_remove+0x86/0xa0 [hyperv_fb] [ 44.111315] vmbus_remove+0x24/0x40 [hv_vmbus] [ 44.111323] device_remove+0x40/0x80 [ 44.111325] device_release_driver_internal+0x20b/0x270 [ 44.111327] ? bus_find_device+0xb3/0xf0 Fix this by moving the release of framebuffer and assosiated memory to fb_ops.fb_destroy function, so that framebuffer framework handles it gracefully. While we fix this, also replace manual registrations/unregistration of framebuffer with devm_register_framebuffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21976", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XvaFhekmoVjuOn94KgTfyA==": { "id": "XvaFhekmoVjuOn94KgTfyA==", "updater": "debian/updater", "name": "CVE-2024-25740", "description": "A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj-\u003ename is not released.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-25740", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Xvvhh6iAcEx/QtBYxuBfzw==": { "id": "Xvvhh6iAcEx/QtBYxuBfzw==", "updater": "debian/updater", "name": "CVE-2024-46728", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check index for aux_rd_interval before using aux_rd_interval has size of 7 and should be checked. This fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46728", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "XwcGNCaKGppyE8H0de1PKQ==": { "id": "XwcGNCaKGppyE8H0de1PKQ==", "updater": "debian/updater", "name": "CVE-2024-50057", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Free IRQ only if it was requested before In polling mode, if no IRQ was requested there is no need to free it. Call devm_free_irq() only if client-\u003eirq is set. This fixes the warning caused by the tps6598x module removal: WARNING: CPU: 2 PID: 333 at kernel/irq/devres.c:144 devm_free_irq+0x80/0x8c ... ... Call trace: devm_free_irq+0x80/0x8c tps6598x_remove+0x28/0x88 [tps6598x] i2c_device_remove+0x2c/0x9c device_remove+0x4c/0x80 device_release_driver_internal+0x1cc/0x228 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 i2c_del_driver+0x54/0x64 tps6598x_i2c_driver_exit+0x18/0xc3c [tps6598x] __arm64_sys_delete_module+0x184/0x264 invoke_syscall+0x48/0x110 el0_svc_common.constprop.0+0xc8/0xe8 do_el0_svc+0x20/0x2c el0_svc+0x28/0x98 el0t_64_sync_handler+0x13c/0x158 el0t_64_sync+0x190/0x194", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50057", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Y6U2P92fk05LBVYfzYisoQ==": { "id": "Y6U2P92fk05LBVYfzYisoQ==", "updater": "debian/updater", "name": "CVE-2026-64565", "description": "In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pcu_process_data()` processes incoming URB data byte by byte. However, it fails to check if the `read_pos` index exceeds IMS_PCU_BUF_SIZE. If a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE, `read_pos` will increment indefinitely. Moreover, since `read_pos` is located immediately after `read_buf`, the attacker can overwrite `read_pos` itself to arbitrarily control the index. This manipulated `read_pos` is subsequently used in `ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a heap buffer overflow. Specifically, an attacker can overwrite the `cmd_done.wait.head` located at offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`. Consequently, when the driver calls `complete(\u0026pcu-\u003ecmd_done)`, it triggers a control flow hijack by using the manipulated pointer. Fix this by adding a bounds check for `read_pos` before writing to `read_buf`. If the packet is too long, discard it, log a warning, and reset the parser state. [dtor: factor out resetting packet state, reset checksum as well]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64565", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YA+baRm92vzKN9/R841SNw==": { "id": "YA+baRm92vzKN9/R841SNw==", "updater": "debian/updater", "name": "CVE-2014-9900", "description": "The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2014-9900", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YBoIkY5E236Ku4x1vswMrQ==": { "id": "YBoIkY5E236Ku4x1vswMrQ==", "updater": "debian/updater", "name": "CVE-2026-68235", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: dce100: skip non-DP stream encoders for DP MST On DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital DIG stream encoders plus one analog DAC encoder. When assigning a stream encoder for a second DisplayPort MST stream, if the preferred digital encoder is already acquired, dce100_find_first_free_match_stream_enc_for_link() falls back to the first free pool entry. That entry may be the analog encoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute. The subsequent atomic commit then dereferences NULL function pointers in link_set_dpms_on() and crashes. Skip encoders without dp_set_stream_attribute when the stream uses a DP signal (including MST). Use dc_is_dp_signal(stream-\u003esignal) for the MST fallback path instead of checking only the link connector signal. Tested on: - GPU: AMD Radeon R7 260X (Bonaire / DCE8) - Board: Supermicro C9X299-PG300 - Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot - Kernel: 7.1.3 (issue observed since 6.19) - Result: kernel oops without patch; dual monitors stable with patch (cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68235", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YF8OfaM1DSxNuPCgGIsTTQ==": { "id": "YF8OfaM1DSxNuPCgGIsTTQ==", "updater": "debian/updater", "name": "CVE-2026-47709", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe \u0026\u0026 uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-47709", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YIFdVIZNby7xlEcg9enH4A==": { "id": "YIFdVIZNby7xlEcg9enH4A==", "updater": "debian/updater", "name": "CVE-2025-11414", "description": "A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11414", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YJVyMngySk6wihPKJdBk/Q==": { "id": "YJVyMngySk6wihPKJdBk/Q==", "updater": "debian/updater", "name": "CVE-2026-45901", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: revert commit_mutex usage in reset path It causes circular lock dependency between commit_mutex, nfnl_subsys_ipset and nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m set' rule run at the same time. Previous patches made it safe to run individual reset handlers concurrently so commit_mutex is no longer required to prevent this.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45901", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YLkLxk5BFdJfmAIDIUmvjQ==": { "id": "YLkLxk5BFdJfmAIDIUmvjQ==", "updater": "debian/updater", "name": "CVE-2026-68108", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calculated buffer size to 0. This bypasses validation and allows GPU firmware to perform out-of-bound memory access. The fix uses 64-bit arithmetic to detect overflow and rejects invalid dimensions before they reach the hardware. V2: remove redundant check V3: modify max height value V4: remove size64 (cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68108", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YOjM5JcoxOtI+tIAYob+AA==": { "id": "YOjM5JcoxOtI+tIAYob+AA==", "updater": "debian/updater", "name": "CVE-2024-26757", "description": "In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore read-only array in md_check_recovery() Usually if the array is not read-write, md_check_recovery() won't register new sync_thread in the first place. And if the array is read-write and sync_thread is registered, md_set_readonly() will unregister sync_thread before setting the array read-only. md/raid follow this behavior hence there is no problem. After commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following hang can be triggered by test shell/integrity-caching.sh: 1) array is read-only. dm-raid update super block: rs_update_sbs ro = mddev-\u003ero mddev-\u003ero = 0 -\u003e set array read-write md_update_sb 2) register new sync thread concurrently. 3) dm-raid set array back to read-only: rs_update_sbs mddev-\u003ero = ro 4) stop the array: raid_dtr md_stop stop_sync_thread set_bit(MD_RECOVERY_INTR, \u0026mddev-\u003erecovery); md_wakeup_thread_directly(mddev-\u003esync_thread); wait_event(..., !test_bit(MD_RECOVERY_RUNNING, \u0026mddev-\u003erecovery)) 5) sync thread done: md_do_sync set_bit(MD_RECOVERY_DONE, \u0026mddev-\u003erecovery); md_wakeup_thread(mddev-\u003ethread); 6) daemon thread can't unregister sync thread: md_check_recovery if (!md_is_rdwr(mddev) \u0026\u0026 !test_bit(MD_RECOVERY_NEEDED, \u0026mddev-\u003erecovery)) return; -\u003e -\u003e MD_RECOVERY_RUNNING can't be cleared, hence step 4 hang; The root cause is that dm-raid manipulate 'mddev-\u003ero' by itself, however, dm-raid really should stop sync thread before setting the array read-only. Unfortunately, I need to read more code before I can refacter the handler of 'mddev-\u003ero' in dm-raid, hence let's fix the problem the easy way for now to prevent dm-raid regression.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26757", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YPFxAW99VI7nQ5swWF2Nqg==": { "id": "YPFxAW99VI7nQ5swWF2Nqg==", "updater": "debian/updater", "name": "CVE-2025-39952", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: avoid buffer overflow in WID string configuration Fix the following copy overflow warning identified by Smatch checker. drivers/net/wireless/microchip/wilc1000/wlan_cfg.c:184 wilc_wlan_parse_response_frame() error: '__memcpy()' 'cfg-\u003es[i]-\u003estr' copy overflow (512 vs 65537) This patch introduces size check before accessing the memory buffer. The checks are base on the WID type of received data from the firmware. For WID string configuration, the size limit is determined by individual element size in 'struct wilc_cfg_str_vals' that is maintained in 'len' field of 'struct wilc_cfg_str'.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39952", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YRihAPX9XQJbgbq8IV5qyQ==": { "id": "YRihAPX9XQJbgbq8IV5qyQ==", "updater": "debian/updater", "name": "CVE-2026-41080", "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41080", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YW3HoFXarBLE8Jq3Htt1wg==": { "id": "YW3HoFXarBLE8Jq3Htt1wg==", "updater": "debian/updater", "name": "CVE-2024-42128", "description": "In the Linux kernel, the following vulnerability has been resolved: leds: an30259a: Use devm_mutex_init() for mutex initialization In this driver LEDs are registered using devm_led_classdev_register() so they are automatically unregistered after module's remove() is done. led_classdev_unregister() calls module's led_set_brightness() to turn off the LEDs and that callback uses mutex which was destroyed already in module's remove() so use devm API instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42128", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YcAav/frJZCC7Lw5hP+MjA==": { "id": "YcAav/frJZCC7Lw5hP+MjA==", "updater": "debian/updater", "name": "CVE-2024-53178", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: Don't leak cfid when reconnect races with open_cached_dir open_cached_dir() may either race with the tcon reconnection even before compound_send_recv() or directly trigger a reconnection via SMB2_open_init() or SMB_query_info_init(). The reconnection process invokes invalidate_all_cached_dirs() via cifs_mark_open_files_invalid(), which removes all cfids from the cfids-\u003eentries list but doesn't drop a ref if has_lease isn't true. This results in the currently-being-constructed cfid not being on the list, but still having a refcount of 2. It leaks if returned from open_cached_dir(). Fix this by setting cfid-\u003ehas_lease when the ref is actually taken; the cfid will not be used by other threads until it has a valid time. Addresses these kmemleaks: unreferenced object 0xffff8881090c4000 (size 1024): comm \"bash\", pid 1860, jiffies 4295126592 hex dump (first 32 bytes): 00 01 00 00 00 00 ad de 22 01 00 00 00 00 ad de ........\"....... 00 ca 45 22 81 88 ff ff f8 dc 4f 04 81 88 ff ff ..E\"......O..... backtrace (crc 6f58c20f): [\u003cffffffff8b895a1e\u003e] __kmalloc_cache_noprof+0x2be/0x350 [\u003cffffffff8bda06e3\u003e] open_cached_dir+0x993/0x1fb0 [\u003cffffffff8bdaa750\u003e] cifs_readdir+0x15a0/0x1d50 [\u003cffffffff8b9a853f\u003e] iterate_dir+0x28f/0x4b0 [\u003cffffffff8b9a9aed\u003e] __x64_sys_getdents64+0xfd/0x200 [\u003cffffffff8cf6da05\u003e] do_syscall_64+0x95/0x1a0 [\u003cffffffff8d00012f\u003e] entry_SYSCALL_64_after_hwframe+0x76/0x7e unreferenced object 0xffff8881044fdcf8 (size 8): comm \"bash\", pid 1860, jiffies 4295126592 hex dump (first 8 bytes): 00 cc cc cc cc cc cc cc ........ backtrace (crc 10c106a9): [\u003cffffffff8b89a3d3\u003e] __kmalloc_node_track_caller_noprof+0x363/0x480 [\u003cffffffff8b7d7256\u003e] kstrdup+0x36/0x60 [\u003cffffffff8bda0700\u003e] open_cached_dir+0x9b0/0x1fb0 [\u003cffffffff8bdaa750\u003e] cifs_readdir+0x15a0/0x1d50 [\u003cffffffff8b9a853f\u003e] iterate_dir+0x28f/0x4b0 [\u003cffffffff8b9a9aed\u003e] __x64_sys_getdents64+0xfd/0x200 [\u003cffffffff8cf6da05\u003e] do_syscall_64+0x95/0x1a0 [\u003cffffffff8d00012f\u003e] entry_SYSCALL_64_after_hwframe+0x76/0x7e And addresses these BUG splats when unmounting the SMB filesystem: BUG: Dentry ffff888140590ba0{i=1000000000080,n=/} still in use (2) [unmount of cifs cifs] WARNING: CPU: 3 PID: 3433 at fs/dcache.c:1536 umount_check+0xd0/0x100 Modules linked in: CPU: 3 UID: 0 PID: 3433 Comm: bash Not tainted 6.12.0-rc4-g850925a8133c-dirty #49 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 RIP: 0010:umount_check+0xd0/0x100 Code: 8d 7c 24 40 e8 31 5a f4 ff 49 8b 54 24 40 41 56 49 89 e9 45 89 e8 48 89 d9 41 57 48 89 de 48 c7 c7 80 e7 db ac e8 f0 72 9a ff \u003c0f\u003e 0b 58 31 c0 5a 5b 5d 41 5c 41 5d 41 5e 41 5f e9 2b e5 5d 01 41 RSP: 0018:ffff88811cc27978 EFLAGS: 00010286 RAX: 0000000000000000 RBX: ffff888140590ba0 RCX: ffffffffaaf20bae RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff8881f6fb6f40 RBP: ffff8881462ec000 R08: 0000000000000001 R09: ffffed1023984ee3 R10: ffff88811cc2771f R11: 00000000016cfcc0 R12: ffff888134383e08 R13: 0000000000000002 R14: ffff8881462ec668 R15: ffffffffaceab4c0 FS: 00007f23bfa98740(0000) GS:ffff8881f6f80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000556de4a6f808 CR3: 0000000123c80000 CR4: 0000000000350ef0 Call Trace: \u003cTASK\u003e d_walk+0x6a/0x530 shrink_dcache_for_umount+0x6a/0x200 generic_shutdown_super+0x52/0x2a0 kill_anon_super+0x22/0x40 cifs_kill_sb+0x159/0x1e0 deactivate_locked_super+0x66/0xe0 cleanup_mnt+0x140/0x210 task_work_run+0xfb/0x170 syscall_exit_to_user_mode+0x29f/0x2b0 do_syscall_64+0xa1/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f23bfb93ae7 Code: ff ff ff ff c3 66 0f 1f 44 00 00 48 8b 0d 11 93 0d 00 f7 d8 64 89 01 b8 ff ff ff ff eb bf 0f 1f 44 00 00 b8 50 00 00 00 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 8b 0d e9 92 0d 00 f7 d8 64 89 ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53178", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YclsiNNGEgEj+fczIqUMpQ==": { "id": "YclsiNNGEgEj+fczIqUMpQ==", "updater": "debian/updater", "name": "CVE-2024-53095", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and some pods mount CIFS servers in non-root network namespaces. The problem rarely happened, but it was always while the pod was dying. The root cause is wrong reference counting for network namespace. CIFS uses kernel sockets, which do not hold refcnt of the netns that the socket belongs to. That means CIFS must ensure the socket is always freed before its netns; otherwise, use-after-free happens. The repro steps are roughly: 1. mount CIFS in a non-root netns 2. drop packets from the netns 3. destroy the netns 4. unmount CIFS We can reproduce the issue quickly with the script [1] below and see the splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled. When the socket is TCP, it is hard to guarantee the netns lifetime without holding refcnt due to async timers. Let's hold netns refcnt for each socket as done for SMC in commit 9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\"). Note that we need to move put_net() from cifs_put_tcp_session() to clean_demultiplex_info(); otherwise, __sock_create() still could touch a freed netns while cifsd tries to reconnect from cifs_demultiplex_thread(). Also, maybe_get_net() cannot be put just before __sock_create() because the code is not under RCU and there is a small chance that the same address happened to be reallocated to another netns. [0]: CIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting... CIFS: Serverclose failed 4 times, giving up Unable to handle kernel paging request at virtual address 14de99e461f84a07 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004 CM = 0, WnR = 0 [14de99e461f84a07] address between user and kernel address ranges Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs CPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1 Hardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018 pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : fib_rules_lookup+0x44/0x238 lr : __fib_lookup+0x64/0xbc sp : ffff8000265db790 x29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01 x26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580 x23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500 x20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000 x14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002 x11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294 x8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000 x5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0 x2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500 Call trace: fib_rules_lookup+0x44/0x238 __fib_lookup+0x64/0xbc ip_route_output_key_hash_rcu+0x2c4/0x398 ip_route_output_key_hash+0x60/0x8c tcp_v4_connect+0x290/0x488 __inet_stream_connect+0x108/0x3d0 inet_stream_connect+0x50/0x78 kernel_connect+0x6c/0xac generic_ip_conne ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53095", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YlR3u9lZW61NKtn5JlnTOg==": { "id": "YlR3u9lZW61NKtn5JlnTOg==", "updater": "debian/updater", "name": "CVE-2025-37952", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks on fp-\u003erefcount are not sufficient to prevent this. The fix takes ft-\u003elock around the section which removes the file from the file table. This prevents two threads acquiring the same file pointer via __close_file_table_ids, as well as the other functions which retrieve a file from the IDR and which already use this same lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37952", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YpBqEuxGaKPIJ0A0P+PjUA==": { "id": "YpBqEuxGaKPIJ0A0P+PjUA==", "updater": "debian/updater", "name": "CVE-2026-31536", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set. If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31536", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yq6/Z75fMM5cPYk+D+3Seg==": { "id": "Yq6/Z75fMM5cPYk+D+3Seg==", "updater": "debian/updater", "name": "CVE-2014-9892", "description": "The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28770164 and Qualcomm internal bug CR568717.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2014-9892", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yq9nncpzUr5K0tgMiAx0rw==": { "id": "Yq9nncpzUr5K0tgMiAx0rw==", "updater": "debian/updater", "name": "CVE-2026-33164", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-33164", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YsKorYDNSlb87ZdIS9kUjQ==": { "id": "YsKorYDNSlb87ZdIS9kUjQ==", "updater": "debian/updater", "name": "CVE-2026-58012", "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58012", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YsKt/LrIX7tM5qDp7LRtvA==": { "id": "YsKt/LrIX7tM5qDp7LRtvA==", "updater": "debian/updater", "name": "CVE-2026-68398", "description": "In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path: l2tp_udp_encap_recv() -\u003e l2tp_recv_common() -\u003e pppol2tp_recv() -\u003e ppp_input(\u0026po-\u003echan) It runs under rcu_read_lock() holding only an l2tp_session reference and takes NO reference on the internal PPP channel (struct channel, chan-\u003eppp) that ppp_input() dereferences. The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel are RCU-safe. But the internal struct channel is a separate allocation that ppp_release_channel() frees with a plain kfree(): close(data socket) -\u003e pppol2tp_release() -\u003e pppox_unbind_sock() -\u003e ppp_unregister_channel() -\u003e ppp_release_channel() -\u003e kfree(pch) For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit (no PPPIOCCONNECT, pch-\u003eppp == NULL) and not bridged, teardown skips both ppp_disconnect_channel()'s synchronize_net() and ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace period. rcu_read_lock() in pppol2tp_recv() does not protect against a plain kfree(), so an in-flight ppp_input() on one CPU can dereference the channel just freed by close() on another CPU. The bug is reachable by an unprivileged user. Defer the channel free to an RCU callback via call_rcu() so the grace period fences any in-flight ppp_input(). The disconnect and unbridge teardown paths already fence with synchronize_net()/synchronize_rcu(); call_rcu() does the same here without stalling the close() path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68398", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YsLoHuuQxyXnuNuD6BKbDg==": { "id": "YsLoHuuQxyXnuNuD6BKbDg==", "updater": "debian/updater", "name": "CVE-2005-0406", "description": "A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2005-0406", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YtV7YaLA+7ggXlLHn+OtFQ==": { "id": "YtV7YaLA+7ggXlLHn+OtFQ==", "updater": "debian/updater", "name": "CVE-2026-43088", "description": "In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY exports PF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr payload space, so IPv6 addresses occupy 32 bytes on the wire. However, `pfkey_sockaddr_fill()` initializes only the first 28 bytes of `struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized. Not every PF_KEY message is affected. The state and policy dump builders already zero the whole message buffer before filling the sockaddr payloads. Keep the fix to the export paths that still append aligned sockaddr payloads with plain `skb_put()`: - `SADB_ACQUIRE` - `SADB_X_NAT_T_NEW_MAPPING` - `SADB_X_MIGRATE` Fix those paths by clearing only the aligned sockaddr tail after `pfkey_sockaddr_fill()`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43088", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yv1KmLtUeUjnUz35el07pg==": { "id": "Yv1KmLtUeUjnUz35el07pg==", "updater": "debian/updater", "name": "CVE-2026-43091", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit xfrm_policy_fini() frees the policy_bydst hash tables after flushing the policy work items and deleting all policies, but it does not wait for concurrent RCU readers to leave their read-side critical sections first. The policy_bydst tables are published via rcu_assign_pointer() and are looked up through rcu_dereference_check(), so netns teardown must also wait for an RCU grace period before freeing the table memory. Fix this by adding synchronize_rcu() before freeing the policy hash tables.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43091", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YwhOz+GeBIjFXWub1Yuf1Q==": { "id": "YwhOz+GeBIjFXWub1Yuf1Q==", "updater": "debian/updater", "name": "CVE-2025-40268", "description": "In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsconfig twice, but when the program exits, free() only frees ctx-\u003esource for the second fsconfig, not the first. Regarding fc-\u003esource, there is no code in the fs context related to its memory reclamation. To fix this memory leak, release the source memory corresponding to ctx or fc before each parsing. syzbot reported: BUG: memory leak unreferenced object 0xffff888128afa360 (size 96): backtrace (crc 79c9c7ba): kstrdup+0x3c/0x80 mm/util.c:84 smb3_fs_context_parse_param+0x229b/0x36c0 fs/smb/client/fs_context.c:1444 BUG: memory leak unreferenced object 0xffff888112c7d900 (size 96): backtrace (crc 79c9c7ba): smb3_fs_context_fullpath+0x70/0x1b0 fs/smb/client/fs_context.c:629 smb3_fs_context_parse_param+0x2266/0x36c0 fs/smb/client/fs_context.c:1438", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40268", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Yx94fa+iH+REwbi33a8p6w==": { "id": "Yx94fa+iH+REwbi33a8p6w==", "updater": "debian/updater", "name": "CVE-2025-68342", "description": "In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data The URB received in gs_usb_receive_bulk_callback() contains a struct gs_host_frame. The length of the data after the header depends on the gs_host_frame hf::flags and the active device features (e.g. time stamping). Introduce a new function gs_usb_get_minimum_length() and check that we have at least received the required amount of data before accessing it. Only copy the data to that skb that has actually been received. [mkl: rename gs_usb_get_minimum_length() -\u003e +gs_usb_get_minimum_rx_length()]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68342", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "YxXrYo+Tio3tXdc6Irqxxg==": { "id": "YxXrYo+Tio3tXdc6Irqxxg==", "updater": "debian/updater", "name": "CVE-2026-68350", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix OOB read from off-by-two in TX status handler The bounds check in carl9170_tx_process_status() uses `i \u003e ((cmd-\u003ehdr.len / 2) + 1)` which is off by two, allowing 2 extra iterations past valid _tx_status entries when the firmware- controlled hdr.ext exceeds hdr.len/2. Fix by using the correct comparison `i \u003e= (cmd-\u003ehdr.len / 2)`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68350", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z2k8gTGRE3tRnaa6C7ph1Q==": { "id": "Z2k8gTGRE3tRnaa6C7ph1Q==", "updater": "debian/updater", "name": "CVE-2025-38283", "description": "In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: bugfix live migration function without VF device driver If the VF device driver is not loaded in the Guest OS and we attempt to perform device data migration, the address of the migrated data will be NULL. The live migration recovery operation on the destination side will access a null address value, which will cause access errors. Therefore, live migration of VMs without added VF device drivers does not require device data migration. In addition, when the queue address data obtained by the destination is empty, device queue recovery processing will not be performed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38283", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z3tjpgDGCLjk3Ec4HecEQQ==": { "id": "Z3tjpgDGCLjk3Ec4HecEQQ==", "updater": "debian/updater", "name": "CVE-2026-40244", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc-\u003ewidth * curc-\u003eheight` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1722`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-40244", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z70NNghfj3CUDoF3RSOhtA==": { "id": "Z70NNghfj3CUDoF3RSOhtA==", "updater": "debian/updater", "name": "CVE-2026-52961", "description": "In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here ]------------ [40243.605956] kernel BUG at fs/ceph/xattr.c:918! [40243.607142] Oops: invalid opcode: 0000 [#1] SMP PTI [40243.608067] CPU: 7 UID: 0 PID: 498762 Comm: kworker/7:1 Not tainted 7.0.0-rc7+ #3 PREEMPT(full) [40243.609700] Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [40243.611820] Workqueue: ceph-msgr ceph_con_workfn [40243.612715] RIP: 0010:__ceph_build_xattrs_blob+0x1b8/0x1e0 [40243.613731] Code: 0f 84 82 fe ff ff e9 cf 8e 56 ff 48 8d 65 e8 31 c0 5b 41 5c 41 5d 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 c3 cc cc cc cc \u003c0f\u003e 0b 4c 8b 62 08 41 8b 85 24 07 00 00 49 83 c4 04 41 89 44 24 fc [40243.616888] RSP: 0018:ffffcc80c4d4b688 EFLAGS: 00010287 [40243.617773] RAX: 0000000000010026 RBX: 0000000000000001 RCX: 0000000000000000 [40243.618928] RDX: ffff8a773798dee0 RSI: 0000000000000000 RDI: 0000000000000000 [40243.620158] RBP: ffffcc80c4d4b6a0 R08: 0000000000000000 R09: 0000000000000000 [40243.621573] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a75f3b58000 [40243.622907] R13: ffff8a75f3b58000 R14: 0000000000000080 R15: 000000000000bffd [40243.624054] FS: 0000000000000000(0000) GS:ffff8a787d1b4000(0000) knlGS:0000000000000000 [40243.625331] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [40243.626269] CR2: 000072f390b623c0 CR3: 000000011c02a003 CR4: 0000000000372ef0 [40243.627408] Call Trace: [40243.627839] \u003cTASK\u003e [40243.628188] __prep_cap+0x3fd/0x4a0 [40243.628789] ? do_raw_spin_unlock+0x4e/0xe0 [40243.629474] ceph_check_caps+0x46a/0xc80 [40243.630094] ? __lock_acquire+0x4a2/0x2650 [40243.630773] ? find_held_lock+0x31/0x90 [40243.631347] ? handle_cap_grant+0x79f/0x1060 [40243.632068] ? lock_release+0xd9/0x300 [40243.632696] ? __mutex_unlock_slowpath+0x3e/0x340 [40243.633429] ? lock_release+0xd9/0x300 [40243.634052] handle_cap_grant+0xcf6/0x1060 [40243.634745] ceph_handle_caps+0x122b/0x2110 [40243.635415] mds_dispatch+0x5bd/0x2160 [40243.636034] ? ceph_con_process_message+0x65/0x190 [40243.636828] ? lock_release+0xd9/0x300 [40243.637431] ceph_con_process_message+0x7a/0x190 [40243.638184] ? kfree+0x311/0x4f0 [40243.638749] ? kfree+0x311/0x4f0 [40243.639268] process_message+0x16/0x1a0 [40243.639915] ? sg_free_table+0x39/0x90 [40243.640572] ceph_con_v2_try_read+0xf58/0x2120 [40243.641255] ? lock_acquire+0xc8/0x300 [40243.641863] ceph_con_workfn+0x151/0x820 [40243.642493] process_one_work+0x22f/0x630 [40243.643093] ? process_one_work+0x254/0x630 [40243.643770] worker_thread+0x1e2/0x400 [40243.644332] ? __pfx_worker_thread+0x10/0x10 [40243.645020] kthread+0x109/0x140 [40243.645560] ? __pfx_kthread+0x10/0x10 [40243.646125] ret_from_fork+0x3f8/0x480 [40243.646752] ? __pfx_kthread+0x10/0x10 [40243.647316] ? __pfx_kthread+0x10/0x10 [40243.647919] ret_from_fork_asm+0x1a/0x30 [40243.648556] \u003c/TASK\u003e [40243.648902] Modules linked in: overlay hctr2 libpolyval chacha libchacha adiantum libnh libpoly1305 essiv intel_rapl_msr intel_rapl_common intel_uncore_frequency_common skx_edac_common nfit kvm_intel kvm irqbypass joydev ghash_clmulni_intel aesni_intel rapl input_leds mac_hid psmouse vga16fb serio_raw vgastate floppy i2c_piix4 pata_acpi bochs qemu_fw_cfg i2c_smbus sch_fq_codel rbd dm_crypt msr parport_pc ppdev lp parport efi_pstore [40243.654766] ---[ end trace 0000000000000000 ]--- Commit d93231a6bc8a (\"ceph: prevent a client from exceeding the MDS maximum xattr size\") moved the required_blob_size computation to before the __build_xattrs() call, introducing a race. __build_xattrs() releases and reacquires i_ceph_lock during execution. In that window, handle_cap_grant() may update i_xattrs.blob with a newer MDS-provided blob and bump i_xattrs.version. When __bui ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z7Zr+aJtnT0rPmKmG4faFw==": { "id": "Z7Zr+aJtnT0rPmKmG4faFw==", "updater": "debian/updater", "name": "CVE-2022-0400", "description": "An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-0400", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z7jfyTdh0hmn3U15zwBAjA==": { "id": "Z7jfyTdh0hmn3U15zwBAjA==", "updater": "debian/updater", "name": "CVE-2005-3660", "description": "Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to finish the transfer by causing the process to become a zombie, or closing the file descriptor without closing an associated reference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2005-3660", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Z7pBeVnuOVlWlFYmFAqamg==": { "id": "Z7pBeVnuOVlWlFYmFAqamg==", "updater": "debian/updater", "name": "CVE-2026-58472", "description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58472", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZCSymtjadlzkXt8CU3F6PA==": { "id": "ZCSymtjadlzkXt8CU3F6PA==", "updater": "debian/updater", "name": "CVE-2026-43318", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify Invalidating a dmabuf will impact other users of the shared BO. In the scenario where process A moves the BO, it needs to inform process B about the move and process B will need to update its page table. The commit fixes a synchronisation bug caused by the use of the ticket: it made amdgpu_vm_handle_moved behave as if updating the page table immediately was correct but in this case it's not. An example is the following scenario, with 2 GPUs and glxgears running on GPU0 and Xorg running on GPU1, on a system where P2P PCI isn't supported: glxgears: export linear buffer from GPU0 and import using GPU1 submit frame rendering to GPU0 submit tiled-\u003elinear blit Xorg: copy of linear buffer The sequence of jobs would be: drm_sched_job_run # GPU0, frame rendering drm_sched_job_queue # GPU0, blit drm_sched_job_done # GPU0, frame rendering drm_sched_job_run # GPU0, blit move linear buffer for GPU1 access # amdgpu_dma_buf_move_notify -\u003e update pt # GPU0 It this point the blit job on GPU0 is still running and would likely produce a page fault.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43318", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZOcBwbKbAM2xtrg277utCw==": { "id": "ZOcBwbKbAM2xtrg277utCw==", "updater": "debian/updater", "name": "CVE-2025-10966", "description": "curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-10966", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZQePqlHHBA7+hwLcam9ocg==": { "id": "ZQePqlHHBA7+hwLcam9ocg==", "updater": "debian/updater", "name": "CVE-2026-44169", "description": "MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-44169", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "mariadb", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZS/gWXbJFn17w55K8PlyRQ==": { "id": "ZS/gWXbJFn17w55K8PlyRQ==", "updater": "debian/updater", "name": "CVE-2026-56131", "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56131", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZSjR/M5ho85GTX2Ee3cGUw==": { "id": "ZSjR/M5ho85GTX2Ee3cGUw==", "updater": "debian/updater", "name": "CVE-2024-26799", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix uninitialized pointer dmactl In the case where __lpass_get_dmactl_handle is called and the driver id dai_id is invalid the pointer dmactl is not being assigned a value, and dmactl contains a garbage value since it has not been initialized and so the null check may not work. Fix this to initialize dmactl to NULL. One could argue that modern compilers will set this to zero, but it is useful to keep this initialized as per the same way in functions __lpass_platform_codec_intf_init and lpass_cdc_dma_daiops_hw_params. Cleans up clang scan build warning: sound/soc/qcom/lpass-cdc-dma.c:275:7: warning: Branch condition evaluates to a garbage value [core.uninitialized.Branch]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26799", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZT6BPilZ5dCEdgXwljpiUg==": { "id": "ZT6BPilZ5dCEdgXwljpiUg==", "updater": "debian/updater", "name": "CVE-2026-68359", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after \"io start\" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68359", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZdJ0aFtVMyqkCxjnG6Hd6w==": { "id": "ZdJ0aFtVMyqkCxjnG6Hd6w==", "updater": "debian/updater", "name": "CVE-2026-68257", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68257", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Zgn/UYJKK4iGOPjyGoKbxg==": { "id": "Zgn/UYJKK4iGOPjyGoKbxg==", "updater": "debian/updater", "name": "TEMP-0601525-BEBB65", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0601525-BEBB65", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libwmf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "Zj7vExxsRx/s2nS5nq7feA==": { "id": "Zj7vExxsRx/s2nS5nq7feA==", "updater": "debian/updater", "name": "CVE-2024-50211", "description": "In the Linux kernel, the following vulnerability has been resolved: udf: refactor inode_bmap() to handle error Refactor inode_bmap() to handle error since udf_next_aext() can return error now. On situations like ftruncate, udf_extend_file() can now detect errors and bail out early without resorting to checking for particular offsets and assuming internal behavior of these functions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50211", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZjN/tXLqyGqAzL0qaRbOdQ==": { "id": "ZjN/tXLqyGqAzL0qaRbOdQ==", "updater": "debian/updater", "name": "CVE-2026-14678", "description": "Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14678", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZkKRW+GbeCTumpVfOln0tw==": { "id": "ZkKRW+GbeCTumpVfOln0tw==", "updater": "debian/updater", "name": "CVE-2026-23214", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: reject new transactions if the fs is fully read-only [BUG] There is a bug report where a heavily fuzzed fs is mounted with all rescue mount options, which leads to the following warnings during unmount: BTRFS: Transaction aborted (error -22) Modules linked in: CPU: 0 UID: 0 PID: 9758 Comm: repro.out Not tainted 6.19.0-rc5-00002-gb71e635feefc #7 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:find_free_extent_update_loop fs/btrfs/extent-tree.c:4208 [inline] RIP: 0010:find_free_extent+0x52f0/0x5d20 fs/btrfs/extent-tree.c:4611 Call Trace: \u003cTASK\u003e btrfs_reserve_extent+0x2cd/0x790 fs/btrfs/extent-tree.c:4705 btrfs_alloc_tree_block+0x1e1/0x10e0 fs/btrfs/extent-tree.c:5157 btrfs_force_cow_block+0x578/0x2410 fs/btrfs/ctree.c:517 btrfs_cow_block+0x3c4/0xa80 fs/btrfs/ctree.c:708 btrfs_search_slot+0xcad/0x2b50 fs/btrfs/ctree.c:2130 btrfs_truncate_inode_items+0x45d/0x2350 fs/btrfs/inode-item.c:499 btrfs_evict_inode+0x923/0xe70 fs/btrfs/inode.c:5628 evict+0x5f4/0xae0 fs/inode.c:837 __dentry_kill+0x209/0x660 fs/dcache.c:670 finish_dput+0xc9/0x480 fs/dcache.c:879 shrink_dcache_for_umount+0xa0/0x170 fs/dcache.c:1661 generic_shutdown_super+0x67/0x2c0 fs/super.c:621 kill_anon_super+0x3b/0x70 fs/super.c:1289 btrfs_kill_super+0x41/0x50 fs/btrfs/super.c:2127 deactivate_locked_super+0xbc/0x130 fs/super.c:474 cleanup_mnt+0x425/0x4c0 fs/namespace.c:1318 task_work_run+0x1d4/0x260 kernel/task_work.c:233 exit_task_work include/linux/task_work.h:40 [inline] do_exit+0x694/0x22f0 kernel/exit.c:971 do_group_exit+0x21c/0x2d0 kernel/exit.c:1112 __do_sys_exit_group kernel/exit.c:1123 [inline] __se_sys_exit_group kernel/exit.c:1121 [inline] __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1121 x64_sys_call+0x2210/0x2210 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe8/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x44f639 Code: Unable to access opcode bytes at 0x44f60f. RSP: 002b:00007ffc15c4e088 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7 RAX: ffffffffffffffda RBX: 00000000004c32f0 RCX: 000000000044f639 RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000001 RBP: 0000000000000001 R08: ffffffffffffffc0 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00000000004c32f0 R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000001 \u003c/TASK\u003e Since rescue mount options will mark the full fs read-only, there should be no new transaction triggered. But during unmount we will evict all inodes, which can trigger a new transaction, and triggers warnings on a heavily corrupted fs. [CAUSE] Btrfs allows new transaction even on a read-only fs, this is to allow log replay happen even on read-only mounts, just like what ext4/xfs do. However with rescue mount options, the fs is fully read-only and cannot be remounted read-write, thus in that case we should also reject any new transactions. [FIX] If we find the fs has rescue mount options, we should treat the fs as error, so that no new transaction can be started.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23214", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZmoBlar9F3NrT8PTSCXqLw==": { "id": "ZmoBlar9F3NrT8PTSCXqLw==", "updater": "debian/updater", "name": "CVE-2026-18477", "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18477", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZpA8oyPAdi7/RehnLZhJwQ==": { "id": "ZpA8oyPAdi7/RehnLZhJwQ==", "updater": "debian/updater", "name": "CVE-2026-68141", "description": "In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC. If the allocation fails, nsk is NULL. The connection-refused path is entered when the listen state check fails, the accept backlog is full, or nsk is NULL. The code unconditionally calls iucv_sock_kill(nsk) in that path. iucv_sock_kill() does not accept a NULL socket pointer and immediately dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL, calling iucv_sock_kill(nsk) results in a NULL pointer dereference. Only call iucv_sock_kill() when a child socket was successfully allocated.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68141", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZwjT/nBmdsy72TmavWU8dw==": { "id": "ZwjT/nBmdsy72TmavWU8dw==", "updater": "debian/updater", "name": "CVE-2024-46860", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change When disabling wifi mt7921_ipv6_addr_change() is called as a notifier. At this point mvif-\u003ephy is already NULL so we cannot use it here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46860", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ZxpziBdNrTlF9WyPF0vZ+A==": { "id": "ZxpziBdNrTlF9WyPF0vZ+A==", "updater": "debian/updater", "name": "CVE-2026-68160", "description": "In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_handle_caps() reads snap_trace_len from the wire-format ceph_mds_caps header and uses it unconditionally to build a fake end pointer (snaptrace + snaptrace_len) that is later handed to ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case: snaptrace = h + 1; snaptrace_len = le32_to_cpu(h-\u003esnap_trace_len); p = snaptrace + snaptrace_len; ... case CEPH_CAP_OP_IMPORT: if (snaptrace_len) { ... if (ceph_update_snap_trace(mdsc, snaptrace, snaptrace + snaptrace_len, false, \u0026realm)) { ... } ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm from snaptrace using ceph_decode_need(\u0026p, e, sizeof(*ri), bad) with the attacker-supplied fake end e == snaptrace + snaptrace_len. With snaptrace_len == 0xFFFFFFFF the bound check is trivially satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past the legitimate msg-\u003efront buffer, and ri-\u003enum_snaps / ri-\u003enum_prior_parent_snaps then drive further out-of-bounds reads of the encoded snap arrays. The eleven msg_version \u003e= 2 .. msg_version \u003e= 12 decoder blocks above the op switch each catch this OOB through their ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit behind a hdr.version-gated if, so a malicious or compromised MDS that sets msg-\u003ehdr.version = 1 reaches the IMPORT path with no version-gated decoder having validated snap_trace_len. The shape has been present since ceph_handle_caps() was introduced. Validate snap_trace_len against the message front buffer before consuming it, using the canonical ceph_decode_need() / ceph_has_room() helper. The helper bounds the length with subtraction (n \u003c= end - p, guarded by end \u003e= p) rather than pointer addition, so it is wrap-safe for the attacker-controlled u32 length on 32-bit builds where p + snap_trace_len could overflow the address space. This matches the rest of the ceph decode path (e.g. the pool_ns_len check a few lines below), and the existing goto bad cleanup already covers this exit path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68160", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a+8diPCjyw/R86R6KSI0bw==": { "id": "a+8diPCjyw/R86R6KSI0bw==", "updater": "debian/updater", "name": "CVE-2026-64508", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space within those allocations as programs are loaded and freed. When fresh code is written into space that a previous program occupied, an indirect jump into the new program can reuse a branch prediction left behind by the old one. Flush the indirect branch predictors before reusing JIT memory so that indirect jumps into a newly written program don't reuse predictions from an old program that occupied the same space. Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for flushing the branch predictors on JIT memory reuse. Architectures that need a flush, can update it to a predictor flush function. By default, its a NOP and does not emit any CALL. Allocations larger than a pack are not covered by this flush. That is safe because cBPF programs (the unprivileged attack surface) are bounded well below a pack size. Issue a warning if this assumption is ever violated while the flush is active.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64508", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "a/h8Yn1UYQgMp+F/8tbQPw==": { "id": "a/h8Yn1UYQgMp+F/8tbQPw==", "updater": "debian/updater", "name": "CVE-2025-40289", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM Otherwise accessing them can cause a crash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40289", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aAqnKFLRNriCGQlG3eKWDg==": { "id": "aAqnKFLRNriCGQlG3eKWDg==", "updater": "debian/updater", "name": "CVE-2024-38594", "description": "In the Linux kernel, the following vulnerability has been resolved: net: stmmac: move the EST lock to struct stmmac_priv Reinitialize the whole EST structure would also reset the mutex lock which is embedded in the EST structure, and then trigger the following warning. To address this, move the lock to struct stmmac_priv. We also need to reacquire the mutex lock when doing this initialization. DEBUG_LOCKS_WARN_ON(lock-\u003emagic != lock) WARNING: CPU: 3 PID: 505 at kernel/locking/mutex.c:587 __mutex_lock+0xd84/0x1068 Modules linked in: CPU: 3 PID: 505 Comm: tc Not tainted 6.9.0-rc6-00053-g0106679839f7-dirty #29 Hardware name: NXP i.MX8MPlus EVK board (DT) pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __mutex_lock+0xd84/0x1068 lr : __mutex_lock+0xd84/0x1068 sp : ffffffc0864e3570 x29: ffffffc0864e3570 x28: ffffffc0817bdc78 x27: 0000000000000003 x26: ffffff80c54f1808 x25: ffffff80c9164080 x24: ffffffc080d723ac x23: 0000000000000000 x22: 0000000000000002 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffc083bc3000 x18: ffffffffffffffff x17: ffffffc08117b080 x16: 0000000000000002 x15: ffffff80d2d40000 x14: 00000000000002da x13: ffffff80d2d404b8 x12: ffffffc082b5a5c8 x11: ffffffc082bca680 x10: ffffffc082bb2640 x9 : ffffffc082bb2698 x8 : 0000000000017fe8 x7 : c0000000ffffefff x6 : 0000000000000001 x5 : ffffff8178fe0d48 x4 : 0000000000000000 x3 : 0000000000000027 x2 : ffffff8178fe0d50 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: __mutex_lock+0xd84/0x1068 mutex_lock_nested+0x28/0x34 tc_setup_taprio+0x118/0x68c stmmac_setup_tc+0x50/0xf0 taprio_change+0x868/0xc9c", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38594", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aBSD9SI0+LjXQAmIuEqC1A==": { "id": "aBSD9SI0+LjXQAmIuEqC1A==", "updater": "debian/updater", "name": "CVE-2026-56406", "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56406", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aBoTsVzPtAMF2Qu8j82kjA==": { "id": "aBoTsVzPtAMF2Qu8j82kjA==", "updater": "debian/updater", "name": "CVE-2026-64001", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory. A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory. Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64001", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aNNHQzxgcXugfFwv/DN3Ag==": { "id": "aNNHQzxgcXugfFwv/DN3Ag==", "updater": "debian/updater", "name": "CVE-2024-38625", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check 'folio' pointer for NULL It can be NULL if bmap is called.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38625", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aNtlFmT+qtMf7OWjLlbpiQ==": { "id": "aNtlFmT+qtMf7OWjLlbpiQ==", "updater": "debian/updater", "name": "CVE-2026-68159", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it to CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack out-of-bounds write. An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer entries at decode time. The bound is well below the old overflow threshold, so it also covers the allocation-size overflow the previous check guarded against. BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds Write of size 4 ... by task exploit kasan_report (mm/kasan/report.c:595) ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833) calc_target (net/ceph/osd_client.c:1638) __submit_request (net/ceph/osd_client.c:2394) ceph_osdc_start_request (net/ceph/osd_client.c:2490) ceph_osdc_call (net/ceph/osd_client.c:5164) rbd_dev_image_probe (drivers/block/rbd.c:6899) do_rbd_add (drivers/block/rbd.c:7138) ... kernel BUG at net/ceph/osdmap.c:2670! [ idryomov: do the same in __decode_pg_upmap_items() ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68159", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aTvTtQyFk6amfTAzFmKVQQ==": { "id": "aTvTtQyFk6amfTAzFmKVQQ==", "updater": "debian/updater", "name": "CVE-2025-29070", "description": "A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because \"this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-29070", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "lcms2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aULCDyTTvZjPfzCejfrcxQ==": { "id": "aULCDyTTvZjPfzCejfrcxQ==", "updater": "debian/updater", "name": "CVE-2024-46787", "description": "In the Linux kernel, the following vulnerability has been resolved: userfaultfd: fix checks for huge PMDs Patch series \"userfaultfd: fix races around pmd_trans_huge() check\", v2. The pmd_trans_huge() code in mfill_atomic() is wrong in three different ways depending on kernel version: 1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit the right two race windows) - I've tested this in a kernel build with some extra mdelay() calls. See the commit message for a description of the race scenario. On older kernels (before 6.5), I think the same bug can even theoretically lead to accessing transhuge page contents as a page table if you hit the right 5 narrow race windows (I haven't tested this case). 2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for detecting PMDs that don't point to page tables. On older kernels (before 6.5), you'd just have to win a single fairly wide race to hit this. I've tested this on 6.1 stable by racing migration (with a mdelay() patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86 VM, that causes a kernel oops in ptlock_ptr(). 3. On newer kernels (\u003e=6.5), for shmem mappings, khugepaged is allowed to yank page tables out from under us (though I haven't tested that), so I think the BUG_ON() checks in mfill_atomic() are just wrong. I decided to write two separate fixes for these (one fix for bugs 1+2, one fix for bug 3), so that the first fix can be backported to kernels affected by bugs 1+2. This patch (of 2): This fixes two issues. I discovered that the following race can occur: mfill_atomic other thread ============ ============ \u003czap PMD\u003e pmdp_get_lockless() [reads none pmd] \u003cbail if trans_huge\u003e \u003cif none:\u003e \u003cpagefault creates transhuge zeropage\u003e __pte_alloc [no-op] \u003czap PMD\u003e \u003cbail if pmd_trans_huge(*dst_pmd)\u003e BUG_ON(pmd_none(*dst_pmd)) I have experimentally verified this in a kernel with extra mdelay() calls; the BUG_ON(pmd_none(*dst_pmd)) triggers. On kernels newer than commit 0d940a9b270b (\"mm/pgtable: allow pte_offset_map[_lock]() to fail\"), this can't lead to anything worse than a BUG_ON(), since the page table access helpers are actually designed to deal with page tables concurrently disappearing; but on older kernels (\u003c=6.4), I think we could probably theoretically race past the two BUG_ON() checks and end up treating a hugepage as a page table. The second issue is that, as Qi Zheng pointed out, there are other types of huge PMDs that pmd_trans_huge() can't catch: devmap PMDs and swap PMDs (in particular, migration PMDs). On \u003c=6.4, this is worse than the first issue: If mfill_atomic() runs on a PMD that contains a migration entry (which just requires winning a single, fairly wide race), it will pass the PMD to pte_offset_map_lock(), which assumes that the PMD points to a page table. Breakage follows: First, the kernel tries to take the PTE lock (which will crash or maybe worse if there is no \"struct page\" for the address bits in the migration entry PMD - I think at least on X86 there usually is no corresponding \"struct page\" thanks to the PTE inversion mitigation, amd64 looks different). If that didn't crash, the kernel would next try to write a PTE into what it wrongly thinks is a page table. As part of fixing these issues, get rid of the check for pmd_trans_huge() before __pte_alloc() - that's redundant, we're going to have to check for that after the __pte_alloc() anyway. Backport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46787", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aUsy5n/c6AxyAdYqvDKZAg==": { "id": "aUsy5n/c6AxyAdYqvDKZAg==", "updater": "debian/updater", "name": "CVE-2025-15649", "description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip-\u003enew($file) where callers expect undef plus $UnzipError.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15649", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aXQ9/hjqCHUJVtN4KDB0uQ==": { "id": "aXQ9/hjqCHUJVtN4KDB0uQ==", "updater": "debian/updater", "name": "CVE-2024-56641", "description": "In the Linux kernel, the following vulnerability has been resolved: net/smc: initialize close_work early to avoid warning We encountered a warning that close_work was canceled before initialization. WARNING: CPU: 7 PID: 111103 at kernel/workqueue.c:3047 __flush_work+0x19e/0x1b0 Workqueue: events smc_lgr_terminate_work [smc] RIP: 0010:__flush_work+0x19e/0x1b0 Call Trace: ? __wake_up_common+0x7a/0x190 ? work_busy+0x80/0x80 __cancel_work_timer+0xe3/0x160 smc_close_cancel_work+0x1a/0x70 [smc] smc_close_active_abort+0x207/0x360 [smc] __smc_lgr_terminate.part.38+0xc8/0x180 [smc] process_one_work+0x19e/0x340 worker_thread+0x30/0x370 ? process_one_work+0x340/0x340 kthread+0x117/0x130 ? __kthread_cancel_work+0x50/0x50 ret_from_fork+0x22/0x30 This is because when smc_close_cancel_work is triggered, e.g. the RDMA driver is rmmod and the LGR is terminated, the conn-\u003eclose_work is flushed before initialization, resulting in WARN_ON(!work-\u003efunc). __smc_lgr_terminate | smc_connect_{rdma|ism} ------------------------------------------------------------- | smc_conn_create \t\t\t\t| \\- smc_lgr_register_conn for conn in lgr-\u003econns_all | \\- smc_conn_kill | \\- smc_close_active_abort | \\- smc_close_cancel_work | \\- cancel_work_sync | \\- __flush_work | \t (close_work) | \t | smc_close_init \t | \\- INIT_WORK(\u0026close_work) So fix this by initializing close_work before establishing the connection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56641", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aXiSjOT7d8P3PHD3zq8S+w==": { "id": "aXiSjOT7d8P3PHD3zq8S+w==", "updater": "debian/updater", "name": "CVE-2025-1153", "description": "A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1153", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aZ5JnYDYnTmgVCL1meuGtw==": { "id": "aZ5JnYDYnTmgVCL1meuGtw==", "updater": "debian/updater", "name": "CVE-2024-56544", "description": "In the Linux kernel, the following vulnerability has been resolved: udmabuf: change folios array from kmalloc to kvmalloc When PAGE_SIZE 4096, MAX_PAGE_ORDER 10, 64bit machine, page_alloc only support 4MB. If above this, trigger this warn and return NULL. udmabuf can change size limit, if change it to 3072(3GB), and then alloc 3GB udmabuf, will fail create. [ 4080.876581] ------------[ cut here ]------------ [ 4080.876843] WARNING: CPU: 3 PID: 2015 at mm/page_alloc.c:4556 __alloc_pages+0x2c8/0x350 [ 4080.878839] RIP: 0010:__alloc_pages+0x2c8/0x350 [ 4080.879470] Call Trace: [ 4080.879473] \u003cTASK\u003e [ 4080.879473] ? __alloc_pages+0x2c8/0x350 [ 4080.879475] ? __warn.cold+0x8e/0xe8 [ 4080.880647] ? __alloc_pages+0x2c8/0x350 [ 4080.880909] ? report_bug+0xff/0x140 [ 4080.881175] ? handle_bug+0x3c/0x80 [ 4080.881556] ? exc_invalid_op+0x17/0x70 [ 4080.881559] ? asm_exc_invalid_op+0x1a/0x20 [ 4080.882077] ? udmabuf_create+0x131/0x400 Because MAX_PAGE_ORDER, kmalloc can max alloc 4096 * (1 \u003c\u003c 10), 4MB memory, each array entry is pointer(8byte), so can save 524288 pages(2GB). Further more, costly order(order 3) may not be guaranteed that it can be applied for, due to fragmentation. This patch change udmabuf array use kvmalloc_array, this can fallback alloc into vmalloc, which can guarantee allocation for any size and does not affect the performance of kmalloc allocations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56544", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aayQJupbsBVQlIfkLyOZzQ==": { "id": "aayQJupbsBVQlIfkLyOZzQ==", "updater": "debian/updater", "name": "CVE-2026-68391", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs to hold refcount to avoid UAF. Take appropriate locks for hci_conn lookups, and take refcount for hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays valid. When accessing conn-\u003estate, ensure hdev-\u003elock is held to avoid data race.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68391", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "abuRlaIjMoxp7JxuUe9ZMQ==": { "id": "abuRlaIjMoxp7JxuUe9ZMQ==", "updater": "debian/updater", "name": "CVE-2026-46017", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: fix deferred split queue races during migration migrate_folio_move() records the deferred split queue state from src and replays it on dst. Replaying it after remove_migration_ptes(src, dst, 0) makes dst visible before it is requeued, so a concurrent rmap-removal path can mark dst partially mapped and trip the WARN in deferred_split_folio(). Move the requeue before remove_migration_ptes() so dst is back on the deferred split queue before it becomes visible again. Because migration still holds dst locked at that point, teach deferred_split_scan() to requeue a folio when folio_trylock() fails. Otherwise a fully mapped underused folio can be dequeued by the shrinker and silently lost from split_queue. [ziy@nvidia.com: move the comment]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46017", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "aigq+yzTxik8E8CLAWPW4w==": { "id": "aigq+yzTxik8E8CLAWPW4w==", "updater": "debian/updater", "name": "CVE-2026-68180", "description": "In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device reference leak intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use. commit 95fc36a234da (\"intel_th: fix device leak on output open()\") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file-\u003ef_op with the output driver file operations before returning, so close runs the output driver release callback instead. For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference. Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68180", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ajXQ+t6g/zl5c5KwrQ6iCw==": { "id": "ajXQ+t6g/zl5c5KwrQ6iCw==", "updater": "debian/updater", "name": "CVE-2026-6844", "description": "A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6844", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "am62M/CpkNn2LwlM/A69bA==": { "id": "am62M/CpkNn2LwlM/A69bA==", "updater": "debian/updater", "name": "CVE-2026-63846", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63846", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "apLsRonbFnUs5fqAcBbkRA==": { "id": "apLsRonbFnUs5fqAcBbkRA==", "updater": "debian/updater", "name": "CVE-2025-38207", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: fix uprobe pte be overwritten when expanding vma Patch series \"Fix uprobe pte be overwritten when expanding vma\". This patch (of 4): We encountered a BUG alert triggered by Syzkaller as follows: BUG: Bad rss-counter state mm:00000000b4a60fca type:MM_ANONPAGES val:1 And we can reproduce it with the following steps: 1. register uprobe on file at zero offset 2. mmap the file at zero offset: addr1 = mmap(NULL, 2 * 4096, PROT_NONE, MAP_PRIVATE, fd, 0); 3. mremap part of vma1 to new vma2: addr2 = mremap(addr1, 4096, 2 * 4096, MREMAP_MAYMOVE); 4. mremap back to orig addr1: mremap(addr2, 4096, 4096, MREMAP_MAYMOVE | MREMAP_FIXED, addr1); In step 3, the vma1 range [addr1, addr1 + 4096] will be remap to new vma2 with range [addr2, addr2 + 8192], and remap uprobe anon page from the vma1 to vma2, then unmap the vma1 range [addr1, addr1 + 4096]. In step 4, the vma2 range [addr2, addr2 + 4096] will be remap back to the addr range [addr1, addr1 + 4096]. Since the addr range [addr1 + 4096, addr1 + 8192] still maps the file, it will take vma_merge_new_range to expand the range, and then do uprobe_mmap in vma_complete. Since the merged vma pgoff is also zero offset, it will install uprobe anon page to the merged vma. However, the upcomming move_page_tables step, which use set_pte_at to remap the vma2 uprobe pte to the merged vma, will overwrite the newly uprobe pte in the merged vma, and lead that pte to be orphan. Since the uprobe pte will be remapped to the merged vma, we can remove the unnecessary uprobe_mmap upon merged vma. This problem was first found in linux-6.6.y and also exists in the community syzkaller: https://lore.kernel.org/all/000000000000ada39605a5e71711@google.com/T/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38207", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "apNb4s14qtsrQ/p0KNYftw==": { "id": "apNb4s14qtsrQ/p0KNYftw==", "updater": "debian/updater", "name": "CVE-2026-31725", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -\u003e /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31725", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "atECatQpyL4OR6Nj8ORK0g==": { "id": "atECatQpyL4OR6Nj8ORK0g==", "updater": "debian/updater", "name": "CVE-2025-15079", "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15079", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "auQHeL2oNVf2NwdOBO/agQ==": { "id": "auQHeL2oNVf2NwdOBO/agQ==", "updater": "debian/updater", "name": "CVE-2026-34379", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34379", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "awprMKbVrDulQWYe0doRPQ==": { "id": "awprMKbVrDulQWYe0doRPQ==", "updater": "debian/updater", "name": "CVE-2024-41082", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: use reserved tag for reg read/write command In some scenarios, if too many commands are issued by nvme command in the same time by user tasks, this may exhaust all tags of admin_q. If a reset (nvme reset or IO timeout) occurs before these commands finish, reconnect routine may fail to update nvme regs due to insufficient tags, which will cause kernel hang forever. In order to workaround this issue, maybe we can let reg_read32()/reg_read64()/reg_write32() use reserved tags. This maybe safe for nvmf: 1. For the disable ctrl path, we will not issue connect command 2. For the enable ctrl / fw activate path, since connect and reg_xx() are called serially. So the reserved tags may still be enough while reg_xx() use reserved tags.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41082", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "axu/TKv6CR+vYzn6x+QHGw==": { "id": "axu/TKv6CR+vYzn6x+QHGw==", "updater": "debian/updater", "name": "CVE-2026-31410", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION Use sb-\u003es_uuid for a proper volume identifier as the primary choice. For filesystems that do not provide a UUID, fall back to stfs.f_fsid obtained from vfs_statfs().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31410", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "axvi+bbvad2fAYBT2fF1/A==": { "id": "axvi+bbvad2fAYBT2fF1/A==", "updater": "debian/updater", "name": "CVE-2026-68186", "description": "In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: set have_execfd only once the interpreter is opened load_misc_binary() raises bprm-\u003ehave_execfd as soon as it sees the 'O' (or 'C') flag. This happens well before it opens the interpreter. If that open fails the flag stays set on the bprm. binfmt_misc is at the head of the format list so an interpreter open failure that returns -ENOEXEC lets the search fall through to a later format. This means it runs the matched binary directly having never staged an interpreter. So bprm-\u003eexecutable is NULL while have_execfd falsely claims a descriptor is present. Consequently, begin_new_exec() dereferences the missing executable: would_dump(bprm, bprm-\u003eexecutable); and NULL derefs. Had it not, the hand-off later in the same function would have failed anyway. FD_ADD(0, bprm-\u003eexecutable) rejects a NULL file with -ENOMEM. Both sites are past the point of no return so the exec cannot be unwound either way. This can be reached by unprivileged users as binfmt_misc can be mounted in user namespaces. So a user can register an 'O' entry whose interpreter lives on a FUSE mount, have the FUSE server fail the open with -ENOEXEC and execute a native ELF file that matches the entry. have_execfd only means anything alongside the executable it describes which is not set until the interpreter has been opened and staged. So lets raise it there, next to execfd_creds, which is already set at that point. An open failure now leaves it clear, so the fallback format derives credentials from the binary and emits no AT_EXECFD, as it would for any native exec. The argv rewrite load_misc_binary() performs before the open is still not undone. This means the binary sees the interpreter path in argv[0] and its own path in argv[1] but that predates this change and only became observable once the exec stopped faulting.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68186", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ayNwOwFahcJX8VpuVbGJUw==": { "id": "ayNwOwFahcJX8VpuVbGJUw==", "updater": "debian/updater", "name": "CVE-2026-56404", "description": "libexpat before 2.8.2 has an integer overflow in addBinding.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56404", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b+yN6F3DrI8g0bS8DE7Ikg==": { "id": "b+yN6F3DrI8g0bS8DE7Ikg==", "updater": "debian/updater", "name": "CVE-2024-26836", "description": "In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix password opcode ordering for workstations The Lenovo workstations require the password opcode to be run before the attribute value is changed (if Admin password is enabled). Tested on some Thinkpads to confirm they are OK with this order too.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26836", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b/gb9s3KrIJfPaaNxJoujw==": { "id": "b/gb9s3KrIJfPaaNxJoujw==", "updater": "debian/updater", "name": "CVE-2017-0630", "description": "An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-0630", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b25sK2nK3uR0z9nGZBhD8g==": { "id": "b25sK2nK3uR0z9nGZBhD8g==", "updater": "debian/updater", "name": "CVE-2026-46330", "description": "In the Linux kernel, the following vulnerability has been resolved: Revert \"net/smc: Introduce TCP ULP support\" This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40. As reported by Al Viro, the TCP ULP support for SMC is fundamentally broken. The implementation attempts to convert an active TCP socket into an SMC socket by modifying the underlying `struct file`, dentry, and inode in-place, which violates core VFS invariants that assume these structures are immutable for an open file, creating a risk of use after free errors and general system instability. Given the severity of this design flaw and the fact that cleaner alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application transparency, the correct course of action is to remove this feature entirely.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46330", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b2VPlgx4qj2KQUTqmyJdew==": { "id": "b2VPlgx4qj2KQUTqmyJdew==", "updater": "debian/updater", "name": "CVE-2023-53261", "description": "In the Linux kernel, the following vulnerability has been resolved: coresight: Fix memory leak in acpi_buffer-\u003epointer There are memory leaks reported by kmemleak: ... unreferenced object 0xffff00213c141000 (size 1024): comm \"systemd-udevd\", pid 2123, jiffies 4294909467 (age 6062.160s) hex dump (first 32 bytes): 04 00 00 00 02 00 00 00 18 10 14 3c 21 00 ff ff ...........\u003c!... 00 00 00 00 00 00 00 00 03 00 00 00 10 00 00 00 ................ backtrace: [\u003c000000004b7c9001\u003e] __kmem_cache_alloc_node+0x2f8/0x348 [\u003c00000000b0fc7ceb\u003e] __kmalloc+0x58/0x108 [\u003c0000000064ff4695\u003e] acpi_os_allocate+0x2c/0x68 [\u003c000000007d57d116\u003e] acpi_ut_initialize_buffer+0x54/0xe0 [\u003c0000000024583908\u003e] acpi_evaluate_object+0x388/0x438 [\u003c0000000017b2e72b\u003e] acpi_evaluate_object_typed+0xe8/0x240 [\u003c000000005df0eac2\u003e] coresight_get_platform_data+0x1b4/0x988 [coresight] ... The ACPI buffer memory (buf.pointer) should be freed. But the buffer is also used after returning from acpi_get_dsd_graph(). Move the temporary variables buf to acpi_coresight_parse_graph(), and free it before the function return to prevent memory leak.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53261", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b7jIcdQJnfDJcThaGSjCKw==": { "id": "b7jIcdQJnfDJcThaGSjCKw==", "updater": "debian/updater", "name": "CVE-2024-26691", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix circular locking dependency The rule inside kvm enforces that the vcpu-\u003emutex is taken *inside* kvm-\u003elock. The rule is violated by the pkvm_create_hyp_vm() which acquires the kvm-\u003elock while already holding the vcpu-\u003emutex lock from kvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by protecting the hyp vm handle with the config_lock, much like we already do for other forms of VM-scoped data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26691", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "b9BwljBVb2STBNXhnDZGew==": { "id": "b9BwljBVb2STBNXhnDZGew==", "updater": "debian/updater", "name": "CVE-2024-42243", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray Patch series \"mm/filemap: Limit page cache size to that supported by xarray\", v2. Currently, xarray can't support arbitrary page cache size. More details can be found from the WARN_ON() statement in xas_split_alloc(). In our test whose code is attached below, we hit the WARN_ON() on ARM64 system where the base page size is 64KB and huge page size is 512MB. The issue was reported long time ago and some discussions on it can be found here [1]. [1] https://www.spinics.net/lists/linux-xfs/msg75404.html In order to fix the issue, we need to adjust MAX_PAGECACHE_ORDER to one supported by xarray and avoid PMD-sized page cache if needed. The code changes are suggested by David Hildenbrand. PATCH[1] adjusts MAX_PAGECACHE_ORDER to that supported by xarray PATCH[2-3] avoids PMD-sized page cache in the synchronous readahead path PATCH[4] avoids PMD-sized page cache for shmem files if needed Test program ============ # cat test.c #define _GNU_SOURCE #include \u003cstdio.h\u003e #include \u003cstdlib.h\u003e #include \u003cunistd.h\u003e #include \u003cstring.h\u003e #include \u003cfcntl.h\u003e #include \u003cerrno.h\u003e #include \u003csys/syscall.h\u003e #include \u003csys/mman.h\u003e #define TEST_XFS_FILENAME\t\"/tmp/data\" #define TEST_SHMEM_FILENAME\t\"/dev/shm/data\" #define TEST_MEM_SIZE\t\t0x20000000 int main(int argc, char **argv) { \tconst char *filename; \tint fd = 0; \tvoid *buf = (void *)-1, *p; \tint pgsize = getpagesize(); \tint ret; \tif (pgsize != 0x10000) { \t\tfprintf(stderr, \"64KB base page size is required\\n\"); \t\treturn -EPERM; \t} \tsystem(\"echo force \u003e /sys/kernel/mm/transparent_hugepage/shmem_enabled\"); \tsystem(\"rm -fr /tmp/data\"); \tsystem(\"rm -fr /dev/shm/data\"); \tsystem(\"echo 1 \u003e /proc/sys/vm/drop_caches\"); \t/* Open xfs or shmem file */ \tfilename = TEST_XFS_FILENAME; \tif (argc \u003e 1 \u0026\u0026 !strcmp(argv[1], \"shmem\")) \t\tfilename = TEST_SHMEM_FILENAME; \tfd = open(filename, O_CREAT | O_RDWR | O_TRUNC); \tif (fd \u003c 0) { \t\tfprintf(stderr, \"Unable to open \u003c%s\u003e\\n\", filename); \t\treturn -EIO; \t} \t/* Extend file size */ \tret = ftruncate(fd, TEST_MEM_SIZE); \tif (ret) { \t\tfprintf(stderr, \"Error %d to ftruncate()\\n\", ret); \t\tgoto cleanup; \t} \t/* Create VMA */ \tbuf = mmap(NULL, TEST_MEM_SIZE, \t\t PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); \tif (buf == (void *)-1) { \t\tfprintf(stderr, \"Unable to mmap \u003c%s\u003e\\n\", filename); \t\tgoto cleanup; \t} \tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf); \tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE); if (ret) { \t\tfprintf(stderr, \"Unable to madvise(MADV_HUGEPAGE)\\n\"); \t\tgoto cleanup; \t} \t/* Populate VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_WRITE); \tif (ret) { \t\tfprintf(stderr, \"Error %d to madvise(MADV_POPULATE_WRITE)\\n\", ret); \t\tgoto cleanup; \t} \t/* Punch the file to enforce xarray split */ \tret = fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE, \t\tTEST_MEM_SIZE - pgsize, pgsize); \tif (ret) \t\tfprintf(stderr, \"Error %d to fallocate()\\n\", ret); cleanup: \tif (buf != (void *)-1) \t\tmunmap(buf, TEST_MEM_SIZE); \tif (fd \u003e 0) \t\tclose(fd); \treturn 0; } # gcc test.c -o test # cat /proc/1/smaps | grep KernelPageSize | head -n 1 KernelPageSize: 64 kB # ./test shmem : ------------[ cut here ]------------ WARNING: CPU: 17 PID: 5253 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\ nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\ nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\ ip_set nf_tables rfkill nfnetlink vfat fat virtio_balloon \\ drm fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 \\ virtio_net sha1_ce net_failover failover virtio_console virtio_blk \\ dimlib virtio_mmio CPU: 17 PID: 5253 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #12 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TC ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42243", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bF08jSMQQwNKtSqSbitR/g==": { "id": "bF08jSMQQwNKtSqSbitR/g==", "updater": "debian/updater", "name": "CVE-2024-26672", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_entry() warn: variable dereferenced before check 'mca_funcs' (see line 368) 357 int amdgpu_mca_smu_get_mca_entry(struct amdgpu_device *adev, \t\t\t\t enum amdgpu_mca_error_type type, 358 int idx, struct mca_bank_entry *entry) 359 { 360 const struct amdgpu_mca_smu_funcs *mca_funcs = \t\t\t\t\t\tadev-\u003emca.mca_funcs; 361 int count; 362 363 switch (type) { 364 case AMDGPU_MCA_ERROR_TYPE_UE: 365 count = mca_funcs-\u003emax_ue_count; mca_funcs is dereferenced here. 366 break; 367 case AMDGPU_MCA_ERROR_TYPE_CE: 368 count = mca_funcs-\u003emax_ce_count; mca_funcs is dereferenced here. 369 break; 370 default: 371 return -EINVAL; 372 } 373 374 if (idx \u003e= count) 375 return -EINVAL; 376 377 if (mca_funcs \u0026\u0026 mca_funcs-\u003emca_get_mca_entry) \t ^^^^^^^^^ Checked too late!", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26672", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bFiZXYN1LhAR839UCAG4ig==": { "id": "bFiZXYN1LhAR839UCAG4ig==", "updater": "debian/updater", "name": "CVE-2026-43042", "description": "In the Linux kernel, the following vulnerability has been resolved: mpls: add seqcount to protect the platform_label{,s} pair The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have an inconsistent view of platform_labels vs platform_label in case of a concurrent resize (resize_platform_label_table, under platform_mutex). This can lead to OOB accesses. This patch adds a seqcount, so that we get a consistent snapshot. Note that mpls_label_ok is also susceptible to this, so the check against RTA_DST in rtm_to_route_config, done outside platform_mutex, is not sufficient. This value gets passed to mpls_label_ok once more in both mpls_route_add and mpls_route_del, so there is no issue, but that additional check must not be removed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43042", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bQ14Sxqd6BxYkrJpOMom+g==": { "id": "bQ14Sxqd6BxYkrJpOMom+g==", "updater": "debian/updater", "name": "CVE-2024-50282", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read() Avoid a possible buffer overflow if size is larger than 4K. (cherry picked from commit f5d873f5825b40d886d03bd2aede91d4cf002434)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50282", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bQkpTmjn4jTZcFsn7mUkdg==": { "id": "bQkpTmjn4jTZcFsn7mUkdg==", "updater": "debian/updater", "name": "CVE-2025-22109", "description": "In the Linux kernel, the following vulnerability has been resolved: ax25: Remove broken autobind Binding AX25 socket by using the autobind feature leads to memory leaks in ax25_connect() and also refcount leaks in ax25_release(). Memory leak was detected with kmemleak: ================================================================ unreferenced object 0xffff8880253cd680 (size 96): backtrace: __kmalloc_node_track_caller_noprof (./include/linux/kmemleak.h:43) kmemdup_noprof (mm/util.c:136) ax25_rt_autobind (net/ax25/ax25_route.c:428) ax25_connect (net/ax25/af_ax25.c:1282) __sys_connect_file (net/socket.c:2045) __sys_connect (net/socket.c:2064) __x64_sys_connect (net/socket.c:2067) do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) ================================================================ When socket is bound, refcounts must be incremented the way it is done in ax25_bind() and ax25_setsockopt() (SO_BINDTODEVICE). In case of autobind, the refcounts are not incremented. This bug leads to the following issue reported by Syzkaller: ================================================================ ax25_connect(): syz-executor318 uses autobind, please contact jreuter@yaina.de ------------[ cut here ]------------ refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 0 PID: 5317 at lib/refcount.c:31 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31 Modules linked in: CPU: 0 UID: 0 PID: 5317 Comm: syz-executor318 Not tainted 6.14.0-rc4-syzkaller-00278-gece144f151ac #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31 ... Call Trace: \u003cTASK\u003e __refcount_dec include/linux/refcount.h:336 [inline] refcount_dec include/linux/refcount.h:351 [inline] ref_tracker_free+0x6af/0x7e0 lib/ref_tracker.c:236 netdev_tracker_free include/linux/netdevice.h:4302 [inline] netdev_put include/linux/netdevice.h:4319 [inline] ax25_release+0x368/0x960 net/ax25/af_ax25.c:1080 __sock_release net/socket.c:647 [inline] sock_close+0xbc/0x240 net/socket.c:1398 __fput+0x3e9/0x9f0 fs/file_table.c:464 __do_sys_close fs/open.c:1580 [inline] __se_sys_close fs/open.c:1565 [inline] __x64_sys_close+0x7f/0x110 fs/open.c:1565 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f ... \u003c/TASK\u003e ================================================================ Considering the issues above and the comments left in the code that say: \"check if we can remove this feature. It is broken.\"; \"autobinding in this may or may not work\"; - it is better to completely remove this feature than to fix it because it is broken and leads to various kinds of memory bugs. Now calling connect() without first binding socket will result in an error (-EINVAL). Userspace software that relies on the autobind feature might get broken. However, this feature does not seem widely used with this specific driver as it was not reliable at any point of time, and it is already broken anyway. E.g. ax25-tools and ax25-apps packages for popular distributions do not use the autobind feature for AF_AX25. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22109", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bSFklTcH++Qe4N7ocEMvdg==": { "id": "bSFklTcH++Qe4N7ocEMvdg==", "updater": "debian/updater", "name": "CVE-2024-43819", "description": "In the Linux kernel, the following vulnerability has been resolved: kvm: s390: Reject memory region operations for ucontrol VMs This change rejects the KVM_SET_USER_MEMORY_REGION and KVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM. This is necessary since ucontrol VMs have kvm-\u003earch.gmap set to 0 and would thus result in a null pointer dereference further in. Memory management needs to be performed in userspace and using the ioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP. Also improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION and KVM_SET_USER_MEMORY_REGION2. [frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43819", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bSGK4tTg10r8DpiEIpZRyA==": { "id": "bSGK4tTg10r8DpiEIpZRyA==", "updater": "debian/updater", "name": "CVE-2024-57974", "description": "In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address change and rehash If a UDP socket changes its local address while it's receiving datagrams, as a result of connect(), there is a period during which a lookup operation might fail to find it, after the address is changed but before the secondary hash (port and address) and the four-tuple hash (local and remote ports and addresses) are updated. Secondary hash chains were introduced by commit 30fff9231fad (\"udp: bind() optimisation\") and, as a result, a rehash operation became needed to make a bound socket reachable again after a connect(). This operation was introduced by commit 719f835853a9 (\"udp: add rehash on connect()\") which isn't however a complete fix: the socket will be found once the rehashing completes, but not while it's pending. This is noticeable with a socat(1) server in UDP4-LISTEN mode, and a client sending datagrams to it. After the server receives the first datagram (cf. _xioopen_ipdgram_listen()), it issues a connect() to the address of the sender, in order to set up a directed flow. Now, if the client, running on a different CPU thread, happens to send a (subsequent) datagram while the server's socket changes its address, but is not rehashed yet, this will result in a failed lookup and a port unreachable error delivered to the client, as apparent from the following reproducer: LEN=$(($(cat /proc/sys/net/core/wmem_default) / 4)) dd if=/dev/urandom bs=1 count=${LEN} of=tmp.in while :; do \ttaskset -c 1 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc \u0026 \tsleep 0.1 || sleep 1 \ttaskset -c 2 socat OPEN:tmp.in UDP4:localhost:1337,shut-null \twait done where the client will eventually get ECONNREFUSED on a write() (typically the second or third one of a given iteration): 2024/11/13 21:28:23 socat[46901] E write(6, 0x556db2e3c000, 8192): Connection refused This issue was first observed as a seldom failure in Podman's tests checking UDP functionality while using pasta(1) to connect the container's network namespace, which leads us to a reproducer with the lookup error resulting in an ICMP packet on a tap device: LOCAL_ADDR=\"$(ip -j -4 addr show|jq -rM '.[] | .addr_info[0] | select(.scope == \"global\").local')\" while :; do \t./pasta --config-net -p pasta.pcap -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc \u0026 \tsleep 0.2 || sleep 1 \tsocat OPEN:tmp.in UDP4:${LOCAL_ADDR}:1337,shut-null \twait \tcmp tmp.in tmp.out done Once this fails: tmp.in tmp.out differ: char 8193, line 29 we can finally have a look at what's going on: $ tshark -r pasta.pcap 1 0.000000 :: ? ff02::16 ICMPv6 110 Multicast Listener Report Message v2 2 0.168690 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 3 0.168767 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 4 0.168806 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 5 0.168827 c6:47:05:8d:dc:04 ? Broadcast ARP 42 Who has 88.198.0.161? Tell 88.198.0.164 6 0.168851 9a:55:9a:55:9a:55 ? c6:47:05:8d:dc:04 ARP 42 88.198.0.161 is at 9a:55:9a:55:9a:55 7 0.168875 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 8 0.168896 88.198.0.164 ? 88.198.0.161 ICMP 590 Destination unreachable (Port unreachable) 9 0.168926 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 10 0.168959 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192 11 0.168989 88.198.0.161 ? 88.198.0.164 UDP 4138 60260 ? 1337 Len=4096 12 0.169010 88.198.0.161 ? 88.198.0.164 UDP 42 60260 ? 1337 Len=0 On the third datagram received, the network namespace of the container initiates an ARP lookup to deliver the ICMP message. In another variant of this reproducer, starting the client with: strace -f pasta --config-net -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,tru ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57974", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bSOhmLSWdup+bnw7AEzTRw==": { "id": "bSOhmLSWdup+bnw7AEzTRw==", "updater": "debian/updater", "name": "CVE-2025-49506", "description": "APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-49506", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "apr-util", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bSQHKOOIEu7zn/5UgFOWJw==": { "id": "bSQHKOOIEu7zn/5UgFOWJw==", "updater": "debian/updater", "name": "CVE-2025-69534", "description": "Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69534", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bV7JkNyzTIO5N9GIRXxGug==": { "id": "bV7JkNyzTIO5N9GIRXxGug==", "updater": "debian/updater", "name": "CVE-2024-26461", "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26461", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bXtl+n71538U32lxPZ+WzQ==": { "id": "bXtl+n71538U32lxPZ+WzQ==", "updater": "debian/updater", "name": "CVE-2026-53108", "description": "In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unmap race with PMD migration entries The following race is possible with migration swap entries or device-private THP entries. e.g. when move_pages is called on a PMD THP page, then there maybe an intermediate state, where PMD entry acts as a migration swap entry (pmd_present() is true). Then if an munmap happens at the same time, then this VM_BUG_ON() can happen in pmdp_huge_get_and_clear_full(). This patch fixes that. Thread A: move_pages() syscall add_folio_for_migration() mmap_read_lock(mm) folio_isolate_lru(folio) mmap_read_unlock(mm) do_move_pages_to_node() migrate_pages() try_to_migrate_one() spin_lock(ptl) set_pmd_migration_entry() pmdp_invalidate() # PMD: _PAGE_INVALID | _PAGE_PTE | pfn set_pmd_at() # PMD: migration swap entry (pmd_present=0) spin_unlock(ptl) [page copy phase] # \u003c--- RACE WINDOW --\u003e Thread B: munmap() mmap_write_downgrade(mm) unmap_vmas() -\u003e zap_pmd_range() zap_huge_pmd() __pmd_trans_huge_lock() pmd_is_huge(): # !pmd_present \u0026\u0026 !pmd_none -\u003e TRUE (swap entry) pmd_lock() -\u003e \t\t# spin_lock(ptl), waits for Thread A to release ptl pmdp_huge_get_and_clear_full() VM_BUG_ON(!pmd_present(*pmdp)) # HITS! [ 287.738700][ T1867] ------------[ cut here ]------------ [ 287.743843][ T1867] kernel BUG at arch/powerpc/mm/book3s64/pgtable.c:187! cpu 0x0: Vector: 700 (Program Check) at [c00000044037f4f0] pc: c000000000094ca4: pmdp_huge_get_and_clear_full+0x6c/0x23c lr: c000000000645dec: zap_huge_pmd+0xb0/0x868 sp: c00000044037f790 msr: 800000000282b033 current = 0xc0000004032c1a00 paca = 0xc000000004fe0000 irqmask: 0x03 irq_happened: 0x09 pid = 1867, comm = a.out kernel BUG at :187! Linux version 6.19.0-12136-g14360d4f917c-dirty (powerpc64le-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #27 SMP PREEMPT Sun Feb 22 10:38:56 IST 2026 enter ? for help [link register ] c000000000645dec zap_huge_pmd+0xb0/0x868 [c00000044037f790] c00000044037f7d0 (unreliable) [c00000044037f7d0] c000000000645dcc zap_huge_pmd+0x90/0x868 [c00000044037f840] c0000000005724cc unmap_page_range+0x176c/0x1f40 [c00000044037fa00] c000000000572ea0 unmap_vmas+0xb0/0x1d8 [c00000044037fa90] c0000000005af254 unmap_region+0xb4/0x128 [c00000044037fb50] c0000000005af400 vms_complete_munmap_vmas+0x138/0x310 [c00000044037fbe0] c0000000005b0f1c do_vmi_align_munmap+0x1ec/0x238 [c00000044037fd30] c0000000005b3688 __vm_munmap+0x170/0x1f8 [c00000044037fdf0] c000000000587f74 sys_munmap+0x2c/0x40 [c00000044037fe10] c000000000032668 system_call_exception+0x128/0x350 [c00000044037fe50] c00000000000d05c system_call_vectored_common+0x15c/0x2ec ---- Exception: 3000 (System Call Vectored) at 0000000010064a2c SP (7fff9b1ee9c0) is in userspace 0:mon\u003e zh commit a30b48bf1b24 (\"mm/migrate_device: implement THP migration of zone device pages\"), enabled migration for device-private PMD entries. Hence this is one other path where this warning could get trigger from. ------------[ cut here ]------------ WARNING: arch/powerpc/mm/book3s64/hash_pgtable.c:199 at hash__pmd_hugepage_update+0x48/0x284, CPU#3: hmm-tests/1905 Modules linked in: test_hmm CPU: 3 UID: 0 PID: 1905 Comm: hmm-tests Tainted: G B W L N 7.0.0-rc1-01438-g7e2f0ee7581c #21 PREEMPT Tainted: [B]=BAD_PAGE, [W]=WARN, [L]=SOFTLOCKUP, [N]=TEST Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) 0x801200 0xf000006 of:SLOF,git-ee03ae pSeries NIP [c000000000096b70] hash__pmd_hugepage_update+0x48/0x284 LR [c000000000096e7c] hash__pmdp_huge_get_and_clear+0xd0/0xd4 Call Trace: [c000000604707670] [c000000004e102b8] 0xc000000004e102b8 (unreliable) [c000000604707700] [c00000000064ec3c] set_pmd_migration_entry+0x414/0x498 [c000000604707760] [c00000000063e5a4] migrate_vma_col ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53108", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bdwKFQO+8VB6A3n5Lckvuw==": { "id": "bdwKFQO+8VB6A3n5Lckvuw==", "updater": "debian/updater", "name": "CVE-2026-68096", "description": "In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe_exe() A deadlock occurs in the audit subsystem when duplicating executable-related rules. When a file is moved (e.g., via do_renameat2()), the VFS layer locks the parent directory (I_MUTEX_PARENT), which synchronously triggers an fsnotify_move event. If an existing executable audit rule matches the file being moved, the audit subsystem catches this event and calls audit_dupe_exe() to duplicate the watch and update the rule. Then, audit_alloc_mark() would call kern_path_parent() to resolve the path, leading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock already held by the task, resulting in the following recursive locking deadlock: ============================================ WARNING: possible recursive locking detected 6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted -------------------------------------------- mv/5099 is trying to acquire lock: ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3}, at: __kern_path_locked+0x10a/0x2f0 but task is already holding lock: ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1){+.+.}-{3:3}, at: lock_two_directories+0x13f/0x2b0 other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1); lock(\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1); *** DEADLOCK *** May be due to missing lock nesting notation 6 locks held by mv/5099: #0: ffff888112a9c440 (sb_writers#13) at: do_renameat2+0x34c/0xbc0 #1: ffff888112a9c790 (\u0026type-\u003es_vfs_rename_key#3) at: do_renameat2+0x415/0xbc0 #2: ffff888132846b58 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/1) at: lock_two_directories+0x13f/0x2b0 #3: ffff888132845358 (\u0026inode-\u003ei_sb-\u003es_type-\u003ei_mutex_dir_key/5) at: lock_two_directories+0x175/0x2b0 #4: ffffffffb3a1fb10 (\u0026fsnotify_mark_srcu) at: fsnotify+0x454/0x28a0 #5: ffffffffaf886230 (audit_filter_mutex) at: audit_update_watch+0x36/0x11e0 stack backtrace: Call Trace: \u003cTASK\u003e dump_stack_lvl+0x6f/0xb0 print_deadlock_bug.cold+0xbd/0xca validate_chain+0x83a/0xf00 __lock_acquire+0xcac/0x1d20 lock_acquire.part.0+0x11b/0x360 down_write_nested+0x9f/0x230 __kern_path_locked+0x10a/0x2f0 kern_path_locked+0x26/0x40 audit_alloc_mark+0xfb/0x4f0 audit_dupe_exe+0x6c/0xe0 audit_dupe_rule+0x6c2/0xc00 audit_update_watch+0x4cc/0x11e0 audit_watch_handle_event+0x12c/0x1b0 send_to_group+0x5d0/0x8b0 fsnotify+0x615/0x28a0 fsnotify_move+0x1d8/0x630 vfs_rename+0xdcd/0x1df0 do_renameat2+0x9d4/0xbc0 __x64_sys_renameat+0x192/0x260 do_syscall_64+0x92/0x180 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f0491fe8c4e Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89 RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001 R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c \u003c/TASK\u003e The aforementioned deadlock can be consistently reproduced by running the script below: audit-dupe-exe-deadlock.sh -------------------------- #!/bin/bash auditctl -D mkdir -p /tmp/foo touch /tmp/file auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr mv /tmp/file /tmp/foo/file rm -Rf /tmp/foo This patch fixes the issue by introducing struct audit_watch_ctx to pass the fsnotify event context down to audit_alloc_mark(). By utilizing the already-resolved directory inode provided by the event, we bypass the kern_path_parent() path resol ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68096", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "becoMjDxhD0zUVLDpif8cA==": { "id": "becoMjDxhD0zUVLDpif8cA==", "updater": "debian/updater", "name": "CVE-2026-53262", "description": "In the Linux kernel, the following vulnerability has been resolved: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() pppol2tp_ioctl() read sock-\u003esk-\u003esk_user_data directly without any locks or reference counting. If a controllable sleep was induced during copy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent socket close could trigger pppol2tp_session_close() asynchronously. This frees the l2tp_session structure via the l2tp_session_del_work workqueue. Upon resuming, the ioctl thread dereferences the stale session pointer, resulting in a Use-After-Free (UAF). Fix this by securely fetching the session reference using the RCU-safe, refcounted helper pppol2tp_sock_to_session(sk) on entry. This locks the session's refcount across the sleep. We structured the function to exit via standard err breaks, guaranteeing that l2tp_session_put() is cleanly called on all return paths to drop the reference. To preserve existing behavior we validate the session and its magic signature only for the specific L2TP commands that require it. This ensures that generic/unknown ioctls called on an unconnected socket still return -ENOIOCTLCMD and correctly fall back to generic handlers (e.g. in sock_do_ioctl()).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53262", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bfUuYbRigpZ1CQq2y/uE9w==": { "id": "bfUuYbRigpZ1CQq2y/uE9w==", "updater": "debian/updater", "name": "CVE-2024-57809", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: imx6: Fix suspend/resume support on i.MX6QDL The suspend/resume functionality is currently broken on the i.MX6QDL platform, as documented in the NXP errata (ERR005723): https://www.nxp.com/docs/en/errata/IMX6DQCE.pdf This patch addresses the issue by sharing most of the suspend/resume sequences used by other i.MX devices, while avoiding modifications to critical registers that disrupt the PCIe functionality. It targets the same problem as the following downstream commit: https://github.com/nxp-imx/linux-imx/commit/4e92355e1f79d225ea842511fcfd42b343b32995 Unlike the downstream commit, this patch also resets the connected PCIe device if possible. Without this reset, certain drivers, such as ath10k or iwlwifi, will crash on resume. The device reset is also done by the driver on other i.MX platforms, making this patch consistent with existing practices. Upon resuming, the kernel will hang and display an error. Here's an example of the error encountered with the ath10k driver: ath10k_pci 0000:01:00.0: Unable to change power state from D3hot to D0, device inaccessible Unhandled fault: imprecise external abort (0x1406) at 0x0106f944 Without this patch, suspend/resume will fail on i.MX6QDL devices if a PCIe device is connected. [kwilczynski: commit log, added tag for stable releases]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57809", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "biBX6JK0iCfEVUm/Gb3CjQ==": { "id": "biBX6JK0iCfEVUm/Gb3CjQ==", "updater": "debian/updater", "name": "CVE-2025-71073", "description": "In the Linux kernel, the following vulnerability has been resolved: Input: lkkbd - disable pending work before freeing device lkkbd_interrupt() schedules lk-\u003etq via schedule_work(), and the work handler lkkbd_reinit() dereferences the lkkbd structure and its serio/input_dev fields. lkkbd_disconnect() and error paths in lkkbd_connect() free the lkkbd structure without preventing the reinit work from being queued again until serio_close() returns. This can allow the work handler to run after the structure has been freed, leading to a potential use-after-free. Use disable_work_sync() instead of cancel_work_sync() to ensure the reinit work cannot be re-queued, and call it both in lkkbd_disconnect() and in lkkbd_connect() error paths after serio_open().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71073", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bjHG8/MdZTTG8aCXn6GAlA==": { "id": "bjHG8/MdZTTG8aCXn6GAlA==", "updater": "debian/updater", "name": "CVE-2026-64139", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 (\"ksmbd: use check_add_overflow() to prevent u16 DACL size overflow\") added check_add_overflow() guards that break out of the ACE-building loops in set_posix_acl_entries_dacl() when the accumulated DACL size would wrap past 65535. However, each iteration allocates a struct smb_sid via kmalloc_obj() at the top of the loop and relies on the kfree(sid) call at the end of the loop body (the 'pass_same_sid' label in the first loop, and the explicit kfree at the tail of the second loop) to release it. The newly introduced 'break' statements bypass those kfree() calls, leaking the sid buffer every time an overflow is detected. A malicious or malformed file with enough POSIX ACL entries to trip the overflow check will leak one or more struct smb_sid allocations on every request that touches the file's DACL, providing a trivial kernel memory exhaustion vector. Free sid before breaking out of the loops to plug the leak.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64139", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bkD27G5x4y2TAqhJBzu7xg==": { "id": "bkD27G5x4y2TAqhJBzu7xg==", "updater": "debian/updater", "name": "CVE-2026-6653", "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6653", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "boBcfhbBL2Rh/aiBtdXUjQ==": { "id": "boBcfhbBL2Rh/aiBtdXUjQ==", "updater": "debian/updater", "name": "CVE-2026-68226", "description": "In the Linux kernel, the following vulnerability has been resolved: media: cx23885: add ioremap return check and cleanup Add a check for the return value of pci_ioremap_bar() in cx23885_dev_setup(). If ioremap for BAR0 fails, release the already allocated PCI memory region, decrement the device count, and return -ENODEV. This prevents a potential null pointer dereference and ensures proper cleanup on memory mapping failure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68226", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "bq3rksXgiXoV6AuXVj+nKg==": { "id": "bq3rksXgiXoV6AuXVj+nKg==", "updater": "debian/updater", "name": "CVE-2025-21693", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: zswap: properly synchronize freeing resources during CPU hotunplug In zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the current CPU at the beginning of the operation is retrieved and used throughout. However, since neither preemption nor migration are disabled, it is possible that the operation continues on a different CPU. If the original CPU is hotunplugged while the acomp_ctx is still in use, we run into a UAF bug as some of the resources attached to the acomp_ctx are freed during hotunplug in zswap_cpu_comp_dead() (i.e. acomp_ctx.buffer, acomp_ctx.req, or acomp_ctx.acomp). The problem was introduced in commit 1ec3b5fe6eec (\"mm/zswap: move to use crypto_acomp API for hardware acceleration\") when the switch to the crypto_acomp API was made. Prior to that, the per-CPU crypto_comp was retrieved using get_cpu_ptr() which disables preemption and makes sure the CPU cannot go away from under us. Preemption cannot be disabled with the crypto_acomp API as a sleepable context is needed. Use the acomp_ctx.mutex to synchronize CPU hotplug callbacks allocating and freeing resources with compression/decompression paths. Make sure that acomp_ctx.req is NULL when the resources are freed. In the compression/decompression paths, check if acomp_ctx.req is NULL after acquiring the mutex (meaning the CPU was offlined) and retry on the new CPU. The initialization of acomp_ctx.mutex is moved from the CPU hotplug callback to the pool initialization where it belongs (where the mutex is allocated). In addition to adding clarity, this makes sure that CPU hotplug cannot reinitialize a mutex that is already locked by compression/decompression. Previously a fix was attempted by holding cpus_read_lock() [1]. This would have caused a potential deadlock as it is possible for code already holding the lock to fall into reclaim and enter zswap (causing a deadlock). A fix was also attempted using SRCU for synchronization, but Johannes pointed out that synchronize_srcu() cannot be used in CPU hotplug notifiers [2]. Alternative fixes that were considered/attempted and could have worked: - Refcounting the per-CPU acomp_ctx. This involves complexity in handling the race between the refcount dropping to zero in zswap_[de]compress() and the refcount being re-initialized when the CPU is onlined. - Disabling migration before getting the per-CPU acomp_ctx [3], but that's discouraged and is a much bigger hammer than needed, and could result in subtle performance issues. [1]https://lkml.kernel.org/20241219212437.2714151-1-yosryahmed@google.com/ [2]https://lkml.kernel.org/20250107074724.1756696-2-yosryahmed@google.com/ [3]https://lkml.kernel.org/20250107222236.2715883-2-yosryahmed@google.com/ [yosryahmed@google.com: remove comment]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21693", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "br7LPYZQDykBoEzkc4rGkg==": { "id": "br7LPYZQDykBoEzkc4rGkg==", "updater": "debian/updater", "name": "CVE-2026-68368", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify that the datagram fits within the declared block length. Additionally, when decoding multiple NTBs from a single socket buffer, subsequent block lengths are not checked against the actual remaining buffer data. With these checks missing, a malicious USB host can specify datagram offsets and lengths that point beyond the block, or supply secondary NTB headers declaring lengths larger than the buffer. skb_put_data() then copies adjacent kernel memory from skb_shared_info into the network skb. Fix this by verifying that sufficient buffer space remains for the NTB header before parsing, handling zero-length block declarations, ensuring that block lengths never exceed the remaining buffer space, and verifying that each datagram payload stays strictly within the block boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68368", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "buEdT4BInhnHtAjlzQ/evA==": { "id": "buEdT4BInhnHtAjlzQ/evA==", "updater": "debian/updater", "name": "CVE-2025-38333", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to bail out in get_new_segment() ------------[ cut here ]------------ WARNING: CPU: 3 PID: 579 at fs/f2fs/segment.c:2832 new_curseg+0x5e8/0x6dc pc : new_curseg+0x5e8/0x6dc Call trace: new_curseg+0x5e8/0x6dc f2fs_allocate_data_block+0xa54/0xe28 do_write_page+0x6c/0x194 f2fs_do_write_node_page+0x38/0x78 __write_node_page+0x248/0x6d4 f2fs_sync_node_pages+0x524/0x72c f2fs_write_checkpoint+0x4bc/0x9b0 __checkpoint_and_complete_reqs+0x80/0x244 issue_checkpoint_thread+0x8c/0xec kthread+0x114/0x1bc ret_from_fork+0x10/0x20 get_new_segment() detects inconsistent status in between free_segmap and free_secmap, let's record such error into super block, and bail out get_new_segment() instead of continue using the segment.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38333", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c+Aib934N9AbqiXYLmIOwQ==": { "id": "c+Aib934N9AbqiXYLmIOwQ==", "updater": "debian/updater", "name": "CVE-2025-28164", "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-28164", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libpng1.6", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c+mqOc/mqFarsH0PO+qZHA==": { "id": "c+mqOc/mqFarsH0PO+qZHA==", "updater": "debian/updater", "name": "CVE-2024-57857", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Remove direct link to net_device Do not manage a per device direct link to net_device. Rely on associated ib_devices net_device management, not doubling the effort locally. A badly managed local link to net_device was causing a 'KASAN: slab-use-after-free' exception during siw_query_port() call.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57857", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c/x21M6pcU8su1V/zbVNTQ==": { "id": "c/x21M6pcU8su1V/zbVNTQ==", "updater": "debian/updater", "name": "CVE-2025-11083", "description": "A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11083", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c0sBmQCRvVCT7737MQwU/Q==": { "id": "c0sBmQCRvVCT7737MQwU/Q==", "updater": "debian/updater", "name": "CVE-2026-64319", "description": "In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen \u003c= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64319", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c1tgx9s3K6ntVYm7+9+Fhw==": { "id": "c1tgx9s3K6ntVYm7+9+Fhw==", "updater": "debian/updater", "name": "CVE-2026-68247", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: range check LFP Data Block panel_type2 While the panel_type from LFP Data Block is range checked, panel_type2 is not. Add a few helpers for range checking, and use them to not only check panel_type2, but also improve clarity and correctness in the panel type selection. Discovered using AI-assisted static analysis confirmed by Intel Product Security. v2: - Fix commit message typo (Michał) - Add is_panel_type_pnp() (Ville) (cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68247", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c5zsAjQ64TJlVMAw69YoFg==": { "id": "c5zsAjQ64TJlVMAw69YoFg==", "updater": "debian/updater", "name": "CVE-2024-53176", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: During unmount, ensure all cached dir instances drop their dentry The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can race with various cached directory operations, which ultimately results in dentries not being dropped and these kernel BUGs: BUG: Dentry ffff88814f37e358{i=1000000000080,n=/} still in use (2) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) ------------[ cut here ]------------ kernel BUG at fs/super.c:661! This happens when a cfid is in the process of being cleaned up when, and has been removed from the cfids-\u003eentries list, including: - Receiving a lease break from the server - Server reconnection triggers invalidate_all_cached_dirs(), which removes all the cfids from the list - The laundromat thread decides to expire an old cfid. To solve these problems, dropping the dentry is done in queued work done in a newly-added cfid_put_wq workqueue, and close_all_cached_dirs() flushes that workqueue after it drops all the dentries of which it's aware. This is a global workqueue (rather than scoped to a mount), but the queued work is minimal. The final cleanup work for cleaning up a cfid is performed via work queued in the serverclose_wq workqueue; this is done separate from dropping the dentries so that close_all_cached_dirs() doesn't block on any server operations. Both of these queued works expect to invoked with a cfid reference and a tcon reference to avoid those objects from being freed while the work is ongoing. While we're here, add proper locking to close_all_cached_dirs(), and locking around the freeing of cfid-\u003edentry.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53176", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c78r6gYTO3VN8WrBjUSEOQ==": { "id": "c78r6gYTO3VN8WrBjUSEOQ==", "updater": "debian/updater", "name": "CVE-2025-22028", "description": "In the Linux kernel, the following vulnerability has been resolved: media: vimc: skip .s_stream() for stopped entities Syzbot reported [1] a warning prompted by a check in call_s_stream() that checks whether .s_stream() operation is warranted for unstarted or stopped subdevs. Add a simple fix in vimc_streamer_pipeline_terminate() ensuring that entities skip a call to .s_stream() unless they have been previously properly started. [1] Syzbot report: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 5933 at drivers/media/v4l2-core/v4l2-subdev.c:460 call_s_stream+0x2df/0x350 drivers/media/v4l2-core/v4l2-subdev.c:460 Modules linked in: CPU: 0 UID: 0 PID: 5933 Comm: syz-executor330 Not tainted 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67 #0 ... Call Trace: \u003cTASK\u003e vimc_streamer_pipeline_terminate+0x218/0x320 drivers/media/test-drivers/vimc/vimc-streamer.c:62 vimc_streamer_pipeline_init drivers/media/test-drivers/vimc/vimc-streamer.c:101 [inline] vimc_streamer_s_stream+0x650/0x9a0 drivers/media/test-drivers/vimc/vimc-streamer.c:203 vimc_capture_start_streaming+0xa1/0x130 drivers/media/test-drivers/vimc/vimc-capture.c:256 vb2_start_streaming+0x15f/0x5a0 drivers/media/common/videobuf2/videobuf2-core.c:1789 vb2_core_streamon+0x2a7/0x450 drivers/media/common/videobuf2/videobuf2-core.c:2348 vb2_streamon drivers/media/common/videobuf2/videobuf2-v4l2.c:875 [inline] vb2_ioctl_streamon+0xf4/0x170 drivers/media/common/videobuf2/videobuf2-v4l2.c:1118 __video_do_ioctl+0xaf0/0xf00 drivers/media/v4l2-core/v4l2-ioctl.c:3122 video_usercopy+0x4d2/0x1620 drivers/media/v4l2-core/v4l2-ioctl.c:3463 v4l2_ioctl+0x1ba/0x250 drivers/media/v4l2-core/v4l2-dev.c:366 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:906 [inline] __se_sys_ioctl fs/ioctl.c:892 [inline] __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f2b85c01b19 ...", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22028", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "c8SYJn1GAxyNkF/7gK0HFg==": { "id": "c8SYJn1GAxyNkF/7gK0HFg==", "updater": "debian/updater", "name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2005-2541", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cCE2kvJ6L+TNVLLtkgOVng==": { "id": "cCE2kvJ6L+TNVLLtkgOVng==", "updater": "debian/updater", "name": "CVE-2026-68158", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted osdmap, out-of-bounds memory accesses may occur in decode_new_up_state_weight(). This happens because the bounds check for the new_state part is based on calculating its length depending on a len value read from the incoming message. This calculation may overflow leading to an incorrect bounds check. Subsequently, out-of-bounds reads may occur when decoding this part. This patch switches the multiplication to use check_mul_overflow() to abort processing the osdmap if an overflow occurred. Therefore, osdmaps/messages containing large values for len that result in a multiplication overflow are treated as invalid. [ idryomov: rename new_state_len -\u003e new_state_item_size, formatting ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68158", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cCGIxICmrHrqqkgDQC8qVA==": { "id": "cCGIxICmrHrqqkgDQC8qVA==", "updater": "debian/updater", "name": "CVE-2026-68143", "description": "In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl-\u003elock. slip_receive_buf() reads those fields and writes through rbuff without holding the lock. An MTU change can therefore race with receive processing. An MTU shrink can expose the new smaller rbuff with the old larger bound, causing an out-of-bounds write. A receive callback which already loaded the old rbuff can instead continue writing after that buffer has been freed. Serialize receive processing with sl_realloc_bufs() by holding sl-\u003elock while consuming each receive batch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68143", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cEkDs9u9Cpspxm4MFYaeWQ==": { "id": "cEkDs9u9Cpspxm4MFYaeWQ==", "updater": "debian/updater", "name": "CVE-2026-43416", "description": "In the Linux kernel, the following vulnerability has been resolved: powerpc, perf: Check that current-\u003emm is alive before getting user callchain It may happen that mm is already released, which leads to kernel panic. This adds the NULL check for current-\u003emm, similarly to commit 20afc60f892d (\"x86, perf: Check that current-\u003emm is alive before getting user callchain\"). I was getting this panic when running a profiling BPF program (profile.py from bcc-tools): [26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0) [26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588 [26215.051952] Faulting instruction address: 0xc00000000020fac0 [26215.051957] Oops: Kernel access of bad area, sig: 11 [#1] [...] [26215.052049] Call Trace: [26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable) [26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30 [26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360 [26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0 [26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274 [...] In addition, move storing the top-level stack entry to generic perf_callchain_user to make sure the top-evel entry is always captured, even if current-\u003emm is NULL. [Maddy: fixed message to avoid checkpatch format style error]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43416", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cFyzieI80PEaY8L5vFgLUg==": { "id": "cFyzieI80PEaY8L5vFgLUg==", "updater": "debian/updater", "name": "CVE-2025-40074", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40074", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cOsJlkk2OUfZSPuuxDW5xQ==": { "id": "cOsJlkk2OUfZSPuuxDW5xQ==", "updater": "debian/updater", "name": "CVE-2026-46111", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in create_big_sync Add hci_conn_valid() check in create_big_sync() to detect stale connections before proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the connection under hci_dev_lock() before dereferencing, matching the pattern used by create_le_conn_complete() and create_pa_complete(). Keep the hci_conn object alive across the async boundary by taking a reference via hci_conn_get() when queueing create_big_sync(), and dropping it in the completion callback. The refcount and the lock are complementary: the refcount keeps the object allocated, while hci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on hdev-\u003econn_hash, as required by hci_conn_del(). hci_conn_put() is called outside hci_dev_unlock() so the final put (which resolves to kfree() via bt_link_release) does not run under hdev-\u003elock, though the release path would be safe either way. Without this, create_big_complete() would unconditionally dereference the conn pointer on error, causing a use-after-free via hci_connect_cfm() and hci_conn_del().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46111", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cPVrahyl220g0Gp/+c+Ekw==": { "id": "cPVrahyl220g0Gp/+c+Ekw==", "updater": "debian/updater", "name": "CVE-2026-23226", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del). Adds rw_semaphore chann_lock to struct ksmbd_session and protects all xa_load/xa_store/xa_erase accesses.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23226", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cS7rkbIe2yBX5287dNi5sg==": { "id": "cS7rkbIe2yBX5287dNi5sg==", "updater": "debian/updater", "name": "CVE-2026-23419", "description": "In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp_tune syzbot reported a circular locking dependency in rds_tcp_tune() where sk_net_refcnt_upgrade() is called while holding the socket lock: ====================================================== WARNING: possible circular locking dependency detected ====================================================== kworker/u10:8/15040 is trying to acquire lock: ffffffff8e9aaf80 (fs_reclaim){+.+.}-{0:0}, at: __kmalloc_cache_noprof+0x4b/0x6f0 but task is already holding lock: ffff88805a3c1ce0 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at: rds_tcp_tune+0xd7/0x930 The issue occurs because sk_net_refcnt_upgrade() performs memory allocation (via get_net_track() -\u003e ref_tracker_alloc()) while the socket lock is held, creating a circular dependency with fs_reclaim. Fix this by moving sk_net_refcnt_upgrade() outside the socket lock critical section. This is safe because the fields modified by the sk_net_refcnt_upgrade() call (sk_net_refcnt, ns_tracker) are not accessed by any concurrent code path at this point. v2: - Corrected fixes tag - check patch line wrap nits - ai commentary nits", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23419", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cTXu3OaxY8CyhRj30KQ3nA==": { "id": "cTXu3OaxY8CyhRj30KQ3nA==", "updater": "debian/updater", "name": "CVE-2026-43073", "description": "In the Linux kernel, the following vulnerability has been resolved: x86-64: rename misleadingly named '__copy_user_nocache()' function This function was a masterclass in bad naming, for various historical reasons. It claimed to be a non-cached user copy. It is literally _neither_ of those things. It's a specialty memory copy routine that uses non-temporal stores for the destination (but not the source), and that does exception handling for both source and destination accesses. Also note that while it works for unaligned targets, any unaligned parts (whether at beginning or end) will not use non-temporal stores, since only words and quadwords can be non-temporal on x86. The exception handling means that it _can_ be used for user space accesses, but not on its own - it needs all the normal \"start user space access\" logic around it. But typically the user space access would be the source, not the non-temporal destination. That was the original intention of this, where the destination was some fragile persistent memory target that needed non-temporal stores in order to catch machine check exceptions synchronously and deal with them gracefully. Thus that non-descriptive name: one use case was to copy from user space into a non-cached kernel buffer. However, the existing users are a mix of that intended use-case, and a couple of random drivers that just did this as a performance tweak. Some of those random drivers then actively misused the user copying version (with STAC/CLAC and all) to do kernel copies without ever even caring about the exception handling, _just_ for the non-temporal destination. Rename it as a first small step to actually make it halfway sane, and change the prototype to be more normal: it doesn't take a user pointer unless the caller has done the proper conversion, and the argument size is the full size_t (it still won't actually copy more than 4GB in one go, but there's also no reason to silently truncate the size argument in the caller). Finally, use this now sanely named function in the NTB code, which mis-used a user copy version (with STAC/CLAC and all) of this interface despite it not actually being a user copy at all.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43073", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cTd4017qSU3BkDE+MzazZQ==": { "id": "cTd4017qSU3BkDE+MzazZQ==", "updater": "debian/updater", "name": "CVE-2026-46059", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN For guests with NRIPS disabled, L1 does not provide NextRIP when running an L2 with an injected soft interrupt, instead it advances the current RIP before running it. KVM uses the current RIP as the NextRIP in vmcb02 to emulate a CPU without NRIPS. However, after L2 runs the first time, NextRIP will be updated by the CPU and/or KVM, and the current RIP is no longer the correct value to use in vmcb02. Hence, after save/restore, use the current RIP if and only if a nested run is pending, otherwise use NextRIP. Give soft_int_next_rip the same treatment, as it's the same logic, just for a narrower use case. [sean: give soft_int_next_rip the same treatment]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46059", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cWQ9Gv0TkIKOhqjDE5i5IA==": { "id": "cWQ9Gv0TkIKOhqjDE5i5IA==", "updater": "debian/updater", "name": "CVE-2024-42156", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of clear-key structures on failure Wipe all sensitive data from stack for all IOCTLs, which convert a clear-key into a protected- or secure-key.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42156", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cX0zpkj0M7q5G5AJpCXepg==": { "id": "cX0zpkj0M7q5G5AJpCXepg==", "updater": "debian/updater", "name": "CVE-2026-68234", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo-\u003epin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_reserved() only allocates a new BO when *bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is NULL, it simply skips creation when *bo_ptr is non-NULL. But it unconditionally reserves, pins, gart allocates and maps the BO afterwards. When the same non-NULL BO pointer is passed in again, for example firmware buffers that live in adev and are re-loaded on every resume / cp_resume / start under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases pin_count unconditionally, however the matching teardown only unpins once, so pin_count never drops to zero, so TTM is not able to move, swap or evict a BO, causing BO leaks. This commit fixes this issue by only pinning the bo once at creation, and repeated calls no longer take additional pin references. (cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68234", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cbSORXfR3xlk/2j/nv5Q1Q==": { "id": "cbSORXfR3xlk/2j/nv5Q1Q==", "updater": "debian/updater", "name": "CVE-2026-46014", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Add missing save/restore handling of LBR MSRs MSR_IA32_DEBUGCTLMSR and LBR MSRs are currently not enumerated by KVM_GET_MSR_INDEX_LIST, and LBR MSRs cannot be set with KVM_SET_MSRS. So save/restore is completely broken. Fix it by adding the MSRs to msrs_to_save_base, and allowing writes to LBR MSRs from userspace only (as they are read-only MSRs) if LBR virtualization is enabled. Additionally, to correctly restore L1's LBRs while L2 is running, make sure the LBRs are copied from the captured VMCB01 save area in svm_copy_vmrun_state(). Note, for VMX, this also fixes a flaw where MSR_IA32_DEBUGCTLMSR isn't reported as an MSR to save/restore. Note #2, over-reporting MSR_IA32_LASTxxx on Intel is ok, as KVM already handles unsupported reads and writes thanks to commit b5e2fec0ebc3 (\"KVM: Ignore DEBUGCTL MSRs with no effect\") (kvm_do_msr_access() will morph the unsupported userspace write into a nop). [sean: guard with lbrv checks, massage changelog]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46014", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cfiD+BYptWNUedEJyRszuw==": { "id": "cfiD+BYptWNUedEJyRszuw==", "updater": "debian/updater", "name": "CVE-2025-59375", "description": "libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-59375", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cfv/88ztD/p87G9Py59kmg==": { "id": "cfv/88ztD/p87G9Py59kmg==", "updater": "debian/updater", "name": "CVE-2026-43352", "description": "In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue The logic used to abort the DMA ring contains several flaws: 1. The driver unconditionally issues a ring abort even when the ring has already stopped. 2. The completion used to wait for abort completion is never re-initialized, resulting in incorrect wait behavior. 3. The abort sequence unintentionally clears RING_CTRL_ENABLE, which resets hardware ring pointers and disrupts the controller state. 4. If the ring is already stopped, the abort operation should be considered successful without attempting further action. Fix the abort handling by checking whether the ring is running before issuing an abort, re-initializing the completion when needed, ensuring that RING_CTRL_ENABLE remains asserted during abort, and treating an already stopped ring as a successful condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43352", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cjf0OCUddVeaOOcznR7L+Q==": { "id": "cjf0OCUddVeaOOcznR7L+Q==", "updater": "debian/updater", "name": "CVE-2026-64590", "description": "In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM driver (e.g. amdgpu for video playback in GNOME Videos / Showtime) triggers a spurious warning: DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \\ overlapping mappings aren't supported WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0 The call chain is: amdgpu_cs_ioctl -\u003e amdgpu_ttm_backend_bind -\u003e dma_buf_map_attachment -\u003e [udmabuf] map_udmabuf -\u003e get_sg_table -\u003e dma_map_sgtable(dev, sg, direction, 0) // attrs=0 -\u003e debug_dma_map_sg -\u003e add_dma_entry -\u003e EEXIST This happens because udmabuf builds a per-page scatter-gather list via sg_set_folio(). When begin_cpu_udmabuf() has already created an sg table mapped for the misc device, and an importer such as amdgpu maps the same pages for its own device via map_udmabuf(), the DMA debug infrastructure sees two active mappings whose physical addresses share cacheline boundaries and warns about the overlap. The DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in add_dma_entry() because it signals that no CPU cache maintenance is performed at map/unmap time, making the cacheline overlap harmless. All other major dma-buf exporters already pass this flag: - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC The CPU sync at map/unmap time is also redundant for udmabuf: begin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit cache synchronization via dma_sync_sgtable_for_cpu/device() when CPU access is requested through the dma-buf interface. Pass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and dma_unmap_sgtable() in udmabuf to suppress the spurious warning and skip the redundant sync.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64590", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "clzVgq3hfrfUfnMH/v6WVA==": { "id": "clzVgq3hfrfUfnMH/v6WVA==", "updater": "debian/updater", "name": "CVE-2024-53051", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Sometimes during hotplug scenario or suspend/resume scenario encoder is not always initialized when intel_hdcp_get_capability add a check to avoid kernel null pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53051", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "cw1TUdWPzmOtwmbS1fp9TA==": { "id": "cw1TUdWPzmOtwmbS1fp9TA==", "updater": "debian/updater", "name": "CVE-2026-22996", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv mlx5e_priv is an unstable structure that can be memset(0) if profile attaching fails, mlx5e_priv in mlx5e_dev devlink private is used to reference the netdev and mdev associated with that struct. Instead, store netdev directly into mlx5e_dev and get mdev from the containing mlx5_adev aux device structure. This fixes a kernel oops in mlx5e_remove when switchdev mode fails due to change profile failure. $ devlink dev eswitch set pci/0000:00:03.0 mode switchdev Error: mlx5_core: Failed setting eswitch to offloads. dmesg: workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12 $ devlink dev reload pci/0000:00:03.0 ==\u003e oops BUG: kernel NULL pointer dereference, address: 0000000000000520 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 3 UID: 0 PID: 521 Comm: devlink Not tainted 6.18.0-rc5+ #117 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_remove+0x68/0x130 RSP: 0018:ffffc900034838f0 EFLAGS: 00010246 RAX: ffff88810283c380 RBX: ffff888101874400 RCX: ffffffff826ffc45 RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000 RBP: ffff888102d789c0 R08: ffff8881007137f0 R09: ffff888100264e10 R10: ffffc90003483898 R11: ffffc900034838a0 R12: ffff888100d261a0 R13: ffff888100d261a0 R14: ffff8881018749a0 R15: ffff888101874400 FS: 00007f8565fea740(0000) GS:ffff88856a759000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000520 CR3: 000000010b11a004 CR4: 0000000000370ef0 Call Trace: \u003cTASK\u003e device_release_driver_internal+0x19c/0x200 bus_remove_device+0xc6/0x130 device_del+0x160/0x3d0 ? devl_param_driverinit_value_get+0x2d/0x90 mlx5_detach_device+0x89/0xe0 mlx5_unload_one_devl_locked+0x3a/0x70 mlx5_devlink_reload_down+0xc8/0x220 devlink_reload+0x7d/0x260 devlink_nl_reload_doit+0x45b/0x5a0 genl_family_rcv_msg_doit+0xe8/0x140", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-22996", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d0aaWDMxUoX+Q6AjYLkMvw==": { "id": "d0aaWDMxUoX+Q6AjYLkMvw==", "updater": "debian/updater", "name": "CVE-2026-64576", "description": "In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to call_nexthop_res_bucket_notifiers(). When nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns -ENOMEM), the error is propagated back before any notifier sets extack._msg, and the error path formats the stale pointer with pr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE this dereferences uninitialized stack memory: Oops: general protection fault, probably for non-canonical address ... KASAN: maybe wild-memory-access in range [...] RIP: 0010:string (lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) _printk (kernel/printk/printk.c:2504) nh_res_bucket_migrate (net/ipv4/nexthop.c:1816) nh_res_table_upkeep (net/ipv4/nexthop.c:1866) rtm_new_nexthop (net/ipv4/nexthop.c:3323) rtnetlink_rcv_msg (net/core/rtnetlink.c:7076) netlink_sendmsg (net/netlink/af_netlink.c:1900) Kernel panic - not syncing: Fatal exception Zero-initialize extack so _msg is NULL on error paths that never set it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64576", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d1LyvMDT4Er4mayGqstCMw==": { "id": "d1LyvMDT4Er4mayGqstCMw==", "updater": "debian/updater", "name": "CVE-2024-58012", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during params Each cpu DAI should associate with a widget. However, the topology might not create the right number of DAI widgets for aggregated amps. And it will cause NULL pointer deference. Check that the DAI widget associated with the CPU DAI is valid to prevent NULL pointer deference due to missing DAI widgets in topologies with aggregated amps.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58012", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d3VShHYQEj/Dm98dDAtH8w==": { "id": "d3VShHYQEj/Dm98dDAtH8w==", "updater": "debian/updater", "name": "CVE-2024-49569", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: unquiesce admin_q before destroy it Kernel will hang on destroy admin_q while we create ctrl failed, such as following calltrace: PID: 23644 TASK: ff2d52b40f439fc0 CPU: 2 COMMAND: \"nvme\" #0 [ff61d23de260fb78] __schedule at ffffffff8323bc15 #1 [ff61d23de260fc08] schedule at ffffffff8323c014 #2 [ff61d23de260fc28] blk_mq_freeze_queue_wait at ffffffff82a3dba1 #3 [ff61d23de260fc78] blk_freeze_queue at ffffffff82a4113a #4 [ff61d23de260fc90] blk_cleanup_queue at ffffffff82a33006 #5 [ff61d23de260fcb0] nvme_rdma_destroy_admin_queue at ffffffffc12686ce #6 [ff61d23de260fcc8] nvme_rdma_setup_ctrl at ffffffffc1268ced #7 [ff61d23de260fd28] nvme_rdma_create_ctrl at ffffffffc126919b #8 [ff61d23de260fd68] nvmf_dev_write at ffffffffc024f362 #9 [ff61d23de260fe38] vfs_write at ffffffff827d5f25 RIP: 00007fda7891d574 RSP: 00007ffe2ef06958 RFLAGS: 00000202 RAX: ffffffffffffffda RBX: 000055e8122a4d90 RCX: 00007fda7891d574 RDX: 000000000000012b RSI: 000055e8122a4d90 RDI: 0000000000000004 RBP: 00007ffe2ef079c0 R8: 000000000000012b R9: 000055e8122a4d90 R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000004 R13: 000055e8122923c0 R14: 000000000000012b R15: 00007fda78a54500 ORIG_RAX: 0000000000000001 CS: 0033 SS: 002b This due to we have quiesced admi_q before cancel requests, but forgot to unquiesce before destroy it, as a result we fail to drain the pending requests, and hang on blk_mq_freeze_queue_wait() forever. Here try to reuse nvme_rdma_teardown_admin_queue() to fix this issue and simplify the code.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49569", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d4ETjtVOtjHfsCmyR87WPA==": { "id": "d4ETjtVOtjHfsCmyR87WPA==", "updater": "debian/updater", "name": "CVE-2026-64210", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this triggering on the ICOSQ is done unprotected. There are 2 such races: A) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is running from a different CPU due to affinity change. This can happen because IRQ triggering is done after napi_complete_done(). At this point the NAPI can be scheduled on a different CPU. Like this: CPU A (old affinity, NAPI tail) CPU B (new affinity, fresh NAPI) ------------------------------- -------------------------------- napi_complete_done() clears SCHED mlx5e_cq_arm(...) napi_schedule_prep() sets SCHED mlx5e_napi_poll() mlx5e_xsk_alloc_rx_mpwqe() mlx5e_icosq_sync_lock() // noop memcpy 640 B UMR body advance sq-\u003epc by 10 mlx5e_trigger_irq(\u0026c-\u003eicosq) wqe_info[pi] = {NOP, 1} mlx5e_post_nop() advances sq-\u003epc B) mlx5e_trigger_irq() is called on the ICOSQ when mlx5e_trigger_napi_icosq() is running. The obvious fix would be to lock the ICOSQ. But ICOSQ has an optimized locking scheme that doesn't work for this scenario. Kick the async ICOSQ instead which is always locked. This issue was noticed in the wild with the following splat: netdevice: ge-0-0-1: Bad OP in ICOSQ CQE: 0xd WARNING: drivers/net/ethernet/mellanox/mlx5/core/en_rx.c:826 [...] [...] Call Trace: \u003cIRQ\u003e mlx5e_napi_poll+0x11d/0x7f0 [mlx5_core] __napi_poll+0x30/0x200 ? skb_defer_free_flush+0x9c/0xc0 net_rx_action+0x2fe/0x3f0 handle_softirqs+0xd8/0x340 __irq_exit_rcu+0xbc/0xe0 common_interrupt+0x85/0xa0 \u003c/IRQ\u003e \u003cTASK\u003e asm_common_interrupt+0x26/0x40 [...] ---[ end trace 0000000000000000 ]--- mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2022, qn 0x8f4, opcode 0xd, syndrome 0x2, vendor syndrome 0x68 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000030: 00 00 00 00 01 00 68 02 01 00 08 f4 de 14 59 d2 WQE DUMP: WQ size 16384 WQ cur size 0, WQE index 0x1e14, len: 64 00000000: 00 00 00 01 d9 ed 80 02 00 00 00 01 d9 ed 90 02 00000010: 00 00 00 01 d9 ed a0 02 00 00 00 01 d9 ed b0 02 00000020: 00 00 00 01 d9 ed c0 02 00 00 00 01 d9 ed d0 02 00000030: 00 00 00 01 d9 ed e0 02 00 00 00 01 d9 ed f0 02 mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2023, qn 0x8f4, opcode 0xd, syndrome 0x5, vendor syndrome 0xf9 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000030: 00 00 00 00 01 00 f9 05 01 00 08 f4 de 15 cf d2", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64210", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d4Wj41RNFZ7ktyiP6AmZ3g==": { "id": "d4Wj41RNFZ7ktyiP6AmZ3g==", "updater": "debian/updater", "name": "CVE-2026-45855", "description": "In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: avoid Non-NCQ command starvation When a non-NCQ command is issued while NCQ commands are being executed, ata_scsi_qc_issue() indicates to the SCSI layer that the command issuing should be deferred by returning SCSI_MLQUEUE_XXX_BUSY. This command deferring is correct and as mandated by the ACS specifications since NCQ and non-NCQ commands cannot be mixed. However, in the case of a host adapter using multiple submission queues, when the target device is under a constant load of NCQ commands, there are no guarantees that requeueing the non-NCQ command will be executed later and it may be deferred again repeatedly as other submission queues can constantly issue NCQ commands from different CPUs ahead of the non-NCQ command. This can lead to very long delays for the execution of non-NCQ commands, and even complete starvation for these commands in the worst case scenario. Since the block layer and the SCSI layer do not distinguish between queueable (NCQ) and non queueable (non-NCQ) commands, libata-scsi SAT implementation must ensure forward progress for non-NCQ commands in the presence of NCQ command traffic. This is similar to what SAS HBAs with a hardware/firmware based SAT implementation do. Implement such forward progress guarantee by limiting requeueing of non-NCQ commands from ata_scsi_qc_issue(): when a non-NCQ command is received and NCQ commands are in-flight, do not force a requeue of the non-NCQ command by returning SCSI_MLQUEUE_XXX_BUSY and instead return 0 to indicate that the command was accepted but hold on to the qc using the new deferred_qc field of struct ata_port. This deferred qc will be issued using the work item deferred_qc_work running the function ata_scsi_deferred_qc_work() once all in-flight commands complete, which is checked with the port qc_defer() callback return value indicating that no further delay is necessary. This check is done using the helper function ata_scsi_schedule_deferred_qc() which is called from ata_scsi_qc_complete(). This thus excludes this mechanism from all internal non-NCQ commands issued by ATA EH. When a port deferred_qc is non NULL, that is, the port has a command waiting for the device queue to drain, the issuing of all incoming commands (both NCQ and non-NCQ) is deferred using the regular busy mechanism. This simplifies the code and also avoids potential denial of service problems if a user issues too many non-NCQ commands. Finally, whenever ata EH is scheduled, regardless of the reason, a deferred qc is always requeued so that it can be retried once EH completes. This is done by calling the function ata_scsi_requeue_deferred_qc() from ata_eh_set_pending(). This avoids the need for any special processing for the deferred qc in case of NCQ error, link or device reset, or device timeout.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45855", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d59u3XRZGdnK2xtdhx8bMg==": { "id": "d59u3XRZGdnK2xtdhx8bMg==", "updater": "debian/updater", "name": "CVE-2026-56132", "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56132", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "d8rA+u4msoco+ymnNKq3tA==": { "id": "d8rA+u4msoco+ymnNKq3tA==", "updater": "debian/updater", "name": "CVE-2026-64341", "description": "In the Linux kernel, the following vulnerability has been resolved: USB: iowarrior: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2] Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect(). [1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\") [2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most other sleeping locks, can still use the lock object after it's unlocked\")", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64341", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dASWaRulk6HSMFrYTrSg/g==": { "id": "dASWaRulk6HSMFrYTrSg/g==", "updater": "debian/updater", "name": "CVE-2024-49906", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointer before try to access it [why \u0026 how] Change the order of the pipe_ctx-\u003eplane_state check to ensure that plane_state is not null before accessing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49906", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dBAGfhWDcEAx2Uc8DY0PeA==": { "id": "dBAGfhWDcEAx2Uc8DY0PeA==", "updater": "debian/updater", "name": "CVE-2026-68243", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU Setting context engine slot N into I915_ENGINE_CLASS_INVALID / I915_ENGINE_CLASS_INVALID_NONE and attempting to apply I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL. Fix that. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68243", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dEb3nK/PwybHr3KGCX3LoA==": { "id": "dEb3nK/PwybHr3KGCX3LoA==", "updater": "debian/updater", "name": "CVE-2026-58055", "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58055", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "nghttp2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dGGcNaPBE98Zf2/IcqDkaA==": { "id": "dGGcNaPBE98Zf2/IcqDkaA==", "updater": "debian/updater", "name": "CVE-2026-43048", "description": "In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid_report_raw_event() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end of the buffer. However, as we have previously seen, doing so can easily result in OOB reads and writes in the subsequent thread of execution. The current suggestion from one of the HID maintainers is to remove the memset() and simply return if the incoming event buffer size is not large enough to fill the associated report. Suggested-by Benjamin Tissoires \u003cbentiss@kernel.org\u003e [bentiss: changed the return value]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43048", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dGQe1jlLm01G2RlSenIKgg==": { "id": "dGQe1jlLm01G2RlSenIKgg==", "updater": "debian/updater", "name": "CVE-2025-69651", "description": "GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69651", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dGkCup6dLBkxUtIMUMHbtQ==": { "id": "dGkCup6dLBkxUtIMUMHbtQ==", "updater": "debian/updater", "name": "CVE-2026-64079", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the per-netns hook ops copy via kmemdup_array(). This leaves a window where the table is visible in the list with ops=NULL. If the pernet exit happens runs concurrently the pre_exit callback finds the table via xt_find_table() and passes the NULL ops pointer to nf_unregister_net_hooks(), causing a NULL dereference: general protection fault in nf_unregister_net_hooks+0xbc/0x150 RIP: nf_unregister_net_hooks (net/netfilter/core.c:613) Call Trace: ipt_unregister_table_pre_exit iptable_mangle_net_pre_exit ops_pre_exit_list cleanup_net Fix by moving the ops allocation into the xtables core so the table is never in the list without valid ops. Also ensure the table is no longer processing packets before its torn down on error unwind. nf_register_net_hooks might have published at least one hook; call synchronize_rcu() if there was an error. audit log register message gets deferred until all operations have passed, this avoids need to emit another ureg message in case of error unwinding. Based on earlier patch by Tristan Madani.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64079", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dHzaD2Y00RGnXHcbRlDrUA==": { "id": "dHzaD2Y00RGnXHcbRlDrUA==", "updater": "debian/updater", "name": "CVE-2022-44032", "description": "An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cmm_open() and cm4000_detach().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-44032", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dIr9Ixsp5HnH41WPm8/HFQ==": { "id": "dIr9Ixsp5HnH41WPm8/HFQ==", "updater": "debian/updater", "name": "CVE-2025-38359", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix in_atomic() handling in do_secure_storage_access() Kernel user spaces accesses to not exported pages in atomic context incorrectly try to resolve the page fault. With debug options enabled call traces like this can be seen: BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1523 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 419074, name: qemu-system-s39 preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 INFO: lockdep is turned off. Preemption disabled at: [\u003c00000383ea47cfa2\u003e] copy_page_from_iter_atomic+0xa2/0x8a0 CPU: 12 UID: 0 PID: 419074 Comm: qemu-system-s39 Tainted: G W 6.16.0-20250531.rc0.git0.69b3a602feac.63.fc42.s390x+debug #1 PREEMPT Tainted: [W]=WARN Hardware name: IBM 3931 A01 703 (LPAR) Call Trace: [\u003c00000383e990d282\u003e] dump_stack_lvl+0xa2/0xe8 [\u003c00000383e99bf152\u003e] __might_resched+0x292/0x2d0 [\u003c00000383eaa7c374\u003e] down_read+0x34/0x2d0 [\u003c00000383e99432f8\u003e] do_secure_storage_access+0x108/0x360 [\u003c00000383eaa724b0\u003e] __do_pgm_check+0x130/0x220 [\u003c00000383eaa842e4\u003e] pgm_check_handler+0x114/0x160 [\u003c00000383ea47d028\u003e] copy_page_from_iter_atomic+0x128/0x8a0 ([\u003c00000383ea47d016\u003e] copy_page_from_iter_atomic+0x116/0x8a0) [\u003c00000383e9c45eae\u003e] generic_perform_write+0x16e/0x310 [\u003c00000383e9eb87f4\u003e] ext4_buffered_write_iter+0x84/0x160 [\u003c00000383e9da0de4\u003e] vfs_write+0x1c4/0x460 [\u003c00000383e9da123c\u003e] ksys_write+0x7c/0x100 [\u003c00000383eaa7284e\u003e] __do_syscall+0x15e/0x280 [\u003c00000383eaa8417e\u003e] system_call+0x6e/0x90 INFO: lockdep is turned off. It is not allowed to take the mmap_lock while in atomic context. Therefore handle such a secure storage access fault as if the accessed page is not mapped: the uaccess function will return -EFAULT, and the caller has to deal with this. Usually this means that the access is retried in process context, which allows to resolve the page fault (or in this case export the page).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38359", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dJSdlRZsvhGjIVE5Ol5PvA==": { "id": "dJSdlRZsvhGjIVE5Ol5PvA==", "updater": "debian/updater", "name": "CVE-2026-68194", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus. mt7921_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the mmio queue ops implement that callback; on USB and SDIO it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:0x0 Call Trace: mt7921_mac_tx_free+0x64/0x310 [mt7921_common] mt7921_rx_check+0x5f/0xf0 [mt7921_common] mt76u_rx_worker+0x1b9/0x620 [mt76_usb] Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for non-mmio devices\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68194", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dK5VsavHbrJfcH/kIwHYaQ==": { "id": "dK5VsavHbrJfcH/kIwHYaQ==", "updater": "debian/updater", "name": "CVE-2026-43204", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6asm: drop DSP responses for closed data streams 'Commit a354f030dbce (\"ASoC: qcom: q6asm: handle the responses after closing\")' attempted to ignore DSP responses arriving after a stream had been closed. However, those responses were still handled, causing lockups. Fix this by unconditionally dropping all DSP responses associated with closed data streams.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43204", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dKgSHf0ATLcRYz460eZ3Cg==": { "id": "dKgSHf0ATLcRYz460eZ3Cg==", "updater": "debian/updater", "name": "CVE-2026-68333", "description": "In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The switch port connect path stores that device in mac-\u003emc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only closes the MAC and frees the dpaa2_mac object. It does not drop the endpoint device reference stored in mac-\u003emc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference before freeing the dpaa2_mac object.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68333", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dNm7m8S2foMYQ6OzUGB8fA==": { "id": "dNm7m8S2foMYQ6OzUGB8fA==", "updater": "debian/updater", "name": "CVE-2026-23465", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: log new dentries when logging parent dir of a conflicting inode If we log the parent directory of a conflicting inode, we are not logging the new dentries of the directory, so when we finish we have the parent directory's inode marked as logged but we did not log its new dentries. As a consequence if the parent directory is explicitly fsynced later and it does not have any new changes since we logged it, the fsync is a no-op and after a power failure the new dentries are missing. Example scenario: $ mkdir foo $ sync $rmdir foo $ mkdir dir1 $ mkdir dir2 # A file with the same name and parent as the directory we just deleted # and was persisted in a past transaction. So the deleted directory's # inode is a conflicting inode of this new file's inode. $ touch foo $ ln foo dir2/link # The fsync on dir2 will log the parent directory (\".\") because the # conflicting inode (deleted directory) does not exists anymore, but it # it does not log its new dentries (dir1). $ xfs_io -c \"fsync\" dir2 # This fsync on the parent directory is no-op, since the previous fsync # logged it (but without logging its new dentries). $ xfs_io -c \"fsync\" . \u003cpower failure\u003e # After log replay dir1 is missing. Fix this by ensuring we log new dir dentries whenever we log the parent directory of a no longer existing conflicting inode. A test case for fstests will follow soon.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23465", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dS8Cxn8/LaNiQCvBYdq7Vg==": { "id": "dS8Cxn8/LaNiQCvBYdq7Vg==", "updater": "debian/updater", "name": "CVE-2025-8941", "description": "A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a \"complete\" fix for CVE-2025-6020.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8941", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "pam", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dSdqqjk3yXpPTfjox/jBBg==": { "id": "dSdqqjk3yXpPTfjox/jBBg==", "updater": "debian/updater", "name": "CVE-2026-68198", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy(). If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info-\u003eaggr_conn) in aggr_module_destroy(). Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68198", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dUtIAkfbSAmbKtPLlwkJwA==": { "id": "dUtIAkfbSAmbKtPLlwkJwA==", "updater": "debian/updater", "name": "CVE-2026-31723", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -\u003e /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31723", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dXyvpx0uFAcdUbyal2rtbg==": { "id": "dXyvpx0uFAcdUbyal2rtbg==", "updater": "debian/updater", "name": "CVE-2024-46775", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate function returns [WHAT \u0026 HOW] Function return values must be checked before data can be used in subsequent functions. This fixes 4 CHECKED_RETURN issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46775", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "daGu3oAT3vmj5Wg7ZkBIOQ==": { "id": "daGu3oAT3vmj5Wg7ZkBIOQ==", "updater": "debian/updater", "name": "CVE-2024-26756", "description": "In the Linux kernel, the following vulnerability has been resolved: md: Don't register sync_thread for reshape directly Currently, if reshape is interrupted, then reassemble the array will register sync_thread directly from pers-\u003erun(), in this case 'MD_RECOVERY_RUNNING' is set directly, however, there is no guarantee that md_do_sync() will be executed, hence stop_sync_thread() will hang because 'MD_RECOVERY_RUNNING' can't be cleared. Last patch make sure that md_do_sync() will set MD_RECOVERY_DONE, however, following hang can still be triggered by dm-raid test shell/lvconvert-raid-reshape.sh occasionally: [root@fedora ~]# cat /proc/1982/stack [\u003c0\u003e] stop_sync_thread+0x1ab/0x270 [md_mod] [\u003c0\u003e] md_frozen_sync_thread+0x5c/0xa0 [md_mod] [\u003c0\u003e] raid_presuspend+0x1e/0x70 [dm_raid] [\u003c0\u003e] dm_table_presuspend_targets+0x40/0xb0 [dm_mod] [\u003c0\u003e] __dm_destroy+0x2a5/0x310 [dm_mod] [\u003c0\u003e] dm_destroy+0x16/0x30 [dm_mod] [\u003c0\u003e] dev_remove+0x165/0x290 [dm_mod] [\u003c0\u003e] ctl_ioctl+0x4bb/0x7b0 [dm_mod] [\u003c0\u003e] dm_ctl_ioctl+0x11/0x20 [dm_mod] [\u003c0\u003e] vfs_ioctl+0x21/0x60 [\u003c0\u003e] __x64_sys_ioctl+0xb9/0xe0 [\u003c0\u003e] do_syscall_64+0xc6/0x230 [\u003c0\u003e] entry_SYSCALL_64_after_hwframe+0x6c/0x74 Meanwhile mddev-\u003erecovery is: MD_RECOVERY_RUNNING | MD_RECOVERY_INTR | MD_RECOVERY_RESHAPE | MD_RECOVERY_FROZEN Fix this problem by remove the code to register sync_thread directly from raid10 and raid5. And let md_check_recovery() to register sync_thread.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26756", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dbr/eJTKVL+PlwpJky5WYQ==": { "id": "dbr/eJTKVL+PlwpJky5WYQ==", "updater": "debian/updater", "name": "CVE-2017-11754", "description": "The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-11754", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dd1K9exjqjFQptWN+pGz8g==": { "id": "dd1K9exjqjFQptWN+pGz8g==", "updater": "debian/updater", "name": "CVE-2024-45015", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable() For cases where the crtc's connectors_changed was set without enable/active getting toggled , there is an atomic_enable() call followed by an atomic_disable() but without an atomic_mode_set(). This results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in the atomic_enable() as the dpu_encoder's connector was cleared in the atomic_disable() but not re-assigned as there was no atomic_mode_set() call. Fix the NULL ptr access by moving the assignment for atomic_enable() and also use drm_atomic_get_new_connector_for_encoder() to get the connector from the atomic_state. Patchwork: https://patchwork.freedesktop.org/patch/606729/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-45015", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ddTPBzeeJYnba7jCapgbAQ==": { "id": "ddTPBzeeJYnba7jCapgbAQ==", "updater": "debian/updater", "name": "CVE-2026-32778", "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32778", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dg3K65C8jJdIi+d/SalX6w==": { "id": "dg3K65C8jJdIi+d/SalX6w==", "updater": "debian/updater", "name": "CVE-2026-43362", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message() encrypts iov[1] in-place, replacing the original plaintext with ciphertext. On a replayable error, the retry sends the same iov[1] which now contains ciphertext instead of the original data, resulting in corruption. The corruption is most likely to be observed when connections are unstable, as reconnects trigger write retries that re-send the already-encrypted data. This affects SFU mknod, MF symlinks, etc. On kernels before 6.10 (prior to the netfs conversion), sync writes also used this path and were similarly affected. The async write path wasn't unaffected as it uses rq_iter which gets deep-copied. Fix by moving the write payload into rq_iter via iov_iter_kvec(), so smb3_init_transform_rq() deep-copies it before encryption.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43362", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dl965O/zOjLqXHSSKKeKCg==": { "id": "dl965O/zOjLqXHSSKKeKCg==", "updater": "debian/updater", "name": "CVE-2026-31502", "description": "In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethernet ports Similar to commit 950803f72547 (\"bonding: fix type confusion in bond_setup_by_slave()\") team has the same class of header_ops type confusion. For non-Ethernet ports, team_setup_by_port() copies port_dev-\u003eheader_ops directly. When the team device later calls dev_hard_header() or dev_parse_header(), these callbacks can run with the team net_device instead of the real lower device, so netdev_priv(dev) is interpreted as the wrong private type and can crash. The syzbot report shows a crash in bond_header_create(), but the root cause is in team: the topology is gre -\u003e bond -\u003e team, and team calls the inherited header_ops with its own net_device instead of the lower device, so bond_header_create() receives a team device and interprets netdev_priv() as bonding private data, causing a type confusion crash. Fix this by introducing team header_ops wrappers for create/parse, selecting a team port under RCU, and calling the lower device callbacks with port-\u003edev, so each callback always sees the correct net_device context. Also pass the selected lower device to the lower parse callback, so recursion is bounded in stacked non-Ethernet topologies and parse callbacks always run with the correct device context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31502", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dlsfp46B9QH8SoQZzW6+/w==": { "id": "dlsfp46B9QH8SoQZzW6+/w==", "updater": "debian/updater", "name": "CVE-2026-64586", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and the debugfs \"reset\" entry both schedule drvr-\u003ebus_reset, whose callback recovers drvr through container_of() and dereferences it. The removal path frees drvr (brcmf_free -\u003e wiphy_free) without draining the work, so a bus_reset callback pending or running during removal can outlive drvr. Cancellation cannot live in brcmf_detach() or brcmf_free(): the work callback reaches teardown through the bus .reset op (PCIe brcmf_pcie_reset -\u003e brcmf_detach; SDIO brcmf_sdio_bus_reset -\u003e brcmf_sdiod_remove -\u003e brcmf_free), so cancelling there would wait for the running work and deadlock. Add a per-bus mutex (bus_reset_lock) and route all arming through brcmf_bus_schedule_reset(), which under the lock skips when the bus is marked removing. Each bus remove entry calls brcmf_bus_cancel_reset_work(), which under the same lock sets removing and cancels the work. Holding the mutex across cancel_work_sync() makes the set-removing + drain step atomic. Every producer reaches the arming path from process context -- the PCIe firmware-halt notification runs in the threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail path runs from the data workqueue -- so the mutex is taken only in sleepable contexts. Where applicable the remove entry first stops the firmware-crash producer: on PCIe mask the mailbox and synchronize_irq; on SDIO unregister the bus interrupt and cancel the data worker, which also reports firmware halts through brcmf_fw_crashed(). The mutex is initialized at bus allocation. The SDIO suspend power-off path frees drvr through the same brcmf_sdiod_remove() and takes the same lock; resume re-allows the work only on a successful re-probe. Also guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire before brcmf_attach() wires up drvr, and it dereferences drvr (bphy_err/brcmf_dev_coredump) before reaching the arming gate. The bus_reset work is shared across buses, so the drain is applied to every remove path: PCIe (the .reset op introduced by the Fixes commit), SDIO (arms the same work through brcmf_fw_crashed()), and USB (via the debugfs \"reset\" entry). cancel_work_sync() drains a running or pending bus_reset work item before removal frees drvr, and patch 1/2 makes the scratch-buffer release safe when reset teardown has already released those DMA buffers. This patch fixes the lifetime of the bus_reset work item itself. It does not attempt to address the separate, pre-existing lifetime of the asynchronous firmware completion started by the PCIe reset path. That callback needs its own lifetime/ownership protocol and is being tracked separately. This issue was found by an in-house static analysis tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64586", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dno/h8+cbyT8NDmhCje7og==": { "id": "dno/h8+cbyT8NDmhCje7og==", "updater": "debian/updater", "name": "CVE-2025-23132", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix to avoid warning in dquot_writeback_dquots() F2FS-fs (dm-59): checkpoint=enable has some unwritten data. ------------[ cut here ]------------ WARNING: CPU: 6 PID: 8013 at fs/quota/dquot.c:691 dquot_writeback_dquots+0x2fc/0x308 pc : dquot_writeback_dquots+0x2fc/0x308 lr : f2fs_quota_sync+0xcc/0x1c4 Call trace: dquot_writeback_dquots+0x2fc/0x308 f2fs_quota_sync+0xcc/0x1c4 f2fs_write_checkpoint+0x3d4/0x9b0 f2fs_issue_checkpoint+0x1bc/0x2c0 f2fs_sync_fs+0x54/0x150 f2fs_do_sync_file+0x2f8/0x814 __f2fs_ioctl+0x1960/0x3244 f2fs_ioctl+0x54/0xe0 __arm64_sys_ioctl+0xa8/0xe4 invoke_syscall+0x58/0x114 checkpoint and f2fs_remount may race as below, resulting triggering warning in dquot_writeback_dquots(). atomic write remount - do_remount - down_write(\u0026sb-\u003es_umount); - f2fs_remount - ioctl - f2fs_do_sync_file - f2fs_sync_fs - f2fs_write_checkpoint - block_operations - locked = down_read_trylock(\u0026sbi-\u003esb-\u003es_umount) : fail to lock due to the write lock was held by remount - up_write(\u0026sb-\u003es_umount); - f2fs_quota_sync - dquot_writeback_dquots - WARN_ON_ONCE(!rwsem_is_locked(\u0026sb-\u003es_umount)) : trigger warning because s_umount lock was unlocked by remount If checkpoint comes from mount/umount/remount/freeze/quotactl, caller of checkpoint has already held s_umount lock, calling dquot_writeback_dquots() in the context should be safe. So let's record task to sbi-\u003eumount_lock_holder, so that checkpoint can know whether the lock has held in the context or not by checking current w/ it. In addition, in order to not misrepresent caller of checkpoint, we should not allow to trigger async checkpoint for those callers: mount/umount/remount/ freeze/quotactl.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-23132", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dqjoY6LI7HXbG/ZNHxRFxg==": { "id": "dqjoY6LI7HXbG/ZNHxRFxg==", "updater": "debian/updater", "name": "CVE-2024-47661", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t [WHAT \u0026 HOW] dmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned 0xFFFF. Fix it by changing it to uint8_t with value of 0xFF. This fixes 2 INTEGER_OVERFLOW issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-47661", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "drbuoWX/fF9k6u07fsRX6Q==": { "id": "drbuoWX/fF9k6u07fsRX6Q==", "updater": "debian/updater", "name": "CVE-2008-1688", "description": "Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-1688", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "m4", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dsSTmk6uj2ELZGZZ+QDrfQ==": { "id": "dsSTmk6uj2ELZGZZ+QDrfQ==", "updater": "debian/updater", "name": "CVE-2026-8932", "description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8932", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dsprIFZqyCzKBLzZu3GFrg==": { "id": "dsprIFZqyCzKBLzZu3GFrg==", "updater": "debian/updater", "name": "CVE-2026-68428", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module reload mmu_destroy_caches() destroys pte_list_desc_cache and mmu_page_header_cache, but leaves both pointers unchanged. The pointers live in kvm.ko, and therefore survive when a vendor module is unloaded while kvm.ko remains loaded. If creation of pte_list_desc_cache fails during a subsequent vendor module load, its assignment sets pte_list_desc_cache to NULL and the error path calls mmu_destroy_caches(). mmu_page_header_cache still points to the cache destroyed during the preceding vendor module unload. Passing that stale pointer to kmem_cache_destroy() causes a slab use-after-free. Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y, CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A one-shot test hook forces pte_list_desc_cache to NULL on the second invocation of kvm_mmu_vendor_module_init(): 1. Load kvm.ko and kvm-intel.ko, creating both caches. 2. Unload only kvm_intel, leaving kvm.ko loaded. 3. Reload kvm_intel and force initialization through the -ENOMEM path. KASAN reports: BUG: KASAN: slab-use-after-free in kvm_mmu_vendor_module_init+0x5b/0x170 [kvm] ... kmem_cache_destroy+0x21/0x1d0 kvm_mmu_vendor_module_init+0x5b/0x170 [kvm] ... Allocated by task 16817: __kmem_cache_create_args+0x12c/0x3b0 __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm] kvm_mmu_vendor_module_init+0x13b/0x170 [kvm] ... Freed by task 16820: kmem_cache_destroy+0x117/0x1d0 kvm_mmu_vendor_module_exit+0x21/0x30 [kvm] Clear both pointers immediately after destroying their caches so that the stored state reflects the caches' lifetime and repeated cleanup is safe. With the fix applied, the same injected vendor module reload fails with -ENOMEM as expected and produces no KASAN report.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68428", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "durgJGXj4cHm6E0amlfNVA==": { "id": "durgJGXj4cHm6E0amlfNVA==", "updater": "debian/updater", "name": "CVE-2026-68251", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68251", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dvmQ2v1rsHGGjW3x+eKSvQ==": { "id": "dvmQ2v1rsHGGjW3x+eKSvQ==", "updater": "debian/updater", "name": "CVE-2026-68294", "description": "In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a single global node id (always 1) and qrtr_ports is a single global xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that global state with no network-namespace check, and qrtr_create() places no restriction on the namespace a socket is created in. As a result an unprivileged process that creates an AF_QIPCRTR socket in a separate network namespace, e.g. via unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams - including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR sockets owned by another namespace, and vice versa. The receiving socket sees such a message as coming from node id 1, indistinguishable from a legitimate local client, breaking the isolation that network namespaces are expected to provide. QRTR is a transport to global hardware endpoints (the modem and other remote processors) and has no per-namespace semantics; its in-kernel name service already creates its socket in init_net only. Confine the socket family to the initial network namespace, as other non-namespace-aware socket families do (see llc_ui_create() and the ieee802154 socket code).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68294", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dvz7cMDPMtmwIDAwMwXWkA==": { "id": "dvz7cMDPMtmwIDAwMwXWkA==", "updater": "debian/updater", "name": "CVE-2023-53781", "description": "In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in tcp_write_timer_handler(). With Eric's ref tracker, syzbot finally found a repro for use-after-free in tcp_write_timer_handler() by kernel TCP sockets. [0] If SMC creates a kernel socket in __smc_create(), the kernel socket is supposed to be freed in smc_clcsock_release() by calling sock_release() when we close() the parent SMC socket. However, at the end of smc_clcsock_release(), the kernel socket's sk_state might not be TCP_CLOSE. This means that we have not called inet_csk_destroy_sock() in __tcp_close() and have not stopped the TCP timers. The kernel socket's TCP timers can be fired later, so we need to hold a refcnt for net as we do for MPTCP subflows in mptcp_subflow_create_socket(). [0]: leaked reference. sk_alloc (./include/net/net_namespace.h:335 net/core/sock.c:2108) inet_create (net/ipv4/af_inet.c:319 net/ipv4/af_inet.c:244) __sock_create (net/socket.c:1546) smc_create (net/smc/af_smc.c:3269 net/smc/af_smc.c:3284) __sock_create (net/socket.c:1546) __sys_socket (net/socket.c:1634 net/socket.c:1618 net/socket.c:1661) __x64_sys_socket (net/socket.c:1672) do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:120) ================================================================== BUG: KASAN: slab-use-after-free in tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594) Read of size 1 at addr ffff888052b65e0d by task syzrepro/18091 CPU: 0 PID: 18091 Comm: syzrepro Tainted: G W 6.3.0-rc4-01174-gb5d54eb5899a #7 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-1.amzn2022.0.1 04/01/2014 Call Trace: \u003cIRQ\u003e dump_stack_lvl (lib/dump_stack.c:107) print_report (mm/kasan/report.c:320 mm/kasan/report.c:430) kasan_report (mm/kasan/report.c:538) tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594) tcp_write_timer (./include/linux/spinlock.h:390 net/ipv4/tcp_timer.c:643) call_timer_fn (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/timer.h:127 kernel/time/timer.c:1701) __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2022) run_timer_softirq (kernel/time/timer.c:2037) __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:572) __irq_exit_rcu (kernel/softirq.c:445 kernel/softirq.c:650) irq_exit_rcu (kernel/softirq.c:664) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1107 (discriminator 14)) \u003c/IRQ\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53781", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dwFzWQHBBqGTbd9kSgDcoA==": { "id": "dwFzWQHBBqGTbd9kSgDcoA==", "updater": "debian/updater", "name": "CVE-2026-68337", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri(), which dereferences the current-\u003ebpf_net_context unconditionally. That context is established on the paths that run tc BPF such as sch_handle_{ingress,egress}(), *except* for the case where {cls,act}_bpf was attached to a proper qdisc. A program running from there reaches the NULL deref in two ways: * It calls bpf_redirect() directly, which dereferences the context at the top of the helper: tc qdisc add dev eth0 root handle 1: red limit 1MB min 10KB max 20KB \\ avpkt 1000 burst 100 qevent early_drop block 10 tc filter add block 10 pref 1 bpf obj redirect.o * It simply returns TC_ACT_REDIRECT without helper call: tcf_qevent_handle() then dispatches to skb_do_redirect(), which dereferences the context Rather than extending bpf_net_context management into the qdisc path, make the redirect helpers refuse to operate when no context exists, and have tcf_qevent_handle() drop a TC_ACT_REDIRECT verdict instead of calling skb_do_redirect(). Previous behaviour was a crash, so nothing regresses by not supporting it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68337", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "dynHmBSsNbcoeh0tpdlFhg==": { "id": "dynHmBSsNbcoeh0tpdlFhg==", "updater": "debian/updater", "name": "CVE-2026-48962", "description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-48962", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "e8oBnqMThOSsFMwmFoH9HQ==": { "id": "e8oBnqMThOSsFMwmFoH9HQ==", "updater": "debian/updater", "name": "CVE-2024-53218", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix race in concurrent f2fs_stop_gc_thread In my test case, concurrent calls to f2fs shutdown report the following stack trace: Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85 Call Trace: \u003cTASK\u003e ? show_regs+0x8b/0xa0 ? __die_body+0x26/0xa0 ? die_addr+0x54/0x90 ? exc_general_protection+0x24b/0x5c0 ? asm_exc_general_protection+0x26/0x30 ? kthread_stop+0x46/0x390 f2fs_stop_gc_thread+0x6c/0x110 f2fs_do_shutdown+0x309/0x3a0 f2fs_ioc_shutdown+0x150/0x1c0 __f2fs_ioctl+0xffd/0x2ac0 f2fs_ioctl+0x76/0xe0 vfs_ioctl+0x23/0x60 __x64_sys_ioctl+0xce/0xf0 x64_sys_call+0x2b1b/0x4540 do_syscall_64+0xa7/0x240 entry_SYSCALL_64_after_hwframe+0x76/0x7e The root cause is a race condition in f2fs_stop_gc_thread() called from different f2fs shutdown paths: [CPU0] [CPU1] ---------------------- ----------------------- f2fs_stop_gc_thread f2fs_stop_gc_thread gc_th = sbi-\u003egc_thread gc_th = sbi-\u003egc_thread kfree(gc_th) sbi-\u003egc_thread = NULL \u003c gc_th != NULL \u003e kthread_stop(gc_th-\u003ef2fs_gc_task) //UAF The commit c7f114d864ac (\"f2fs: fix to avoid use-after-free in f2fs_stop_gc_thread()\") attempted to fix this issue by using a read semaphore to prevent races between shutdown and remount threads, but it fails to prevent all race conditions. Fix it by converting to write lock of s_umount in f2fs_do_shutdown().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53218", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "e8yl8xEHcBMt6QNxIxnCxw==": { "id": "e8yl8xEHcBMt6QNxIxnCxw==", "updater": "debian/updater", "name": "CVE-2025-38692", "description": "In the Linux kernel, the following vulnerability has been resolved: exfat: add cluster chain loop check for dir An infinite loop may occur if the following conditions occur due to file system corruption. (1) Condition for exfat_count_dir_entries() to loop infinitely. - The cluster chain includes a loop. - There is no UNUSED entry in the cluster chain. (2) Condition for exfat_create_upcase_table() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and up-case table entry in the cluster chain of the root directory. (3) Condition for exfat_load_bitmap() to loop infinitely. - The cluster chain of the root directory includes a loop. - There are no UNUSED entry and bitmap entry in the cluster chain of the root directory. (4) Condition for exfat_find_dir_entry() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. (5) Condition for exfat_check_dir_empty() to loop infinitely. - The cluster chain includes a loop. - The unused directory entries were exhausted by some operation. - All files and sub-directories under the directory are deleted. This commit adds checks to break the above infinite loop.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38692", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "e9wCn09MX9e/m/J6umidJA==": { "id": "e9wCn09MX9e/m/J6umidJA==", "updater": "debian/updater", "name": "CVE-2026-43308", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() There is no need to BUG(), we can just return an error and log an error message.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43308", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eA2NK3nIYMq+exBDZhhXCA==": { "id": "eA2NK3nIYMq+exBDZhhXCA==", "updater": "debian/updater", "name": "CVE-2025-39744", "description": "In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work During rcu_read_unlock_special(), if this happens during irq_exit(), we can lockup if an IPI is issued. This is because the IPI itself triggers the irq_exit() path causing a recursive lock up. This is precisely what Xiongfeng found when invoking a BPF program on the trace_tick_stop() tracepoint As shown in the trace below. Fix by managing the irq_work state correctly. irq_exit() __irq_exit_rcu() /* in_hardirq() returns false after this */ preempt_count_sub(HARDIRQ_OFFSET) tick_irq_exit() tick_nohz_irq_exit() \t tick_nohz_stop_sched_tick() \t trace_tick_stop() /* a bpf prog is hooked on this trace point */ \t\t __bpf_trace_tick_stop() \t\t bpf_trace_run2() \t\t\t rcu_read_unlock_special() /* will send a IPI to itself */ \t\t\t irq_work_queue_on(\u0026rdp-\u003edefer_qs_iw, rdp-\u003ecpu); A simple reproducer can also be obtained by doing the following in tick_irq_exit(). It will hang on boot without the patch: static inline void tick_irq_exit(void) { +\trcu_read_lock(); +\tWRITE_ONCE(current-\u003ercu_read_unlock_special.b.need_qs, true); +\trcu_read_unlock(); + [neeraj: Apply Frederic's suggested fix for PREEMPT_RT]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39744", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eAPPNp2r6gp30swyIPgs8A==": { "id": "eAPPNp2r6gp30swyIPgs8A==", "updater": "debian/updater", "name": "CVE-2025-22037", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn-\u003epreauth_info is not allocated. This patch add KSMBD_SESS_NEED_SETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22037", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eAkF4gcKeYvDteK2Fky90g==": { "id": "eAkF4gcKeYvDteK2Fky90g==", "updater": "debian/updater", "name": "CVE-2026-68156", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth-\u003eauthorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au-\u003ebuf-\u003evec.iov_base and au-\u003ebuf-\u003evec.iov_len in struct ceph_auth_handshake. These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available. If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au-\u003ebuf and allocates a new one. If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth-\u003eauthorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth-\u003eauthorizer_buf and auth-\u003eauthorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68156", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eFmZwmd/PF/L5BwzrUL8Bg==": { "id": "eFmZwmd/PF/L5BwzrUL8Bg==", "updater": "debian/updater", "name": "CVE-2026-50219", "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-50219", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eJWQkT2e9DpqDKZu/3OPSA==": { "id": "eJWQkT2e9DpqDKZu/3OPSA==", "updater": "debian/updater", "name": "CVE-2025-38237", "description": "In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() In fimc_is_hw_change_mode(), the function changes camera modes without waiting for hardware completion, risking corrupted data or system hangs if subsequent operations proceed before the hardware is ready. Add fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration, ensuring hardware state synchronization and stable interrupt handling.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38237", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eKnrUNUJQNJOChCt3LUUxg==": { "id": "eKnrUNUJQNJOChCt3LUUxg==", "updater": "debian/updater", "name": "CVE-2024-52560", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() Extended the `mi_enum_attr()` function interface with an additional parameter, `struct ntfs_inode *ni`, to allow marking the inode as bad as soon as an error is detected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-52560", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eMJT7VG/NT94FNjcwFGj7g==": { "id": "eMJT7VG/NT94FNjcwFGj7g==", "updater": "debian/updater", "name": "CVE-2026-57433", "description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-57433", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eMcft8C1+SHqjR2CjpyZMQ==": { "id": "eMcft8C1+SHqjR2CjpyZMQ==", "updater": "debian/updater", "name": "CVE-2025-38248", "description": "In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev dummy1 type bridge_slave mcast_router 2 $ bridge -d mdb show | grep router router ports on br1: dummy1 # ip link set dev br1 type bridge mcast_vlan_snooping 1 $ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled: # ip link set dev dummy1 type bridge_slave mcast_router 0 # ip link set dev dummy1 type bridge_slave mcast_router 2 $ bridge -d mdb show | grep router router ports on br1: dummy1 Since commit 4b30ae9adb04 (\"net: bridge: mcast: re-implement br_multicast_{enable, disable}_port functions\"), when per-VLAN multicast snooping is enabled, multicast disablement on a port will disable the per-{port, VLAN} multicast contexts and not the per-port one. As a result, a port will remain in the global router port list even after it is deleted. This will lead to a use-after-free [1] when the list is traversed (when adding a new port to the list, for example): # ip link del dev dummy1 # ip link add name dummy2 up master br1 type dummy # ip link set dev dummy2 type bridge_slave mcast_router 2 Similarly, stale entries can also be found in the per-VLAN router port list. When per-VLAN multicast snooping is disabled, the per-{port, VLAN} contexts are disabled on each port and the port is removed from the per-VLAN router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 mcast_vlan_snooping 1 # ip link add name dummy1 up master br1 type dummy # bridge vlan add vid 2 dev dummy1 # bridge vlan global set vid 2 dev br1 mcast_snooping 1 # bridge vlan set vid 2 dev dummy1 mcast_router 2 $ bridge vlan global show dev br1 vid 2 | grep router router ports: dummy1 # ip link set dev br1 type bridge mcast_vlan_snooping 0 $ bridge vlan global show dev br1 vid 2 | grep router However, the port can be re-added to the per-VLAN list even when per-VLAN multicast snooping is disabled: # bridge vlan set vid 2 dev dummy1 mcast_router 0 # bridge vlan set vid 2 dev dummy1 mcast_router 2 $ bridge vlan global show dev br1 vid 2 | grep router router ports: dummy1 When the VLAN is deleted from the port, the per-{port, VLAN} multicast context will not be disabled since multicast snooping is not enabled on the VLAN. As a result, the port will remain in the per-VLAN router port list even after it is no longer member in the VLAN. This will lead to a use-after-free [2] when the list is traversed (when adding a new port to the list, for example): # ip link add name dummy2 up master br1 type dummy # bridge vlan add vid 2 dev dummy2 # bridge vlan del vid 2 dev dummy1 # bridge vlan set vid 2 dev dummy2 mcast_router 2 Fix these issues by removing the port from the relevant (global or per-VLAN) router port list in br_multicast_port_ctx_deinit(). The function is invoked during port deletion with the per-port multicast context and during VLAN deletion with the per-{port, VLAN} multicast context. Note that deleting the multicast router timer is not enough as it only takes care of the temporary multicast router states (1 or 3) and not the permanent one (2). [1] BUG: KASAN: slab-out-of-bounds in br_multicast_add_router.part.0+0x3f1/0x560 Write of size 8 at addr ffff888004a67328 by task ip/384 [...] Call Trace: \u003cTASK\u003e dump_stack ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38248", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eSEHklhq8w2Gxt4i9Oe9kA==": { "id": "eSEHklhq8w2Gxt4i9Oe9kA==", "updater": "debian/updater", "name": "CVE-2026-43010", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable kprobe_multi programs at attach time kprobe.multi programs run in atomic/RCU context and cannot sleep. However, bpf_kprobe_multi_link_attach() did not validate whether the program being attached had the sleepable flag set, allowing sleepable helpers such as bpf_copy_from_user() to be invoked from a non-sleepable context. This causes a \"sleeping function called from invalid context\" splat: BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo preempt_count: 1, expected: 0 RCU nest depth: 2, expected: 0 Fix this by rejecting sleepable programs early in bpf_kprobe_multi_link_attach(), before any further processing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43010", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eV+P3z67kBdWDC5tFoPXmw==": { "id": "eV+P3z67kBdWDC5tFoPXmw==", "updater": "debian/updater", "name": "CVE-2025-71138", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add missing NULL pointer check for pingpong interface It is checked almost always in dpu_encoder_phys_wb_setup_ctl(), but in a single place the check is missing. Also use convenient locals instead of phys_enc-\u003e* where available. Patchwork: https://patchwork.freedesktop.org/patch/693860/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71138", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eW+REV5eOe0Z0hdA+hyoQw==": { "id": "eW+REV5eOe0Z0hdA+hyoQw==", "updater": "debian/updater", "name": "CVE-2026-58015", "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58015", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eW5sSwfH19cOVhqOjFPExA==": { "id": "eW5sSwfH19cOVhqOjFPExA==", "updater": "debian/updater", "name": "CVE-2024-42123", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free err_addr in some special case. So set the err_addr to NULL to avoid the warnings.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42123", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ebIgfG/AuFXg1JE3bCfp2g==": { "id": "ebIgfG/AuFXg1JE3bCfp2g==", "updater": "debian/updater", "name": "CVE-2026-45985", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O When allocating blocks during within-EOF DIO and writeback with dioread_nolock enabled, EXT4_GET_BLOCKS_PRE_IO was set to split an existing large unwritten extent. However, EXT4_GET_BLOCKS_CONVERT was set when calling ext4_split_convert_extents(), which may potentially result in stale data issues. Assume we have an unwritten extent, and then DIO writes the second half. [UUUUUUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUUUUUU] extent status tree |\u003c- -\u003e| ----\u003e dio write this range First, ext4_iomap_alloc() call ext4_map_blocks() with EXT4_GET_BLOCKS_PRE_IO, EXT4_GET_BLOCKS_UNWRIT_EXT and EXT4_GET_BLOCKS_CREATE flags set. ext4_map_blocks() find this extent and call ext4_split_convert_extents() with EXT4_GET_BLOCKS_CONVERT and the above flags set. Then, ext4_split_convert_extents() calls ext4_split_extent() with EXT4_EXT_MAY_ZEROOUT, EXT4_EXT_MARK_UNWRIT2 and EXT4_EXT_DATA_VALID2 flags set, and it calls ext4_split_extent_at() to split the second half with EXT4_EXT_DATA_VALID2, EXT4_EXT_MARK_UNWRIT1, EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_MARK_UNWRIT2 flags set. However, ext4_split_extent_at() failed to insert extent since a temporary lack -ENOSPC. It zeroes out the first half but convert the entire on-disk extent to written since the EXT4_EXT_DATA_VALID2 flag set, but left the second half as unwritten in the extent status tree. [0000000000SSSSSS] data S: stale data, 0: zeroed [WWWWWWWWWWWWWWWW] on-disk extent W: written extent [WWWWWWWWWWUUUUUU] extent status tree Finally, if the DIO failed to write data to the disk, the stale data in the second half will be exposed once the cached extent entry is gone. Fix this issue by not passing EXT4_GET_BLOCKS_CONVERT when splitting an unwritten extent before submitting I/O, and make ext4_split_convert_extents() to zero out the entire extent range to zero for this case, and also mark the extent in the extent status tree for consistency.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45985", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ec8TXpqSyie6lk8Ngt/5pQ==": { "id": "ec8TXpqSyie6lk8Ngt/5pQ==", "updater": "debian/updater", "name": "CVE-2025-40170", "description": "In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst-\u003edev from sk_setup_caps() and sk_dst_gso_max_size(). Also use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(), and ip_dst_mtu_maybe_forward(). ip4_dst_hoplimit() can use dst_dev_net_rcu().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40170", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ecHm30RV2osv+vIdsYl1hg==": { "id": "ecHm30RV2osv+vIdsYl1hg==", "updater": "debian/updater", "name": "CVE-2026-16241", "description": "Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-16241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eeINYwTym7iJf+A3+yWIxw==": { "id": "eeINYwTym7iJf+A3+yWIxw==", "updater": "debian/updater", "name": "CVE-2023-53846", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on direct node in truncate_dnode() syzbot reports below bug: BUG: KASAN: slab-use-after-free in f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574 Read of size 4 at addr ffff88802a25c000 by task syz-executor148/5000 CPU: 1 PID: 5000 Comm: syz-executor148 Not tainted 6.4.0-rc7-syzkaller-00041-ge660abd551f1 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574 truncate_dnode+0x229/0x2e0 fs/f2fs/node.c:944 f2fs_truncate_inode_blocks+0x64b/0xde0 fs/f2fs/node.c:1154 f2fs_do_truncate_blocks+0x4ac/0xf30 fs/f2fs/file.c:721 f2fs_truncate_blocks+0x7b/0x300 fs/f2fs/file.c:749 f2fs_truncate.part.0+0x4a5/0x630 fs/f2fs/file.c:799 f2fs_truncate include/linux/fs.h:825 [inline] f2fs_setattr+0x1738/0x2090 fs/f2fs/file.c:1006 notify_change+0xb2c/0x1180 fs/attr.c:483 do_truncate+0x143/0x200 fs/open.c:66 handle_truncate fs/namei.c:3295 [inline] do_open fs/namei.c:3640 [inline] path_openat+0x2083/0x2750 fs/namei.c:3791 do_filp_open+0x1ba/0x410 fs/namei.c:3818 do_sys_openat2+0x16d/0x4c0 fs/open.c:1356 do_sys_open fs/open.c:1372 [inline] __do_sys_creat fs/open.c:1448 [inline] __se_sys_creat fs/open.c:1442 [inline] __x64_sys_creat+0xcd/0x120 fs/open.c:1442 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The root cause is, inodeA references inodeB via inodeB's ino, once inodeA is truncated, it calls truncate_dnode() to truncate data blocks in inodeB's node page, it traverse mapping data from node-\u003ei.i_addr[0] to node-\u003ei.i_addr[ADDRS_PER_BLOCK() - 1], result in out-of-boundary access. This patch fixes to add sanity check on dnode page in truncate_dnode(), so that, it can help to avoid triggering such issue, and once it encounters such issue, it will record newly introduced ERROR_INVALID_NODE_REFERENCE error into superblock, later fsck can detect such issue and try repairing. Also, it removes f2fs_truncate_data_blocks() for cleanup due to the function has only one caller, and uses f2fs_truncate_data_blocks_range() instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53846", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eg0zr8Uw6LmL6IroDlS7wQ==": { "id": "eg0zr8Uw6LmL6IroDlS7wQ==", "updater": "debian/updater", "name": "CVE-2025-1147", "description": "A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1147", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ejWOPQWvocqi5S9aDnis4A==": { "id": "ejWOPQWvocqi5S9aDnis4A==", "updater": "debian/updater", "name": "CVE-2026-63825", "description": "In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge global branch counters with loop induction variables as an optimization. In inflate_fast(), the inner copy loops get transformed so that the GCOV counter value is loaded multiple times to compute the loop base address, start index, and end bound. Since GCOV counters are global (not per-CPU), concurrent execution on different CPUs causes the counter to change between loads, producing inconsistent values and out-of-bounds memory writes. The crash manifests during IPComp (IP Payload Compression) processing when inflate_fast() runs concurrently on multiple CPUs: BUG: unable to handle page fault for address: ffffd0a3c0902ffa RIP: inflate_fast+1431 Call Trace: zlib_inflate __deflate_decompress crypto_comp_decompress ipcomp_decompress [xfrm_ipcomp] ipcomp_input [xfrm_ipcomp] xfrm_input At the crash point, the compiler generated three loads from the same global GCOV counter (__gcov0.inflate_fast+216) to compute base, start, and end for an indexed loop. Another CPU modified the counter between loads, making the values inconsistent - the write went 3.4 MB past a 65 KB buffer. Add -fprofile-update=prefer-atomic to CFLAGS_GCOV at the global level in the top-level Makefile, guarded by a try-run compile test. The test compiles a minimal program with and without -fprofile-update=prefer-atomic using the full KBUILD_CFLAGS, then compares undefined symbols in the resulting object files. If prefer-atomic introduces new undefined references (such as __atomic_fetch_add_8 on i386 or __aarch64_ldadd8_relax on arm64 with outline-atomics), the flag is not added -- the kernel does not link against libatomic. On architectures where GCC inlines 64-bit atomic counter updates (x86_64, s390, ...) the test passes and the flag is enabled, preventing the compiler from merging counters with loop induction variables and fixing the observed concurrent-access crash. On architectures where the flag would introduce libatomic dependencies, it is silently omitted and behaviour is no worse than before this patch. Move the CFLAGS_GCOV block from its original position (before the arch Makefile include) to after the core KBUILD_CFLAGS assignments but before the scripts/Makefile.gcc-plugins include. This placement ensures the try-run test sees arch-specific flags (-m32, -march=, -mno-outline-atomics) while avoiding GCC plugin flags (-fplugin=) that would break the test on clean builds when plugin shared objects do not yet exist.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63825", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ekhzxIHRTH4nfurC7aQlwQ==": { "id": "ekhzxIHRTH4nfurC7aQlwQ==", "updater": "debian/updater", "name": "CVE-2025-1148", "description": "A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1148", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "epW/pSv8hD8g7lw/GzsiZg==": { "id": "epW/pSv8hD8g7lw/GzsiZg==", "updater": "debian/updater", "name": "CVE-2026-64580", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst() releases the device reference with netdev_put() but leaves xdst-\u003eu.dst.dev set. dst_destroy() later calls netdev_put(dst-\u003edev) again, so the same net_device reference is released twice, underflowing its refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for \u003cdev\u003e to become free\"). Clear xdst-\u003eu.dst.dev after the netdev_put(), the same way the XFRM device-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in net/xfrm/xfrm_device.c NULL -\u003edev when releasing the reference on error. ref_tracker: reference already released. ref_tracker: allocated in: xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86) ... udpv6_sendmsg (net/ipv6/udp.c:1696) ... ref_tracker: freed in: xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90) ... WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780 dst_destroy (net/core/dst.c:115) rcu_core handle_softirqs ...", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64580", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "esFy+BTeKuM/9GkyYe9/tw==": { "id": "esFy+BTeKuM/9GkyYe9/tw==", "updater": "debian/updater", "name": "CVE-2024-35942", "description": "In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to hdmimix domain According to i.MX8MP RM and HDMI ADD, the fdcc clock is part of hdmi rx verification IP that should not enable for HDMI TX. But actually if the clock is disabled before HDMI/LCDIF probe, LCDIF will not get pixel clock from HDMI PHY and print the error logs: [CRTC:39:crtc-2] vblank wait timed out WARNING: CPU: 2 PID: 9 at drivers/gpu/drm/drm_atomic_helper.c:1634 drm_atomic_helper_wait_for_vblanks.part.0+0x23c/0x260 Add fdcc clock to LCDIF and HDMI TX power domains to fix the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35942", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "evy4OzzM2ENIuS4DaluP/g==": { "id": "evy4OzzM2ENIuS4DaluP/g==", "updater": "debian/updater", "name": "CVE-2024-58096", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng-\u003elock for ath11k_hal_srng_* in monitor mode ath11k_hal_srng_* should be used with srng-\u003elock to protect srng data. For ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(), they use ath11k_hal_srng_* for many times but never call srng-\u003elock. So when running (full) monitor mode, warning will occur: RIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] Call Trace: ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k] ? idr_alloc_u32+0x97/0xd0 ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k] ath11k_dp_service_srng+0x289/0x5a0 [ath11k] ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k] __napi_poll+0x30/0x1f0 net_rx_action+0x198/0x320 __do_softirq+0xdd/0x319 So add srng-\u003elock for them to avoid such warnings. Inorder to fetch the srng-\u003elock, should change srng's definition from 'void' to 'struct hal_srng'. And initialize them elsewhere to prevent one line of code from being too long. This is consistent with other ring process functions, such as ath11k_dp_process_rx(). Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58096", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ewHqN0+8nyoWSAsnW89H3g==": { "id": "ewHqN0+8nyoWSAsnW89H3g==", "updater": "debian/updater", "name": "CVE-2024-39508", "description": "In the Linux kernel, the following vulnerability has been resolved: io_uring/io-wq: Use set_bit() and test_bit() at worker-\u003eflags Utilize set_bit() and test_bit() on worker-\u003eflags within io_uring/io-wq to address potential data races. The structure io_worker-\u003eflags may be accessed through various data paths, leading to concurrency issues. When KCSAN is enabled, it reveals data races occurring in io_worker_handle_work and io_wq_activate_free_worker functions. \t BUG: KCSAN: data-race in io_worker_handle_work / io_wq_activate_free_worker \t write to 0xffff8885c4246404 of 4 bytes by task 49071 on cpu 28: \t io_worker_handle_work (io_uring/io-wq.c:434 io_uring/io-wq.c:569) \t io_wq_worker (io_uring/io-wq.c:?) \u003csnip\u003e \t read to 0xffff8885c4246404 of 4 bytes by task 49024 on cpu 5: \t io_wq_activate_free_worker (io_uring/io-wq.c:? io_uring/io-wq.c:285) \t io_wq_enqueue (io_uring/io-wq.c:947) \t io_queue_iowq (io_uring/io_uring.c:524) \t io_req_task_submit (io_uring/io_uring.c:1511) \t io_handle_tw_list (io_uring/io_uring.c:1198) \u003csnip\u003e Line numbers against commit 18daea77cca6 (\"Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm\"). These races involve writes and reads to the same memory location by different tasks running on different CPUs. To mitigate this, refactor the code to use atomic operations such as set_bit(), test_bit(), and clear_bit() instead of basic \"and\" and \"or\" operations. This ensures thread-safe manipulation of worker flags. Also, move `create_index` to avoid holes in the structure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-39508", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ewtS4cA0J2mjfFxq/QBEkg==": { "id": "ewtS4cA0J2mjfFxq/QBEkg==", "updater": "debian/updater", "name": "CVE-2026-64082", "description": "In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64082", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "eyoPFYt1ipSpBRtbyo16hg==": { "id": "eyoPFYt1ipSpBRtbyo16hg==", "updater": "debian/updater", "name": "CVE-2026-16239", "description": "Type confusion in PostgreSQL \"portal\"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-16239", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ez/7MlfWRA47u/CUpm+W6w==": { "id": "ez/7MlfWRA47u/CUpm+W6w==", "updater": "debian/updater", "name": "CVE-2026-64481", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs35l41: Fix firmware load work teardown cs35l41_hda creates ALSA controls whose private data points at the cs35l41_hda object. The firmware load control can also queue fw_load_work. Those controls are not removed on component unbind, and device remove only cancels fw_load_work through cs35l41_remove_dsp(). That helper is skipped when halo_initialized is false. With firmware_autostart disabled, a firmware load can be requested before the DSP has been initialized. If the component or device is removed before the queued work runs, the worker can run after teardown and dereference driver state that is no longer valid. Track the created controls and remove them on unbind so no new control callback can reach the driver data or queue more work. Then cancel fw_load_work to drain any request that was already queued. Also cancel the work unconditionally during device remove before runtime PM teardown.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64481", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f+L/NxbWRWtyU7efEy5kwA==": { "id": "f+L/NxbWRWtyU7efEy5kwA==", "updater": "debian/updater", "name": "CVE-2026-66011", "description": "ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-66011", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f/he7Poe7++v+chxeZckAw==": { "id": "f/he7Poe7++v+chxeZckAw==", "updater": "debian/updater", "name": "CVE-2016-20012", "description": "OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-20012", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f02LQCCq0NBxbynpJcK7PA==": { "id": "f02LQCCq0NBxbynpJcK7PA==", "updater": "debian/updater", "name": "CVE-2026-64400", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted path attempts to escape the share boundary using parent-directory components ('..'), vfs_path_parent_lookup() detects this and immediately fails, returning -EXDEV. However, a bug exists in __ksmbd_vfs_kern_path() under caseless mode. The function fails to intercept the -EXDEV error and erroneously falls through to the caseless retry logic, which is intended only for genuinely missing files. During this retry process, the path is reconstructed, leading to an unintended LOOKUP_BENEATH bypass that allows write-capable users to create zero-length files or directories outside the exported share. Fix this by ensuring that the execution only proceeds to the caseless lookup retry when the error is specifically -ENOENT. Any other errors, such as -EXDEV from a path traversal attempt, must be returned immediately.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64400", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f09/sxMi7D7F9rcfxRlDsw==": { "id": "f09/sxMi7D7F9rcfxRlDsw==", "updater": "debian/updater", "name": "CVE-2026-11856", "description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11856", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f22/JqHREO/iFR5wVxKZDA==": { "id": "f22/JqHREO/iFR5wVxKZDA==", "updater": "debian/updater", "name": "CVE-2026-31487", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1] Also note that we do not enable the driver_override feature of struct bus_type, as SPI - in contrast to most other buses - passes \"\" to sysfs_emit() when the driver_override pointer is NULL. Thus, printing \"\\n\" instead of \"(null)\\n\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31487", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f3CTm99In33LVLjnI20WkA==": { "id": "f3CTm99In33LVLjnI20WkA==", "updater": "debian/updater", "name": "CVE-2025-38206", "description": "In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : free -\u003evol_utbl exfat_load_default_upcase_table : return error exfat_kill_sb() delayed_free() exfat_free_upcase_table() \u003c--------- double free This patch set -\u003evol_util as NULL after freeing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38206", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f3MVLCaGFMZhT666w6avPg==": { "id": "f3MVLCaGFMZhT666w6avPg==", "updater": "debian/updater", "name": "CVE-2025-22048", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: div by 0 in subprog` triggers a panic at the ld.bu instruction. The ld.bu insn is trying to load byte from memory address returned by the subprog. The subprog actually set the correct address at the a5 register (dedicated register for BPF return values). But at commit 73c359d1d356 (\"LoongArch: BPF: Sign-extend return values\") we also sign extended a5 to the a0 register (return value in LoongArch). For function call insn, we later propagate the a0 register back to a5 register. This is right for native calls but wrong for bpf2bpf calls which expect zero-extended return value in a5 register. So only move a0 to a5 for native calls (i.e. non-BPF_PSEUDO_CALL).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22048", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f3vaferRpevg8b0DyptSqw==": { "id": "f3vaferRpevg8b0DyptSqw==", "updater": "debian/updater", "name": "CVE-2025-15661", "description": "libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-15661", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f52mHBMxaML8BIIi27ptmw==": { "id": "f52mHBMxaML8BIIi27ptmw==", "updater": "debian/updater", "name": "CVE-2026-68185", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Move jump_label_init() before parse_early_param() When enabling both CONFIG_MEM_ALLOC_PROFILING=y and CONFIG_MEM_ALLOC_PROFILING_ENABLED_BY_DEFAULT=y, then diabling memory profiling by adding the boot parameter 'sysctl.vm.mem_profiling=0' will cause the kernel failed to boot. After analysis, this is because jump_label_init() must be called before parse_early_param(), the early param handlers may modify static keys by static_branch_enable/disable(). Fix this by moving jump_label_init() to before parse_early_param(). The solution is similar to other architectures.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68185", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f6AXHBxcapnzSbd6qwVDwA==": { "id": "f6AXHBxcapnzSbd6qwVDwA==", "updater": "debian/updater", "name": "CVE-2026-68199", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA window size aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to compute a kzalloc size and stored in rxtid-\u003ehold_q_sz, leading to zero-size or overflowed allocations and subsequent out-of-bounds access. Clean up any previously active aggregation session for the TID first, then return early when win_sz is out of the valid range, instead of proceeding with a broken allocation size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68199", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "f7Zd/PugLsAhu1y1p1pb/Q==": { "id": "f7Zd/PugLsAhu1y1p1pb/Q==", "updater": "debian/updater", "name": "CVE-2026-63853", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit fd852c048b46f9825e904a4f3f4538fe9d8827d9)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63853", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fC+PYOiejjO7X8tsRGcjvQ==": { "id": "fC+PYOiejjO7X8tsRGcjvQ==", "updater": "debian/updater", "name": "CVE-2026-43009", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as a destination, thus receiving the old value from the memory location. The current backtracking logic does not account for this. It treats atomic fetch operations the same as regular stores where the src register is only an input. This leads the backtrack_insn to fail to propagate precision to the stack location, which is then not marked as precise! Later, the verifier's path pruning can incorrectly consider two states equivalent when they differ in terms of stack state. Meaning, two branches can be treated as equivalent and thus get pruned when they should not be seen as such. Fix it as follows: Extend the BPF_LDX handling in backtrack_insn to also cover atomic fetch operations via is_atomic_fetch_insn() helper. When the fetch dst register is being tracked for precision, clear it, and propagate precision over to the stack slot. For non-stack memory, the precision walk stops at the atomic instruction, same as regular BPF_LDX. This covers all fetch variants. Before: 0: (b7) r1 = 8 ; R1=8 1: (7b) *(u64 *)(r10 -8) = r1 ; R1=8 R10=fp0 fp-8=8 2: (b7) r2 = 0 ; R2=0 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2) ; R2=8 R10=fp0 fp-8=mmmmmmmm 4: (bf) r3 = r10 ; R3=fp0 R10=fp0 5: (0f) r3 += r2 mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1 mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10 mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2) mark_precise: frame0: regs=r2 stack= before 2: (b7) r2 = 0 6: R2=8 R3=fp8 6: (b7) r0 = 0 ; R0=0 7: (95) exit After: 0: (b7) r1 = 8 ; R1=8 1: (7b) *(u64 *)(r10 -8) = r1 ; R1=8 R10=fp0 fp-8=8 2: (b7) r2 = 0 ; R2=0 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2) ; R2=8 R10=fp0 fp-8=mmmmmmmm 4: (bf) r3 = r10 ; R3=fp0 R10=fp0 5: (0f) r3 += r2 mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1 mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10 mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2) mark_precise: frame0: regs= stack=-8 before 2: (b7) r2 = 0 mark_precise: frame0: regs= stack=-8 before 1: (7b) *(u64 *)(r10 -8) = r1 mark_precise: frame0: regs=r1 stack= before 0: (b7) r1 = 8 6: R2=8 R3=fp8 6: (b7) r0 = 0 ; R0=0 7: (95) exit", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43009", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fC/P2jWl2xsImLa95cteRQ==": { "id": "fC/P2jWl2xsImLa95cteRQ==", "updater": "debian/updater", "name": "CVE-2026-68373", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() at76_guess_freq() checks only that the received frame is at least a bare 802.11 header (24 bytes) before subtracting the fixed management-body offset: \tlen -= el_off; For both beacon and probe response frames, el_off is 36. If the frame is shorter than el_off, subtracting it causes the calculated IE length to wrap. The length is eventually passed to cfg80211_find_elem_match() as a very large unsigned value, so the element walk runs beyond the RX skb. This path is reached from at76_rx_tasklet() while scanning. If the device delivers a truncated beacon or probe response, the oversized IE length causes an out-of-bounds read during scanning. Skip the IE lookup if the frame does not reach the variable elements, before subtracting el_off.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68373", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fCfk1NFnDb8OiVjOSfRa6Q==": { "id": "fCfk1NFnDb8OiVjOSfRa6Q==", "updater": "debian/updater", "name": "CVE-2026-68153", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files before client teardown ceph_destroy_client() tears down the monitor client before removing the per-client debugfs files. A concurrent read of the monmap debugfs file can enter monmap_show() after ceph_monc_stop() has freed monc-\u003emonmap, triggering a use-after-free. Remove the debugfs files before stopping the OSD and monitor clients. debugfs_remove() drains active handlers and prevents new accesses, so the debugfs callbacks can no longer race the rest of client teardown.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68153", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fD3V8WvG+u7QpTEDqTMUAw==": { "id": "fD3V8WvG+u7QpTEDqTMUAw==", "updater": "debian/updater", "name": "CVE-2024-50166", "description": "In the Linux kernel, the following vulnerability has been resolved: fsl/fman: Fix refcount handling of fman-related devices In mac_probe() there are multiple calls to of_find_device_by_node(), fman_bind() and fman_port_bind() which takes references to of_dev-\u003edev. Not all references taken by these calls are released later on error path in mac_probe() and in mac_remove() which lead to reference leaks. Add references release.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50166", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fGD9z3bMt3Zy2s6flXa9PQ==": { "id": "fGD9z3bMt3Zy2s6flXa9PQ==", "updater": "debian/updater", "name": "CVE-2024-50028", "description": "In the Linux kernel, the following vulnerability has been resolved: thermal: core: Reference count the zone in thermal_zone_get_by_id() There are places in the thermal netlink code where nothing prevents the thermal zone object from going away while being accessed after it has been returned by thermal_zone_get_by_id(). To address this, make thermal_zone_get_by_id() get a reference on the thermal zone device object to be returned with the help of get_device(), under thermal_list_lock, and adjust all of its callers to this change with the help of the cleanup.h infrastructure.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50028", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fI/7lxwm3vQ3N/j0g7Qz4g==": { "id": "fI/7lxwm3vQ3N/j0g7Qz4g==", "updater": "debian/updater", "name": "CVE-2026-64556", "description": "In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT only. This can leave inconsistent group state when a removed event is a group leader and the group contains siblings without remove_on_exec. If the group was active, the surviving siblings can remain active and attached to the removed leader's sibling list, but are no longer represented by a valid group leader on the PMU context active lists. A later close of the removed leader uses DETACH_GROUP and can promote the still-active siblings from this stale group state. The next schedule-in can then add an already-linked active_list entry again, corrupting the PMU context active list. With DEBUG_LIST enabled, this is caught as a list_add double-add in merge_sched_in(). Fix this by detaching group relationships when remove_on_exec removes an event. This preserves the existing task-exit and revoke behavior, while ensuring surviving siblings are ungrouped before the removed event leaves the context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64556", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fI1cxD6IkyVtdqUWMiiHAg==": { "id": "fI1cxD6IkyVtdqUWMiiHAg==", "updater": "debian/updater", "name": "CVE-2025-37776", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37776", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fIOBZLi+PdPMNcRduPMSyQ==": { "id": "fIOBZLi+PdPMNcRduPMSyQ==", "updater": "debian/updater", "name": "CVE-2023-5841", "description": "Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-5841", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fJ/sIb8ANcg6WDYkQtkeAg==": { "id": "fJ/sIb8ANcg6WDYkQtkeAg==", "updater": "debian/updater", "name": "CVE-2025-12840", "description": "Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-12840", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fOZ09WQ2S529qRiEbktTWA==": { "id": "fOZ09WQ2S529qRiEbktTWA==", "updater": "debian/updater", "name": "CVE-2025-11840", "description": "A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11840", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fOeXs+kiuyq8k7gYZR0Evg==": { "id": "fOeXs+kiuyq8k7gYZR0Evg==", "updater": "debian/updater", "name": "CVE-2025-23129", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path If a shared IRQ is used by the driver due to platform limitation, then the IRQ affinity hint is set right after the allocation of IRQ vectors in ath11k_pci_alloc_msi(). This does no harm unless one of the functions requesting the IRQ fails and attempt to free the IRQ. This results in the below warning: WARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c Call trace: free_irq+0x278/0x29c ath11k_pcic_free_irq+0x70/0x10c [ath11k] ath11k_pci_probe+0x800/0x820 [ath11k_pci] local_pci_probe+0x40/0xbc The warning is due to not clearing the affinity hint before freeing the IRQs. So to fix this issue, clear the IRQ affinity hint before calling ath11k_pcic_free_irq() in the error path. The affinity will be cleared once again further down the error path due to code organization, but that does no harm. Tested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-23129", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fVbaDjJ+wmNFZEEpBOAEqw==": { "id": "fVbaDjJ+wmNFZEEpBOAEqw==", "updater": "debian/updater", "name": "CVE-2026-32740", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32740", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fZVpSeqDPAMZq+eNz0K+JA==": { "id": "fZVpSeqDPAMZq+eNz0K+JA==", "updater": "debian/updater", "name": "CVE-2026-46225", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller deregistration Make sure to deregister the controller before releasing underlying resources like DMA during driver unbind.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46225", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fbYAG8GGSRzTqm7WqFUn6w==": { "id": "fbYAG8GGSRzTqm7WqFUn6w==", "updater": "debian/updater", "name": "CVE-2026-68204", "description": "In the Linux kernel, the following vulnerability has been resolved: media: vivid: check for vb2_is_busy() when toggling caps The vivid_update_format_cap/out() functions must only be called if the capture/output queue are not busy. But for the controls that select the CROP/COMPOSE/SCALE capability that is not checked. Only when streaming starts will they be set to 'grabbed' and it is impossible to change the control, but between REQBUFS and STREAMON you are still allowed to set these controls. Since vivid_update_format_cap/out will change the format, this can cause unexpected results. Besides adding these checks, also add a WARN_ON in vivid_update_format_cap/out() if the queue is busy. I'm 90% certain that this is the cause of this syzbot bug: https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89 But since we never have reproducers, it is hard to be certain. In any case, these checks are needed regardless.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68204", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fgbOPWAFsTd3RMyFiveWZg==": { "id": "fgbOPWAFsTd3RMyFiveWZg==", "updater": "debian/updater", "name": "CVE-2017-11755", "description": "The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-11755", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fkPgHfvVMKu1Gs6F8yWv7g==": { "id": "fkPgHfvVMKu1Gs6F8yWv7g==", "updater": "debian/updater", "name": "CVE-2026-68331", "description": "In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The Ethernet connect path stores that device in mac-\u003emc_dev and keeps it for the lifetime of the connected MAC object. However, the disconnect path only disconnects and closes the MAC before freeing the dpaa2_mac object. It does not drop the endpoint device reference stored in mac-\u003emc_dev, so every successful connect leaks that device reference when the MAC is later disconnected. Drop the endpoint device reference after closing the MAC and before freeing the dpaa2_mac object.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68331", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fnopR10wShgmhhhPsuEeJw==": { "id": "fnopR10wShgmhhhPsuEeJw==", "updater": "debian/updater", "name": "CVE-2023-6277", "description": "An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-6277", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "frvuZApIP1qQmX+Pqjd9xQ==": { "id": "frvuZApIP1qQmX+Pqjd9xQ==", "updater": "debian/updater", "name": "CVE-2023-31085", "description": "An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd-\u003eerasesize), used indirectly by ctrl_cdev_ioctl, when mtd-\u003eerasesize is 0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31085", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fuR5h+zOLXeaugOCtTvDxQ==": { "id": "fuR5h+zOLXeaugOCtTvDxQ==", "updater": "debian/updater", "name": "CVE-2025-39726", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time. Unfortunately as of today the s390/ism driver in Linux does not honor that requirement. This patch aims to rectify that. This problem was discovered based on Aliaksei's bug report which states that for certain workloads the ISM functions end up entering error state (with PEC 2 as seen from the logs) after a while and as a consequence connections handled by the respective function break, and for future connection requests the ISM device is not considered -- given it is in a dysfunctional state. During further debugging PEC 3A was observed as well. A kernel message like [ 1211.244319] zpci: 061a:00:00.0: Event 0x2 reports an error for PCI function 0x61a is a reliable indicator of the stated function entering error state with PEC 2. Let me also point out that a kernel message like [ 1211.244325] zpci: 061a:00:00.0: The ism driver bound to the device does not support error recovery is a reliable indicator that the ISM function won't be auto-recovered because the ISM driver currently lacks support for it. On a technical level, without this synchronization, commands (inputs to the FW) may be partially or fully overwritten (corrupted) by another CPU trying to issue commands on the same function. There is hard evidence that this can lead to DMB token values being used as DMB IOVAs, leading to PEC 2 PCI events indicating invalid DMA. But this is only one of the failure modes imaginable. In theory even completely losing one command and executing another one twice and then trying to interpret the outputs as if the command we intended to execute was actually executed and not the other one is also possible. Frankly, I don't feel confident about providing an exhaustive list of possible consequences.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39726", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fwbh8/ZdzRiNd4UOFeO8kw==": { "id": "fwbh8/ZdzRiNd4UOFeO8kw==", "updater": "debian/updater", "name": "CVE-2026-68448", "description": "In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae222a5ff0c (\"vfs: allow copy_file_range to copy across devices\") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type. The same commit added checks to verify same sb copy for filesystems that implement -\u003ecopy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs. The two remaining fs which implement -\u003ecopy_file_range(), cifs and overlayfs started to support cross-sb copy from this time. While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds. This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied. Fix the latter case by explicitly verifying read access to source file with the source overlayfs mounter creds. The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68448", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "fwqbK2vWdHEAxL0oK2ZkOA==": { "id": "fwqbK2vWdHEAxL0oK2ZkOA==", "updater": "debian/updater", "name": "CVE-2025-40333", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix infinite loop in __insert_extent_tree() When we get wrong extent info data, and look up extent_node in rb tree, it will cause infinite loop (CONFIG_F2FS_CHECK_FS=n). Avoiding this by return NULL and print some kernel messages in that case.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40333", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "g0ZIb1T8gqxy9GnBZHrs4w==": { "id": "g0ZIb1T8gqxy9GnBZHrs4w==", "updater": "debian/updater", "name": "CVE-2022-27943", "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-27943", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "gcc-12", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "g0lNlx+qGIfIvwARrGZIZA==": { "id": "g0lNlx+qGIfIvwARrGZIZA==", "updater": "debian/updater", "name": "CVE-2026-64006", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift and rshift, the shift operations are performed in a loop over 32-bit words. The loop calculates the shifted value and write it to dst, and then immediately reads from src to calculate the carry for the next iteration. Because src and dst could point to the same memory location, the carry is incorrectly calculated using the newly modified dst value instead of the original src value. Adding a temporary local variable to cache the original value before writing to dst and using it for the carry calculation solves the problem. In addition, partial overlap is rejected from control plane for all kind of operations including byteorder. This was tested with the following bytecode: table test_table ip flags 0 use 1 handle 1 ip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1 ip test_table test_chain 2 [ immediate reg 1 0x44332211 0x88776655 ] [ bitwise reg 1 = ( reg 1 \u003c\u003c 0x08000000 ) ] [ cmp eq reg 1 0x66443322 0x00887766 ] [ counter pkts 0 bytes 0 ] ip test_table test_chain 4 3 [ immediate reg 1 0x44332211 0x88776655 ] [ bitwise reg 1 = ( reg 1 \u003c\u003c 0x08000000 ) ] [ cmp eq reg 1 0x55443322 0x00887766 ] [ counter pkts 21794 bytes 1917798 ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64006", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "g19H+ehDjsC8ZfUqpdQz7g==": { "id": "g19H+ehDjsC8ZfUqpdQz7g==", "updater": "debian/updater", "name": "CVE-2026-64026", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg This improves the fix for CVE-2026-43500. Fix the pagecache corruption from in-place decryption of a DATA packet transmitted locally by splice() by getting rid of the packet sharing in the I/O thread and unconditionally extracting the packet content into a bounce buffer in which the buffer is decrypted. recvmsg() (or the kernel equivalent) then copies the data from the bounce buffer to the destination buffer. The sk_buff then remains unmodified. This has an additional advantage in that the packet is then arranged in the buffer with the correct alignment required for the crypto algorithms to process directly. The performance of the crypto does seem to be a little faster and, surprisingly, the unencrypted performance doesn't seem to change much - possibly due to removing complexity from the I/O thread. Yet another advantage is that the I/O thread doesn't have to copy packets which would slow down packet distribution, ACK generation, etc.. The buffer belongs to the call and is allocated initially at 2K, sufficiently large to hold a whole jumbo subpacket, but the buffer will be increased in size if needed. However, to take this work, MSG_PEEK may cause a later packet to be decrypted into the buffer, in which case the earlier one will need re-decrypting for a subsequent recvmsg(). Note that rx_pkt_offset may legitimately see 0 as a valid offset now, so switch to using USHRT_MAX to indicate an invalid offset. Note also that I would generally prefer to replace the buffers of the current sk_buff with a new kmalloc'd buffer of the right size, ditching the old data and frags as this makes the handling of MSG_PEEK easier and removes the re-decryption issue, but this looks like quite a complicated thing to achieve. skb_morph() looks half way to what I want, but I don't want to have to allocate a new sk_buff.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64026", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gAHDj/wjeA1RlKJMa+beqg==": { "id": "gAHDj/wjeA1RlKJMa+beqg==", "updater": "debian/updater", "name": "CVE-2026-43185", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp-\u003emax_recv_size and req-\u003epreferred_send_size to a signed int before computing min_t(int, ...). A maliciously provided preferred_send_size of 0x80000000 will return as smaller than max_recv_size, and then be used to set the maximum allowed alowed receive size for the next message. By sending a second message with a large value (\u003e1420 bytes) the attacker can then achieve a heap buffer overflow. This fix replaces min_t(int, ...) with min_t(u32)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43185", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gBevJICSLIQl0IiTPmQ6qg==": { "id": "gBevJICSLIQl0IiTPmQ6qg==", "updater": "debian/updater", "name": "CVE-2025-22113", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: avoid journaling sb update on error if journal is destroying Presently we always BUG_ON if trying to start a transaction on a journal marked with JBD2_UNMOUNT, since this should never happen. However, while ltp running stress tests, it was observed that in case of some error handling paths, it is possible for update_super_work to start a transaction after the journal is destroyed eg: (umount) ext4_kill_sb kill_block_super generic_shutdown_super sync_filesystem /* commits all txns */ evict_inodes /* might start a new txn */ ext4_put_super \tflush_work(\u0026sbi-\u003es_sb_upd_work) /* flush the workqueue */ jbd2_journal_destroy journal_kill_thread journal-\u003ej_flags |= JBD2_UNMOUNT; jbd2_journal_commit_transaction jbd2_journal_get_descriptor_buffer jbd2_journal_bmap ext4_journal_bmap ext4_map_blocks ... ext4_inode_error ext4_handle_error schedule_work(\u0026sbi-\u003es_sb_upd_work) /* work queue kicks in */ update_super_work jbd2_journal_start start_this_handle BUG_ON(journal-\u003ej_flags \u0026 JBD2_UNMOUNT) Hence, introduce a new mount flag to indicate journal is destroying and only do a journaled (and deferred) update of sb if this flag is not set. Otherwise, just fallback to an un-journaled commit. Further, in the journal destroy path, we have the following sequence: 1. Set mount flag indicating journal is destroying 2. force a commit and wait for it 3. flush pending sb updates This sequence is important as it ensures that, after this point, there is no sb update that might be journaled so it is safe to update the sb outside the journal. (To avoid race discussed in 2d01ddc86606) Also, we don't need a similar check in ext4_grp_locked_error since it is only called from mballoc and AFAICT it would be always valid to schedule work here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22113", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gFgtzKPw4TudAad/Fcnixg==": { "id": "gFgtzKPw4TudAad/Fcnixg==", "updater": "debian/updater", "name": "CVE-2026-18508", "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18508", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gH8QEPM8ngOb72/e2psndg==": { "id": "gH8QEPM8ngOb72/e2psndg==", "updater": "debian/updater", "name": "CVE-2022-2961", "description": "A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-2961", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gHf+ohzp2wBUa81nDxLHzQ==": { "id": "gHf+ohzp2wBUa81nDxLHzQ==", "updater": "debian/updater", "name": "CVE-2024-26914", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix incorrect mpc_combine array size [why] MAX_SURFACES is per stream, while MAX_PLANES is per asic. The mpc_combine is an array that records all the planes per asic. Therefore MAX_PLANES should be used as the array size. Using MAX_SURFACES causes array overflow when there are more than 3 planes. [how] Use the MAX_PLANES for the mpc_combine array size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26914", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gIEQo5B1M9YN4hmFor01HQ==": { "id": "gIEQo5B1M9YN4hmFor01HQ==", "updater": "debian/updater", "name": "CVE-2018-17977", "description": "The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-17977", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gIdEieYO/ntsLE6wtAmolw==": { "id": "gIdEieYO/ntsLE6wtAmolw==", "updater": "debian/updater", "name": "CVE-2024-40969", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: don't set RO when shutting down f2fs Shutdown does not check the error of thaw_super due to readonly, which causes a deadlock like below. f2fs_ioc_shutdown(F2FS_GOING_DOWN_FULLSYNC) issue_discard_thread - bdev_freeze - freeze_super - f2fs_stop_checkpoint() - f2fs_handle_critical_error - sb_start_write - set RO - waiting - bdev_thaw - thaw_super_locked - return -EINVAL, if sb_rdonly() - f2fs_stop_discard_thread -\u003e wait for kthread_stop(discard_thread);", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-40969", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gJF2RoXEUj/4hrZaYhzyJg==": { "id": "gJF2RoXEUj/4hrZaYhzyJg==", "updater": "debian/updater", "name": "CVE-2026-58013", "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58013", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gKT2K6FFmDBgo4l9aOgYBw==": { "id": "gKT2K6FFmDBgo4l9aOgYBw==", "updater": "debian/updater", "name": "CVE-2025-38595", "description": "In the Linux kernel, the following vulnerability has been resolved: xen: fix UAF in dmabuf_exp_from_pages() [dma_buf_fd() fixes; no preferences regarding the tree it goes through - up to xen folks] As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it). However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its -\u003erelease()), we have a UAF. dma_buf_fd() is a combination of reserving a descriptor and fd_install(). gntdev dmabuf_exp_from_pages() calls it and then proceeds to access the objects destroyed on close - starting with gntdev_dmabuf itself. Fix that by doing reserving descriptor before anything else and do fd_install() only when everything had been set up.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38595", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gKllHD4ZF3u6+sYpimhiHQ==": { "id": "gKllHD4ZF3u6+sYpimhiHQ==", "updater": "debian/updater", "name": "CVE-2025-38636", "description": "In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using DA monitors tracepoints with KASAN enabled triggers the following warning: BUG: KASAN: global-out-of-bounds in do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0 Read of size 32 at addr ffffffffaada8980 by task ... Call Trace: \u003cTASK\u003e [...] do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0 ? __pfx_do_trace_event_raw_event_event_da_monitor+0x10/0x10 ? trace_event_sncid+0x83/0x200 trace_event_sncid+0x163/0x200 [...] The buggy address belongs to the variable: automaton_snep+0x4e0/0x5e0 This is caused by the tracepoints reading 32 bytes __array instead of __string from the automata definition. Such strings are literals and reading 32 bytes ends up in out of bound memory accesses (e.g. the next automaton's data in this case). The error is harmless as, while printing the string, we stop at the null terminator, but it should still be fixed. Use the __string facilities while defining the tracepoints to avoid reading out of bound memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38636", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gKmkpT34vBHPSq1IVRTgvQ==": { "id": "gKmkpT34vBHPSq1IVRTgvQ==", "updater": "debian/updater", "name": "CVE-2026-68449", "description": "In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 \u0026 1) is always true and 0 \u003c\u003c= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68449", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gKs+7YLrqwmMe1IHwKZE4A==": { "id": "gKs+7YLrqwmMe1IHwKZE4A==", "updater": "debian/updater", "name": "CVE-2016-8678", "description": "The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says \"This is a Q64 issue and we do not support Q64.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-8678", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gMBJpO9BkmdlfyUVgqxitw==": { "id": "gMBJpO9BkmdlfyUVgqxitw==", "updater": "debian/updater", "name": "CVE-2025-39981", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix possible UAFs This attemps to fix possible UAFs caused by struct mgmt_pending being freed while still being processed like in the following trace, in order to fix mgmt_pending_valid is introduce and use to check if the mgmt_pending hasn't been removed from the pending list, on the complete callbacks it is used to check and in addtion remove the cmd from the list while holding mgmt_pending_lock to avoid TOCTOU problems since if the cmd is left on the list it can still be accessed and freed. BUG: KASAN: slab-use-after-free in mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223 Read of size 8 at addr ffff8880709d4dc0 by task kworker/u11:0/55 CPU: 0 UID: 0 PID: 55 Comm: kworker/u11:0 Not tainted 6.16.4 #2 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace: \u003cTASK\u003e dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223 hci_cmd_sync_work+0x210/0x3a0 net/bluetooth/hci_sync.c:332 process_one_work kernel/workqueue.c:3238 [inline] process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3321 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402 kthread+0x711/0x8a0 kernel/kthread.c:464 ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 home/kwqcheii/source/fuzzing/kernel/kasan/linux-6.16.4/arch/x86/entry/entry_64.S:245 \u003c/TASK\u003e Allocated by task 12210: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:377 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:394 kasan_kmalloc include/linux/kasan.h:260 [inline] __kmalloc_cache_noprof+0x230/0x3d0 mm/slub.c:4364 kmalloc_noprof include/linux/slab.h:905 [inline] kzalloc_noprof include/linux/slab.h:1039 [inline] mgmt_pending_new+0x65/0x1e0 net/bluetooth/mgmt_util.c:269 mgmt_pending_add+0x35/0x140 net/bluetooth/mgmt_util.c:296 __add_adv_patterns_monitor+0x130/0x200 net/bluetooth/mgmt.c:5247 add_adv_patterns_monitor+0x214/0x360 net/bluetooth/mgmt.c:5364 hci_mgmt_cmd+0x9c9/0xef0 net/bluetooth/hci_sock.c:1719 hci_sock_sendmsg+0x6ca/0xef0 net/bluetooth/hci_sock.c:1839 sock_sendmsg_nosec net/socket.c:714 [inline] __sock_sendmsg+0x219/0x270 net/socket.c:729 sock_write_iter+0x258/0x330 net/socket.c:1133 new_sync_write fs/read_write.c:593 [inline] vfs_write+0x5c9/0xb30 fs/read_write.c:686 ksys_write+0x145/0x250 fs/read_write.c:738 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 12221: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68 kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:576 poison_slab_object mm/kasan/common.c:247 [inline] __kasan_slab_free+0x62/0x70 mm/kasan/common.c:264 kasan_slab_free include/linux/kasan.h:233 [inline] slab_free_hook mm/slub.c:2381 [inline] slab_free mm/slub.c:4648 [inline] kfree+0x18e/0x440 mm/slub.c:4847 mgmt_pending_free net/bluetooth/mgmt_util.c:311 [inline] mgmt_pending_foreach+0x30d/0x380 net/bluetooth/mgmt_util.c:257 __mgmt_power_off+0x169/0x350 net/bluetooth/mgmt.c:9444 hci_dev_close_sync+0x754/0x1330 net/bluetooth/hci_sync.c:5290 hci_dev_do_close net/bluetooth/hci_core.c:501 [inline] hci_dev_close+0x108/0x200 net/bluetooth/hci_core.c:526 sock_do_ioctl+0xd9/0x300 net/socket.c:1192 sock_ioctl+0x576/0x790 net/socket.c:1313 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:907 [inline] __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39981", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gSuQ5dqvcMhkLbF4/1v2/A==": { "id": "gSuQ5dqvcMhkLbF4/1v2/A==", "updater": "debian/updater", "name": "CVE-2026-68098", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying ACEs before consuming the full input DACL when size accounting overflows. When that happens, num_aces reflects only the ACEs that were actually copied into the output DACL, but set_posix_acl_entries_dacl() still receives nt_num_aces and uses it to walk the existing ACE array during dedup. That makes the dedup walk scan past the copied ACE array and inspect buffer tail that does not contain valid ACEs. Split the two meanings currently carried by the NT ACE count. Pass the number of copied NT ACEs to bound the dedup walk, and preserve the original \"input DACL had NT ACEs\" state separately for the Everyone/default ACL fallback. This keeps the dedup walk aligned with the ACEs that are actually present in the rebuilt DACL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68098", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gVMCgMuPTTEnybcY++CgSw==": { "id": "gVMCgMuPTTEnybcY++CgSw==", "updater": "debian/updater", "name": "CVE-2026-58050", "description": "libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58050", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libssh2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gay3MyHX7w8wsA1EXoF3dQ==": { "id": "gay3MyHX7w8wsA1EXoF3dQ==", "updater": "debian/updater", "name": "CVE-2026-64192", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However, if the BPF LSM is not explicitly enabled at boot time (e.g. omitted from the \"lsm=\" boot parameter), lsm_prepare() is never executed for the BPF LSM. Consequently, the BPF inode security blob offset (bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at its default compiled size of 8 bytes instead of being updated to a valid offset past the reserved struct rcu_head (typically 16 bytes or more). When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE map, bpf_inode() evaluates inode-\u003ei_security + 8. This erroneously aliases the struct rcu_head.func callback pointer at the beginning of the inode-\u003ei_security blob. During subsequent map element cleanup or inode destruction, writing NULL to owner_storage clears the queued RCU callback pointer. When rcu_do_batch() later executes the queued callback, it attempts an instruction fetch at address 0x0, triggering an immediate kernel panic. Fix this by introducing a global bpf_lsm_initialized boolean flag marked with __ro_after_init. Set this flag to true inside bpf_lsm_init() when the LSM framework successfully registers the BPF LSM. Gate map allocation in inode_storage_map_alloc() on this flag, returning -EOPNOTSUPP if the BPF LSM is in turn uninitialized. This fail-fast approach prevents userspace from allocating inode storage maps when the supporting BPF LSM infrastructure is absent, avoiding zombie map states.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64192", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gc0jFzxcW25N62GQDKSqMQ==": { "id": "gc0jFzxcW25N62GQDKSqMQ==", "updater": "debian/updater", "name": "CVE-2026-64213", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sashiko reports: lm90_alert() executes in the smbus alert context and calls lm90_update_confreg() to disable the hardware alert line, without acquiring hwmon_lock. Concurrently, sysfs write operations (such as lm90_write_convrate) hold the hwmon_lock, temporarily modify data-\u003econfig, and then restore it. If an alert interrupt occurs concurrently with a sysfs write, the sysfs path will overwrite the alert handler's modifications to data-\u003econfig and the hardware register. This unintentionally re-enables the hardware alert line while the alarm is still active, causing an interrupt storm. Add the missing lock to lm90_alert() to solve the problem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64213", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gg8om0EaDGmaluF17orLqg==": { "id": "gg8om0EaDGmaluF17orLqg==", "updater": "debian/updater", "name": "CVE-2026-64463", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres rt1711h_probe() registers the TCPCI port before requesting the interrupt and enabling alert interrupts. If either of those later steps fails, the probe function returns without unregistering the TCPCI port. The explicit unregister currently only happens from the remove callback. Register a devres action immediately after tcpci_register_port() succeeds, so tcpci_unregister_port() runs on later probe failures and on driver detach. Drop the remove callback to avoid unregistering the same port twice. This issue was identified during our ongoing static-analysis research while reviewing kernel code.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64463", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gmmLCpwndlyXmMBrnZn0Lw==": { "id": "gmmLCpwndlyXmMBrnZn0Lw==", "updater": "debian/updater", "name": "CVE-2025-66862", "description": "A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66862", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gobA70V8S+fBhe3etA88AQ==": { "id": "gobA70V8S+fBhe3etA88AQ==", "updater": "debian/updater", "name": "CVE-2025-37956", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. It will cause a kernel oops from d_alloc. This patch return the error when attempting to rename a file or directory with an empty new name string.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37956", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gpWgVqaQmhTigA4n4UKLcw==": { "id": "gpWgVqaQmhTigA4n4UKLcw==", "updater": "debian/updater", "name": "CVE-2025-37800", "description": "In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads \"uevent\" device attribute at the same time as another threads unbinds the device from its driver, change to dev-\u003edriver from a valid pointer to NULL may result in crash. Fix this by using READ_ONCE() when fetching the pointer, and take bus' drivers klist lock to make sure driver instance will not disappear while we access it. Use WRITE_ONCE() when setting the driver pointer to ensure there is no tearing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37800", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gt5sb+F8Vt96IRL1gx4D9g==": { "id": "gt5sb+F8Vt96IRL1gx4D9g==", "updater": "debian/updater", "name": "CVE-2023-2953", "description": "A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-2953", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openldap", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gtf6IZ1G6pyIA4U2B7AsmQ==": { "id": "gtf6IZ1G6pyIA4U2B7AsmQ==", "updater": "debian/updater", "name": "CVE-2008-3134", "description": "Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-3134", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gy2AALhX/hsEZnzWIdHdWw==": { "id": "gy2AALhX/hsEZnzWIdHdWw==", "updater": "debian/updater", "name": "CVE-2024-49970", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN401 'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four elements, corresponding to the four calls to stream_enc_regs() in the array initializer. This means that valid indices for this array are 0, 1, 2, and 3. The error message 'stream_enc_regs' 4 \u003c= 5 below, is indicating that there is an attempt to access this array with an index of 5, which is out of bounds. This could lead to undefined behavior Here, eng_id is used as an index to access the stream_enc_regs array. If eng_id is 5, this would result in an out-of-bounds access on the stream_enc_regs array. Thus fixing Buffer overflow error in dcn401_stream_encoder_create Found by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn401/dcn401_resource.c:1209 dcn401_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 \u003c= 5", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49970", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gyC7EL6tB6bwD1BROgqS6w==": { "id": "gyC7EL6tB6bwD1BROgqS6w==", "updater": "debian/updater", "name": "CVE-2026-43253", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/amd: move wait_on_sem() out of spinlock With iommu.strict=1, the existing completion wait path can cause soft lockups under stressed environment, as wait_on_sem() busy-waits under the spinlock with interrupts disabled. Move the completion wait in iommu_completion_wait() out of the spinlock. wait_on_sem() only polls the hardware-updated cmd_sem and does not require iommu-\u003elock, so holding the lock during the busy wait unnecessarily increases contention and extends the time with interrupts disabled.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43253", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gyVItLDvKyiNCqhC3vwT0Q==": { "id": "gyVItLDvKyiNCqhC3vwT0Q==", "updater": "debian/updater", "name": "CVE-2026-64060", "description": "In the Linux kernel, the following vulnerability has been resolved: netfs: Fix leak of request in netfs_write_begin() error handling Fix netfs_write_begin() to not leak our ref on the request in the event that we get an error from netfs_wait_for_read().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64060", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "gyst6sbdN8tJ7Od9cn3GJw==": { "id": "gyst6sbdN8tJ7Od9cn3GJw==", "updater": "debian/updater", "name": "CVE-2026-68365", "description": "In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status packet reports transmit credits returned by the device. edge_interrupt_callback() adds the 16-bit value to txCredits without checking maxTxCredits. edge_write() uses txCredits minus the software FIFO count as the amount of data that fits. Since the FIFO is allocated with maxTxCredits bytes, txCredits exceeding maxTxCredits can cause OOB write in ring buffer. Cap accumulated credits at maxTxCredits. Conforming devices should never hit the cap.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68365", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "h4QHAJEWozjnyL48yC+Q2A==": { "id": "h4QHAJEWozjnyL48yC+Q2A==", "updater": "debian/updater", "name": "CVE-2026-46157", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race. And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well, which confuses the operation completely, as spotted by fuzzing. Fix it by covering runtime.oss.trigger bit fled also with the existing params_lock mutex in both snd_pcm_oss_get_trigger() and snd_pcm_oss_poll().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46157", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "h9BaEX+pzwj1f9hCTlIewA==": { "id": "h9BaEX+pzwj1f9hCTlIewA==", "updater": "debian/updater", "name": "CVE-2026-68196", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length before subtracting header wilc_parse_assoc_resp_info() computes the trailing IE length as \ties_len = buffer_len - sizeof(*res); without first checking that buffer_len is at least sizeof(struct wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a received association response (host_int_parse_assoc_resp_info() passes hif_drv-\u003eassoc_resp / assoc_resp_info_len straight in) and must be validated before the driver accesses the fixed header. For a frame shorter than the 6-byte fixed header, the subtraction wraps. For a four-byte response the result is truncated to a u16 ies_len of 65534, so kmemdup() then attempts to copy 65534 bytes starting at buffer + sizeof(*res), beyond the valid association-response data (CWE-125). A response shorter than four bytes can also cause an out-of-bounds read of res-\u003estatus_code at offsets 2 and 3. Reject frames too short to hold the fixed header before touching the header or computing ies_len. Also set the connection status to a failure on this path: the caller falls through to a \"conn_info-\u003estatus == WLAN_STATUS_SUCCESS\" check after the parser returns, so leaving the status untouched could let a malformed short response be treated as a successful association.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68196", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hAcRHS8h0bMTgAczqVlCXw==": { "id": "hAcRHS8h0bMTgAczqVlCXw==", "updater": "debian/updater", "name": "CVE-2026-64038", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Stop work before releasing hwmon device Sashiko reports: In lm90_probe(), the devm action to cancel the alert_work and report_work (lm90_restore_conf) is registered in lm90_init_client() before devm_hwmon_device_register_with_info() is called. Because devm executes cleanup actions in reverse order during module unbind or probe failure, the hwmon device is unregistered and freed first. If lm90_alert_work() or lm90_report_alarms() runs in the window between the hwmon device being freed and the delayed works being cancelled, lm90_update_alarms() will dereference the freed data-\u003ehwmon_dev here. Fix the problem by canceling the workers separately after registering the hwmon device and before registering the interrupt handler. This ensures that the workers are canceled after interrupts are disabled and before the hwmon device is released. Add \"shutdown\" flag to indicate that device shutdown is in progress to prevent workers from being re-armed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64038", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hE5ON6NcQF/ZdeAv4cBeyw==": { "id": "hE5ON6NcQF/ZdeAv4cBeyw==", "updater": "debian/updater", "name": "CVE-2026-68480", "description": "In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution. Fixup register state as if the Safe-RET sequence executed successfully by \"emulating\" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68480", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hHuds3Mc9Bpql1Z9vbWn2g==": { "id": "hHuds3Mc9Bpql1Z9vbWn2g==", "updater": "debian/updater", "name": "CVE-2024-53079", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/thp: fix deferred split unqueue naming and locking Recent changes are putting more pressure on THP deferred split queues: under load revealing long-standing races, causing list_del corruptions, \"Bad page state\"s and worse (I keep BUGs in both of those, so usually don't get to see how badly they end up without). The relevant recent changes being 6.8's mTHP, 6.10's mTHP swapout, and 6.12's mTHP swapin, improved swap allocation, and underused THP splitting. Before fixing locking: rename misleading folio_undo_large_rmappable(), which does not undo large_rmappable, to folio_unqueue_deferred_split(), which is what it does. But that and its out-of-line __callee are mm internals of very limited usability: add comment and WARN_ON_ONCEs to check usage; and return a bool to say if a deferred split was unqueued, which can then be used in WARN_ON_ONCEs around safety checks (sparing callers the arcane conditionals in __folio_unqueue_deferred_split()). Just omit the folio_unqueue_deferred_split() from free_unref_folios(), all of whose callers now call it beforehand (and if any forget then bad_page() will tell) - except for its caller put_pages_list(), which itself no longer has any callers (and will be deleted separately). Swapout: mem_cgroup_swapout() has been resetting folio-\u003ememcg_data 0 without checking and unqueueing a THP folio from deferred split list; which is unfortunate, since the split_queue_lock depends on the memcg (when memcg is enabled); so swapout has been unqueueing such THPs later, when freeing the folio, using the pgdat's lock instead: potentially corrupting the memcg's list. __remove_mapping() has frozen refcount to 0 here, so no problem with calling folio_unqueue_deferred_split() before resetting memcg_data. That goes back to 5.4 commit 87eaceb3faa5 (\"mm: thp: make deferred split shrinker memcg aware\"): which included a check on swapcache before adding to deferred queue, but no check on deferred queue before adding THP to swapcache. That worked fine with the usual sequence of events in reclaim (though there were a couple of rare ways in which a THP on deferred queue could have been swapped out), but 6.12 commit dafff3f4c850 (\"mm: split underused THPs\") avoids splitting underused THPs in reclaim, which makes swapcache THPs on deferred queue commonplace. Keep the check on swapcache before adding to deferred queue? Yes: it is no longer essential, but preserves the existing behaviour, and is likely to be a worthwhile optimization (vmstat showed much more traffic on the queue under swapping load if the check was removed); update its comment. Memcg-v1 move (deprecated): mem_cgroup_move_account() has been changing folio-\u003ememcg_data without checking and unqueueing a THP folio from the deferred list, sometimes corrupting \"from\" memcg's list, like swapout. Refcount is non-zero here, so folio_unqueue_deferred_split() can only be used in a WARN_ON_ONCE to validate the fix, which must be done earlier: mem_cgroup_move_charge_pte_range() first try to split the THP (splitting of course unqueues), or skip it if that fails. Not ideal, but moving charge has been requested, and khugepaged should repair the THP later: nobody wants new custom unqueueing code just for this deprecated case. The 87eaceb3faa5 commit did have the code to move from one deferred list to another (but was not conscious of its unsafety while refcount non-0); but that was removed by 5.6 commit fac0516b5534 (\"mm: thp: don't need care deferred split queue in memcg charge move path\"), which argued that the existence of a PMD mapping guarantees that the THP cannot be on a deferred list. As above, false in rare cases, and now commonly false. Backport to 6.11 should be straightforward. Earlier backports must take care that other _deferred_list fixes and dependencies are included. There is not a strong case for backports, but they can fix cornercases.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53079", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hLgns+5VPBgBxKIOHCmUAQ==": { "id": "hLgns+5VPBgBxKIOHCmUAQ==", "updater": "debian/updater", "name": "CVE-2024-49920", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before multiple uses [WHAT \u0026 HOW] Poniters, such as stream_enc and dc-\u003ebw_vbios, are null checked previously in the same function, so Coverity warns \"implies that stream_enc and dc-\u003ebw_vbios might be null\". They are used multiple times in the subsequent code and need to be checked. This fixes 10 FORWARD_NULL issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49920", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hNTPziyPr0zH92JXPH3A5Q==": { "id": "hNTPziyPr0zH92JXPH3A5Q==", "updater": "debian/updater", "name": "CVE-2023-25193", "description": "hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-25193", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "harfbuzz", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hPYi8glMBvStMRV421SnXQ==": { "id": "hPYi8glMBvStMRV421SnXQ==", "updater": "debian/updater", "name": "CVE-2016-9581", "description": "An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9581", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hPf8NZdo1gT8Bb3FUXhP/w==": { "id": "hPf8NZdo1gT8Bb3FUXhP/w==", "updater": "debian/updater", "name": "CVE-2026-68325", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size. Check the capacity at the common found label before parsing the HID and UID or writing the entry.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68325", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hSujAslBKEPcDUtT6cHujA==": { "id": "hSujAslBKEPcDUtT6cHujA==", "updater": "debian/updater", "name": "CVE-2026-68132", "description": "In the Linux kernel, the following vulnerability has been resolved: super: fix emergency thaw deadlock on frozen block devices do_thaw_all_callback() calls bdev_thaw() while holding sb-\u003es_umount exclusively. If the block device was frozen via bdev_freeze() dropping the last block layer freeze reference calls fs_bdev_thaw() which reacquires s_umount: do_thaw_all_callback(sb) super_lock_excl(sb) # holds sb-\u003es_umount bdev_thaw(sb-\u003es_bdev) mutex_lock(\u0026bdev-\u003ebd_fsfreeze_mutex) # bd_fsfreeze_count drops 1 -\u003e 0 bd_holder_ops-\u003ethaw == fs_bdev_thaw get_bdev_super(bdev) bdev_super_lock(bdev, true) super_lock(sb, true) down_write(\u0026sb-\u003es_umount) # same task: deadlock The emergency thaw worker deadlocks against itself holding both s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount, freeze, or thaw of that filesystem and block device. [ 81.878470] sysrq: Show Blocked State [ 81.880140] task:kworker/0:1 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208060 flags:0x00080000 [ 81.884876] Workqueue: events do_thaw_all [ 81.886656] Call Trace: [ 81.887759] \u003cTASK\u003e [ 81.888763] __schedule+0x579/0x1420 [ 81.890372] schedule+0x3a/0x100 [ 81.891794] schedule_preempt_disabled+0x15/0x30 [ 81.893848] rwsem_down_write_slowpath+0x1ea/0x900 [ 81.895191] ? __pfx_do_thaw_all_callback+0x10/0x10 [ 81.896528] down_write+0xbd/0xc0 [ 81.897505] super_lock+0x91/0x180 [ 81.898457] ? __mutex_lock+0xa99/0x1140 [ 81.900748] ? __mutex_unlock_slowpath+0x1f/0x400 [ 81.902069] bdev_super_lock+0x5b/0x150 [ 81.903132] get_bdev_super+0x10/0x60 [ 81.904042] fs_bdev_thaw+0x23/0xf0 [ 81.904755] bdev_thaw+0x82/0x100 [ 81.905484] do_thaw_all_callback+0x2c/0x50 [ 81.906298] __iterate_supers+0x5d/0x130 [ 81.907067] do_thaw_all+0x20/0x40 [ 81.907739] process_one_work+0x206/0x5e0 [ 81.908545] worker_thread+0x1e2/0x3c0 [ 81.909339] ? __pfx_worker_thread+0x10/0x10 [ 81.910171] kthread+0xf4/0x130 [ 81.910799] ? __pfx_kthread+0x10/0x10 [ 81.911528] ret_from_fork+0x2e2/0x3b0 [ 81.912259] ? __pfx_kthread+0x10/0x10 [ 81.913010] ret_from_fork_asm+0x1a/0x30 [ 81.913806] \u003c/TASK\u003e bdev_super_lock() even documents the violated requirement with lockdep_assert_not_held(\u0026sb-\u003es_umount). Acquiring bd_fsfreeze_mutex under s_umount also inverts the bd_fsfreeze_mutex vs. s_umount ordering established by bdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer freeze even when the recursive path isn't hit. Fix this by not holding s_umount around the bdev_thaw() loop at all. Pin the superblock with an active reference instead as filesystems_freeze_callback() does. The active reference keeps the superblock from being shut down and so -\u003es_bdev stays valid without holding s_umount. The block-layer-held freeze is dropped by fs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as a regular unfreeze would and thaw_super_locked() handles filesystem-level freezes as before. The emergency thaw path has deadlocked like this in one form or another for a long long time but the current exclusively-held shape dates back to commit [1] where thaw_bdev() already ended in thaw_super() with s_umount held by do_thaw_all_callback().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68132", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hUVvVaAQhwSwgFrBD1MdTg==": { "id": "hUVvVaAQhwSwgFrBD1MdTg==", "updater": "debian/updater", "name": "CVE-2026-73283", "description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-73283", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hbsENkHIOQnmxsyPIblNZQ==": { "id": "hbsENkHIOQnmxsyPIblNZQ==", "updater": "debian/updater", "name": "CVE-2019-11191", "description": "The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat. NOTE: the software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-11191", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hc9IJmOmNudYf6pO7HrB2g==": { "id": "hc9IJmOmNudYf6pO7HrB2g==", "updater": "debian/updater", "name": "CVE-2026-68162", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl-\u003edata, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously registered its per-net sysctls from sctp_defaults_init(), while the control socket is created later from sctp_ctrlsock_init(). This exposed a window during initialization where auth_enable was writable before net-\u003esctp.ctl_sock existed, and a teardown window where auth_enable stayed writable after inet_ctl_sock_destroy() had released the control socket. Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after sctp_ctl_sock_init() succeeds, and unregister the sysctl table before destroying the control socket in sctp_ctrlsock_exit(). If sysctl registration fails after the control socket was created, destroy the control socket in the same init path. Make sctp_sysctl_net_unregister() tolerate a missing header and clear the saved pointer so init-error and exit paths can safely share the unregister helper.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68162", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hju8ng9CG1pc4cQuvE/AIw==": { "id": "hju8ng9CG1pc4cQuvE/AIw==", "updater": "debian/updater", "name": "CVE-2025-40328", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached_fid() find_or_create_cached_dir() could grab a new reference after kref_put() had seen the refcount drop to zero but before cfid_list_lock is acquired in smb2_close_cached_fid(), leading to use-after-free. Switch to kref_put_lock() so cfid_release() is called with cfid_list_lock held, closing that gap.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40328", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hoU7b3nCpZ8AGIjXIp7o0A==": { "id": "hoU7b3nCpZ8AGIjXIp7o0A==", "updater": "debian/updater", "name": "CVE-2025-8176", "description": "A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8176", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hoc7dG+Mk8W7soxdxHhlhA==": { "id": "hoc7dG+Mk8W7soxdxHhlhA==", "updater": "debian/updater", "name": "CVE-2024-49988", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: add refcnt to ksmbd_conn struct When sending an oplock break request, opinfo-\u003econn is used, But freed -\u003econn can be used on multichannel. This patch add a reference count to the ksmbd_conn struct so that it can be freed when it is no longer used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49988", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hrRIVmXshFU+iVUyHoT8iA==": { "id": "hrRIVmXshFU+iVUyHoT8iA==", "updater": "debian/updater", "name": "CVE-2025-40054", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF issue in f2fs_merge_page_bio() As JY reported in bugzilla [1], Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98 lr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4 CPU: 3 UID: 0 PID: 6790 Comm: kworker/u16:3 Tainted: P B W OE 6.12.30-android16-5-maybe-dirty-4k #1 5f7701c9cbf727d1eebe77c89bbbeb3371e895e5 Tainted: [P]=PROPRIETARY_MODULE, [B]=BAD_PAGE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Workqueue: writeback wb_workfn (flush-254:49) Call trace: f2fs_is_cp_guaranteed+0x70/0x98 f2fs_inplace_write_data+0x174/0x2f4 f2fs_do_write_data_page+0x214/0x81c f2fs_write_single_data_page+0x28c/0x764 f2fs_write_data_pages+0x78c/0xce4 do_writepages+0xe8/0x2fc __writeback_single_inode+0x4c/0x4b4 writeback_sb_inodes+0x314/0x540 __writeback_inodes_wb+0xa4/0xf4 wb_writeback+0x160/0x448 wb_workfn+0x2f0/0x5dc process_scheduled_works+0x1c8/0x458 worker_thread+0x334/0x3f0 kthread+0x118/0x1ac ret_from_fork+0x10/0x20 [1] https://bugzilla.kernel.org/show_bug.cgi?id=220575 The panic was caused by UAF issue w/ below race condition: kworker - writepages - f2fs_write_cache_pages - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_merge_page_bio - add_inu_page : cache page #1 into bio \u0026 cache bio in io-\u003ebio_list - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_merge_page_bio - add_inu_page : cache page #2 into bio which is linked in io-\u003ebio_list \t\t\t\t\t\twrite \t\t\t\t\t\t- f2fs_write_begin \t\t\t\t\t\t: write page #1 \t\t\t\t\t\t - f2fs_folio_wait_writeback \t\t\t\t\t\t - f2fs_submit_merged_ipu_write \t\t\t\t\t\t - f2fs_submit_write_bio \t\t\t\t\t\t : submit bio which inclues page #1 and #2 \t\t\t\t\t\tsoftware IRQ \t\t\t\t\t\t- f2fs_write_end_io \t\t\t\t\t\t - fscrypt_free_bounce_page \t\t\t\t\t\t : freed bounced page which belongs to page #2 - inc_page_count( , WB_DATA_TYPE(data_folio), false) : data_folio points to fio-\u003eencrypted_page the bounced page can be freed before accessing it in f2fs_is_cp_guarantee() It can reproduce w/ below testcase: Run below script in shell #1: for ((i=1;i\u003e0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\ -c \"pwrite 0 32k\" -c \"fdatasync\" Run below script in shell #2: for ((i=1;i\u003e0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\ -c \"pwrite 0 32k\" -c \"fdatasync\" So, in f2fs_merge_page_bio(), let's avoid using fio-\u003eencrypted_page after commit page into internal ipu cache.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40054", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "huYa0W+0g8fZ2PeXYJCMOQ==": { "id": "huYa0W+0g8fZ2PeXYJCMOQ==", "updater": "debian/updater", "name": "CVE-2026-31592", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm-\u003elock Take and hold kvm-\u003elock for before checking sev_guest() in sev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm-\u003elock is held (or KVM can guarantee KVM_SEV_INIT{2} has completed and can't rollack state). If KVM_SEV_INIT{2} fails, KVM can end up trying to add to a not-yet-initialized sev-\u003eregions_list, e.g. triggering a #GP Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 110 UID: 0 PID: 72717 Comm: syz.15.11462 Tainted: G U W O 6.16.0-smp-DEV #1 NONE Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.52.0-0 10/28/2024 RIP: 0010:sev_mem_enc_register_region+0x3f0/0x4f0 ../include/linux/list.h:83 Code: \u003c41\u003e 80 3c 04 00 74 08 4c 89 ff e8 f1 c7 a2 00 49 39 ed 0f 84 c6 00 RSP: 0018:ffff88838647fbb8 EFLAGS: 00010256 RAX: dffffc0000000000 RBX: 1ffff92015cf1e0b RCX: dffffc0000000000 RDX: 0000000000000000 RSI: 0000000000001000 RDI: ffff888367870000 RBP: ffffc900ae78f050 R08: ffffea000d9e0007 R09: 1ffffd4001b3c000 R10: dffffc0000000000 R11: fffff94001b3c001 R12: 0000000000000000 R13: ffff8982ab0bde00 R14: ffffc900ae78f058 R15: 0000000000000000 FS: 00007f34e9dc66c0(0000) GS:ffff89ee64d33000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe180adef98 CR3: 000000047210e000 CR4: 0000000000350ef0 Call Trace: \u003cTASK\u003e kvm_arch_vm_ioctl+0xa72/0x1240 ../arch/x86/kvm/x86.c:7371 kvm_vm_ioctl+0x649/0x990 ../virt/kvm/kvm_main.c:5363 __se_sys_ioctl+0x101/0x170 ../fs/ioctl.c:51 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x6f/0x1f0 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f34e9f7e9a9 Code: \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f34e9dc6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007f34ea1a6080 RCX: 00007f34e9f7e9a9 RDX: 0000200000000280 RSI: 000000008010aebb RDI: 0000000000000007 RBP: 00007f34ea000d69 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 00007f34ea1a6080 R15: 00007ffce77197a8 \u003c/TASK\u003e with a syzlang reproducer that looks like: syz_kvm_add_vcpu$x86(0x0, \u0026(0x7f0000000040)={0x0, \u0026(0x7f0000000180)=ANY=[], 0x70}) (async) syz_kvm_add_vcpu$x86(0x0, \u0026(0x7f0000000080)={0x0, \u0026(0x7f0000000180)=ANY=[@ANYBLOB=\"...\"], 0x4f}) (async) r0 = openat$kvm(0xffffffffffffff9c, \u0026(0x7f0000000200), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = openat$kvm(0xffffffffffffff9c, \u0026(0x7f0000000240), 0x0, 0x0) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) ioctl$KVM_SET_CLOCK(r3, 0xc008aeba, \u0026(0x7f0000000040)={0x1, 0x8, 0x0, 0x5625e9b0}) (async) ioctl$KVM_SET_PIT2(r3, 0x8010aebb, \u0026(0x7f0000000280)={[...], 0x5}) (async) ioctl$KVM_SET_PIT2(r1, 0x4070aea0, 0x0) (async) r4 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) (async) ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, \u0026(0x7f0000000400)={0x0, 0x0, 0x0, 0x2000, \u0026(0x7f0000001000/0x2000)=nil}) (async) r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2) close(r0) (async) openat$kvm(0xffffffffffffff9c, \u0026(0x7f0000000000), 0x8000, 0x0) (async) ioctl$KVM_SET_GUEST_DEBUG(r5, 0x4048ae9b, \u0026(0x7f0000000300)={0x4376ea830d46549b, 0x0, [0x46, 0x0, 0x0, 0x0, 0x0, 0x1000]}) (async) ioctl$KVM_RUN(r5, 0xae80, 0x0) Opportunistically use guard() to avoid having to define a new error label and goto usage.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31592", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hvrnL6/SCX8xDjTn++W9GA==": { "id": "hvrnL6/SCX8xDjTn++W9GA==", "updater": "debian/updater", "name": "CVE-2026-59997", "description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-59997", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hw1aS7NFesUo2f+sJX9NiQ==": { "id": "hw1aS7NFesUo2f+sJX9NiQ==", "updater": "debian/updater", "name": "CVE-2020-11725", "description": "snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info-\u003eowner line, which later affects a private_size*count multiplication for unspecified \"interesting side effects.\" NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers were added that were unfamiliar with the misuse of the info-\u003eowner field to represent data unrelated to the \"owner\" concept. The existing callers, SNDRV_CTL_IOCTL_ELEM_ADD and SNDRV_CTL_IOCTL_ELEM_REPLACE, have been designed to misuse the info-\u003eowner field in a safe way", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-11725", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "hwXuy8O1w56Q1F9dXbVfAQ==": { "id": "hwXuy8O1w56Q1F9dXbVfAQ==", "updater": "debian/updater", "name": "CVE-2023-54013", "description": "In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix locking for runpm vs reclaim For cases where icc_bw_set() can be called in callbaths that could deadlock against shrinker/reclaim, such as runpm resume, we need to decouple the icc locking. Introduce a new icc_bw_lock for cases where we need to serialize bw aggregation and update to decouple that from paths that require memory allocation such as node/link creation/ destruction. Fixes this lockdep splat: ====================================================== WARNING: possible circular locking dependency detected 6.2.0-rc8-debug+ #554 Not tainted ------------------------------------------------------ ring0/132 is trying to acquire lock: ffffff80871916d0 (\u0026gmu-\u003elock){+.+.}-{3:3}, at: a6xx_pm_resume+0xf0/0x234 but task is already holding lock: ffffffdb5aee57e8 (dma_fence_map){++++}-{0:0}, at: msm_job_run+0x68/0x150 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -\u003e #4 (dma_fence_map){++++}-{0:0}: __dma_fence_might_wait+0x74/0xc0 dma_resv_lockdep+0x1f4/0x2f4 do_one_initcall+0x104/0x2bc kernel_init_freeable+0x344/0x34c kernel_init+0x30/0x134 ret_from_fork+0x10/0x20 -\u003e #3 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}: fs_reclaim_acquire+0x80/0xa8 slab_pre_alloc_hook.constprop.0+0x40/0x25c __kmem_cache_alloc_node+0x60/0x1cc __kmalloc+0xd8/0x100 topology_parse_cpu_capacity+0x8c/0x178 get_cpu_for_node+0x88/0xc4 parse_cluster+0x1b0/0x28c parse_cluster+0x8c/0x28c init_cpu_topology+0x168/0x188 smp_prepare_cpus+0x24/0xf8 kernel_init_freeable+0x18c/0x34c kernel_init+0x30/0x134 ret_from_fork+0x10/0x20 -\u003e #2 (fs_reclaim){+.+.}-{0:0}: __fs_reclaim_acquire+0x3c/0x48 fs_reclaim_acquire+0x54/0xa8 slab_pre_alloc_hook.constprop.0+0x40/0x25c __kmem_cache_alloc_node+0x60/0x1cc __kmalloc+0xd8/0x100 kzalloc.constprop.0+0x14/0x20 icc_node_create_nolock+0x4c/0xc4 icc_node_create+0x38/0x58 qcom_icc_rpmh_probe+0x1b8/0x248 platform_probe+0x70/0xc4 really_probe+0x158/0x290 __driver_probe_device+0xc8/0xe0 driver_probe_device+0x44/0x100 __driver_attach+0xf8/0x108 bus_for_each_dev+0x78/0xc4 driver_attach+0x2c/0x38 bus_add_driver+0xd0/0x1d8 driver_register+0xbc/0xf8 __platform_driver_register+0x30/0x3c qnoc_driver_init+0x24/0x30 do_one_initcall+0x104/0x2bc kernel_init_freeable+0x344/0x34c kernel_init+0x30/0x134 ret_from_fork+0x10/0x20 -\u003e #1 (icc_lock){+.+.}-{3:3}: __mutex_lock+0xcc/0x3c8 mutex_lock_nested+0x30/0x44 icc_set_bw+0x88/0x2b4 _set_opp_bw+0x8c/0xd8 _set_opp+0x19c/0x300 dev_pm_opp_set_opp+0x84/0x94 a6xx_gmu_resume+0x18c/0x804 a6xx_pm_resume+0xf8/0x234 adreno_runtime_resume+0x2c/0x38 pm_generic_runtime_resume+0x30/0x44 __rpm_callback+0x15c/0x174 rpm_callback+0x78/0x7c rpm_resume+0x318/0x524 __pm_runtime_resume+0x78/0xbc adreno_load_gpu+0xc4/0x17c msm_open+0x50/0x120 drm_file_alloc+0x17c/0x228 drm_open_helper+0x74/0x118 drm_open+0xa0/0x144 drm_stub_open+0xd4/0xe4 chrdev_open+0x1b8/0x1e4 do_dentry_open+0x2f8/0x38c vfs_open+0x34/0x40 path_openat+0x64c/0x7b4 do_filp_open+0x54/0xc4 do_sys_openat2+0x9c/0x100 do_sys_open+0x50/0x7c __arm64_sys_openat+0x28/0x34 invoke_syscall+0x8c/0x128 el0_svc_common.constprop.0+0xa0/0x11c do_el0_ ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54013", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i+rrqjPcomFeN8diE7L33A==": { "id": "i+rrqjPcomFeN8diE7L33A==", "updater": "debian/updater", "name": "CVE-2025-69644", "description": "An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69644", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i/qfmVnfw478DUjEfi5wrQ==": { "id": "i/qfmVnfw478DUjEfi5wrQ==", "updater": "debian/updater", "name": "CVE-2025-38182", "description": "In the Linux kernel, the following vulnerability has been resolved: ublk: santizize the arguments from userspace when adding a device Sanity check the values for queue depth and number of queues we get from userspace when adding a device.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38182", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i1s4S05MBwRzcUxGMEEy+A==": { "id": "i1s4S05MBwRzcUxGMEEy+A==", "updater": "debian/updater", "name": "CVE-2025-69645", "description": "Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69645", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i2AkMMRWwQC/zP2vb2ZDEQ==": { "id": "i2AkMMRWwQC/zP2vb2ZDEQ==", "updater": "debian/updater", "name": "CVE-2026-64578", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) SMB2 request, ksmbd_smb2_check_message() reads pdu-\u003eStructureSize2 without first checking that the compound element is large enough to contain it. StructureSize2 is a 2-byte field at offset 64 (__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element. The compound-walking logic only guarantees that a full 64-byte SMB2 header is present for the trailing element: when NextCommand is 0, len is reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A remote client can craft a compound request whose last element has exactly 64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte past the receive buffer, producing a slab-out-of-bounds read. BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402) Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14 The buggy address is located 172 bytes inside of allocated 173-byte region Workqueue: ksmbd-io handle_ksmbd_work Call Trace: ... kasan_report (mm/kasan/report.c:595) ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402) handle_ksmbd_work (fs/smb/server/server.c:119) process_one_work (kernel/workqueue.c:3314) worker_thread (kernel/workqueue.c:3397) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) Reject any compound element that is too small to hold StructureSize2 before dereferencing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64578", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "i5e3aCZ3KFF1VAfPW3LZVQ==": { "id": "i5e3aCZ3KFF1VAfPW3LZVQ==", "updater": "debian/updater", "name": "CVE-2018-6951", "description": "An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-6951", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iCypsGLRz0uLfvrJIEyGzA==": { "id": "iCypsGLRz0uLfvrJIEyGzA==", "updater": "debian/updater", "name": "CVE-2019-16230", "description": "drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics card occurs during boot. It is not attacker controllable and OOM at that time is highly unlikely", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16230", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iEDMueHFmszLRMIGHWZmww==": { "id": "iEDMueHFmszLRMIGHWZmww==", "updater": "debian/updater", "name": "CVE-2020-14145", "description": "The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2020-14145", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iIogkXVmWzUQmvCLYwSVyA==": { "id": "iIogkXVmWzUQmvCLYwSVyA==", "updater": "debian/updater", "name": "CVE-2025-37807", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kmemleak warning for percpu hashmap Vlad Poenaru reported the following kmemleak issue: unreferenced object 0x606fd7c44ac8 (size 32): backtrace (crc 0): pcpu_alloc_noprof+0x730/0xeb0 bpf_map_alloc_percpu+0x69/0xc0 prealloc_init+0x9d/0x1b0 htab_map_alloc+0x363/0x510 map_create+0x215/0x3a0 __sys_bpf+0x16b/0x3e0 __x64_sys_bpf+0x18/0x20 do_syscall_64+0x7b/0x150 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Further investigation shows the reason is due to not 8-byte aligned store of percpu pointer in htab_elem_set_ptr(): *(void __percpu **)(l-\u003ekey + key_size) = pptr; Note that the whole htab_elem alignment is 8 (for x86_64). If the key_size is 4, that means pptr is stored in a location which is 4 byte aligned but not 8 byte aligned. In mm/kmemleak.c, scan_block() scans the memory based on 8 byte stride, so it won't detect above pptr, hence reporting the memory leak. In htab_map_alloc(), we already have htab-\u003eelem_size = sizeof(struct htab_elem) + round_up(htab-\u003emap.key_size, 8); if (percpu) htab-\u003eelem_size += sizeof(void *); else htab-\u003eelem_size += round_up(htab-\u003emap.value_size, 8); So storing pptr with 8-byte alignment won't cause any problem and can fix kmemleak too. The issue can be reproduced with bpf selftest as well: 1. Enable CONFIG_DEBUG_KMEMLEAK config 2. Add a getchar() before skel destroy in test_hash_map() in prog_tests/for_each.c. The purpose is to keep map available so kmemleak can be detected. 3. run './test_progs -t for_each/hash_map \u0026' and a kmemleak should be reported.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37807", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iKw4ydcJcdKtvLNGHH6VHA==": { "id": "iKw4ydcJcdKtvLNGHH6VHA==", "updater": "debian/updater", "name": "CVE-2024-46754", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input_action_end_bpf() first. Martin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL probably didn't work since it was introduced in commit 04d4b274e2a (\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the per-CPU variable seg6_bpf_srh_states::srh is never assigned in the self test case but each BPF function expects it. Remove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46754", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iOyLmeTOvgguVhp+6I7Gmw==": { "id": "iOyLmeTOvgguVhp+6I7Gmw==", "updater": "debian/updater", "name": "CVE-2026-6019", "description": "http.cookies.Morsel.js_output() returns an inline \u003cscript\u003e snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence \u003c/script\u003e inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6019", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iPYyKUE/vmQTv1il4lqxEg==": { "id": "iPYyKUE/vmQTv1il4lqxEg==", "updater": "debian/updater", "name": "CVE-2026-43490", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43490", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iSKNzZ2VWxhWfx0M40PIwQ==": { "id": "iSKNzZ2VWxhWfx0M40PIwQ==", "updater": "debian/updater", "name": "CVE-2023-39327", "description": "A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-39327", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iShLWfacVbWp+yrwXBiO+A==": { "id": "iShLWfacVbWp+yrwXBiO+A==", "updater": "debian/updater", "name": "CVE-2025-39850", "description": "In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects When the \"proxy\" option is enabled on a VXLAN device, the device will suppress ARP requests and IPv6 Neighbor Solicitation messages if it is able to reply on behalf of the remote host. That is, if a matching and valid neighbor entry is configured on the VXLAN device whose MAC address is not behind the \"any\" remote (0.0.0.0 / ::). The code currently assumes that the FDB entry for the neighbor's MAC address points to a valid remote destination, but this is incorrect if the entry is associated with an FDB nexthop group. This can result in a NPD [1][3] which can be reproduced using [2][4]. Fix by checking that the remote destination exists before dereferencing it. [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 4 UID: 0 PID: 365 Comm: arping Not tainted 6.17.0-rc2-virtme-g2a89cb21162c #2 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 RIP: 0010:vxlan_xmit+0xb58/0x15f0 [...] Call Trace: \u003cTASK\u003e dev_hard_start_xmit+0x5d/0x1c0 __dev_queue_xmit+0x246/0xfd0 packet_sendmsg+0x113a/0x1850 __sock_sendmsg+0x38/0x70 __sys_sendto+0x126/0x180 __x64_sys_sendto+0x24/0x30 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x4b/0x53 [2] #!/bin/bash ip address add 192.0.2.1/32 dev lo ip nexthop add id 1 via 192.0.2.2 fdb ip nexthop add id 10 group 1 fdb ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 4789 proxy ip neigh add 192.0.2.3 lladdr 00:11:22:33:44:55 nud perm dev vx0 bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10 arping -b -c 1 -s 192.0.2.1 -I vx0 192.0.2.3 [3] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 13 UID: 0 PID: 372 Comm: ndisc6 Not tainted 6.17.0-rc2-virtmne-g6ee90cb26014 #3 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1v996), BIOS 1.17.0-4.fc41 04/01/2x014 RIP: 0010:vxlan_xmit+0x803/0x1600 [...] Call Trace: \u003cTASK\u003e dev_hard_start_xmit+0x5d/0x1c0 __dev_queue_xmit+0x246/0xfd0 ip6_finish_output2+0x210/0x6c0 ip6_finish_output+0x1af/0x2b0 ip6_mr_output+0x92/0x3e0 ip6_send_skb+0x30/0x90 rawv6_sendmsg+0xe6e/0x12e0 __sock_sendmsg+0x38/0x70 __sys_sendto+0x126/0x180 __x64_sys_sendto+0x24/0x30 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f383422ec77 [4] #!/bin/bash ip address add 2001:db8:1::1/128 dev lo ip nexthop add id 1 via 2001:db8:1::1 fdb ip nexthop add id 10 group 1 fdb ip link add name vx0 up type vxlan id 10010 local 2001:db8:1::1 dstport 4789 proxy ip neigh add 2001:db8:1::3 lladdr 00:11:22:33:44:55 nud perm dev vx0 bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10 ndisc6 -r 1 -s 2001:db8:1::1 -w 1 2001:db8:1::3 vx0", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39850", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iVx3xbnEEWX0lvHLuILwkg==": { "id": "iVx3xbnEEWX0lvHLuILwkg==", "updater": "debian/updater", "name": "CVE-2026-53089", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in offloaded map/prog info fill When querying info for an offloaded BPF map or program, bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() obtain the network namespace with get_net(dev_net(offmap-\u003enetdev)). However, the associated netdev's netns may be racing with teardown during netns destruction. If the netns refcount has already reached 0, get_net() performs a refcount_t increment on 0, triggering: refcount_t: addition on 0; use-after-free. Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains valid, they cannot prevent the netns refcount from reaching zero. Fix this by using maybe_get_net() instead of get_net(). maybe_get_net() uses refcount_inc_not_zero() and returns NULL if the refcount is already zero, which causes ns_get_path_cb() to fail and the caller to return -ENOENT -- the correct behavior when the netns is being destroyed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53089", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iW60tBIRU0UpLCmeaBsyxQ==": { "id": "iW60tBIRU0UpLCmeaBsyxQ==", "updater": "debian/updater", "name": "CVE-2024-57984", "description": "In the Linux kernel, the following vulnerability has been resolved: i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition In dw_i3c_common_probe, \u0026master-\u003ehj_work is bound with dw_i3c_hj_work. And dw_i3c_master_irq_handler can call dw_i3c_master_irq_handle_ibis function to start the work. If we remove the module which will call dw_i3c_common_remove to make cleanup, it will free master-\u003ebase through i3c_master_unregister while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | dw_i3c_hj_work dw_i3c_common_remove | i3c_master_unregister(\u0026master-\u003ebase) | device_unregister(\u0026master-\u003edev) | device_release | //free master-\u003ebase | | i3c_master_do_daa(\u0026master-\u003ebase) | //use master-\u003ebase Fix it by ensuring that the work is canceled before proceeding with the cleanup in dw_i3c_common_remove.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57984", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iXEcxB2DfPdWKg5BNEWY1Q==": { "id": "iXEcxB2DfPdWKg5BNEWY1Q==", "updater": "debian/updater", "name": "CVE-2025-40158", "description": "In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40158", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iXfwRorHjxpSQP/Y3LKYmw==": { "id": "iXfwRorHjxpSQP/Y3LKYmw==", "updater": "debian/updater", "name": "CVE-2024-38622", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add callback function pointer check before its call In dpu_core_irq_callback_handler() callback function pointer is compared to NULL, but then callback function is unconditionally called by this pointer. Fix this bug by adding conditional return. Found by Linux Verification Center (linuxtesting.org) with SVACE. Patchwork: https://patchwork.freedesktop.org/patch/588237/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38622", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iXw7N4NbGRzgDoEs3/8Mgw==": { "id": "iXw7N4NbGRzgDoEs3/8Mgw==", "updater": "debian/updater", "name": "CVE-2026-68202", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the destructor queue_delete() closes the queue timer, then frees it. snd_seq_timer_close() clears q-\u003etimer-\u003etimeri. snd_use_lock_sync() then drains borrowers, and snd_seq_timer_delete() frees q-\u003etimer. A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT that took a queueptr() use_lock reference before the queue was unlinked runs snd_seq_timer_open() after the close. Open refuses re-open only while timeri is set, and the close just cleared it, so it re-opens timeri. snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop() is a no-op, because running was cleared first. So it frees q-\u003etimer with the instance still live. The queue is freed next. The instance stays on the global timer with callback_data pointing at the freed queue. A non-owner START on the unlocked queue arms it. The next tick derefs the freed queue in snd_seq_timer_interrupt(). Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and no queue ownership required. Close any lingering instance in the destructor. There, -\u003etimeri can no longer change: the queue is unlinked and all use_lock borrowers have drained, so no snd_seq_queue_use() can re-open it. Close it before clearing q-\u003etimer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt() to finish, and that callback still reads q-\u003etimer (via snd_seq_check_queue()), so q-\u003etimer must stay valid until it drains.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68202", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iY0B8c3S8KaeJYJfnX7c7A==": { "id": "iY0B8c3S8KaeJYJfnX7c7A==", "updater": "debian/updater", "name": "CVE-2024-57804", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs The driver, through the SAS transport, exposes a sysfs interface to enable/disable PHYs in a controller/expander setup. When multiple PHYs are disabled and enabled in rapid succession, the persistent and current config pages related to SAS IO unit/SAS Expander pages could get corrupted. Use separate memory for each config request.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57804", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iZX1sSr7/tbc8mtMDlBUxQ==": { "id": "iZX1sSr7/tbc8mtMDlBUxQ==", "updater": "debian/updater", "name": "CVE-2026-45893", "description": "In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix \u0026 Optimize table creation from possibly unaligned memory Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses. - Added Fixes tag - Added \"Fix \u0026\" to description as this doesn't just optimize but fixes a potential unaligned memory access [jj: remove duplicate word \"convert\" in comment trigger checkpatch warning]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45893", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iZoWxs61dvDHFXevR0jvWw==": { "id": "iZoWxs61dvDHFXevR0jvWw==", "updater": "debian/updater", "name": "CVE-2026-68362", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set unconditionally even when ath11k_core_qmi_firmware_ready() fails. This leaves the driver in an inconsistent state where initialization is considered complete although the firmware ready handling did not finish successfully. During the subsequent SSR, the driver enters the restart path based on this incorrect state and dereferences uninitialized srng members, resulting in a NULL pointer dereference. Call trace: ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P) ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k] ath11k_core_restart+0x40/0x168 [ath11k] Fix this by: - skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set - setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds - setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling on error Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68362", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iaZLD1oLC/nOU24rKE4c5Q==": { "id": "iaZLD1oLC/nOU24rKE4c5Q==", "updater": "debian/updater", "name": "CVE-2024-57975", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when run_delalloc_nocow() failed [BUG] With CONFIG_DEBUG_VM set, test case generic/476 has some chance to crash with the following VM_BUG_ON_FOLIO(): BTRFS error (device dm-3): cow_file_range failed, start 1146880 end 1253375 len 106496 ret -28 BTRFS error (device dm-3): run_delalloc_nocow failed, start 1146880 end 1253375 len 106496 ret -28 page: refcount:4 mapcount:0 mapping:00000000592787cc index:0x12 pfn:0x10664 aops:btrfs_aops [btrfs] ino:101 dentry name(?):\"f1774\" flags: 0x2fffff80004028(uptodate|lru|private|node=0|zone=2|lastcpupid=0xfffff) page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio)) ------------[ cut here ]------------ kernel BUG at mm/page-writeback.c:2992! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP CPU: 2 UID: 0 PID: 3943513 Comm: kworker/u24:15 Tainted: G OE 6.12.0-rc7-custom+ #87 Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022 Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs] pc : folio_clear_dirty_for_io+0x128/0x258 lr : folio_clear_dirty_for_io+0x128/0x258 Call trace: folio_clear_dirty_for_io+0x128/0x258 btrfs_folio_clamp_clear_dirty+0x80/0xd0 [btrfs] __process_folios_contig+0x154/0x268 [btrfs] extent_clear_unlock_delalloc+0x5c/0x80 [btrfs] run_delalloc_nocow+0x5f8/0x760 [btrfs] btrfs_run_delalloc_range+0xa8/0x220 [btrfs] writepage_delalloc+0x230/0x4c8 [btrfs] extent_writepage+0xb8/0x358 [btrfs] extent_write_cache_pages+0x21c/0x4e8 [btrfs] btrfs_writepages+0x94/0x150 [btrfs] do_writepages+0x74/0x190 filemap_fdatawrite_wbc+0x88/0xc8 start_delalloc_inodes+0x178/0x3a8 [btrfs] btrfs_start_delalloc_roots+0x174/0x280 [btrfs] shrink_delalloc+0x114/0x280 [btrfs] flush_space+0x250/0x2f8 [btrfs] btrfs_async_reclaim_data_space+0x180/0x228 [btrfs] process_one_work+0x164/0x408 worker_thread+0x25c/0x388 kthread+0x100/0x118 ret_from_fork+0x10/0x20 Code: 910a8021 a90363f7 a9046bf9 94012379 (d4210000) ---[ end trace 0000000000000000 ]--- [CAUSE] The first two lines of extra debug messages show the problem is caused by the error handling of run_delalloc_nocow(). E.g. we have the following dirtied range (4K blocksize 4K page size): 0 16K 32K |//////////////////////////////////////| | Pre-allocated | And the range [0, 16K) has a preallocated extent. - Enter run_delalloc_nocow() for range [0, 16K) Which found range [0, 16K) is preallocated, can do the proper NOCOW write. - Enter fallback_to_fow() for range [16K, 32K) Since the range [16K, 32K) is not backed by preallocated extent, we have to go COW. - cow_file_range() failed for range [16K, 32K) So cow_file_range() will do the clean up by clearing folio dirty, unlock the folios. Now the folios in range [16K, 32K) is unlocked. - Enter extent_clear_unlock_delalloc() from run_delalloc_nocow() Which is called with PAGE_START_WRITEBACK to start page writeback. But folios can only be marked writeback when it's properly locked, thus this triggered the VM_BUG_ON_FOLIO(). Furthermore there is another hidden but common bug that run_delalloc_nocow() is not clearing the folio dirty flags in its error handling path. This is the common bug shared between run_delalloc_nocow() and cow_file_range(). [FIX] - Clear folio dirty for range [@start, @cur_offset) Introduce a helper, cleanup_dirty_folios(), which will find and lock the folio in the range, clear the dirty flag and start/end the writeback, with the extra handling for the @locked_folio. - Introduce a helper to clear folio dirty, start and end writeback - Introduce a helper to record the last failed COW range end This is to trace which range we should skip, to avoid double unlocking. - Skip the failed COW range for the e ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57975", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "il7wrKgnv2XFHYQrPt6FUw==": { "id": "il7wrKgnv2XFHYQrPt6FUw==", "updater": "debian/updater", "name": "CVE-2024-43850", "description": "In the Linux kernel, the following vulnerability has been resolved: soc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove The following warning is seen during bwmon_remove due to refcount imbalance, fix this by releasing the OPPs after use. Logs: WARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158 Hardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT) ... Call trace: _opp_table_kref_release+0x150/0x158 dev_pm_opp_remove_table+0x100/0x1b4 devm_pm_opp_of_table_release+0x10/0x1c devm_action_release+0x14/0x20 devres_release_all+0xa4/0x104 device_unbind_cleanup+0x18/0x60 device_release_driver_internal+0x1ec/0x228 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 platform_driver_unregister+0x14/0x20 bwmon_driver_exit+0x18/0x524 [icc_bwmon] __arm64_sys_delete_module+0x184/0x264 invoke_syscall+0x48/0x118 el0_svc_common.constprop.0+0xc8/0xe8 do_el0_svc+0x20/0x2c el0_svc+0x34/0xdc el0t_64_sync_handler+0x13c/0x158 el0t_64_sync+0x190/0x194 --[ end trace 0000000000000000 ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43850", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "inNW/oB7BMbIgnOSCVi/1A==": { "id": "inNW/oB7BMbIgnOSCVi/1A==", "updater": "debian/updater", "name": "CVE-2026-46147", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() Two bugs exist in the vCPU initialisation path: 1. If a check fails after hyp_pin_shared_mem() succeeds, the cleanup path jumps to 'unlock' without calling unpin_host_vcpu() or unpin_host_sve_state(), permanently leaking pin references on the host vCPU and SVE state pages. Extract a register_hyp_vcpu() helper that performs the checks and the store. When register_hyp_vcpu() returns an error, call unpin_host_vcpu() and unpin_host_sve_state() inline before falling through to the existing 'unlock' label. 2. register_hyp_vcpu() publishes the new vCPU pointer into 'hyp_vm-\u003evcpus[]' with a bare store, allowing a concurrent caller of pkvm_load_hyp_vcpu() to observe a partially initialised vCPU object. Ensure the store uses smp_store_release() and the load uses smp_load_acquire(). While 'vm_table_lock' currently serialises the store and the load, these barriers ensure the reader sees the fully initialised 'hyp_vcpu' object even if there were a lockless path or if the lock's own ordering guarantees were insufficient for nested object initialization.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46147", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "inaCY6PIXgALdUE7MAms4g==": { "id": "inaCY6PIXgALdUE7MAms4g==", "updater": "debian/updater", "name": "CVE-2024-57999", "description": "In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW Power Hypervisor can possibily allocate MMIO window intersecting with Dynamic DMA Window (DDW) range, which is over 32-bit addressing. These MMIO pages needs to be marked as reserved so that IOMMU doesn't map DMA buffers in this range. The current code is not marking these pages correctly which is resulting in LPAR to OOPS while booting. The stack is at below BUG: Unable to handle kernel data access on read at 0xc00800005cd40000 Faulting instruction address: 0xc00000000005cdac Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries Modules linked in: af_packet rfkill ibmveth(X) lpfc(+) nvmet_fc nvmet nvme_keyring crct10dif_vpmsum nvme_fc nvme_fabrics nvme_core be2net(+) nvme_auth rtc_generic nfsd auth_rpcgss nfs_acl lockd grace sunrpc fuse configfs ip_tables x_tables xfs libcrc32c dm_service_time ibmvfc(X) scsi_transport_fc vmx_crypto gf128mul crc32c_vpmsum dm_mirror dm_region_hash dm_log dm_multipath dm_mod sd_mod scsi_dh_emc scsi_dh_rdac scsi_dh_alua t10_pi crc64_rocksoft_generic crc64_rocksoft sg crc64 scsi_mod Supported: Yes, External CPU: 8 PID: 241 Comm: kworker/8:1 Kdump: loaded Not tainted 6.4.0-150600.23.14-default #1 SLE15-SP6 b44ee71c81261b9e4bab5e0cde1f2ed891d5359b Hardware name: IBM,9080-M9S POWER9 (raw) 0x4e2103 0xf000005 of:IBM,FW950.B0 (VH950_149) hv:phyp pSeries Workqueue: events work_for_cpu_fn NIP: c00000000005cdac LR: c00000000005e830 CTR: 0000000000000000 REGS: c00001400c9ff770 TRAP: 0300 Not tainted (6.4.0-150600.23.14-default) MSR: 800000000280b033 \u003cSF,VEC,VSX,EE,FP,ME,IR,DR,RI,LE\u003e CR: 24228448 XER: 00000001 CFAR: c00000000005cdd4 DAR: c00800005cd40000 DSISR: 40000000 IRQMASK: 0 GPR00: c00000000005e830 c00001400c9ffa10 c000000001987d00 c00001400c4fe800 GPR04: 0000080000000000 0000000000000001 0000000004000000 0000000000800000 GPR08: 0000000004000000 0000000000000001 c00800005cd40000 ffffffffffffffff GPR12: 0000000084228882 c00000000a4c4f00 0000000000000010 0000080000000000 GPR16: c00001400c4fe800 0000000004000000 0800000000000000 c00000006088b800 GPR20: c00001401a7be980 c00001400eff3800 c000000002a2da68 000000000000002b GPR24: c0000000026793a8 c000000002679368 000000000000002a c0000000026793c8 GPR28: 000008007effffff 0000080000000000 0000000000800000 c00001400c4fe800 NIP [c00000000005cdac] iommu_table_reserve_pages+0xac/0x100 LR [c00000000005e830] iommu_init_table+0x80/0x1e0 Call Trace: [c00001400c9ffa10] [c00000000005e810] iommu_init_table+0x60/0x1e0 (unreliable) [c00001400c9ffa90] [c00000000010356c] iommu_bypass_supported_pSeriesLP+0x9cc/0xe40 [c00001400c9ffc30] [c00000000005c300] dma_iommu_dma_supported+0xf0/0x230 [c00001400c9ffcb0] [c00000000024b0c4] dma_supported+0x44/0x90 [c00001400c9ffcd0] [c00000000024b14c] dma_set_mask+0x3c/0x80 [c00001400c9ffd00] [c0080000555b715c] be_probe+0xc4/0xb90 [be2net] [c00001400c9ffdc0] [c000000000986f3c] local_pci_probe+0x6c/0x110 [c00001400c9ffe40] [c000000000188f28] work_for_cpu_fn+0x38/0x60 [c00001400c9ffe70] [c00000000018e454] process_one_work+0x314/0x620 [c00001400c9fff10] [c00000000018f280] worker_thread+0x2b0/0x620 [c00001400c9fff90] [c00000000019bb18] kthread+0x148/0x150 [c00001400c9fffe0] [c00000000000ded8] start_kernel_thread+0x14/0x18 There are 2 issues in the code 1. The index is \"int\" while the address is \"unsigned long\". This results in negative value when setting the bitmap. 2. The DMA offset is page shifted but the MMIO range is used as-is (64-bit address). MMIO address needs to be page shifted as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57999", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "innhwwtG+k3NRp4Z1S3aPw==": { "id": "innhwwtG+k3NRp4Z1S3aPw==", "updater": "debian/updater", "name": "CVE-2025-38195", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to handle kernel paging request at virtual address 0x0 ... Call Trace: [\u003c900000000023c30c\u003e] huge_pte_offset+0x3c/0x58 [\u003c900000000057fd4c\u003e] hugetlb_follow_page_mask+0x74/0x438 [\u003c900000000051fee8\u003e] __get_user_pages+0xe0/0x4c8 [\u003c9000000000522414\u003e] faultin_page_range+0x84/0x380 [\u003c9000000000564e8c\u003e] madvise_vma_behavior+0x534/0xa48 [\u003c900000000056689c\u003e] do_madvise+0x1bc/0x3e8 [\u003c9000000000566df4\u003e] sys_madvise+0x24/0x38 [\u003c90000000015b9e88\u003e] do_syscall+0x78/0x98 [\u003c9000000000221f18\u003e] handle_syscall+0xb8/0x158 In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38195", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ipbNqEv3q9WHV7lrDHCung==": { "id": "ipbNqEv3q9WHV7lrDHCung==", "updater": "debian/updater", "name": "CVE-2024-46813", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check link_index before accessing dc-\u003elinks[] [WHY \u0026 HOW] dc-\u003elinks[] has max size of MAX_LINKS and NULL is return when trying to access with out-of-bound index. This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46813", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "iuA4+apRQjkon3Iu/gGtXQ==": { "id": "iuA4+apRQjkon3Iu/gGtXQ==", "updater": "debian/updater", "name": "CVE-2026-46266", "description": "In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet can set the protocol field to 255 and match this socket, leading to FNHE cache changes. inner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)/Raw(\"TEST\") pkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1\")/ICMP(type=3, code=4, nexthopmtu=576)/inner \"man 7 raw\" states: A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able to send any IP protocol that is specified in the passed header. Receiving of all IP protocols via IPPROTO_RAW is not possible using raw sockets. Make sure we drop these malicious packets.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46266", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "izsq1j3LIr6xfhULctXn1Q==": { "id": "izsq1j3LIr6xfhULctXn1Q==", "updater": "debian/updater", "name": "CVE-2023-54233", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54233", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j+HKy5fI+gwanQcT0VJVzw==": { "id": "j+HKy5fI+gwanQcT0VJVzw==", "updater": "debian/updater", "name": "CVE-2026-53265", "description": "In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de (\"dm cache policy smq: fix missing locks in invalidating cache blocks\") added mq-\u003elock around the destructive part of smq_invalidate_mapping(), but left the e-\u003eallocated check outside the critical section. That leaves a check-then-act race. Two concurrent invalidators can both observe e-\u003eallocated as true before either of them takes mq-\u003elock. The first invalidator that acquires the lock removes the entry from the queues and hash table and then calls free_entry(), which clears e-\u003eallocated and puts the entry back on the free list. The second invalidator can then acquire mq-\u003elock and continue with the stale result of the unlocked check. This can corrupt the SMQ queues or hash table by deleting an entry that is no longer on those structures. It can also hit the allocation check in free_entry() when the same entry is freed again. Move the allocation check under mq-\u003elock so the predicate and the destructive operations are serialized by the same lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53265", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j1xnWego+ON5RA1EyBY9Hg==": { "id": "j1xnWego+ON5RA1EyBY9Hg==", "updater": "debian/updater", "name": "CVE-2025-40355", "description": "In the Linux kernel, the following vulnerability has been resolved: sysfs: check visibility before changing group attribute ownership Since commit 0c17270f9b92 (\"net: sysfs: Implement is_visible for phys_(port_id, port_name, switch_id)\"), __dev_change_net_namespace() can hit WARN_ON() when trying to change owner of a file that isn't visible. See the trace below: WARNING: CPU: 6 PID: 2938 at net/core/dev.c:12410 __dev_change_net_namespace+0xb89/0xc30 CPU: 6 UID: 0 PID: 2938 Comm: incusd Not tainted 6.17.1-1-mainline #1 PREEMPT(full) 4b783b4a638669fb644857f484487d17cb45ed1f Hardware name: Framework Laptop 13 (AMD Ryzen 7040Series)/FRANMDCP07, BIOS 03.07 02/19/2025 RIP: 0010:__dev_change_net_namespace+0xb89/0xc30 [...] Call Trace: \u003cTASK\u003e ? if6_seq_show+0x30/0x50 do_setlink.isra.0+0xc7/0x1270 ? __nla_validate_parse+0x5c/0xcc0 ? security_capable+0x94/0x1a0 rtnl_newlink+0x858/0xc20 ? update_curr+0x8e/0x1c0 ? update_entity_lag+0x71/0x80 ? sched_balance_newidle+0x358/0x450 ? psi_task_switch+0x113/0x2a0 ? __pfx_rtnl_newlink+0x10/0x10 rtnetlink_rcv_msg+0x346/0x3e0 ? sched_clock+0x10/0x30 ? __pfx_rtnetlink_rcv_msg+0x10/0x10 netlink_rcv_skb+0x59/0x110 netlink_unicast+0x285/0x3c0 ? __alloc_skb+0xdb/0x1a0 netlink_sendmsg+0x20d/0x430 ____sys_sendmsg+0x39f/0x3d0 ? import_iovec+0x2f/0x40 ___sys_sendmsg+0x99/0xe0 __sys_sendmsg+0x8a/0xf0 do_syscall_64+0x81/0x970 ? __sys_bind+0xe3/0x110 ? syscall_exit_work+0x143/0x1b0 ? do_syscall_64+0x244/0x970 ? sock_alloc_file+0x63/0xc0 ? syscall_exit_work+0x143/0x1b0 ? do_syscall_64+0x244/0x970 ? alloc_fd+0x12e/0x190 ? put_unused_fd+0x2a/0x70 ? do_sys_openat2+0xa2/0xe0 ? syscall_exit_work+0x143/0x1b0 ? do_syscall_64+0x244/0x970 ? exc_page_fault+0x7e/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e [...] \u003c/TASK\u003e Fix this by checking is_visible() before trying to touch the attribute.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40355", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j3Jq5DMS3iHLl7p8JZ9cAQ==": { "id": "j3Jq5DMS3iHLl7p8JZ9cAQ==", "updater": "debian/updater", "name": "CVE-2026-49337", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-49337", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j7/3bA8hjorM6rPdwZBKqw==": { "id": "j7/3bA8hjorM6rPdwZBKqw==", "updater": "debian/updater", "name": "CVE-2015-2877", "description": "Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states \"Basically if you care about this attack vector, disable deduplication.\" Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2015-2877", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j8iy7RKfxZethWyioJYxlw==": { "id": "j8iy7RKfxZethWyioJYxlw==", "updater": "debian/updater", "name": "CVE-2023-39191", "description": "An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-39191", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j9wLU3+UtGm5/f7Rj8ErXg==": { "id": "j9wLU3+UtGm5/f7Rj8ErXg==", "updater": "debian/updater", "name": "CVE-2026-23330", "description": "In the Linux kernel, the following vulnerability has been resolved: nfc: nci: complete pending data exchange on device close In nci_close_device(), complete any pending data exchange before closing. The data exchange callback (e.g. rawsock_data_exchange_complete) holds a socket reference. NIPA occasionally hits this leak: unreferenced object 0xff1100000f435000 (size 2048): comm \"nci_dev\", pid 3954, jiffies 4295441245 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 27 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 '..@............ backtrace (crc ec2b3c5): __kmalloc_noprof+0x4db/0x730 sk_prot_alloc.isra.0+0xe4/0x1d0 sk_alloc+0x36/0x760 rawsock_create+0xd1/0x540 nfc_sock_create+0x11f/0x280 __sock_create+0x22d/0x630 __sys_socket+0x115/0x1d0 __x64_sys_socket+0x72/0xd0 do_syscall_64+0x117/0xfc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23330", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "j9y+IM7NanO51P1/fIO3nw==": { "id": "j9y+IM7NanO51P1/fIO3nw==", "updater": "debian/updater", "name": "CVE-2025-1180", "description": "A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1180", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jAT5nCGVIS6apnWN5nWkJg==": { "id": "jAT5nCGVIS6apnWN5nWkJg==", "updater": "debian/updater", "name": "CVE-2024-46811", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params-\u003eclk_table.entries is 8. [How] Assert if soc.num_states greater than 8.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46811", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jCxEr8JHsUgFjPxyQutQDQ==": { "id": "jCxEr8JHsUgFjPxyQutQDQ==", "updater": "debian/updater", "name": "CVE-2026-68418", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent user-triggered null deref on QP create Previously, the user QP creation path would only attempt to populate iwqp-\u003eiwpbl if the user-provided req.user_wqe_bufs field was non-zero. The problem is that iwqp-\u003eiwpbl is unconditionally dereferenced later on in irdma_setup_virt_qp. While there was a check for iwqp-\u003eiwpbl != NULL, this check would only occur if req.user_wqe_bufs was non-zero. The end result is that a user could send a zero user_wqe_bufs value and trigger a null ptr deref. Fix this by unconditionally calling irdma_get_pbl and bailing if it fails, similar to the CQ and SRQ paths.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68418", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jG8/PDXriWa9vWg87ttnrQ==": { "id": "jG8/PDXriWa9vWg87ttnrQ==", "updater": "debian/updater", "name": "CVE-2024-27010", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix mirred deadlock on device recursion When the mirred action is used on a classful egress qdisc and a packet is mirrored or redirected to self we hit a qdisc lock deadlock. See trace below. [..... other info removed for brevity....] [ 82.890906] [ 82.890906] ============================================ [ 82.890906] WARNING: possible recursive locking detected [ 82.890906] 6.8.0-05205-g77fadd89fe2d-dirty #213 Tainted: G W [ 82.890906] -------------------------------------------- [ 82.890906] ping/418 is trying to acquire lock: [ 82.890906] ffff888006994110 (\u0026sch-\u003eq.lock){+.-.}-{3:3}, at: __dev_queue_xmit+0x1778/0x3550 [ 82.890906] [ 82.890906] but task is already holding lock: [ 82.890906] ffff888006994110 (\u0026sch-\u003eq.lock){+.-.}-{3:3}, at: __dev_queue_xmit+0x1778/0x3550 [ 82.890906] [ 82.890906] other info that might help us debug this: [ 82.890906] Possible unsafe locking scenario: [ 82.890906] [ 82.890906] CPU0 [ 82.890906] ---- [ 82.890906] lock(\u0026sch-\u003eq.lock); [ 82.890906] lock(\u0026sch-\u003eq.lock); [ 82.890906] [ 82.890906] *** DEADLOCK *** [ 82.890906] [..... other info removed for brevity....] Example setup (eth0-\u003eeth0) to recreate tc qdisc add dev eth0 root handle 1: htb default 30 tc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\ action mirred egress redirect dev eth0 Another example(eth0-\u003eeth1-\u003eeth0) to recreate tc qdisc add dev eth0 root handle 1: htb default 30 tc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\ action mirred egress redirect dev eth1 tc qdisc add dev eth1 root handle 1: htb default 30 tc filter add dev eth1 handle 1: protocol ip prio 2 matchall \\ action mirred egress redirect dev eth0 We fix this by adding an owner field (CPU id) to struct Qdisc set after root qdisc is entered. When the softirq enters it a second time, if the qdisc owner is the same CPU, the packet is dropped to break the loop.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-27010", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jHHTwsFpYzooo5vrSwGKhA==": { "id": "jHHTwsFpYzooo5vrSwGKhA==", "updater": "debian/updater", "name": "CVE-2025-30258", "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-30258", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "gnupg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jHQXL8f5Ll8ieaW4clVTQw==": { "id": "jHQXL8f5Ll8ieaW4clVTQw==", "updater": "debian/updater", "name": "CVE-2026-64567", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. That header is stored in the tree_root under a key with type 0, which the tree-checker has no case for, so neither count is validated before the load trusts it. The load loops num_entries times and maps the next page whenever the current one runs out, going through io_ctl_check_crc() -\u003e io_ctl_map_page(), which does io_ctl-\u003epages[io_ctl-\u003eindex++]. But pages[] is allocated in io_ctl_init() from the cache inode's i_size, not from num_entries: \tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE); \tio_ctl-\u003epages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS); So if num_entries claims more records than the pages can hold, io_ctl-\u003eindex runs off the end of pages[]. The write side never hits this because io_ctl_add_entry() and io_ctl_add_bitmap() both stop once io_ctl-\u003eindex \u003e= io_ctl-\u003enum_pages; the read side just never had the same check. To trigger it, take a clean cache (num_entries = \u003cN\u003e here), set num_entries in the header to 0x10000, and fix up the leaf checksum so it still passes the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read 65536 entries, io_ctl-\u003eindex walks up to 16, and pages[16] is read past the array: BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58 io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820) load_free_space_cache (fs/btrfs/free-space-cache.c:1017) caching_thread (fs/btrfs/block-group.c:880) btrfs_work_helper (fs/btrfs/async-thread.c:312) process_one_work worker_thread kthread ret_from_fork free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc() at line 565, which is why that is the frame KASAN names. The out-of-bounds slot is then treated as a struct page and handed to crc32c(), so the bad read turns into a GP fault. Add the missing check to io_ctl_check_crc(), which is where both the entry loop and the bitmap loop end up. When num_entries is too large the load now fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds the free space from the extent tree, so a valid cache is never rejected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64567", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jNYd/zgCFBkDRlsDFtS4MQ==": { "id": "jNYd/zgCFBkDRlsDFtS4MQ==", "updater": "debian/updater", "name": "CVE-2026-50142", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-50142", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jNf5Ky/aCfpj1zuKEL6RhQ==": { "id": "jNf5Ky/aCfpj1zuKEL6RhQ==", "updater": "debian/updater", "name": "CVE-2025-68296", "description": "In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs. VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct fb_info.node, which is set by register_framebuffer(). As the fb-helper code currently sets up VGA switcheroo before registering the framebuffer, the value of node is -1 and therefore not a legal value. For example, fbcon uses the value within set_con2fb_map() [1] as an index into an array. Moving vga_switcheroo_client_fb_set() after register_framebuffer() can result in VGA switching that does not switch fbcon correctly. Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(), which already holds the console lock. Fbdev calls fbcon_fb_registered() from within register_framebuffer(). Serializes the helper with VGA switcheroo's call to fbcon_remap_all(). Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info as parameter, it really only needs the contained fbcon state. Moving the call to fbcon initialization is therefore cleaner than before. Only amdgpu, i915, nouveau and radeon support vga_switcheroo. For all other drivers, this change does nothing.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68296", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jRZ1mZCh6vaS3zFUu7kTfQ==": { "id": "jRZ1mZCh6vaS3zFUu7kTfQ==", "updater": "debian/updater", "name": "CVE-2026-68104", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove() to unregister from global list prior to releasing acp_genpd memory, and clear the pointer after free. (cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68104", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jSmJL+G9oPI6MUI27LQFSg==": { "id": "jSmJL+G9oPI6MUI27LQFSg==", "updater": "debian/updater", "name": "CVE-2024-49921", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check null pointers before used [WHAT \u0026 HOW] Poniters, such as dc-\u003eclk_mgr, are null checked previously in the same function, so Coverity warns \"implies that \"dc-\u003eclk_mgr\" might be null\". As a result, these pointers need to be checked when used again. This fixes 10 FORWARD_NULL issues reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49921", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jcHyaunHiTExlq7AibAZqw==": { "id": "jcHyaunHiTExlq7AibAZqw==", "updater": "debian/updater", "name": "CVE-2026-68155", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in the cluster. Currently, a monmap indicating that there are zero monitors in the cluster is treated as valid. However, it is impossible to have zero monitors in the cluster and still receive a valid monmap from a monitor. Therefore, such a monmap must be corrupted and should be treated as invalid. Furthermore, a monmap with a monitor count of zero can subsequently crash the client when attempting to open a session with a monitor in __open_session(). This happens because the \"BUG_ON(monc-\u003emonmap-\u003enum_mon \u003c 1)\" assertion in pick_new_mon() is triggered. This patch extends a check in ceph_monmap_decode() to also reject arriving mon_maps with num_mon == 0 rather than only with num_mon \u003e CEPH_MAX_MON. [ idryomov: drop \"log output for unusual values of num_mon\" part ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68155", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jcvnkSTQb1UhujW6CRJ4uA==": { "id": "jcvnkSTQb1UhujW6CRJ4uA==", "updater": "debian/updater", "name": "CVE-2018-20712", "description": "A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-20712", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "je6ZqfWg3ctmGtEqprl3eg==": { "id": "je6ZqfWg3ctmGtEqprl3eg==", "updater": "debian/updater", "name": "CVE-2025-11495", "description": "A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11495", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jhjhpZEqUsE/GgGdvBBzpw==": { "id": "jhjhpZEqUsE/GgGdvBBzpw==", "updater": "debian/updater", "name": "CVE-2024-43901", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference for DTN log in DCN401 When users run the command: cat /sys/kernel/debug/dri/0/amdgpu_dm_dtn_log The following NULL pointer dereference happens: [ +0.000003] BUG: kernel NULL pointer dereference, address: NULL [ +0.000005] #PF: supervisor instruction fetch in kernel mode [ +0.000002] #PF: error_code(0x0010) - not-present page [ +0.000002] PGD 0 P4D 0 [ +0.000004] Oops: 0010 [#1] PREEMPT SMP NOPTI [ +0.000003] RIP: 0010:0x0 [ +0.000008] Code: Unable to access opcode bytes at 0xffffffffffffffd6. [...] [ +0.000002] PKRU: 55555554 [ +0.000002] Call Trace: [ +0.000002] \u003cTASK\u003e [ +0.000003] ? show_regs+0x65/0x70 [ +0.000006] ? __die+0x24/0x70 [ +0.000004] ? page_fault_oops+0x160/0x470 [ +0.000006] ? do_user_addr_fault+0x2b5/0x690 [ +0.000003] ? prb_read_valid+0x1c/0x30 [ +0.000005] ? exc_page_fault+0x8c/0x1a0 [ +0.000005] ? asm_exc_page_fault+0x27/0x30 [ +0.000012] dcn10_log_color_state+0xf9/0x510 [amdgpu] [ +0.000306] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000003] ? vsnprintf+0x2fb/0x600 [ +0.000009] dcn10_log_hw_state+0xfd0/0xfe0 [amdgpu] [ +0.000218] ? __mod_memcg_lruvec_state+0xe8/0x170 [ +0.000008] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000002] ? debug_smp_processor_id+0x17/0x20 [ +0.000003] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000002] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000002] ? set_ptes.isra.0+0x2b/0x90 [ +0.000004] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000002] ? _raw_spin_unlock+0x19/0x40 [ +0.000004] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000002] ? do_anonymous_page+0x337/0x700 [ +0.000004] dtn_log_read+0x82/0x120 [amdgpu] [ +0.000207] full_proxy_read+0x66/0x90 [ +0.000007] vfs_read+0xb0/0x340 [ +0.000005] ? __count_memcg_events+0x79/0xe0 [ +0.000002] ? srso_alias_return_thunk+0x5/0xfbef5 [ +0.000003] ? count_memcg_events.constprop.0+0x1e/0x40 [ +0.000003] ? handle_mm_fault+0xb2/0x370 [ +0.000003] ksys_read+0x6b/0xf0 [ +0.000004] __x64_sys_read+0x19/0x20 [ +0.000003] do_syscall_64+0x60/0x130 [ +0.000004] entry_SYSCALL_64_after_hwframe+0x6e/0x76 [ +0.000003] RIP: 0033:0x7fdf32f147e2 [...] This error happens when the color log tries to read the gamut remap information from DCN401 which is not initialized in the dcn401_dpp_funcs which leads to a null pointer dereference. This commit addresses this issue by adding a proper guard to access the gamut_remap callback in case the specific ASIC did not implement this function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-43901", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ji/RKwpIMAc9Vv0dRY+IJg==": { "id": "ji/RKwpIMAc9Vv0dRY+IJg==", "updater": "debian/updater", "name": "CVE-2025-8961", "description": "A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8961", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jiLyHD81qvPLMEUaTrdWlQ==": { "id": "jiLyHD81qvPLMEUaTrdWlQ==", "updater": "debian/updater", "name": "CVE-2025-71289", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle attr_set_size() errors when truncating files If attr_set_size() fails while truncating down, the error is silently ignored and the inode may be left in an inconsistent state.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71289", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jlrTr1dyDTh1M5CunQeb0w==": { "id": "jlrTr1dyDTh1M5CunQeb0w==", "updater": "debian/updater", "name": "CVE-2025-37860", "description": "In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run before efx-\u003enet_dev is created; consequently, we cannot netif_set_tso_max_size() or _segs() at this point. Move those netif calls to ef100_probe_netdev(), and also replace netif_err within the design params code with pci_err.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37860", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "josbSdjNIEYt2YuT3t31lA==": { "id": "josbSdjNIEYt2YuT3t31lA==", "updater": "debian/updater", "name": "CVE-2026-68338", "description": "In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po-\u003enum, unregisters the protocol hook when needed, drops po-\u003ebind_lock, and later restores po-\u003enum and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po-\u003eifindex to -1 and clearing po-\u003eprot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po-\u003eifindex == -1 as an invalidated binding after reacquiring po-\u003ebind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po-\u003enum as before, but do not re-register the hook if device unregister already detached the socket.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68338", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "joye5blYiU3Lze42WmGVIQ==": { "id": "joye5blYiU3Lze42WmGVIQ==", "updater": "debian/updater", "name": "CVE-2024-58097", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor destination ring While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. However, sometimes the driver cannot obtain a valid buffer corresponding to the buf_id received from the hardware. This causes an infinite loop in the destination processing, resulting in a kernel crash. kernel log: ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed Fix this by skipping the problematic buf_id and reaping the next entry, replacing the break with the next MSDU processing. Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58097", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jpl1YKH9X76u2ReYrgD2uQ==": { "id": "jpl1YKH9X76u2ReYrgD2uQ==", "updater": "debian/updater", "name": "CVE-2026-14662", "description": "Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14662", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jvXo8L+w0I5IeZJsE5sQ8Q==": { "id": "jvXo8L+w0I5IeZJsE5sQ8Q==", "updater": "debian/updater", "name": "CVE-2023-4133", "description": "A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-4133", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jwCtKZlExxG3oKjYCyqGAg==": { "id": "jwCtKZlExxG3oKjYCyqGAg==", "updater": "debian/updater", "name": "CVE-2024-50289", "description": "In the Linux kernel, the following vulnerability has been resolved: media: av7110: fix a spectre vulnerability As warned by smatch: \tdrivers/staging/media/av7110/av7110_ca.c:270 dvb_ca_ioctl() warn: potential spectre issue 'av7110-\u003eci_slot' [w] (local cap) There is a spectre-related vulnerability at the code. Fix it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50289", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jxeBZQT0rZDcUDj8Kd0PtQ==": { "id": "jxeBZQT0rZDcUDj8Kd0PtQ==", "updater": "debian/updater", "name": "CVE-2025-11839", "description": "A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11839", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "jyWDLwaa34WPueVKizEYAQ==": { "id": "jyWDLwaa34WPueVKizEYAQ==", "updater": "debian/updater", "name": "CVE-2026-53015", "description": "In the Linux kernel, the following vulnerability has been resolved: erofs: unify lcn as u64 for 32-bit platforms As sashiko reported [1], `lcn` was typed as `unsigned long` (or `unsigned int` sometimes), which is only 32 bits wide on 32-bit platforms, which causes `(lcn \u003c\u003c lclusterbits)` to be truncated at 4 GiB. In order to consolidate the logic, just use `u64` consistently around the codebase. [1] https://sashiko.dev/r/20260420034612.1899973-1-hsiangkao%40linux.alibaba.com", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53015", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k4fnMU3FBc/o62cw/deQ3A==": { "id": "k4fnMU3FBc/o62cw/deQ3A==", "updater": "debian/updater", "name": "CVE-2021-4217", "description": "A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-4217", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "unzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k5+7SpZcwh35X7eYTNm4mg==": { "id": "k5+7SpZcwh35X7eYTNm4mg==", "updater": "debian/updater", "name": "CVE-2026-3446", "description": "When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3446", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "k68Qrm+GmbkyaCk2lSsCEg==": { "id": "k68Qrm+GmbkyaCk2lSsCEg==", "updater": "debian/updater", "name": "CVE-2026-64577", "description": "In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb-\u003edata; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb-\u003edata below skb-\u003ehead, tripping skb_under_panic(). Fix it by dropping the packet when skb_pull_data() fails. skbuff: skb_under_panic: ... kernel BUG at net/core/skbuff.c:214! Call Trace: skb_push (net/core/skbuff.c:2648) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82) gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920) udp_queue_rcv_one_skb (net/ipv4/udp.c:2388) ... Kernel panic - not syncing: Fatal exception in interrupt", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64577", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kBTtYe13ix5ni1oAgQJaJg==": { "id": "kBTtYe13ix5ni1oAgQJaJg==", "updater": "debian/updater", "name": "CVE-2025-22039", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both smb_check_perm_dacl() and smb_inherit_dacl(). This could result in out-of-bounds memory access and a kernel crash when dereferencing the DACL pointer. This patch converts dacloffset to unsigned int and uses check_add_overflow() to validate access to the DACL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22039", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kBdlZauBxTfq+9SvHKQRIA==": { "id": "kBdlZauBxTfq+9SvHKQRIA==", "updater": "debian/updater", "name": "CVE-2026-43299", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() [BUG] There is a bug report that when btrfs hits ENOSPC error in a critical path, btrfs flips RO (this part is expected, although the ENOSPC bug still needs to be addressed). The problem is after the RO flip, if there is a read repair pending, we can hit the ASSERT() inside btrfs_repair_io_failure() like the following: BTRFS info (device vdc): relocating block group 30408704 flags metadata|raid1 ------------[ cut here ]------------ BTRFS: Transaction aborted (error -28) WARNING: fs/btrfs/extent-tree.c:3235 at __btrfs_free_extent.isra.0+0x453/0xfd0, CPU#1: btrfs/383844 Modules linked in: kvm_intel kvm irqbypass [...] ---[ end trace 0000000000000000 ]--- BTRFS info (device vdc state EA): 2 enospc errors during balance BTRFS info (device vdc state EA): balance: ended with status: -30 BTRFS error (device vdc state EA): parent transid verify failed on logical 30556160 mirror 2 wanted 8 found 6 BTRFS error (device vdc state EA): bdev /dev/nvme0n1 errs: wr 0, rd 0, flush 0, corrupt 10, gen 0 [...] assertion failed: !(fs_info-\u003esb-\u003es_flags \u0026 SB_RDONLY) :: 0, in fs/btrfs/bio.c:938 ------------[ cut here ]------------ assertion failed: !(fs_info-\u003esb-\u003es_flags \u0026 SB_RDONLY) :: 0, in fs/btrfs/bio.c:938 kernel BUG at fs/btrfs/bio.c:938! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 868 Comm: kworker/u8:13 Tainted: G W N 6.19.0-rc6+ #4788 PREEMPT(full) Tainted: [W]=WARN, [N]=TEST Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 Workqueue: btrfs-endio simple_end_io_work RIP: 0010:btrfs_repair_io_failure.cold+0xb2/0x120 RSP: 0000:ffffc90001d2bcf0 EFLAGS: 00010246 RAX: 0000000000000051 RBX: 0000000000001000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffffff8305cf42 RDI: 00000000ffffffff RBP: 0000000000000002 R08: 00000000fffeffff R09: ffffffff837fa988 R10: ffffffff8327a9e0 R11: 6f69747265737361 R12: ffff88813018d310 R13: ffff888168b8a000 R14: ffffc90001d2bd90 R15: ffff88810a169000 FS: 0000000000000000(0000) GS:ffff8885e752c000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 ------------[ cut here ]------------ [CAUSE] The cause of -ENOSPC error during the test case btrfs/124 is still unknown, although it's known that we still have cases where metadata can be over-committed but can not be fulfilled correctly, thus if we hit such ENOSPC error inside a critical path, we have no choice but abort the current transaction. This will mark the fs read-only. The problem is inside the btrfs_repair_io_failure() path that we require the fs not to be mount read-only. This is normally fine, but if we are doing a read-repair meanwhile the fs flips RO due to a critical error, we can enter btrfs_repair_io_failure() with super block set to read-only, thus triggering the above crash. [FIX] Just replace the ASSERT() with a proper return if the fs is already read-only.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43299", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kBrSwqqu9R+58yY5supBMg==": { "id": "kBrSwqqu9R+58yY5supBMg==", "updater": "debian/updater", "name": "CVE-2025-69652", "description": "GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69652", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kHTcuX2ojk+Ouhq9aqnFmg==": { "id": "kHTcuX2ojk+Ouhq9aqnFmg==", "updater": "debian/updater", "name": "CVE-2026-11979", "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11979", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libxml2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kKJMMvyEOKqokJ0bzYC2Cw==": { "id": "kKJMMvyEOKqokJ0bzYC2Cw==", "updater": "debian/updater", "name": "CVE-2026-31722", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -\u003e /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the borrowed_net flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31722", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kM8v6NxzXQPaH6W0rRyY+Q==": { "id": "kM8v6NxzXQPaH6W0rRyY+Q==", "updater": "debian/updater", "name": "CVE-2025-21969", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd After the hci sync command releases l2cap_conn, the hci receive data work queue references the released l2cap_conn when sending to the upper layer. Add hci dev lock to the hci receive data work queue to synchronize the two. [1] BUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954 Read of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837 CPU: 0 UID: 0 PID: 5837 Comm: kworker/u9:2 Not tainted 6.13.0-rc5-syzkaller-00163-gab75170520d4 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: hci1 hci_rx_work Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x169/0x550 mm/kasan/report.c:489 kasan_report+0x143/0x180 mm/kasan/report.c:602 l2cap_build_cmd net/bluetooth/l2cap_core.c:2964 [inline] l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954 l2cap_sig_send_rej net/bluetooth/l2cap_core.c:5502 [inline] l2cap_sig_channel net/bluetooth/l2cap_core.c:5538 [inline] l2cap_recv_frame+0x221f/0x10db0 net/bluetooth/l2cap_core.c:6817 hci_acldata_packet net/bluetooth/hci_core.c:3797 [inline] hci_rx_work+0x508/0xdb0 net/bluetooth/hci_core.c:4040 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310 worker_thread+0x870/0xd30 kernel/workqueue.c:3391 kthread+0x2f0/0x390 kernel/kthread.c:389 ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 \u003c/TASK\u003e Allocated by task 5837: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3f/0x80 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:377 [inline] __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394 kasan_kmalloc include/linux/kasan.h:260 [inline] __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329 kmalloc_noprof include/linux/slab.h:901 [inline] kzalloc_noprof include/linux/slab.h:1037 [inline] l2cap_conn_add+0xa9/0x8e0 net/bluetooth/l2cap_core.c:6860 l2cap_connect_cfm+0x115/0x1090 net/bluetooth/l2cap_core.c:7239 hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline] hci_remote_features_evt+0x68e/0xac0 net/bluetooth/hci_event.c:3726 hci_event_func net/bluetooth/hci_event.c:7473 [inline] hci_event_packet+0xac2/0x1540 net/bluetooth/hci_event.c:7525 hci_rx_work+0x3f3/0xdb0 net/bluetooth/hci_core.c:4035 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310 worker_thread+0x870/0xd30 kernel/workqueue.c:3391 kthread+0x2f0/0x390 kernel/kthread.c:389 ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 Freed by task 54: kasan_save_stack mm/kasan/common.c:47 [inline] kasan_save_track+0x3f/0x80 mm/kasan/common.c:68 kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582 poison_slab_object mm/kasan/common.c:247 [inline] __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264 kasan_slab_free include/linux/kasan.h:233 [inline] slab_free_hook mm/slub.c:2353 [inline] slab_free mm/slub.c:4613 [inline] kfree+0x196/0x430 mm/slub.c:4761 l2cap_connect_cfm+0xcc/0x1090 net/bluetooth/l2cap_core.c:7235 hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline] hci_conn_failed+0x287/0x400 net/bluetooth/hci_conn.c:1266 hci_abort_conn_sync+0x56c/0x11f0 net/bluetooth/hci_sync.c:5603 hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:332 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310 worker_thread+0x870/0xd30 kernel/workqueue.c:3391 kthread+0x2f0/0x390 kernel/kthread.c:389 ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21969", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kNbL6Sq5E91SdgHe7lP4dA==": { "id": "kNbL6Sq5E91SdgHe7lP4dA==", "updater": "debian/updater", "name": "CVE-2026-31432", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received, and the first command (READ) consumes most of the response buffer, ksmbd could write beyond the allocated buffer while building a security descriptor. The root cause was that smb2_get_info_sec() checked buffer space using ppntsd_size from xattr, while build_sec_desc() often synthesized a significantly larger descriptor from POSIX ACLs. This patch introduces smb_acl_sec_desc_scratch_len() to accurately compute the final descriptor size beforehand, performs proper buffer checking with smb2_calc_max_out_buf_len(), and uses exact-sized allocation + iov pinning.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31432", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kO53yCiQCcDnlmEzidxYNQ==": { "id": "kO53yCiQCcDnlmEzidxYNQ==", "updater": "debian/updater", "name": "CVE-2026-53117", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/cio: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53117", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kOlCFWKyH7sZJbv3K91zAA==": { "id": "kOlCFWKyH7sZJbv3K91zAA==", "updater": "debian/updater", "name": "CVE-2007-3476", "description": "Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-3476", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libwmf", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kZ0cFnzel9Dx3vpxtGT7Kg==": { "id": "kZ0cFnzel9Dx3vpxtGT7Kg==", "updater": "debian/updater", "name": "CVE-2025-21985", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT \u0026 HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is necessary to check location against MAX_HPO_DP2_ENCODERS. Similiarly, disp_cfg_stream_location can be used as an array index which should be 0..5, so the ASSERT's conditions should be less without equal.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21985", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ka7CS6AmNsxHCjw2UdKtvg==": { "id": "ka7CS6AmNsxHCjw2UdKtvg==", "updater": "debian/updater", "name": "CVE-2026-62292", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-62292", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kaqNCfRrzo98RV67uaLNDw==": { "id": "kaqNCfRrzo98RV67uaLNDw==", "updater": "debian/updater", "name": "CVE-2011-3374", "description": "It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-3374", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "apt", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kd9XNSBjIRt8Gh/ZOvPQDA==": { "id": "kd9XNSBjIRt8Gh/ZOvPQDA==", "updater": "debian/updater", "name": "CVE-2025-38426", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add basic validation for RAS header If RAS header read from EEPROM is corrupted, it could result in trying to allocate huge memory for reading the records. Add some validation to header fields.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38426", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kdRMgKCnW9CeTfNdZwcQkQ==": { "id": "kdRMgKCnW9CeTfNdZwcQkQ==", "updater": "debian/updater", "name": "CVE-2024-2193", "description": "A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-2193", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "keb0BYbqks2Jt/xv1VHGMQ==": { "id": "keb0BYbqks2Jt/xv1VHGMQ==", "updater": "debian/updater", "name": "CVE-2019-19070", "description": "A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-19070", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kfLGxTKoKicnK/rNfBjRJg==": { "id": "kfLGxTKoKicnK/rNfBjRJg==", "updater": "debian/updater", "name": "CVE-2019-16229", "description": "drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16229", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "khK00kzr+C+QKwVhupsvEw==": { "id": "khK00kzr+C+QKwVhupsvEw==", "updater": "debian/updater", "name": "CVE-2026-68152", "description": "In the Linux kernel, the following vulnerability has been resolved: amt: fix use-after-free in AMT delayed works When an AMT device is removed, pending delayed works can still access the freed amt_dev structure, which may result in kernel crashes or memory corruption. amt_dev_stop() cancels req_wq and discovery_wq with cancel_delayed_work_sync(), but these works can be scheduled again from event_wq after the cancellation. This allows delayed works to access the freed amt_dev structure after the netdev has been released. The following is a simple race scenario: CPU0 CPU1 amt_dev_stop() cancel_delayed_work_sync() amt_event_work() mod_delayed_work(req_wq) free netdev req_wq accesses freed amt_dev Use disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and discovery_wq from being queued again and wait for running work items to complete. The delayed works are disabled after initialization in amt_newlink() and enabled only when the device is successfully opened. This keeps the delayed work lifecycle synchronized with the lifetime of the AMT device.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68152", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kidvWKi8nb4dqsT8EqCASw==": { "id": "kidvWKi8nb4dqsT8EqCASw==", "updater": "debian/updater", "name": "CVE-2024-36949", "description": "In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait all processes being evicted If there are more than one device doing reset in parallel, the first device will call kfd_suspend_all_processes() to evict all processes on all devices, this call takes time to finish. other device will start reset and recover without waiting. if the process has not been evicted before doing recover, it will be restored, then caused page fault.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36949", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kk0BeSmKqmzGoT7xIOWJaw==": { "id": "kk0BeSmKqmzGoT7xIOWJaw==", "updater": "debian/updater", "name": "CVE-2024-46698", "description": "In the Linux kernel, the following vulnerability has been resolved: video/aperture: optionally match the device in sysfb_disable() In aperture_remove_conflicting_pci_devices(), we currently only call sysfb_disable() on vga class devices. This leads to the following problem when the pimary device is not VGA compatible: 1. A PCI device with a non-VGA class is the boot display 2. That device is probed first and it is not a VGA device so sysfb_disable() is not called, but the device resources are freed by aperture_detach_platform_device() 3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable() 4. NULL pointer dereference via sysfb_disable() since the resources have already been freed by aperture_detach_platform_device() when it was called by the other device. Fix this by passing a device pointer to sysfb_disable() and checking the device to determine if we should execute it or not. v2: Fix build when CONFIG_SCREEN_INFO is not set v3: Move device check into the mutex Drop primary variable in aperture_remove_conflicting_pci_devices() Drop __init on pci sysfb_pci_dev_is_enabled()", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46698", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kn5p/OUsWwHeiiKEcjDSmw==": { "id": "kn5p/OUsWwHeiiKEcjDSmw==", "updater": "debian/updater", "name": "CVE-2026-64146", "description": "In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initialization commit bb88e8da0025 (\"erofs: use meta buffers for xattr operations\") converted xattr operations to use on-stack erofs_buf instances. erofs_init_inode_xattrs() uses such a metabuf while reading the inline xattr header and shared xattr id array. Some error paths after erofs_read_metabuf() leave through out_unlock without dropping the metabuf, so the folio reference can leak. Consolidate the cleanup at out_unlock. erofs_put_metabuf() is a no-op if no folio has been acquired, and this keeps all paths after taking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64146", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kpNPngHrM4VAz6i1yHUbpg==": { "id": "kpNPngHrM4VAz6i1yHUbpg==", "updater": "debian/updater", "name": "CVE-2025-21634", "description": "In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: remove kernfs active break A warning was found: WARNING: CPU: 10 PID: 3486953 at fs/kernfs/file.c:828 CPU: 10 PID: 3486953 Comm: rmdir Kdump: loaded Tainted: G RIP: 0010:kernfs_should_drain_open_files+0x1a1/0x1b0 RSP: 0018:ffff8881107ef9e0 EFLAGS: 00010202 RAX: 0000000080000002 RBX: ffff888154738c00 RCX: dffffc0000000000 RDX: 0000000000000007 RSI: 0000000000000004 RDI: ffff888154738c04 RBP: ffff888154738c04 R08: ffffffffaf27fa15 R09: ffffed102a8e7180 R10: ffff888154738c07 R11: 0000000000000000 R12: ffff888154738c08 R13: ffff888750f8c000 R14: ffff888750f8c0e8 R15: ffff888154738ca0 FS: 00007f84cd0be740(0000) GS:ffff8887ddc00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000555f9fbe00c8 CR3: 0000000153eec001 CR4: 0000000000370ee0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: kernfs_drain+0x15e/0x2f0 __kernfs_remove+0x165/0x300 kernfs_remove_by_name_ns+0x7b/0xc0 cgroup_rm_file+0x154/0x1c0 cgroup_addrm_files+0x1c2/0x1f0 css_clear_dir+0x77/0x110 kill_css+0x4c/0x1b0 cgroup_destroy_locked+0x194/0x380 cgroup_rmdir+0x2a/0x140 It can be explained by: rmdir \t\t\t\techo 1 \u003e cpuset.cpus \t\t\t\tkernfs_fop_write_iter // active=0 cgroup_rm_file kernfs_remove_by_name_ns\tkernfs_get_active // active=1 __kernfs_remove\t\t\t\t\t // active=0x80000002 kernfs_drain\t\t\tcpuset_write_resmask wait_event //waiting (active == 0x80000001) \t\t\t\tkernfs_break_active_protection \t\t\t\t// active = 0x80000001 // continue \t\t\t\tkernfs_unbreak_active_protection \t\t\t\t// active = 0x80000002 ... kernfs_should_drain_open_files // warning occurs \t\t\t\tkernfs_put_active This warning is caused by 'kernfs_break_active_protection' when it is writing to cpuset.cpus, and the cgroup is removed concurrently. The commit 3a5a6d0c2b03 (\"cpuset: don't nest cgroup_mutex inside get_online_cpus()\") made cpuset_hotplug_workfn asynchronous, This change involves calling flush_work(), which can create a multiple processes circular locking dependency that involve cgroup_mutex, potentially leading to a deadlock. To avoid deadlock. the commit 76bb5ab8f6e3 (\"cpuset: break kernfs active protection in cpuset_write_resmask()\") added 'kernfs_break_active_protection' in the cpuset_write_resmask. This could lead to this warning. After the commit 2125c0034c5d (\"cgroup/cpuset: Make cpuset hotplug processing synchronous\"), the cpuset_write_resmask no longer needs to wait the hotplug to finish, which means that concurrent hotplug and cpuset operations are no longer possible. Therefore, the deadlock doesn't exist anymore and it does not have to 'break active protection' now. To fix this warning, just remove kernfs_break_active_protection operation in the 'cpuset_write_resmask'.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21634", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kpPp/LVicTFSGqQuIUP0fQ==": { "id": "kpPp/LVicTFSGqQuIUP0fQ==", "updater": "debian/updater", "name": "CVE-2025-68320", "description": "In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The following warning was seen when we try to connect using ssh to the device. BUG: sleeping function called from invalid context at kernel/locking/mutex.c:575 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 104, name: dropbear preempt_count: 1, expected: 0 INFO: lockdep is turned off. CPU: 0 UID: 0 PID: 104 Comm: dropbear Tainted: G W 6.18.0-rc2-00399-g6f1ab1b109b9-dirty #530 NONE Tainted: [W]=WARN Hardware name: Generic DT based system Call trace: unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x7c/0xac dump_stack_lvl from __might_resched+0x16c/0x2b0 __might_resched from __mutex_lock+0x64/0xd34 __mutex_lock from mutex_lock_nested+0x1c/0x24 mutex_lock_nested from lan966x_stats_get+0x5c/0x558 lan966x_stats_get from dev_get_stats+0x40/0x43c dev_get_stats from dev_seq_printf_stats+0x3c/0x184 dev_seq_printf_stats from dev_seq_show+0x10/0x30 dev_seq_show from seq_read_iter+0x350/0x4ec seq_read_iter from seq_read+0xfc/0x194 seq_read from proc_reg_read+0xac/0x100 proc_reg_read from vfs_read+0xb0/0x2b0 vfs_read from ksys_read+0x6c/0xec ksys_read from ret_fast_syscall+0x0/0x1c Exception stack(0xf0b11fa8 to 0xf0b11ff0) 1fa0: 00000001 00001000 00000008 be9048d8 00001000 00000001 1fc0: 00000001 00001000 00000008 00000003 be905920 0000001e 00000000 00000001 1fe0: 0005404c be9048c0 00018684 b6ec2cd8 It seems that we are using a mutex in a atomic context which is wrong. Change the mutex with a spinlock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68320", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kq6Qe3EeFnn/jFkC4GiCWA==": { "id": "kq6Qe3EeFnn/jFkC4GiCWA==", "updater": "debian/updater", "name": "CVE-2021-3847", "description": "An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-3847", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kqQebcoRkl7um6sT0akMiw==": { "id": "kqQebcoRkl7um6sT0akMiw==", "updater": "debian/updater", "name": "CVE-2026-50813", "description": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-50813", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kqzISkE3CskWY60zyXu7Og==": { "id": "kqzISkE3CskWY60zyXu7Og==", "updater": "debian/updater", "name": "CVE-2025-38064", "description": "In the Linux kernel, the following vulnerability has been resolved: virtio: break and reset virtio devices on device_shutdown() Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory accesses during the hang. \tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected \tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected \t... It was traced down to virtio-console. Kexec works fine if virtio-console is not in use. The issue is that virtio-console continues to write to the MMIO even after underlying virtio-pci device is reset. Additionally, Eric noticed that IOMMUs are reset before devices, if devices are not reset on shutdown they continue to poke at guest memory and get errors from the IOMMU. Some devices get wedged then. The problem can be solved by breaking all virtio devices on virtio bus shutdown, then resetting them.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38064", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kuhXZolaYNXAtDpu9lnamQ==": { "id": "kuhXZolaYNXAtDpu9lnamQ==", "updater": "debian/updater", "name": "CVE-2026-68340", "description": "In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks The OCC poll response parser walks a counted list of sensor data blocks. It used the static backing-array capacity as the parse boundary, but a transport response makes only data_length bytes current and valid. A truncated response can therefore make the parser consume a block header or block extent outside the current response. Use data_length as the parent boundary, prove the fixed poll header and each current block header before reading them, and prove the complete block before advancing. Keep parsed sensor metadata local until the complete response has passed validation, then publish it. Propagate malformed-response errors before publishing the OCC as active.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68340", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "kvTVIa5bq/R/nK1M8mwXTQ==": { "id": "kvTVIa5bq/R/nK1M8mwXTQ==", "updater": "debian/updater", "name": "CVE-2025-37893", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. Debugging the issues shows that the JITed image missing a jirl instruction at the end of the epilogue. There are two passes in JIT compiling, the first pass set the flags and the second pass generates JIT code based on those flags. With BPF progs mixing bpf2bpf and tailcalls, build_prologue() generates N insns in the first pass and then generates N+1 insns in the second pass. This makes epilogue_offset off by one and we will jump to some unexpected insn and cause lockup. Fix this by inserting a nop insn.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37893", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l/LCnnKtIXI6QIMXQyAmyg==": { "id": "l/LCnnKtIXI6QIMXQyAmyg==", "updater": "debian/updater", "name": "CVE-2023-53353", "description": "In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release() The memory manager IDR is currently destroyed when user releases the file descriptor. However, at this point the user context might be still held, and memory buffers might be still in use. Later on, calls to release those buffers will fail due to not finding their handles in the IDR, leading to a memory leak. To avoid this leak, split the IDR destruction from the memory manager fini, and postpone it to hpriv_release() when there is no user context and no buffers are used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53353", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l/kNLokvToElk8R5OEG1Hw==": { "id": "l/kNLokvToElk8R5OEG1Hw==", "updater": "debian/updater", "name": "CVE-2026-55655", "description": "A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-55655", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l0KK0xXzbXVKX6MCmaR4mA==": { "id": "l0KK0xXzbXVKX6MCmaR4mA==", "updater": "debian/updater", "name": "CVE-2025-38438", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak. sof_pdata-\u003etplg_filename can have address allocated by kstrdup() and can be overwritten. Memory leak was detected with kmemleak: unreferenced object 0xffff88812391ff60 (size 16): comm \"kworker/4:1\", pid 161, jiffies 4294802931 hex dump (first 16 bytes): 73 6f 66 2d 68 64 61 2d 67 65 6e 65 72 69 63 00 sof-hda-generic. backtrace (crc 4bf1675c): __kmalloc_node_track_caller_noprof+0x49c/0x6b0 kstrdup+0x46/0xc0 hda_machine_select.cold+0x1de/0x12cf [snd_sof_intel_hda_generic] sof_init_environment+0x16f/0xb50 [snd_sof] sof_probe_continue+0x45/0x7c0 [snd_sof] sof_probe_work+0x1e/0x40 [snd_sof] process_one_work+0x894/0x14b0 worker_thread+0x5e5/0xfb0 kthread+0x39d/0x760 ret_from_fork+0x31/0x70 ret_from_fork_asm+0x1a/0x30", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38438", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l5T8L+VKYOFTQZLSZbrRew==": { "id": "l5T8L+VKYOFTQZLSZbrRew==", "updater": "debian/updater", "name": "CVE-2024-36951", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: range check cp bad op exception interrupts Due to a CP interrupt bug, bad packet garbage exception codes are raised. Do a range check so that the debugger and runtime do not receive garbage codes. Update the user api to guard exception code type checking as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36951", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "l7FhOF2AzGUuX4kVh9umhw==": { "id": "l7FhOF2AzGUuX4kVh9umhw==", "updater": "debian/updater", "name": "CVE-2026-53185", "description": "In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL. zram_bvec_write_partial() passes its parent bio down, so for ZRAM_WB slots the read is dispatched asynchronously and zram_read_page() returns 0 while the bio is still in flight. The caller then runs memcpy_from_bvec(), zram_write_page() and __free_page() on the buffer, leaving the async read to write into a freed page. zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d (\"zram: fix synchronous reads\") for the same reason; the write_partial counterpart was missed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53185", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lA7ruehTmgKgvtJi2MUvog==": { "id": "lA7ruehTmgKgvtJi2MUvog==", "updater": "debian/updater", "name": "CVE-2025-40139", "description": "In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL. Using sk_dst_get(sk)-\u003edev could trigger UAF. Let's use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock() after kernel_getsockname(). Note that the returned value of smc_clc_prfx_set() is not used in the caller. While at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu() not to touch dst there.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40139", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lCqUsiwpCWdi15QTuyEemA==": { "id": "lCqUsiwpCWdi15QTuyEemA==", "updater": "debian/updater", "name": "CVE-2023-52920", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from stack in precision tracking Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset. To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don't touch idx field for maximum performance, as it's checked most frequently during backtracking. This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches. There are only three differences in selftests' BPF object files according to veristat, all in the positive direction (less states). File Program Insns (A) Insns (B) Insns (DIFF) States (A) States (B) States (DIFF) -------------------------------------- ------------- --------- --------- ------------- ---------- ---------- ------------- test_cls_redirect_dynptr.bpf.linked3.o cls_redirect 2987 2864 -123 (-4.12%) 240 231 -9 (-3.75%) xdp_synproxy_kern.bpf.linked3.o syncookie_tc 82848 82661 -187 (-0.23%) 5107 5073 -34 (-0.67%) xdp_synproxy_kern.bpf.linked3.o syncookie_xdp 85116 84964 -152 (-0.18%) 5162 5130 -32 (-0.62%) Note, I avoided renaming jmp_history to more generic insn_hist to minimize number of lines changed and potential merge conflicts between bpf and bpf-next trees. Notice also cur_hist_entry pointer reset to NULL at the beginning of instruction verification loop. This pointer avoids the problem of relying on last jump history entry's insn_idx to determine whether we already have entry for current instruction or not. It can happen that we added jump history entry because current instruction is_jmp_point(), but also we need to add instruction flags for stack access. In this case, we don't want to entries, so we need to reuse last added entry, if it is present. Relying on insn_idx comparison has the same ambiguity problem as the one that was fixed recently in [0], so we avoid that. [0] https://patchwork.kernel.org/project/netdevbpf/patch/20231110002638.4168352-3-andrii@kernel.org/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52920", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lD3fwWxRJRf7QGu76Yui/A==": { "id": "lD3fwWxRJRf7QGu76Yui/A==", "updater": "debian/updater", "name": "CVE-2025-21825", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT During the update procedure, when overwrite element in a pre-allocated htab, the freeing of old_element is protected by the bucket lock. The reason why the bucket lock is necessary is that the old_element has already been stashed in htab-\u003eextra_elems after alloc_htab_elem() returns. If freeing the old_element after the bucket lock is unlocked, the stashed element may be reused by concurrent update procedure and the freeing of old_element will run concurrently with the reuse of the old_element. However, the invocation of check_and_free_fields() may acquire a spin-lock which violates the lockdep rule because its caller has already held a raw-spin-lock (bucket lock). The following warning will be reported when such race happens: BUG: scheduling while atomic: test_progs/676/0x00000003 3 locks held by test_progs/676: #0: ffffffff864b0240 (rcu_read_lock_trace){....}-{0:0}, at: bpf_prog_test_run_syscall+0x2c0/0x830 #1: ffff88810e961188 (\u0026htab-\u003elockdep_key){....}-{2:2}, at: htab_map_update_elem+0x306/0x1500 #2: ffff8881f4eac1b8 (\u0026base-\u003esoftirq_expiry_lock){....}-{2:2}, at: hrtimer_cancel_wait_running+0xe9/0x1b0 Modules linked in: bpf_testmod(O) Preemption disabled at: [\u003cffffffff817837a3\u003e] htab_map_update_elem+0x293/0x1500 CPU: 0 UID: 0 PID: 676 Comm: test_progs Tainted: G ... 6.12.0+ #11 Tainted: [W]=WARN, [O]=OOT_MODULE Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)... Call Trace: \u003cTASK\u003e dump_stack_lvl+0x57/0x70 dump_stack+0x10/0x20 __schedule_bug+0x120/0x170 __schedule+0x300c/0x4800 schedule_rtlock+0x37/0x60 rtlock_slowlock_locked+0x6d9/0x54c0 rt_spin_lock+0x168/0x230 hrtimer_cancel_wait_running+0xe9/0x1b0 hrtimer_cancel+0x24/0x30 bpf_timer_delete_work+0x1d/0x40 bpf_timer_cancel_and_free+0x5e/0x80 bpf_obj_free_fields+0x262/0x4a0 check_and_free_fields+0x1d0/0x280 htab_map_update_elem+0x7fc/0x1500 bpf_prog_9f90bc20768e0cb9_overwrite_cb+0x3f/0x43 bpf_prog_ea601c4649694dbd_overwrite_timer+0x5d/0x7e bpf_prog_test_run_syscall+0x322/0x830 __sys_bpf+0x135d/0x3ca0 __x64_sys_bpf+0x75/0xb0 x64_sys_call+0x1b5/0xa10 do_syscall_64+0x3b/0xc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 ... \u003c/TASK\u003e It seems feasible to break the reuse and refill of per-cpu extra_elems into two independent parts: reuse the per-cpu extra_elems with bucket lock being held and refill the old_element as per-cpu extra_elems after the bucket lock is unlocked. However, it will make the concurrent overwrite procedures on the same CPU return unexpected -E2BIG error when the map is full. Therefore, the patch fixes the lock problem by breaking the cancelling of bpf_timer into two steps for PREEMPT_RT: 1) use hrtimer_try_to_cancel() and check its return value 2) if the timer is running, use hrtimer_cancel() through a kworker to cancel it again Considering that the current implementation of hrtimer_cancel() will try to acquire a being held softirq_expiry_lock when the current timer is running, these steps above are reasonable. However, it also has downside. When the timer is running, the cancelling of the timer is delayed when releasing the last map uref. The delay is also fixable (e.g., break the cancelling of bpf timer into two parts: one part in locked scope, another one in unlocked scope), it can be revised later if necessary. It is a bit hard to decide the right fix tag. One reason is that the problem depends on PREEMPT_RT which is enabled in v6.12. Considering the softirq_expiry_lock lock exists since v5.4 and bpf_timer is introduced in v5.15, the bpf_timer commit is used in the fixes tag and an extra depends-on tag is added to state the dependency on PREEMPT_RT. Depends-on: v6.12+ with PREEMPT_RT enabled", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21825", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lFPS8RnV0dISMcAPV4q8QQ==": { "id": "lFPS8RnV0dISMcAPV4q8QQ==", "updater": "debian/updater", "name": "CVE-2026-10536", "description": "A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-10536", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lFQqA2gRtutYweiePnvnDQ==": { "id": "lFQqA2gRtutYweiePnvnDQ==", "updater": "debian/updater", "name": "CVE-2026-46204", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46204", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lGk38AMlVf6u9+M+1fHkew==": { "id": "lGk38AMlVf6u9+M+1fHkew==", "updater": "debian/updater", "name": "CVE-2025-40071", "description": "In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Don't block input queue by waiting MSC Currently gsm_queue() processes incoming frames and when opening a DLC channel it calls gsm_dlci_open() which calls gsm_modem_update(). If basic mode is used it calls gsm_modem_upd_via_msc() and it cannot block the input queue by waiting the response to come into the same input queue. Instead allow sending Modem Status Command without waiting for remote end to respond. Define a new function gsm_modem_send_initial_msc() for this purpose. As MSC is only valid for basic encoding, it does not do anything for advanced or when convergence layer type 2 is used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40071", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lKw7TsGs0QExvrzGu983hw==": { "id": "lKw7TsGs0QExvrzGu983hw==", "updater": "debian/updater", "name": "CVE-2025-21894", "description": "In the Linux kernel, the following vulnerability has been resolved: net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC Actually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only ENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash if VFs are used to test one-step timestamp, the crash log as follows. [ 129.110909] Unable to handle kernel paging request at virtual address 00000000000080c0 [ 129.287769] Call trace: [ 129.290219] enetc_port_mac_wr+0x30/0xec (P) [ 129.294504] enetc_start_xmit+0xda4/0xe74 [ 129.298525] enetc_xmit+0x70/0xec [ 129.301848] dev_hard_start_xmit+0x98/0x118", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21894", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lLwJoWtSVfftOhbbYJ+RRg==": { "id": "lLwJoWtSVfftOhbbYJ+RRg==", "updater": "debian/updater", "name": "CVE-2026-53009", "description": "In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -\u003e ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53009", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lTH6RQt00L2k/ovUGND4sA==": { "id": "lTH6RQt00L2k/ovUGND4sA==", "updater": "debian/updater", "name": "CVE-2026-43310", "description": "In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC For the i.MX8MQ platform, there is a hardware limitation: the g1 VPU and g2 VPU cannot decode simultaneously; otherwise, it will cause below bus error and produce corrupted pictures, even potentially lead to system hang. [ 110.527986] hantro-vpu 38310000.video-codec: frame decode timed out. [ 110.583517] hantro-vpu 38310000.video-codec: bus error detected. Therefore, it is necessary to ensure that g1 and g2 operate alternately. This allows for successful multi-instance decoding of H.264 and HEVC. To achieve this, g1 and g2 share the same v4l2_m2m_dev, and then the v4l2_m2m_dev can handle the scheduling.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43310", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lbq4vh2+ZnForhi6QFyAFA==": { "id": "lbq4vh2+ZnForhi6QFyAFA==", "updater": "debian/updater", "name": "CVE-2024-44941", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 Read of size 4 at addr ffff8880739ab220 by task syz-executor200/5097 CPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 do_read_inode fs/f2fs/inode.c:509 [inline] f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560 f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237 generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413 exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444 exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584 do_handle_to_path fs/fhandle.c:155 [inline] handle_to_path fs/fhandle.c:210 [inline] do_handle_open+0x495/0x650 fs/fhandle.c:226 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f We missed to cover sanity_check_extent_cache() w/ extent cache lock, so, below race case may happen, result in use after free issue. - f2fs_iget - do_read_inode - f2fs_init_read_extent_tree : add largest extent entry in to cache \t\t\t\t\t- shrink \t\t\t\t\t - f2fs_shrink_read_extent_tree \t\t\t\t\t - __shrink_extent_tree \t\t\t\t\t - __detach_extent_node \t\t\t\t\t : drop largest extent entry - sanity_check_extent_cache : access et-\u003elargest w/o lock let's refactor sanity_check_extent_cache() to avoid extent cache access and call it before f2fs_init_read_extent_tree() to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-44941", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lfk6+WpQ1adbnURKkfPv2w==": { "id": "lfk6+WpQ1adbnURKkfPv2w==", "updater": "debian/updater", "name": "CVE-2024-46808", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range [Why \u0026 How] ASSERT if return NULL from kcalloc.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46808", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lg4ziUlz/8WSEmaAMQG+XA==": { "id": "lg4ziUlz/8WSEmaAMQG+XA==", "updater": "debian/updater", "name": "CVE-2026-68227", "description": "In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the driver state lifetime so that it is released on driver unbind.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68227", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lj0olDIEOqoIZRmBl/tcnA==": { "id": "lj0olDIEOqoIZRmBl/tcnA==", "updater": "debian/updater", "name": "CVE-2026-43443", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions. Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43443", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lkUXzRlvRP1wTsMOeSJoCQ==": { "id": "lkUXzRlvRP1wTsMOeSJoCQ==", "updater": "debian/updater", "name": "CVE-2025-28162", "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-28162", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libpng1.6", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ln1Lq6qzUC1Ys0m8YLemFA==": { "id": "ln1Lq6qzUC1Ys0m8YLemFA==", "updater": "debian/updater", "name": "CVE-2026-31777", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Check the error for index mapping The ctxfi driver blindly assumed a proper value returned from daio_device_index(), but it's not always true. Add a proper error check to deal with the error from the function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31777", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lngFfpAJvbin9hXK0qoQYg==": { "id": "lngFfpAJvbin9hXK0qoQYg==", "updater": "debian/updater", "name": "CVE-2022-0563", "description": "A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-0563", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lr3UWI+X5MYZjlxk+Wat/w==": { "id": "lr3UWI+X5MYZjlxk+Wat/w==", "updater": "debian/updater", "name": "CVE-2026-31560", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: spi-dw-dma: fix print error log when wait finish transaction If an error occurs, the device may not have a current message. In this case, the system will crash. In this case, it's better to use dev from the struct ctlr (struct spi_controller*).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31560", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lwESZdMBFhWpWDqCRMz8Vw==": { "id": "lwESZdMBFhWpWDqCRMz8Vw==", "updater": "debian/updater", "name": "CVE-2026-64144", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb-\u003esetup_packet leak in error paths The setup_packet of control urb is not freed if usb_submit_urb fails or the submitted urb is killed. Add free in these two paths.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64144", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lxUGTdEKAk+ElV/adgJrxA==": { "id": "lxUGTdEKAk+ElV/adgJrxA==", "updater": "debian/updater", "name": "CVE-2025-70873", "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-70873", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lxbSICKaJJFo0IPqGvWzRg==": { "id": "lxbSICKaJJFo0IPqGvWzRg==", "updater": "debian/updater", "name": "CVE-2023-53857", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: bpf_sk_storage: Fix invalid wait context lockdep report './test_progs -t test_local_storage' reported a splat: [ 27.137569] ============================= [ 27.138122] [ BUG: Invalid wait context ] [ 27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G O [ 27.139542] ----------------------------- [ 27.140106] test_progs/1729 is trying to lock: [ 27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130 [ 27.141834] other info that might help us debug this: [ 27.142437] context-{5:5} [ 27.142856] 2 locks held by test_progs/1729: [ 27.143352] #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40 [ 27.144492] #1: ffff888107deb2c0 (\u0026storage-\u003elock){..-.}-{2:2}, at: bpf_local_storage_update+0x39e/0x8e0 [ 27.145855] stack backtrace: [ 27.146274] CPU: 0 PID: 1729 Comm: test_progs Tainted: G O 6.5.0-03980-gd11ae1b16b0a #247 [ 27.147550] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014 [ 27.149127] Call Trace: [ 27.149490] \u003cTASK\u003e [ 27.149867] dump_stack_lvl+0x130/0x1d0 [ 27.152609] dump_stack+0x14/0x20 [ 27.153131] __lock_acquire+0x1657/0x2220 [ 27.153677] lock_acquire+0x1b8/0x510 [ 27.157908] local_lock_acquire+0x29/0x130 [ 27.159048] obj_cgroup_charge+0xf4/0x3c0 [ 27.160794] slab_pre_alloc_hook+0x28e/0x2b0 [ 27.161931] __kmem_cache_alloc_node+0x51/0x210 [ 27.163557] __kmalloc+0xaa/0x210 [ 27.164593] bpf_map_kzalloc+0xbc/0x170 [ 27.165147] bpf_selem_alloc+0x130/0x510 [ 27.166295] bpf_local_storage_update+0x5aa/0x8e0 [ 27.167042] bpf_fd_sk_storage_update_elem+0xdb/0x1a0 [ 27.169199] bpf_map_update_value+0x415/0x4f0 [ 27.169871] map_update_elem+0x413/0x550 [ 27.170330] __sys_bpf+0x5e9/0x640 [ 27.174065] __x64_sys_bpf+0x80/0x90 [ 27.174568] do_syscall_64+0x48/0xa0 [ 27.175201] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 27.175932] RIP: 0033:0x7effb40e41ad [ 27.176357] Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 8b 0d8 [ 27.179028] RSP: 002b:00007ffe64c21fc8 EFLAGS: 00000202 ORIG_RAX: 0000000000000141 [ 27.180088] RAX: ffffffffffffffda RBX: 00007ffe64c22768 RCX: 00007effb40e41ad [ 27.181082] RDX: 0000000000000020 RSI: 00007ffe64c22008 RDI: 0000000000000002 [ 27.182030] RBP: 00007ffe64c21ff0 R08: 0000000000000000 R09: 00007ffe64c22788 [ 27.183038] R10: 0000000000000064 R11: 0000000000000202 R12: 0000000000000000 [ 27.184006] R13: 00007ffe64c22788 R14: 00007effb42a1000 R15: 0000000000000000 [ 27.184958] \u003c/TASK\u003e It complains about acquiring a local_lock while holding a raw_spin_lock. It means it should not allocate memory while holding a raw_spin_lock since it is not safe for RT. raw_spin_lock is needed because bpf_local_storage supports tracing context. In particular for task local storage, it is easy to get a \"current\" task PTR_TO_BTF_ID in tracing bpf prog. However, task (and cgroup) local storage has already been moved to bpf mem allocator which can be used after raw_spin_lock. The splat is for the sk storage. For sk (and inode) storage, it has not been moved to bpf mem allocator. Using raw_spin_lock or not, kzalloc(GFP_ATOMIC) could theoretically be unsafe in tracing context. However, the local storage helper requires a verifier accepted sk pointer (PTR_TO_BTF_ID), it is hypothetical if that (mean running a bpf prog in a kzalloc unsafe context and also able to hold a verifier accepted sk pointer) could happen. This patch avoids kzalloc after raw_spin_lock to silent the splat. There is an existing kzalloc before the raw_spin_lock. At that point, a kzalloc is very likely required because a lookup has just been done before. Thus, this patch always does the kzalloc before acq ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53857", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lxpghzTAGPYPM4qIkJMJ5A==": { "id": "lxpghzTAGPYPM4qIkJMJ5A==", "updater": "debian/updater", "name": "CVE-2026-23472", "description": "In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room() and uart_write() behave inconsistently when xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were never properly initialized): - uart_write_room() returns kfifo_avail() which can be \u003e 0 - uart_write() checks xmit_buf and returns 0 if NULL This inconsistency causes an infinite loop in drivers that rely on tty_write_room() to determine if they can write: while (tty_write_room(tty) \u003e 0) { written = tty-\u003eops-\u003ewrite(...); // written is always 0, loop never exits } For example, caif_serial's handle_tx() enters an infinite loop when used with PORT_UNKNOWN serial ports, causing system hangs. Fix by making uart_write_room() also check xmit_buf and return 0 if it's NULL, consistent with uart_write(). Reproducer: https://gist.github.com/mrpre/d9a694cc0e19828ee3bc3b37983fde13", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23472", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "lzdlTLkaw2hqoABNUvAwFA==": { "id": "lzdlTLkaw2hqoABNUvAwFA==", "updater": "debian/updater", "name": "CVE-2024-53216", "description": "In the Linux kernel, the following vulnerability has been resolved: nfsd: release svc_expkey/svc_export with rcu_work The last reference for `cache_head` can be reduced to zero in `c_show` and `e_show`(using `rcu_read_lock` and `rcu_read_unlock`). Consequently, `svc_export_put` and `expkey_put` will be invoked, leading to two issues: 1. The `svc_export_put` will directly free ex_uuid. However, `e_show`/`c_show` will access `ex_uuid` after `cache_put`, which can trigger a use-after-free issue, shown below. ================================================================== BUG: KASAN: slab-use-after-free in svc_export_show+0x362/0x430 [nfsd] Read of size 1 at addr ff11000010fdc120 by task cat/870 CPU: 1 UID: 0 PID: 870 Comm: cat Not tainted 6.12.0-rc3+ #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x53/0x70 print_address_description.constprop.0+0x2c/0x3a0 print_report+0xb9/0x280 kasan_report+0xae/0xe0 svc_export_show+0x362/0x430 [nfsd] c_show+0x161/0x390 [sunrpc] seq_read_iter+0x589/0x770 seq_read+0x1e5/0x270 proc_reg_read+0xe1/0x140 vfs_read+0x125/0x530 ksys_read+0xc1/0x160 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Allocated by task 830: kasan_save_stack+0x20/0x40 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc_node_track_caller_noprof+0x1bc/0x400 kmemdup_noprof+0x22/0x50 svc_export_parse+0x8a9/0xb80 [nfsd] cache_do_downcall+0x71/0xa0 [sunrpc] cache_write_procfs+0x8e/0xd0 [sunrpc] proc_reg_write+0xe1/0x140 vfs_write+0x1a5/0x6d0 ksys_write+0xc1/0x160 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 868: kasan_save_stack+0x20/0x40 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x37/0x50 kfree+0xf3/0x3e0 svc_export_put+0x87/0xb0 [nfsd] cache_purge+0x17f/0x1f0 [sunrpc] nfsd_destroy_serv+0x226/0x2d0 [nfsd] nfsd_svc+0x125/0x1e0 [nfsd] write_threads+0x16a/0x2a0 [nfsd] nfsctl_transaction_write+0x74/0xa0 [nfsd] vfs_write+0x1a5/0x6d0 ksys_write+0xc1/0x160 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e 2. We cannot sleep while using `rcu_read_lock`/`rcu_read_unlock`. However, `svc_export_put`/`expkey_put` will call path_put, which subsequently triggers a sleeping operation due to the following `dput`. ============================= WARNING: suspicious RCU usage 5.10.0-dirty #141 Not tainted ----------------------------- ... Call Trace: dump_stack+0x9a/0xd0 ___might_sleep+0x231/0x240 dput+0x39/0x600 path_put+0x1b/0x30 svc_export_put+0x17/0x80 e_show+0x1c9/0x200 seq_read_iter+0x63f/0x7c0 seq_read+0x226/0x2d0 vfs_read+0x113/0x2c0 ksys_read+0xc9/0x170 do_syscall_64+0x33/0x40 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Fix these issues by using `rcu_work` to help release `svc_expkey`/`svc_export`. This approach allows for an asynchronous context to invoke `path_put` and also facilitates the freeing of `uuid/exp/key` after an RCU grace period.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53216", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m+XmqJ5VHL/uAOCj13Gx3g==": { "id": "m+XmqJ5VHL/uAOCj13Gx3g==", "updater": "debian/updater", "name": "CVE-2024-50135", "description": "In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev-\u003eonline_queues field, therefore nvme_pci_update_nr_queues() should avoid racing against it, otherwise we could end up passing invalid values to blk_mq_update_nr_hw_queues(). WARNING: CPU: 39 PID: 61303 at drivers/pci/msi/api.c:347 pci_irq_get_affinity+0x187/0x210 Workqueue: nvme-reset-wq nvme_reset_work [nvme] RIP: 0010:pci_irq_get_affinity+0x187/0x210 Call Trace: \u003cTASK\u003e ? blk_mq_pci_map_queues+0x87/0x3c0 ? pci_irq_get_affinity+0x187/0x210 blk_mq_pci_map_queues+0x87/0x3c0 nvme_pci_map_queues+0x189/0x460 [nvme] blk_mq_update_nr_hw_queues+0x2a/0x40 nvme_reset_work+0x1be/0x2a0 [nvme] Fix the bug by locking the shutdown_lock mutex before using dev-\u003eonline_queues. Give up if nvme_dev_disable() is running or if it has been executed already.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50135", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m0SyM5ZUWH/WciovBYjlmA==": { "id": "m0SyM5ZUWH/WciovBYjlmA==", "updater": "debian/updater", "name": "CVE-2026-68223", "description": "In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open() function previously jumped directly to err_m2m_release when vdec_init_ctrls() failed, skipping release of the m2m context. This caused a resource leak. Fix it by introducing a proper err_m2m_ctx_release label that calls v4l2_m2m_ctx_release(sess-\u003em2m_ctx) before releasing the m2m device. This was identified via kmemleak: unreferenced object 0xffff0000205d6878 (size 8): comm \"v4l_id\", pid 5289, jiffies 4294938580 hex dump (first 8 bytes): 40 d2 49 18 00 00 ff ff @.I..... backtrace (crc d3204599): kmemleak_alloc+0xc8/0xf0 __kvmalloc_node_noprof+0x60c/0x850 v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev] vdec_open+0x1f4/0x788 [meson_vdec] v4l2_open+0x144/0x460 [videodev] chrdev_open+0x1ac/0x500 do_dentry_open+0x3f0/0xfe8 vfs_open+0x68/0x320 do_open+0x2d8/0x9a8 path_openat+0x1d0/0x4f0 do_filp_open+0x190/0x380 do_sys_openat2+0xf8/0x1b0 __arm64_sys_openat+0x13c/0x1e8 invoke_syscall+0xdc/0x268 el0_svc_common.constprop.0+0x178/0x258 do_el0_svc+0x4c/0x70", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68223", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m0UDwMzBwVFEWXmEOBxvUA==": { "id": "m0UDwMzBwVFEWXmEOBxvUA==", "updater": "debian/updater", "name": "CVE-2025-21907", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: memory-failure: update ttu flag inside unmap_poisoned_folio Patch series \"mm: memory_failure: unmap poisoned folio during migrate properly\", v3. Fix two bugs during folio migration if the folio is poisoned. This patch (of 3): Commit 6da6b1d4a7df (\"mm/hwpoison: convert TTU_IGNORE_HWPOISON to TTU_HWPOISON\") introduce TTU_HWPOISON to replace TTU_IGNORE_HWPOISON in order to stop send SIGBUS signal when accessing an error page after a memory error on a clean folio. However during page migration, anon folio must be set with TTU_HWPOISON during unmap_*(). For pagecache we need some policy just like the one in hwpoison_user_mappings to set this flag. So move this policy from hwpoison_user_mappings to unmap_poisoned_folio to handle this warning properly. Warning will be produced during unamp poison folio with the following log: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 365 at mm/rmap.c:1847 try_to_unmap_one+0x8fc/0xd3c Modules linked in: CPU: 1 UID: 0 PID: 365 Comm: bash Tainted: G W 6.13.0-rc1-00018-gacdb4bbda7ab #42 Tainted: [W]=WARN Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015 pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : try_to_unmap_one+0x8fc/0xd3c lr : try_to_unmap_one+0x3dc/0xd3c Call trace: try_to_unmap_one+0x8fc/0xd3c (P) try_to_unmap_one+0x3dc/0xd3c (L) rmap_walk_anon+0xdc/0x1f8 rmap_walk+0x3c/0x58 try_to_unmap+0x88/0x90 unmap_poisoned_folio+0x30/0xa8 do_migrate_range+0x4a0/0x568 offline_pages+0x5a4/0x670 memory_block_action+0x17c/0x374 memory_subsys_offline+0x3c/0x78 device_offline+0xa4/0xd0 state_store+0x8c/0xf0 dev_attr_store+0x18/0x2c sysfs_kf_write+0x44/0x54 kernfs_fop_write_iter+0x118/0x1a8 vfs_write+0x3a8/0x4bc ksys_write+0x6c/0xf8 __arm64_sys_write+0x1c/0x28 invoke_syscall+0x44/0x100 el0_svc_common.constprop.0+0x40/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x30/0xd0 el0t_64_sync_handler+0xc8/0xcc el0t_64_sync+0x198/0x19c ---[ end trace 0000000000000000 ]--- [mawupeng1@huawei.com: unmap_poisoned_folio(): remove shadowed local `mapping', per Miaohe]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21907", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m1TezlMZQnewh2w+eeh1Pg==": { "id": "m1TezlMZQnewh2w+eeh1Pg==", "updater": "debian/updater", "name": "CVE-2025-40303", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: ensure no dirty metadata is written back for an fs with errors [BUG] During development of a minor feature (make sure all btrfs_bio::end_io() is called in task context), I noticed a crash in generic/388, where metadata writes triggered new works after btrfs_stop_all_workers(). It turns out that it can even happen without any code modification, just using RAID5 for metadata and the same workload from generic/388 is going to trigger the use-after-free. [CAUSE] If btrfs hits an error, the fs is marked as error, no new transaction is allowed thus metadata is in a frozen state. But there are some metadata modifications before that error, and they are still in the btree inode page cache. Since there will be no real transaction commit, all those dirty folios are just kept as is in the page cache, and they can not be invalidated by invalidate_inode_pages2() call inside close_ctree(), because they are dirty. And finally after btrfs_stop_all_workers(), we call iput() on btree inode, which triggers writeback of those dirty metadata. And if the fs is using RAID56 metadata, this will trigger RMW and queue new works into rmw_workers, which is already stopped, causing warning from queue_work() and use-after-free. [FIX] Add a special handling for write_one_eb(), that if the fs is already in an error state, immediately mark the bbio as failure, instead of really submitting them. Then during close_ctree(), iput() will just discard all those dirty tree blocks without really writing them back, thus no more new jobs for already stopped-and-freed workqueues. The extra discard in write_one_eb() also acts as an extra safenet. E.g. the transaction abort is triggered by some extent/free space tree corruptions, and since extent/free space tree is already corrupted some tree blocks may be allocated where they shouldn't be (overwriting existing tree blocks). In that case writing them back will further corrupting the fs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40303", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "m2kTWYyEXt2b8Y+bpHExMw==": { "id": "m2kTWYyEXt2b8Y+bpHExMw==", "updater": "debian/updater", "name": "CVE-2026-68327", "description": "In the Linux kernel, the following vulnerability has been resolved: wan: wanxl: Only reset hardware after BAR mapping wanxl_pci_init_one() stores the freshly allocated card in driver data before the PLX BAR is mapped. Several early probe failures then unwind through wanxl_pci_remove_one(), including failure to allocate the coherent status area or to restore the DMA mask. wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and wanxl_reset() dereferences card-\u003eplx. On those early failures card-\u003eplx is still NULL, so the error path can dereference a NULL MMIO pointer. Only issue the hardware reset once the BAR mapping exists. The remaining cleanup in wanxl_pci_remove_one() already checks whether later resources were allocated. This issue was found by a static analysis checker and confirmed by manual source review.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68327", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mAWVuLFcEHWzKwVWF+mmow==": { "id": "mAWVuLFcEHWzKwVWF+mmow==", "updater": "debian/updater", "name": "CVE-2026-68301", "description": "In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix memory leak on slave unregistration by removing synced VLANs When an HSR master device is brought UP, it auto-adds VLAN 0 via vlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B). If a slave device is later unregistered while HSR is active (e.g., during netns cleanup or interface destruction), hsr_del_port() is called to detach the slave port from the HSR master. However, hsr_del_port() currently does not delete the VLAN IDs that were synced to the slave device by HSR. As a result, the slave device retains a refcount on VID 0 (and any other synced VLANs). When the slave device is destroyed, its vlan_info / vlan_vid_info structure remains allocated, leading to a memory leak. Fix this by calling vlan_vids_del_by_dev(port-\u003edev, master-\u003edev) in hsr_del_port() before unlinking slave A or slave B ports, matching the propagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid() and the cleanup behavior in bonding and team drivers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68301", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mCcaCnP8f52+vu9b5rtNnA==": { "id": "mCcaCnP8f52+vu9b5rtNnA==", "updater": "debian/updater", "name": "CVE-2026-24515", "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-24515", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mCd+YBwD6U6filBaB3HE/g==": { "id": "mCd+YBwD6U6filBaB3HE/g==", "updater": "debian/updater", "name": "CVE-2025-61143", "description": "libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-61143", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mDBfTSXZ1+wA7otb2RysUQ==": { "id": "mDBfTSXZ1+wA7otb2RysUQ==", "updater": "debian/updater", "name": "CVE-2026-16118", "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-16118", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mHbTjMj1rjOIPJCq59mrig==": { "id": "mHbTjMj1rjOIPJCq59mrig==", "updater": "debian/updater", "name": "CVE-2025-7458", "description": "An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-7458", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mN2DbEhW6VqTjos2JoPnGg==": { "id": "mN2DbEhW6VqTjos2JoPnGg==", "updater": "debian/updater", "name": "CVE-2025-37856", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: harden block_group::bg_list against list_del() races As far as I can tell, these calls of list_del_init() on bg_list cannot run concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(), as they are in transaction error paths and situations where the block group is readonly. However, if there is any chance at all of racing with mark_bg_unused(), or a different future user of bg_list, better to be safe than sorry. Otherwise we risk the following interleaving (bg_list refcount in parens) T1 (some random op) T2 (btrfs_mark_bg_unused) !list_empty(\u0026bg-\u003ebg_list); (1) list_del_init(\u0026bg-\u003ebg_list); (1) list_move_tail (1) btrfs_put_block_group (0) btrfs_delete_unused_bgs bg = list_first_entry list_del_init(\u0026bg-\u003ebg_list); btrfs_put_block_group(bg); (-1) Ultimately, this results in a broken ref count that hits zero one deref early and the real final deref underflows the refcount, resulting in a WARNING.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37856", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mOwqF5f1oo/f3Hy4A5hQEA==": { "id": "mOwqF5f1oo/f3Hy4A5hQEA==", "updater": "debian/updater", "name": "CVE-2026-32739", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32739", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mQ7+TqdAO4YZAHkoGQlD8Q==": { "id": "mQ7+TqdAO4YZAHkoGQlD8Q==", "updater": "debian/updater", "name": "CVE-2023-32570", "description": "VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-32570", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "dav1d", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mQUiqOxBu6sTcRb5JQuOcg==": { "id": "mQUiqOxBu6sTcRb5JQuOcg==", "updater": "debian/updater", "name": "CVE-2025-22127", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadloop in prepare_compress_overwrite() Jan Prusakowski reported a kernel hang issue as below: When running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I encountered a problem in generic/475 test where fsstress process gets blocked in __f2fs_write_data_pages() and the test hangs. The options I used are: MKFS_OPTIONS -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc MOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc INFO: task kworker/u8:0:11 blocked for more than 122 seconds. Not tainted 6.14.0-rc3-xfstests-lockdep #1 \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:kworker/u8:0 state:D stack:0 pid:11 tgid:11 ppid:2 task_flags:0x4208160 flags:0x00004000 Workqueue: writeback wb_workfn (flush-253:0) Call Trace: \u003cTASK\u003e __schedule+0x309/0x8e0 schedule+0x3a/0x100 schedule_preempt_disabled+0x15/0x30 __mutex_lock+0x59a/0xdb0 __f2fs_write_data_pages+0x3ac/0x400 do_writepages+0xe8/0x290 __writeback_single_inode+0x5c/0x360 writeback_sb_inodes+0x22f/0x570 wb_writeback+0xb0/0x410 wb_do_writeback+0x47/0x2f0 wb_workfn+0x5a/0x1c0 process_one_work+0x223/0x5b0 worker_thread+0x1d5/0x3c0 kthread+0xfd/0x230 ret_from_fork+0x31/0x50 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e The root cause is: once generic/475 starts toload error table to dm device, f2fs_prepare_compress_overwrite() will loop reading compressed cluster pages due to IO error, meanwhile it has held .writepages lock, it can block all other writeback tasks. Let's fix this issue w/ below changes: - add f2fs_handle_page_eio() in prepare_compress_overwrite() to detect IO error. - detect cp_error earler in f2fs_read_multi_pages().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22127", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mQY2cBerKZkBCxSHL8eURg==": { "id": "mQY2cBerKZkBCxSHL8eURg==", "updater": "debian/updater", "name": "CVE-2025-71074", "description": "In the Linux kernel, the following vulnerability has been resolved: functionfs: fix the open/removal races ffs_epfile_open() can race with removal, ending up with file-\u003eprivate_data pointing to freed object. There is a total count of opened files on functionfs (both ep0 and dynamic ones) and when it hits zero, dynamic files get removed. Unfortunately, that removal can happen while another thread is in ffs_epfile_open(), but has not incremented the count yet. In that case open will succeed, leaving us with UAF on any subsequent read() or write(). The root cause is that ffs-\u003eopened is misused; atomic_dec_and_test() vs. atomic_add_return() is not a good idea, when object remains visible all along. To untangle that \t* serialize openers on ffs-\u003emutex (both for ep0 and for dynamic files) \t* have dynamic ones use atomic_inc_not_zero() and fail if we had zero -\u003eopened; in that case the file we are opening is doomed. \t* have the inodes of dynamic files marked on removal (from the callback of simple_recursive_removal()) - clear -\u003ei_private there. \t* have open of dynamic ones verify they hadn't been already removed, along with checking that state is FFS_ACTIVE.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71074", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mTD/V/e2oknhxg1DQ/f4hA==": { "id": "mTD/V/e2oknhxg1DQ/f4hA==", "updater": "debian/updater", "name": "CVE-2023-37769", "description": "stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-37769", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "pixman", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mYbCqE0WYSxXEX/p4j3j/w==": { "id": "mYbCqE0WYSxXEX/p4j3j/w==", "updater": "debian/updater", "name": "CVE-2026-43456", "description": "In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306 RSP: 0018:ffffc90004aff760 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e RDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900 RBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000 R10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780 R13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0 Call Trace: \u003cTASK\u003e ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900 dev_hard_header include/linux/netdevice.h:3439 [inline] packet_snd net/packet/af_packet.c:3028 [inline] packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592 ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646 __sys_sendmsg+0x170/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe1a0e6c1a9 When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device: bond_dev-\u003eheader_ops = slave_dev-\u003eheader_ops; This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(),all use netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private data (struct bonding) instead of the expected type (e.g. struct ip_tunnel), leading to garbage values being read and kernel crashes. Fix this by introducing bond_header_ops with wrapper functions that delegate to the active slave's header_ops using the slave's own device. This ensures netdev_priv() in the slave's header functions always receives the correct device. The fix is placed in the bonding driver rather than individual device drivers, as the root cause is bond blindly inheriting header_ops from the slave without considering that these callbacks expect a specific netdev_priv() layout. The type confusion can be observed by adding a printk in ipgre_header() and running the following commands: ip link add dummy0 type dummy ip addr add 10.0.0.1/24 dev dummy0 ip link set dummy0 up ip link add gre1 type gre local 10.0.0.1 ip link add bond1 type bond mode active-backup ip link set gre1 master bond1 ip link set gre1 up ip link set bond1 up ip addr add fe80::1/64 dev bond1", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43456", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mcxEec0DnlmZz3+CmevTKg==": { "id": "mcxEec0DnlmZz3+CmevTKg==", "updater": "debian/updater", "name": "CVE-2025-1176", "description": "A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1176", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mi24MOG36XGGY3jdy9tVog==": { "id": "mi24MOG36XGGY3jdy9tVog==", "updater": "debian/updater", "name": "CVE-2026-43244", "description": "In the Linux kernel, the following vulnerability has been resolved: kcm: fix zero-frag skb in frag_list on partial sendmsg error Syzkaller reported a warning in kcm_write_msgs() when processing a message with a zero-fragment skb in the frag_list. When kcm_sendmsg() fills MAX_SKB_FRAGS fragments in the current skb, it allocates a new skb (tskb) and links it into the frag_list before copying data. If the copy subsequently fails (e.g. -EFAULT from user memory), tskb remains in the frag_list with zero fragments: head skb (msg being assembled, NOT yet in sk_write_queue) +-----------+ | frags[17] | (MAX_SKB_FRAGS, all filled with data) | frag_list-+--\u003e tskb +-----------+ +----------+ | frags[0] | (empty! copy failed before filling) +----------+ For SOCK_SEQPACKET with partial data already copied, the error path saves this message via partial_message for later completion. For SOCK_SEQPACKET, sock_write_iter() automatically sets MSG_EOR, so a subsequent zero-length write(fd, NULL, 0) completes the message and queues it to sk_write_queue. kcm_write_msgs() then walks the frag_list and hits: WARN_ON(!skb_shinfo(skb)-\u003enr_frags) TCP has a similar pattern where skbs are enqueued before data copy and cleaned up on failure via tcp_remove_empty_skb(). KCM was missing the equivalent cleanup. Fix this by tracking the predecessor skb (frag_prev) when allocating a new frag_list entry. On error, if the tail skb has zero frags, use frag_prev to unlink and free it in O(1) without walking the singly-linked frag_list. frag_prev is safe to dereference because the entire message chain is only held locally (or in kcm-\u003eseq_skb) and is not added to sk_write_queue until MSG_EOR, so the send path cannot free it underneath us. Also change the WARN_ON to WARN_ON_ONCE to avoid flooding the log if the condition is somehow hit repeatedly. There are currently no KCM selftests in the kernel tree; a simple reproducer is available at [1]. [1] https://gist.github.com/mrpre/a94d431c757e8d6f168f4dd1a3749daa", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43244", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "miGlfWYNWZUhM6Uu5lXXWQ==": { "id": "miGlfWYNWZUhM6Uu5lXXWQ==", "updater": "debian/updater", "name": "CVE-2025-7709", "description": "An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-7709", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mjzU8fYHUEmYm86e389JVw==": { "id": "mjzU8fYHUEmYm86e389JVw==", "updater": "debian/updater", "name": "CVE-2025-66865", "description": "An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66865", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mmtl2ec/o09W0FXFeHnmQg==": { "id": "mmtl2ec/o09W0FXFeHnmQg==", "updater": "debian/updater", "name": "CVE-2025-7546", "description": "A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-7546", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mmxHxuvoy6NJ2C1Mq41y3Q==": { "id": "mmxHxuvoy6NJ2C1Mq41y3Q==", "updater": "debian/updater", "name": "CVE-2026-43053", "description": "In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivation When inactivating an inode with node-format extended attributes, xfs_attr3_node_inactive() invalidates all child leaf/node blocks via xfs_trans_binval(), but intentionally does not remove the corresponding entries from their parent node blocks. The implicit assumption is that xfs_attr_inactive() will truncate the entire attr fork to zero extents afterwards, so log recovery will never reach the root node and follow those stale pointers. However, if a log shutdown occurs after the leaf/node block cancellations commit but before the attr bmap truncation commits, this assumption breaks. Recovery replays the attr bmap intact (the inode still has attr fork extents), but suppresses replay of all cancelled leaf/node blocks, maybe leaving them as stale data on disk. On the next mount, xlog_recover_process_iunlinks() retries inactivation and attempts to read the root node via the attr bmap. If the root node was not replayed, reading the unreplayed root block triggers a metadata verification failure immediately; if it was replayed, following its child pointers to unreplayed child blocks triggers the same failure: XFS (pmem0): Metadata corruption detected at xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78 XFS (pmem0): Unmount and run xfs_repair XFS (pmem0): First 128 bytes of corrupted metadata buffer: 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ XFS (pmem0): metadata I/O error in \"xfs_da_read_buf+0x104/0x190\" at daddr 0x78 len 8 error 117 Fix this in two places: In xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a child block, immediately remove the entry that references it from the parent node in the same transaction. This eliminates the window where the parent holds a pointer to a cancelled block. Once all children are removed, the now-empty root node is converted to a leaf block within the same transaction. This node-to-leaf conversion is necessary for crash safety. If the system shutdown after the empty node is written to the log but before the second-phase bmap truncation commits, log recovery will attempt to verify the root block on disk. xfs_da3_node_verify() does not permit a node block with count == 0; such a block will fail verification and trigger a metadata corruption shutdown. on the other hand, leaf blocks are allowed to have this transient state. In xfs_attr_inactive(), split the attr fork truncation into two explicit phases. First, truncate all extents beyond the root block (the child extents whose parent references have already been removed above). Second, invalidate the root block and truncate the attr bmap to zero in a single transaction. The two operations in the second phase must be atomic: as long as the attr bmap has any non-zero length, recovery can follow it to the root block, so the root block invalidation must commit together with the bmap-to-zero truncation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43053", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mpo3/WeOVY4plMVPjn+etw==": { "id": "mpo3/WeOVY4plMVPjn+etw==", "updater": "debian/updater", "name": "CVE-2025-21885", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers While using nvme target with use_srq on, below kernel panic is noticed. [ 549.698111] bnxt_en 0000:41:00.0 enp65s0np0: FEC autoneg off encoding: Clause 91 RS(544,514) [ 566.393619] Oops: divide error: 0000 [#1] PREEMPT SMP NOPTI .. [ 566.393799] \u003cTASK\u003e [ 566.393807] ? __die_body+0x1a/0x60 [ 566.393823] ? die+0x38/0x60 [ 566.393835] ? do_trap+0xe4/0x110 [ 566.393847] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [ 566.393867] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [ 566.393881] ? do_error_trap+0x7c/0x120 [ 566.393890] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [ 566.393911] ? exc_divide_error+0x34/0x50 [ 566.393923] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [ 566.393939] ? asm_exc_divide_error+0x16/0x20 [ 566.393966] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [ 566.393997] bnxt_qplib_create_srq+0xc9/0x340 [bnxt_re] [ 566.394040] bnxt_re_create_srq+0x335/0x3b0 [bnxt_re] [ 566.394057] ? srso_return_thunk+0x5/0x5f [ 566.394068] ? __init_swait_queue_head+0x4a/0x60 [ 566.394090] ib_create_srq_user+0xa7/0x150 [ib_core] [ 566.394147] nvmet_rdma_queue_connect+0x7d0/0xbe0 [nvmet_rdma] [ 566.394174] ? lock_release+0x22c/0x3f0 [ 566.394187] ? srso_return_thunk+0x5/0x5f Page size and shift info is set only for the user space SRQs. Set page size and page shift for kernel space SRQs also.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21885", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mqvRSx6ER1B7t4SdSaZBpg==": { "id": "mqvRSx6ER1B7t4SdSaZBpg==", "updater": "debian/updater", "name": "CVE-2026-68401", "description": "In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Sashiko (locally) reports multiple out-of-bound issues in ffa_setup_and_transmit: 1) Writing ep_mem_access-\u003ereserved can write out of bounds for FFA versions \u003c 1.2 as ffa_emad_size_get() returns 16 bytes in that case while reserved has an offset of 24. Instead of zeroing fields, memset the struct to zero first based on the FFA version. 2) Make sure there is enough size to write constituents. While at it, convert the only sizeof() in the driver that uses a type instead of variable.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68401", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ms6HlDT8WIxnDT/547gqTQ==": { "id": "ms6HlDT8WIxnDT/547gqTQ==", "updater": "debian/updater", "name": "CVE-2024-46681", "description": "In the Linux kernel, the following vulnerability has been resolved: pktgen: use cpus_read_lock() in pg_net_init() I have seen the WARN_ON(smp_processor_id() != cpu) firing in pktgen_thread_worker() during tests. We must use cpus_read_lock()/cpus_read_unlock() around the for_each_online_cpu(cpu) loop. While we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46681", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "msRoLpQ5RRmll+h3oQOUPw==": { "id": "msRoLpQ5RRmll+h3oQOUPw==", "updater": "debian/updater", "name": "CVE-2023-53149", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: avoid deadlock in fs reclaim with page writeback Ext4 has a filesystem wide lock protecting ext4_writepages() calls to avoid races with switching of journalled data flag or inode format. This lock can however cause a deadlock like: CPU0 CPU1 ext4_writepages() percpu_down_read(sbi-\u003es_writepages_rwsem); ext4_change_inode_journal_flag() percpu_down_write(sbi-\u003es_writepages_rwsem); - blocks, all readers block from now on ext4_do_writepages() ext4_init_io_end() kmem_cache_zalloc(io_end_cachep, GFP_KERNEL) fs_reclaim frees dentry... dentry_unlink_inode() iput() - last ref =\u003e iput_final() - inode dirty =\u003e write_inode_now()... ext4_writepages() tries to acquire sbi-\u003es_writepages_rwsem and blocks forever Make sure we cannot recurse into filesystem reclaim from writeback code to avoid the deadlock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53149", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "msiaP6ZPjE6ydV5RJ2powg==": { "id": "msiaP6ZPjE6ydV5RJ2powg==", "updater": "debian/updater", "name": "CVE-2026-43137", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix NULL pointer dereference If there's a mismatch between the DAI links in the machine driver and the topology, it is possible that the playback/capture widget is not set, especially in the case of loopback capture for echo reference where we use the dummy DAI link. Return the error when the widget is not set to avoid a null pointer dereference like below when the topology is broken. RIP: 0010:hda_dai_get_ops.isra.0+0x14/0xa0 [snd_sof_intel_hda_common]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43137", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "msrb9fEz9Kqe2tYzX4cNRg==": { "id": "msrb9fEz9Kqe2tYzX4cNRg==", "updater": "debian/updater", "name": "CVE-2024-57795", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Remove the direct link to net_device The similar patch in siw is in the link: https://git.kernel.org/rdma/rdma/c/16b87037b48889 This problem also occurred in RXE. The following analyze this problem. In the following Call Traces: \" BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 net/core/dev.c:8782 Read of size 4 at addr ffff8880554640b0 by task kworker/1:4/5295 CPU: 1 UID: 0 PID: 5295 Comm: kworker/1:4 Not tainted 6.12.0-rc3-syzkaller-00399-g9197b73fd7bb #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: infiniband ib_cache_event_task Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 dev_get_flags+0x188/0x1d0 net/core/dev.c:8782 rxe_query_port+0x12d/0x260 drivers/infiniband/sw/rxe/rxe_verbs.c:60 __ib_query_port drivers/infiniband/core/device.c:2111 [inline] ib_query_port+0x168/0x7d0 drivers/infiniband/core/device.c:2143 ib_cache_update+0x1a9/0xb80 drivers/infiniband/core/cache.c:1494 ib_cache_event_task+0xf3/0x1e0 drivers/infiniband/core/cache.c:1568 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310 worker_thread+0x870/0xd30 kernel/workqueue.c:3391 kthread+0x2f2/0x390 kernel/kthread.c:389 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 \u003c/TASK\u003e \" 1). In the link [1], \" infiniband syz2: set down \" This means that on 839.350575, the event ib_cache_event_task was sent andi queued in ib_wq. 2). In the link [1], \" team0 (unregistering): Port device team_slave_0 removed \" It indicates that before 843.251853, the net device should be freed. 3). In the link [1], \" BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 \" This means that on 850.559070, this slab-use-after-free problem occurred. In all, on 839.350575, the event ib_cache_event_task was sent and queued in ib_wq, before 843.251853, the net device veth was freed. on 850.559070, this event was executed, and the mentioned freed net device was called. Thus, the above call trace occurred. [1] https://syzkaller.appspot.com/x/log.txt?x=12e7025f980000", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57795", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mtsJHWk1Bpn3p7vhoDLtug==": { "id": "mtsJHWk1Bpn3p7vhoDLtug==", "updater": "debian/updater", "name": "CVE-2026-46293", "description": "In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access during output registration UBSAN reported an out of bounds access during registration of the last two outputs. This out of bounds access occurs because space is only allocated in the hws array for two PLLs and the four output dividers that each has, but the defined IDs contain two DLLS and their two outputs each, which are not supported by the driver. The ID order is PLLs -\u003e DLLs -\u003e PLL outputs -\u003e DLL outputs. Decrement the PLL output IDs by two while adding them to the array to avoid the problem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46293", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "muQ9JOZI+Lpy3i1Gy2YS9A==": { "id": "muQ9JOZI+Lpy3i1Gy2YS9A==", "updater": "debian/updater", "name": "CVE-2024-46760", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: usb: schedule rx work after everything is set up Right now it's possible to hit NULL pointer dereference in rtw_rx_fill_rx_status on hw object and/or its fields because initialization routine can start getting USB replies before rtw_dev is fully setup. The stack trace looks like this: rtw_rx_fill_rx_status rtw8821c_query_rx_desc rtw_usb_rx_handler ... queue_work rtw_usb_read_port_complete ... usb_submit_urb rtw_usb_rx_resubmit rtw_usb_init_rx rtw_usb_probe So while we do the async stuff rtw_usb_probe continues and calls rtw_register_hw, which does all kinds of initialization (e.g. via ieee80211_register_hw) that rtw_rx_fill_rx_status relies on. Fix this by moving the first usb_submit_urb after everything is set up. For me, this bug manifested as: [ 8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped [ 8.910904] rtw_8821cu 1-1:1.2: hw-\u003econf.chandef.chan NULL in rtw_rx_fill_rx_status because I'm using Larry's backport of rtw88 driver with the NULL checks in rtw_rx_fill_rx_status.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46760", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mv4PinVh5v3tJxVjLXJruQ==": { "id": "mv4PinVh5v3tJxVjLXJruQ==", "updater": "debian/updater", "name": "CVE-2026-68409", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU: \tsta_info_free_link(\u0026alloc-\u003einfo); \tkfree_rcu(alloc, rcu_head); The RX fast path reads link_sta under rcu_read_lock and writes the percpu stats. A reader that resolved link_sta before the removal keeps the pointer. The container stays alive from the kfree_rcu, so the read still works. But the percpu block it points to is already freed. This needs uses_rss. That is when pcpu_rx_stats exists. The full STA teardown frees the deflink stats only after synchronize_net(). The link removal path had no such barrier. The race is hard to win in practice, but the free should still wait for RCU. Free the link together with its data from a single RCU callback, so the percpu block is reclaimed only after readers drain.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68409", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mwBbCDmV+BFi1OG3VKzdzg==": { "id": "mwBbCDmV+BFi1OG3VKzdzg==", "updater": "debian/updater", "name": "CVE-2026-14669", "description": "Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14669", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mxiTANJZC5hMGOWhQIq9Wg==": { "id": "mxiTANJZC5hMGOWhQIq9Wg==", "updater": "debian/updater", "name": "CVE-2026-53613", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53613", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "mxkBwL2NcQ/jra18Jzk9Vg==": { "id": "mxkBwL2NcQ/jra18Jzk9Vg==", "updater": "debian/updater", "name": "CVE-2026-50812", "description": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-50812", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "sqlite3", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n0V5sg2R2RKEdXaGiJ1trQ==": { "id": "n0V5sg2R2RKEdXaGiJ1trQ==", "updater": "debian/updater", "name": "CVE-2026-62363", "description": "ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-62363", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "imagemagick", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n1G51+pDWdZffLujptzXqQ==": { "id": "n1G51+pDWdZffLujptzXqQ==", "updater": "debian/updater", "name": "CVE-2026-63999", "description": "In the Linux kernel, the following vulnerability has been resolved: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops-\u003eget_rxfh() to populate them. If get_rxfh() fails, the function returns an error without freeing the allocation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63999", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "n2hgQh2mltiPUrbZeKTKfw==": { "id": "n2hgQh2mltiPUrbZeKTKfw==", "updater": "debian/updater", "name": "CVE-2026-68127", "description": "In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling pskb_may_pull(). On a non-linear skb whose transport header sits in a page fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head() and free the old skb head, leaving ip6h dangling; the following get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator() uses ip6h (and the iaddr derived from it) again after the csum-adjust call and additionally writes the new locator through that pointer. Impact: a remote IPv6 packet routed through a configured ILA csum-adjust-transport route or receive-side mapping triggers a slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or mapping requires CAP_NET_ADMIN to configure, but trigger packets are unauthenticated once it exists. Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport() before the csum-diff read. In ila_update_ipv6_locator() only the ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in that case alone before the destination-address write; the neutral-map modes never pull and keep their cached pointers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68127", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nATdasCaoRj0zKLOYIzA7g==": { "id": "nATdasCaoRj0zKLOYIzA7g==", "updater": "debian/updater", "name": "CVE-2024-35887", "description": "In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, the ax25_ds_del_timer() that calls del_timer() in it will return directly. As a result, the use-after-free bugs could happen, one of the scenarios is shown below: (Thread 1) | (Thread 2) | ax25_ds_timeout() ax25_dev_device_down() | ax25_ds_del_timer() | del_timer() | ax25_dev_put() //FREE | | ax25_dev-\u003e //USE In order to mitigate bugs, when the device is detaching, use timer_shutdown_sync() to stop the timer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35887", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nCU1KSyyHi3FvXLK34YLSg==": { "id": "nCU1KSyyHi3FvXLK34YLSg==", "updater": "debian/updater", "name": "CVE-2026-18938", "description": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-18938", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "p11-kit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nDFXJBzen2MLc53jRlGtgw==": { "id": "nDFXJBzen2MLc53jRlGtgw==", "updater": "debian/updater", "name": "CVE-2025-68183", "description": "In the Linux kernel, the following vulnerability has been resolved: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr Currently when both IMA and EVM are in fix mode, the IMA signature will be reset to IMA hash if a program first stores IMA signature in security.ima and then writes/removes some other security xattr for the file. For example, on Fedora, after booting the kernel with \"ima_appraise=fix evm=fix ima_policy=appraise_tcb\" and installing rpm-plugin-ima, installing/reinstalling a package will not make good reference IMA signature generated. Instead IMA hash is generated, # getfattr -m - -d -e hex /usr/bin/bash # file: usr/bin/bash security.ima=0x0404... This happens because when setting security.selinux, the IMA_DIGSIG flag that had been set early was cleared. As a result, IMA hash is generated when the file is closed. Similarly, IMA signature can be cleared on file close after removing security xattr like security.evm or setting/removing ACL. Prevent replacing the IMA file signature with a file hash, by preventing the IMA_DIGSIG flag from being reset. Here's a minimal C reproducer which sets security.selinux as the last step which can also replaced by removing security.evm or setting ACL, #include \u003cstdio.h\u003e #include \u003csys/xattr.h\u003e #include \u003cfcntl.h\u003e #include \u003cunistd.h\u003e #include \u003cstring.h\u003e #include \u003cstdlib.h\u003e int main() { const char* file_path = \"/usr/sbin/test_binary\"; const char* hex_string = \"030204d33204490066306402304\"; int length = strlen(hex_string); char* ima_attr_value; int fd; fd = open(file_path, O_WRONLY|O_CREAT|O_EXCL, 0644); if (fd == -1) { perror(\"Error opening file\"); return 1; } ima_attr_value = (char*)malloc(length / 2 ); for (int i = 0, j = 0; i \u003c length; i += 2, j++) { sscanf(hex_string + i, \"%2hhx\", \u0026ima_attr_value[j]); } if (fsetxattr(fd, \"security.ima\", ima_attr_value, length/2, 0) == -1) { perror(\"Error setting extended attribute\"); close(fd); return 1; } const char* selinux_value= \"system_u:object_r:bin_t:s0\"; if (fsetxattr(fd, \"security.selinux\", selinux_value, strlen(selinux_value), 0) == -1) { perror(\"Error setting extended attribute\"); close(fd); return 1; } close(fd); return 0; }", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68183", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nEDHnAt98ommvxFRwuVpOA==": { "id": "nEDHnAt98ommvxFRwuVpOA==", "updater": "debian/updater", "name": "CVE-2025-37977", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set then descriptors are non-cacheable and the iocc shareability bits should be disabled. Without this UFS can end up in an incompatible configuration and suffer from random cache related stability issues.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37977", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nHnLyc0i3LGGWSzAPhyYKw==": { "id": "nHnLyc0i3LGGWSzAPhyYKw==", "updater": "debian/updater", "name": "CVE-2023-52586", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add mutex lock in control vblank irq Add a mutex lock to control vblank irq to synchronize vblank enable/disable operations happening from different threads to prevent race conditions while registering/unregistering the vblank irq callback. v4: -Removed vblank_ctl_lock from dpu_encoder_virt, so it is only a parameter of dpu_encoder_phys. -Switch from atomic refcnt to a simple int counter as mutex has now been added v3: Mistakenly did not change wording in last version. It is done now. v2: Slightly changed wording of commit message Patchwork: https://patchwork.freedesktop.org/patch/571854/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52586", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nICJsssx8SRrJtkPaGWSwQ==": { "id": "nICJsssx8SRrJtkPaGWSwQ==", "updater": "debian/updater", "name": "CVE-2025-38585", "description": "In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() When gmin_get_config_var() calls efi.get_variable() and the EFI variable is larger than the expected buffer size, two behaviors combine to create a stack buffer overflow: 1. gmin_get_config_var() does not return the proper error code when efi.get_variable() fails. It returns the stale 'ret' value from earlier operations instead of indicating the EFI failure. 2. When efi.get_variable() returns EFI_BUFFER_TOO_SMALL, it updates *out_len to the required buffer size but writes no data to the output buffer. However, due to bug #1, gmin_get_var_int() believes the call succeeded. The caller gmin_get_var_int() then performs: - Allocates val[CFG_VAR_NAME_MAX + 1] (65 bytes) on stack - Calls gmin_get_config_var(dev, is_gmin, var, val, \u0026len) with len=64 - If EFI variable is \u003e64 bytes, efi.get_variable() sets len=required_size - Due to bug #1, thinks call succeeded with len=required_size - Executes val[len] = 0, writing past end of 65-byte stack buffer This creates a stack buffer overflow when EFI variables are larger than 64 bytes. Since EFI variables can be controlled by firmware or system configuration, this could potentially be exploited for code execution. Fix the bug by returning proper error codes from gmin_get_config_var() based on EFI status instead of stale 'ret' value. The gmin_get_var_int() function is called during device initialization for camera sensor configuration on Intel Bay Trail and Cherry Trail platforms using the atomisp camera stack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38585", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nIhEjmVZOLLsxjuIgK19MQ==": { "id": "nIhEjmVZOLLsxjuIgK19MQ==", "updater": "debian/updater", "name": "CVE-2026-46302", "description": "In the Linux kernel, the following vulnerability has been resolved: selinux: allow multiple opens of /sys/fs/selinux/policy Currently there can only be a single open of /sys/fs/selinux/policy at any time. This allows any process to block any other process from reading the kernel policy. The original motivation seems to have been a mix of preventing an inconsistent view of the policy size and preventing userspace from allocating kernel memory without bound, but this is arguably equally bad. Eliminate the policy_opened flag and shrink the critical section that the policy mutex is held. While we are making changes here, drop a couple of extraneous BUG_ONs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46302", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nKoGjNh27GCeUMT2dK/Gdg==": { "id": "nKoGjNh27GCeUMT2dK/Gdg==", "updater": "debian/updater", "name": "CVE-2024-53179", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of signing key Customers have reported use-after-free in @ses-\u003eauth_key.response with SMB2.1 + sign mounts which occurs due to following race: task A task B cifs_mount() dfs_mount_share() get_session() cifs_mount_get_session() cifs_send_recv() cifs_get_smb_ses() compound_send_recv() cifs_setup_session() smb2_setup_request() kfree_sensitive() smb2_calc_signature() crypto_shash_setkey() *UAF* Fix this by ensuring that we have a valid @ses-\u003eauth_key.response by checking whether @ses-\u003eses_status is SES_GOOD or SES_EXITING with @ses-\u003eses_lock held. After commit 24a9799aa8ef (\"smb: client: fix UAF in smb2_reconnect_server()\"), we made sure to call -\u003elogoff() only when @ses was known to be good (e.g. valid -\u003eauth_key.response), so it's safe to access signing key when @ses-\u003eses_status == SES_EXITING.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53179", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nN3RuidIOX87KUHmtXIlYw==": { "id": "nN3RuidIOX87KUHmtXIlYw==", "updater": "debian/updater", "name": "CVE-2025-21696", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: clear uffd-wp PTE/PMD state on mremap() When mremap()ing a memory region previously registered with userfaultfd as write-protected but without UFFD_FEATURE_EVENT_REMAP, an inconsistency in flag clearing leads to a mismatch between the vma flags (which have uffd-wp cleared) and the pte/pmd flags (which do not have uffd-wp cleared). This mismatch causes a subsequent mprotect(PROT_WRITE) to trigger a warning in page_table_check_pte_flags() due to setting the pte to writable while uffd-wp is still set. Fix this by always explicitly clearing the uffd-wp pte/pmd flags on any such mremap() so that the values are consistent with the existing clearing of VM_UFFD_WP. Be careful to clear the logical flag regardless of its physical form; a PTE bit, a swap PTE bit, or a PTE marker. Cover PTE, huge PMD and hugetlb paths.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21696", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nQ0YMG97Bm6YVHjHJkVM4w==": { "id": "nQ0YMG97Bm6YVHjHJkVM4w==", "updater": "debian/updater", "name": "CVE-2025-1372", "description": "A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1372", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nQRVDJA8dS+gnrKQ9Z1CkQ==": { "id": "nQRVDJA8dS+gnrKQ9Z1CkQ==", "updater": "debian/updater", "name": "CVE-2026-63962", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() svdm_consume_modes() checks pmdata-\u003ealtmodes against the array size once before the loop over the count, but forgot to check the bound at every point in the loop. In the well-behaved SVDM discovery flow this is harmless because each of at most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX modes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX]. But the CMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming ACK with any request the port actually sent. Once port-\u003epartner is set, an unsolicited Discover Modes ACK is consumed unconditionally. A broken or malicious port partner can therefore drive altmodes to ALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra Discover Modes ACK with seven VDOs. Because the pre-loop check passes, the loop could then writes up to five entries past altmode_desc[]. For mode_data_prime the next field in struct tcpm_port is the partner_altmode[] pointer array, which then receives partner-chosen SVID/VDO bytes. Move the bound check inside the loop so the array can never be indexed past ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner supplies or how the function was reached.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63962", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nUTdm61H5wpWvjqAxaXYSg==": { "id": "nUTdm61H5wpWvjqAxaXYSg==", "updater": "debian/updater", "name": "CVE-2026-68397", "description": "In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock, drops the lock, and then passes the socket to the afiucv_hs_callback_*() handlers without holding a reference. AF_IUCV sockets are not RCU-protected and are freed synchronously by iucv_sock_kill() -\u003e sock_put(), so a concurrent close can free the socket in the window between read_unlock() and the handler, which then dereferences freed memory (for example sk-\u003esk_data_ready() in afiucv_hs_callback_syn()). Take a reference with sock_hold() while the socket is still on the list and release it with sock_put() once the handler has run.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68397", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nUqm8sU2PJyxkU75BauqBQ==": { "id": "nUqm8sU2PJyxkU75BauqBQ==", "updater": "debian/updater", "name": "CVE-2026-64579", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert xfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert loop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or fail. But its guard is inverted: it skips policies with prefixlen \u003c threshold and preallocates for the rest. prefixlen \u003c threshold is exactly when policy_hash_bysel() returns NULL and the reinsert takes the allocating xfrm_policy_inexact_insert() path. So the loop preallocates for the exact policies (which never allocate) and skips the inexact ones, whose bin/node is then allocated GFP_ATOMIC during reinsert. On failure the error path only WARN_ONCE()s and continues, leaving a poisoned bydst node; the next rebuild's hlist_del_rcu() dereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure, deterministic via failslab. Invert the guard so preallocation covers exactly the reinserted policies; the reinsert then allocates nothing and cannot fail. Crash: Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead...] ... Workqueue: events xfrm_hash_rebuild RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190 RAX: dead000000000122 (LIST_POISON2 + offset) ... Call Trace: hlist_del_rcu (include/linux/rculist.h:599) xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365) process_one_work (kernel/workqueue.c:3322) worker_thread (kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) ... Kernel panic - not syncing: Fatal exception in interrupt", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64579", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nXMMuqzw9RtwcJ6EHriBaw==": { "id": "nXMMuqzw9RtwcJ6EHriBaw==", "updater": "debian/updater", "name": "CVE-2026-41142", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-41142", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "na/ugY9lH08smavOJFuCMw==": { "id": "na/ugY9lH08smavOJFuCMw==", "updater": "debian/updater", "name": "CVE-2024-44963", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON() when freeing tree block after error When freeing a tree block, at btrfs_free_tree_block(), if we fail to create a delayed reference we don't deal with the error and just do a BUG_ON(). The error most likely to happen is -ENOMEM, and we have a comment mentioning that only -ENOMEM can happen, but that is not true, because in case qgroups are enabled any error returned from btrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned from btrfs_search_slot() for example) can be propagated back to btrfs_free_tree_block(). So stop doing a BUG_ON() and return the error to the callers and make them abort the transaction to prevent leaking space. Syzbot was triggering this, likely due to memory allocation failure injection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-44963", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ndJ5GEAWepa3cRd6DbKPJw==": { "id": "ndJ5GEAWepa3cRd6DbKPJw==", "updater": "debian/updater", "name": "CVE-2025-66864", "description": "An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66864", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nfQRE3FnBHWnn4FiLmrVoA==": { "id": "nfQRE3FnBHWnn4FiLmrVoA==", "updater": "debian/updater", "name": "CVE-2026-68367", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: synchronize delayed set_alt with teardown The f_tcm set_alt() path defers endpoint setup to a work item and completes the delayed status response from process context. The delayed work uses f_tcm private state and may complete the setup request after disconnect or function teardown has already moved on. Cancel and drain the delayed set_alt work when the function is unbound or freed. For disable paths, which are reached under the composite device lock, use a small state machine and a non-sleeping cancellation path instead of cancel_work_sync(). If the work is already running, mark it cancelled and let the worker own the cleanup; otherwise tcm_disable() can cancel the queued work and clean up immediately. Also serialize the final delayed-status completion with the cancellation check while holding the composite device lock. This prevents a disconnect from clearing delayed_status while the worker is about to complete the control request. Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x66/0xa0 print_report+0xce/0x630 ? tcm_delayed_set_alt+0x6c/0xef0 ? srso_alias_return_thunk+0x5/0xfbef5 ? __virt_addr_valid+0x188/0x320 ? tcm_delayed_set_alt+0x6c/0xef0 kasan_report+0xe0/0x110 ? tcm_delayed_set_alt+0x6c/0xef0 tcm_delayed_set_alt+0x6c/0xef0 ? __pfx_tcm_delayed_set_alt+0x10/0x10 ? process_one_work+0x4cb/0xb90 ? rcu_is_watching+0x20/0x50 ? tcm_delayed_set_alt+0x9/0xef0 process_one_work+0x4d7/0xb90 ? __pfx_process_one_work+0x10/0x10 ? srso_alias_return_thunk+0x5/0xfbef5 ? __list_add_valid_or_report+0x37/0xf0 ? __pfx_tcm_delayed_set_alt+0x10/0x10 ? srso_alias_return_thunk+0x5/0xfbef5 worker_thread+0x2d8/0x570 ? __pfx_worker_thread+0x10/0x10 kthread+0x1ad/0x1f0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x3c9/0x540 ? __pfx_ret_from_fork+0x10/0x10 ? srso_alias_return_thunk+0x5/0xfbef5 ? __switch_to+0x2e9/0x730 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e Allocated by task 544: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 tcm_alloc+0x68/0x180 usb_get_function+0x36/0x60 config_usb_cfg_link+0x125/0x1b0 configfs_symlink+0x322/0x890 vfs_symlink+0xc2/0x270 filename_symlinkat+0x295/0x2f0 __x64_sys_symlinkat+0x62/0x90 do_syscall_64+0x115/0x6a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 661: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x43/0x70 kfree+0x2f9/0x530 config_usb_cfg_unlink+0x173/0x1e0 configfs_unlink+0x1fa/0x340 vfs_unlink+0x15c/0x510 filename_unlinkat+0x2ba/0x450 __x64_sys_unlinkat+0x63/0x90 do_syscall_64+0x115/0x6a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68367", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nfe3l/Qiy6DgNuk9w1rfsg==": { "id": "nfe3l/Qiy6DgNuk9w1rfsg==", "updater": "debian/updater", "name": "CVE-2025-68190", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() kcalloc() may fail. When WS is non-zero and allocation fails, ectx.ws remains NULL while ectx.ws_size is set, leading to a potential NULL pointer dereference in atom_get_src_int() when accessing WS entries. Return -ENOMEM on allocation failure to avoid the NULL dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68190", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "niZVkyT1xeY52WsrQOz+8Q==": { "id": "niZVkyT1xeY52WsrQOz+8Q==", "updater": "debian/updater", "name": "CVE-2023-45853", "description": "MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-45853", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "zlib", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "njKjXe24Zkq17Blj9of/EA==": { "id": "njKjXe24Zkq17Blj9of/EA==", "updater": "debian/updater", "name": "CVE-2024-53068", "description": "In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier() The scmi_dev-\u003ename is released prematurely in __scmi_device_destroy(), which causes slab-use-after-free when accessing scmi_dev-\u003ename in scmi_bus_notifier(). So move the release of scmi_dev-\u003ename to scmi_device_release() to avoid slab-use-after-free. | BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec | Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1 | | CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1 | Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT) | Call trace: | dump_backtrace+0x94/0x114 | show_stack+0x18/0x24 | dump_stack_lvl+0x48/0x60 | print_report+0xf4/0x5b0 | kasan_report+0xa4/0xec | __asan_report_load1_noabort+0x20/0x2c | strncmp+0xe4/0xec | scmi_bus_notifier+0x5c/0x54c | notifier_call_chain+0xb4/0x31c | blocking_notifier_call_chain+0x68/0x9c | bus_notify+0x54/0x78 | device_del+0x1bc/0x840 | device_unregister+0x20/0xb4 | __scmi_device_destroy+0xac/0x280 | scmi_device_destroy+0x94/0xd0 | scmi_chan_setup+0x524/0x750 | scmi_probe+0x7fc/0x1508 | platform_probe+0xc4/0x19c | really_probe+0x32c/0x99c | __driver_probe_device+0x15c/0x3c4 | driver_probe_device+0x5c/0x170 | __driver_attach+0x1c8/0x440 | bus_for_each_dev+0xf4/0x178 | driver_attach+0x3c/0x58 | bus_add_driver+0x234/0x4d4 | driver_register+0xf4/0x3c0 | __platform_driver_register+0x60/0x88 | scmi_driver_init+0xb0/0x104 | do_one_initcall+0xb4/0x664 | kernel_init_freeable+0x3c8/0x894 | kernel_init+0x24/0x1e8 | ret_from_fork+0x10/0x20 | | Allocated by task 1: | kasan_save_stack+0x2c/0x54 | kasan_set_track+0x2c/0x40 | kasan_save_alloc_info+0x24/0x34 | __kasan_kmalloc+0xa0/0xb8 | __kmalloc_node_track_caller+0x6c/0x104 | kstrdup+0x48/0x84 | kstrdup_const+0x34/0x40 | __scmi_device_create.part.0+0x8c/0x408 | scmi_device_create+0x104/0x370 | scmi_chan_setup+0x2a0/0x750 | scmi_probe+0x7fc/0x1508 | platform_probe+0xc4/0x19c | really_probe+0x32c/0x99c | __driver_probe_device+0x15c/0x3c4 | driver_probe_device+0x5c/0x170 | __driver_attach+0x1c8/0x440 | bus_for_each_dev+0xf4/0x178 | driver_attach+0x3c/0x58 | bus_add_driver+0x234/0x4d4 | driver_register+0xf4/0x3c0 | __platform_driver_register+0x60/0x88 | scmi_driver_init+0xb0/0x104 | do_one_initcall+0xb4/0x664 | kernel_init_freeable+0x3c8/0x894 | kernel_init+0x24/0x1e8 | ret_from_fork+0x10/0x20 | | Freed by task 1: | kasan_save_stack+0x2c/0x54 | kasan_set_track+0x2c/0x40 | kasan_save_free_info+0x38/0x5c | __kasan_slab_free+0xe8/0x164 | __kmem_cache_free+0x11c/0x230 | kfree+0x70/0x130 | kfree_const+0x20/0x40 | __scmi_device_destroy+0x70/0x280 | scmi_device_destroy+0x94/0xd0 | scmi_chan_setup+0x524/0x750 | scmi_probe+0x7fc/0x1508 | platform_probe+0xc4/0x19c | really_probe+0x32c/0x99c | __driver_probe_device+0x15c/0x3c4 | driver_probe_device+0x5c/0x170 | __driver_attach+0x1c8/0x440 | bus_for_each_dev+0xf4/0x178 | driver_attach+0x3c/0x58 | bus_add_driver+0x234/0x4d4 | driver_register+0xf4/0x3c0 | __platform_driver_register+0x60/0x88 | scmi_driver_init+0xb0/0x104 | do_one_initcall+0xb4/0x664 | kernel_init_freeable+0x3c8/0x894 | kernel_init+0x24/0x1e8 | ret_from_fork+0x10/0x20", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53068", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nmLo+5oFZcZwsNKc/4TkXA==": { "id": "nmLo+5oFZcZwsNKc/4TkXA==", "updater": "debian/updater", "name": "CVE-2025-71129", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they should follow LoongArch calling conventions. Sign extend its arguments properly to avoid kernel panic. This is done by adding a new emit_abi_ext() helper. The emit_abi_ext() helper performs extension in place meaning a value already store in the target register (Note: this is different from the existing sign_extend() helper and thus we can't reuse it).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71129", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nnjR/U14S0Gli7ekeQUwIA==": { "id": "nnjR/U14S0Gli7ekeQUwIA==", "updater": "debian/updater", "name": "CVE-2025-38272", "description": "In the Linux kernel, the following vulnerability has been resolved: net: dsa: b53: do not enable EEE on bcm63xx BCM63xx internal switches do not support EEE, but provide multiple RGMII ports where external PHYs may be connected. If one of these PHYs are EEE capable, we may try to enable EEE for the MACs, which then hangs the system on access of the (non-existent) EEE registers. Fix this by checking if the switch actually supports EEE before attempting to configure it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38272", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "nxfFlxrPmdAebW4GstXgtg==": { "id": "nxfFlxrPmdAebW4GstXgtg==", "updater": "debian/updater", "name": "CVE-2019-6461", "description": "An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-6461", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "cairo", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o+J4rA1seQs4hgsSwwbzQg==": { "id": "o+J4rA1seQs4hgsSwwbzQg==", "updater": "debian/updater", "name": "CVE-2024-26948", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add a dc_state NULL check in dc_state_release [How] Check wheather state is NULL before releasing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26948", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o//PejU8uemBRUHDfRoRJA==": { "id": "o//PejU8uemBRUHDfRoRJA==", "updater": "debian/updater", "name": "CVE-2025-40206", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefmap expressions Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive calls: BUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12) [...] Call Trace: __find_rr_leaf+0x99/0x230 fib6_table_lookup+0x13b/0x2d0 ip6_pol_route+0xa4/0x400 fib6_rule_lookup+0x156/0x240 ip6_route_output_flags+0xc6/0x150 __nf_ip6_route+0x23/0x50 synproxy_send_tcp_ipv6+0x106/0x200 synproxy_send_client_synack_ipv6+0x1aa/0x1f0 nft_synproxy_do_eval+0x263/0x310 nft_do_chain+0x5a8/0x5f0 [nf_tables nft_do_chain_inet+0x98/0x110 nf_hook_slow+0x43/0xc0 __ip6_local_out+0xf0/0x170 ip6_local_out+0x17/0x70 synproxy_send_tcp_ipv6+0x1a2/0x200 synproxy_send_client_synack_ipv6+0x1aa/0x1f0 [...] Implement objref and objrefmap expression validate functions. Currently, only NFT_OBJECT_SYNPROXY object type requires validation. This will also handle a jump to a chain using a synproxy object from the OUTPUT hook. Now when trying to reference a synproxy object in the OUTPUT hook, nft will produce the following error: synproxy_crash.nft: Error: Could not process rule: Operation not supported synproxy name mysynproxy ^^^^^^^^^^^^^^^^^^^^^^^^", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40206", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o0ecraUnR3jJvtQR7V8UVw==": { "id": "o0ecraUnR3jJvtQR7V8UVw==", "updater": "debian/updater", "name": "CVE-2026-53345", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When marking a page dirty, complain about not having a running/loaded vCPU if and only if the VM is still alive, i.e. its refcount is non-zero. This will allow fixing a memory leak for x86 SEV-ES guests without hitting what is effectively a false positive on the WARN. For some SEV-ES VM-Exits, KVM keeps a writable mapping of a guest page across an exit to userspace, and typically unmaps the page on the next KVM_RUN. But if userspace never calls KVM_RUN after such an exit, then KVM needs to unmap the page when the vCPU is destroyed, which in turn triggers the WARN about not having a running vCPU. Alternatively, SEV-ES could temporarily load the vCPU to suppress the WARN, as is done in nested_vmx_free_vcpu() (but for completely unrelated reasons; suppressing WARN from nested_put_vmcs12_pages() is pure happenstance). But loading a vCPU during destruction is gross (ideally nVMX code would be cleaned up), risks complicating the SEV-ES code (KVM would need to ensure the temporarily load()+put() only runs when the vCPU isn't already loaded), and is ultimately pointless. The motivation for the WARN is to guard against KVM dirtying guest memory without pushing the corresponding GFN to the active vCPU's dirty ring, e.g. to ensure userspace doesn't miss a dirty page. But for the VM's refcount to reach zero, there can't be _any_ userspace mappings to the dirty ring, as mapping the dirty ring requires doing mmap() on the vCPU FD. I.e. if userspace had a valid mapping for the dirty ring, then the vCPU file and thus the owning VM would still be alive. And so since userspace can't possibly reach the dirty ring, whether or not KVM technically \"misses\" a push to the dirty ring is irrelevant.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53345", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o2NMtZKjIaTGadvHG5mp6Q==": { "id": "o2NMtZKjIaTGadvHG5mp6Q==", "updater": "debian/updater", "name": "CVE-2026-68081", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid guest while emulating VMLAUNCH or VMRESUME. The invalid guest state path doesn't use nested_vmx_vmexit() as that API is intended to be used if and only if L2 is active, and the open coded equivalent neglects to put the vmcs12 pages. Failure to put the vmcs12 pages leaks any pinned pages (and/or mappings) if L1 retries VMLAUNCH/VMRESUME. Note, the !from_vmenter scenario doesn't suffer the same problem, as vmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is active, i.e. if a \"full\" VM-Exit is guaranteed before KVM will retry getting vmcs12 pages.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68081", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o2j1vMVAP/vlfzZZpode4A==": { "id": "o2j1vMVAP/vlfzZZpode4A==", "updater": "debian/updater", "name": "CVE-2025-39705", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a Null pointer dereference vulnerability [Why] A null pointer dereference vulnerability exists in the AMD display driver's (DC module) cleanup function dc_destruct(). When display control context (dc-\u003ectx) construction fails (due to memory allocation failure), this pointer remains NULL. During subsequent error handling when dc_destruct() is called, there's no NULL check before dereferencing the perf_trace member (dc-\u003ectx-\u003eperf_trace), causing a kernel null pointer dereference crash. [How] Check if dc-\u003ectx is non-NULL before dereferencing. (Updated commit text and removed unnecessary error message) (cherry picked from commit 9dd8e2ba268c636c240a918e0a31e6feaee19404)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39705", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o2jo+ACRJMvwEfq9dh6AZw==": { "id": "o2jo+ACRJMvwEfq9dh6AZw==", "updater": "debian/updater", "name": "CVE-2026-31537", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.send_io.bcredits It turns out that our code will corrupt the stream of reassabled data transfer messages when we trigger an immendiate (empty) send. In order to fix this we'll have a single 'batch' credit per connection. And code getting that credit is free to use as much messages until remaining_length reaches 0, then the batch credit it given back and the next logical send can happen.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31537", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "o5vXQMQiLzL6AxMfR8vX6A==": { "id": "o5vXQMQiLzL6AxMfR8vX6A==", "updater": "debian/updater", "name": "CVE-2025-21831", "description": "In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 (\"PCI: Put PCIe ports into D3 during suspend\") sets the policy that all PCIe ports are allowed to use D3. When the system is suspended if the port is not power manageable by the platform and won't be used for wakeup via a PME this sets up the policy for these ports to go into D3hot. This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. This manifests as a system hang. On the affected Device + BIOS combination, add a quirk for the root port of the problematic controller to ensure that these root ports are not put into D3hot at suspend. This patch is based on https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com but with the added condition both in the documentation and in the code to apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only the affected root ports.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21831", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oAJV6yKgQS6xMKtIhAlSqg==": { "id": "oAJV6yKgQS6xMKtIhAlSqg==", "updater": "debian/updater", "name": "CVE-2026-8328", "description": "The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8328", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oE5rFIgE+cUQmwp2YVokrw==": { "id": "oE5rFIgE+cUQmwp2YVokrw==", "updater": "debian/updater", "name": "CVE-2025-68379", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix null deref on srq-\u003erq.queue after resize failure A NULL pointer dereference can occur in rxe_srq_chk_attr() when ibv_modify_srq() is invoked twice in succession under certain error conditions. The first call may fail in rxe_queue_resize(), which leads rxe_srq_from_attr() to set srq-\u003erq.queue = NULL. The second call then triggers a crash (null deref) when accessing srq-\u003erq.queue-\u003ebuf-\u003eindex_mask. Call Trace: \u003cTASK\u003e rxe_modify_srq+0x170/0x480 [rdma_rxe] ? __pfx_rxe_modify_srq+0x10/0x10 [rdma_rxe] ? uverbs_try_lock_object+0x4f/0xa0 [ib_uverbs] ? rdma_lookup_get_uobject+0x1f0/0x380 [ib_uverbs] ib_uverbs_modify_srq+0x204/0x290 [ib_uverbs] ? __pfx_ib_uverbs_modify_srq+0x10/0x10 [ib_uverbs] ? tryinc_node_nr_active+0xe6/0x150 ? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs] ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x2c0/0x470 [ib_uverbs] ? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs] ? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs] ib_uverbs_run_method+0x55a/0x6e0 [ib_uverbs] ? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs] ib_uverbs_cmd_verbs+0x54d/0x800 [ib_uverbs] ? __pfx_ib_uverbs_cmd_verbs+0x10/0x10 [ib_uverbs] ? __pfx___raw_spin_lock_irqsave+0x10/0x10 ? __pfx_do_vfs_ioctl+0x10/0x10 ? ioctl_has_perm.constprop.0.isra.0+0x2c7/0x4c0 ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 ib_uverbs_ioctl+0x13e/0x220 [ib_uverbs] ? __pfx_ib_uverbs_ioctl+0x10/0x10 [ib_uverbs] __x64_sys_ioctl+0x138/0x1c0 do_syscall_64+0x82/0x250 ? fdget_pos+0x58/0x4c0 ? ksys_write+0xf3/0x1c0 ? __pfx_ksys_write+0x10/0x10 ? do_syscall_64+0xc8/0x250 ? __pfx_vm_mmap_pgoff+0x10/0x10 ? fget+0x173/0x230 ? fput+0x2a/0x80 ? ksys_mmap_pgoff+0x224/0x4c0 ? do_syscall_64+0xc8/0x250 ? do_user_addr_fault+0x37b/0xfe0 ? clear_bhb_loop+0x50/0xa0 ? clear_bhb_loop+0x50/0xa0 ? clear_bhb_loop+0x50/0xa0 entry_SYSCALL_64_after_hwframe+0x76/0x7e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68379", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oIMZkhmE1zTNLf+KmwFMBw==": { "id": "oIMZkhmE1zTNLf+KmwFMBw==", "updater": "debian/updater", "name": "CVE-2026-8924", "description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8924", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oJmCZHz0uc7KgDTvu6vBSQ==": { "id": "oJmCZHz0uc7KgDTvu6vBSQ==", "updater": "debian/updater", "name": "CVE-2024-26953", "description": "In the Linux kernel, the following vulnerability has been resolved: net: esp: fix bad handling of pages from page_pool When the skb is reorganized during esp_output (!esp-\u003einline), the pages coming from the original skb fragments are supposed to be released back to the system through put_page. But if the skb fragment pages are originating from a page_pool, calling put_page on them will trigger a page_pool leak which will eventually result in a crash. This leak can be easily observed when using CONFIG_DEBUG_VM and doing ipsec + gre (non offloaded) forwarding: BUG: Bad page state in process ksoftirqd/16 pfn:1451b6 page:00000000de2b8d32 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1451b6000 pfn:0x1451b6 flags: 0x200000000000000(node=0|zone=2) page_type: 0xffffffff() raw: 0200000000000000 dead000000000040 ffff88810d23c000 0000000000000000 raw: 00000001451b6000 0000000000000001 00000000ffffffff 0000000000000000 page dumped because: page_pool leak Modules linked in: ip_gre gre mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat nf_nat xt_addrtype br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay zram zsmalloc fuse [last unloaded: mlx5_core] CPU: 16 PID: 96 Comm: ksoftirqd/16 Not tainted 6.8.0-rc4+ #22 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x36/0x50 bad_page+0x70/0xf0 free_unref_page_prepare+0x27a/0x460 free_unref_page+0x38/0x120 esp_ssg_unref.isra.0+0x15f/0x200 esp_output_tail+0x66d/0x780 esp_xmit+0x2c5/0x360 validate_xmit_xfrm+0x313/0x370 ? validate_xmit_skb+0x1d/0x330 validate_xmit_skb_list+0x4c/0x70 sch_direct_xmit+0x23e/0x350 __dev_queue_xmit+0x337/0xba0 ? nf_hook_slow+0x3f/0xd0 ip_finish_output2+0x25e/0x580 iptunnel_xmit+0x19b/0x240 ip_tunnel_xmit+0x5fb/0xb60 ipgre_xmit+0x14d/0x280 [ip_gre] dev_hard_start_xmit+0xc3/0x1c0 __dev_queue_xmit+0x208/0xba0 ? nf_hook_slow+0x3f/0xd0 ip_finish_output2+0x1ca/0x580 ip_sublist_rcv_finish+0x32/0x40 ip_sublist_rcv+0x1b2/0x1f0 ? ip_rcv_finish_core.constprop.0+0x460/0x460 ip_list_rcv+0x103/0x130 __netif_receive_skb_list_core+0x181/0x1e0 netif_receive_skb_list_internal+0x1b3/0x2c0 napi_gro_receive+0xc8/0x200 gro_cell_poll+0x52/0x90 __napi_poll+0x25/0x1a0 net_rx_action+0x28e/0x300 __do_softirq+0xc3/0x276 ? sort_range+0x20/0x20 run_ksoftirqd+0x1e/0x30 smpboot_thread_fn+0xa6/0x130 kthread+0xcd/0x100 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x31/0x50 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork_asm+0x11/0x20 \u003c/TASK\u003e The suggested fix is to introduce a new wrapper (skb_page_unref) that covers page refcounting for page_pool pages as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26953", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oTkz0SJHnY95W0zjomipFw==": { "id": "oTkz0SJHnY95W0zjomipFw==", "updater": "debian/updater", "name": "CVE-2025-39990", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_helper_proto kernel test robot reported verifier bug [1] where the helper func pointer could be NULL due to disabled config option. As Alexei suggested we could check on that in get_helper_proto directly. Marking tail_call helper func with BPF_PTR_POISON, because it is unused by design. [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39990", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oV54bC4E88mNdD0K7mJgPQ==": { "id": "oV54bC4E88mNdD0K7mJgPQ==", "updater": "debian/updater", "name": "CVE-2025-21870", "description": "In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Other, non DAI copier widgets could have the same stream name (sname) as the ALH copier and in that case the copier-\u003edata is NULL, no alh_data is attached, which could lead to NULL pointer dereference. We could check for this NULL pointer in sof_ipc4_prepare_copier_module() and avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai() will miscalculate the ALH device count, causing broken audio. The correct fix is to harden the matching logic by making sure that the 1. widget is a DAI widget - so dai = w-\u003eprivate is valid 2. the dai (and thus the copier) is ALH copier", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21870", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oXhrmejScbhntbL1S6AJTw==": { "id": "oXhrmejScbhntbL1S6AJTw==", "updater": "debian/updater", "name": "CVE-2024-35961", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Register devlink first under devlink lock In case device is having a non fatal FW error during probe, the driver will report the error to user via devlink. This will trigger a WARN_ON, since mlx5 is calling devlink_register() last. In order to avoid the WARN_ON[1], change mlx5 to invoke devl_register() first under devlink lock. [1] WARNING: CPU: 5 PID: 227 at net/devlink/health.c:483 devlink_recover_notify.constprop.0+0xb8/0xc0 CPU: 5 PID: 227 Comm: kworker/u16:3 Not tainted 6.4.0-rc5_for_upstream_min_debug_2023_06_12_12_38 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Workqueue: mlx5_health0000:08:00.0 mlx5_fw_reporter_err_work [mlx5_core] RIP: 0010:devlink_recover_notify.constprop.0+0xb8/0xc0 Call Trace: \u003cTASK\u003e ? __warn+0x79/0x120 ? devlink_recover_notify.constprop.0+0xb8/0xc0 ? report_bug+0x17c/0x190 ? handle_bug+0x3c/0x60 ? exc_invalid_op+0x14/0x70 ? asm_exc_invalid_op+0x16/0x20 ? devlink_recover_notify.constprop.0+0xb8/0xc0 devlink_health_report+0x4a/0x1c0 mlx5_fw_reporter_err_work+0xa4/0xd0 [mlx5_core] process_one_work+0x1bb/0x3c0 ? process_one_work+0x3c0/0x3c0 worker_thread+0x4d/0x3c0 ? process_one_work+0x3c0/0x3c0 kthread+0xc6/0xf0 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x1f/0x30 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35961", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oZ9JVmNUhJ/PNpWTcaxqQA==": { "id": "oZ9JVmNUhJ/PNpWTcaxqQA==", "updater": "debian/updater", "name": "CVE-2024-53147", "description": "In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei-\u003ehint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption. This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53147", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "obUBIS09Ii79M9cd8FFKpg==": { "id": "obUBIS09Ii79M9cd8FFKpg==", "updater": "debian/updater", "name": "CVE-2018-18064", "description": "cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-18064", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "cairo", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oe29ifZuovUIe0KY+GzIGA==": { "id": "oe29ifZuovUIe0KY+GzIGA==", "updater": "debian/updater", "name": "CVE-2026-53102", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() mt76_connac_mcu_alloc_sta_req() allocates an skb which is expected to be freed eventually by mt76_mcu_skb_send_msg(). However, currently if an intermediate function fails before sending, the allocated skb is leaked. Specifically, mt76_connac_mcu_sta_wed_update() and mt76_connac_mcu_sta_key_tlv() may fail, leading to an immediate memory leak in the error path. Fix this by explicitly freeing the skb in these error paths. Commit 7c0f63fe37a5 (\"wifi: mt76: mt7996: fix memory leak on mt7996_mcu_sta_key_tlv error\") made a similar change. Compile tested only. Issue found using a prototype static analysis tool and code review.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53102", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oiZ3IyYpSYlSJn1LdOeXCQ==": { "id": "oiZ3IyYpSYlSJn1LdOeXCQ==", "updater": "debian/updater", "name": "CVE-2026-68253", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/hdcp: check streams[] bounds before overflow The data-\u003estreams[] overflow check is done after the buffer overflow has already happened. Move the overflow check before the write. Side note, emitting a warning splat with a backtrace might be overkill here, but prefer not changing the behaviour other than not doing the overrun. Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68253", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "oldZxrZr+ML2Z5vdlIjivg==": { "id": "oldZxrZr+ML2Z5vdlIjivg==", "updater": "debian/updater", "name": "CVE-2025-38734", "description": "In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ 16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003 0 [ 16.447134] #PF: supervisor read access in kernel mod e [ 16.447516] #PF: error_code(0x0000) - not-present pag e [ 16.447878] PGD 0 P4D 0 [ 16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT I [ 16.448409] CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Tainted: G OE 6.13.0-rc3-g89e8a75fda73-dirty #4 2 [ 16.449124] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODUL E [ 16.449502] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/201 4 [ 16.450201] Workqueue: smc_hs_wq smc_listen_wor k [ 16.450531] RIP: 0010:smc_listen_work+0xc02/0x159 0 [ 16.452158] RSP: 0018:ffffb5ab40053d98 EFLAGS: 0001024 6 [ 16.452526] RAX: 0000000000000001 RBX: 0000000000000002 RCX: 000000000000030 0 [ 16.452994] RDX: 0000000000000280 RSI: 00003513840053f0 RDI: 000000000000000 0 [ 16.453492] RBP: ffffa097808e3800 R08: ffffa09782dba1e0 R09: 000000000000000 5 [ 16.453987] R10: 0000000000000000 R11: 0000000000000000 R12: ffffa0978274640 0 [ 16.454497] R13: 0000000000000000 R14: 0000000000000000 R15: ffffa09782d4092 0 [ 16.454996] FS: 0000000000000000(0000) GS:ffffa097bbc00000(0000) knlGS:000000000000000 0 [ 16.455557] CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003 3 [ 16.455961] CR2: 0000000000000030 CR3: 0000000102788004 CR4: 0000000000770ef 0 [ 16.456459] PKRU: 5555555 4 [ 16.456654] Call Trace : [ 16.456832] \u003cTASK \u003e [ 16.456989] ? __die+0x23/0x7 0 [ 16.457215] ? page_fault_oops+0x180/0x4c 0 [ 16.457508] ? __lock_acquire+0x3e6/0x249 0 [ 16.457801] ? exc_page_fault+0x68/0x20 0 [ 16.458080] ? asm_exc_page_fault+0x26/0x3 0 [ 16.458389] ? smc_listen_work+0xc02/0x159 0 [ 16.458689] ? smc_listen_work+0xc02/0x159 0 [ 16.458987] ? lock_is_held_type+0x8f/0x10 0 [ 16.459284] process_one_work+0x1ea/0x6d 0 [ 16.459570] worker_thread+0x1c3/0x38 0 [ 16.459839] ? __pfx_worker_thread+0x10/0x1 0 [ 16.460144] kthread+0xe0/0x11 0 [ 16.460372] ? __pfx_kthread+0x10/0x1 0 [ 16.460640] ret_from_fork+0x31/0x5 0 [ 16.460896] ? __pfx_kthread+0x10/0x1 0 [ 16.461166] ret_from_fork_asm+0x1a/0x3 0 [ 16.461453] \u003c/TASK \u003e [ 16.461616] Modules linked in: bpf_testmod(OE) [last unloaded: bpf_testmod(OE) ] [ 16.462134] CR2: 000000000000003 0 [ 16.462380] ---[ end trace 0000000000000000 ]--- [ 16.462710] RIP: 0010:smc_listen_work+0xc02/0x1590 The direct cause of this issue is that after smc_listen_out_connected(), newclcsock-\u003esk may be NULL since it will releases the smcsk. Therefore, if the application closes the socket immediately after accept, newclcsock-\u003esk can be NULL. A possible execution order could be as follows: smc_listen_work | userspace ----------------------------------------------------------------- lock_sock(sk) | smc_listen_out_connected() | | \\- smc_listen_out | | | \\- release_sock | | |- sk-\u003esk_data_ready() | | fd = accept(); | close(fd); | \\- socket-\u003esk = NULL; /* newclcsock-\u003esk is NULL now */ SMC_STAT_SERV_SUCC_INC(sock_net(newclcsock-\u003esk)) Since smc_listen_out_connected() will not fail, simply swapping the order of the code can easily fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38734", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "otDNMIC20yfGt48e132yeQ==": { "id": "otDNMIC20yfGt48e132yeQ==", "updater": "debian/updater", "name": "CVE-2026-68245", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() The vm pointer returned from amdgpu_vm_get_vm_from_pasid() is only valid while the lock is still being held. Once xa_unlock_irqrestore is called and returned, the pointer is no longer under lock and is subject to modification. Since, the caller still dereferences vm-\u003etask_info in amdgpu_vm_get_task_info_vm() after the lock is removed, this causes a use after unlock problem. Remove the lifetime issue present in amdgpu_vm_get_task_info_pasid() through removing the amdgpu_vm_get_vm_from_pasid() function from amdgpu_vm.c and making the relevant code inline to hold the lock while it is still in use. (cherry picked from commit 9d01579f3f868b333acc901815972685989092c7)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68245", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ozPRwqwtgPcs1i1CZrMe7A==": { "id": "ozPRwqwtgPcs1i1CZrMe7A==", "updater": "debian/updater", "name": "CVE-2025-71315", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vkms' vblank timer with the DRM implementation. The DRM code is identical in concept, but differs in implementation. Vblank timers are covered in vblank helpers and initializer macros, so remove the corresponding hrtimer in struct vkms_output. The vblank timer calls vkms' custom timeout code via handle_vblank_timeout in struct drm_crtc_helper_funcs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71315", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "p123ESKFXzhDZdIqbkw/aA==": { "id": "p123ESKFXzhDZdIqbkw/aA==", "updater": "debian/updater", "name": "CVE-2024-46776", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Run DC_LOG_DC after checking link-\u003elink_enc [WHAT] The DC_LOG_DC should be run after link-\u003elink_enc is checked, not before. This fixes 1 REVERSE_INULL issue reported by Coverity.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-46776", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "p18kTHw6vPdSaxQ1n59IXw==": { "id": "p18kTHw6vPdSaxQ1n59IXw==", "updater": "debian/updater", "name": "CVE-2023-53491", "description": "In the Linux kernel, the following vulnerability has been resolved: start_kernel: Add __no_stack_protector function attribute Back during the discussion of commit a9a3ed1eff36 (\"x86: Fix early boot crash on gcc-10, third try\") we discussed the need for a function attribute to control the omission of stack protectors on a per-function basis; at the time Clang had support for no_stack_protector but GCC did not. This was fixed in gcc-11. Now that the function attribute is available, let's start using it. Callers of boot_init_stack_canary need to use this function attribute unless they're compiled with -fno-stack-protector, otherwise the canary stored in the stack slot of the caller will differ upon the call to boot_init_stack_canary. This will lead to a call to __stack_chk_fail() then panic.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53491", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "p1l5BO+8RYtfzObLk3HHFw==": { "id": "p1l5BO+8RYtfzObLk3HHFw==", "updater": "debian/updater", "name": "CVE-2024-42317", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: avoid PMD-size page cache if needed xarray can't support arbitrary page cache size. the largest and supported page cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71 (\"mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\"). However, it's possible to have 512MB page cache in the huge memory's collapsing path on ARM64 system whose base page size is 64KB. 512MB page cache is breaking the limitation and a warning is raised when the xarray entry is split as shown in the following example. [root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize KernelPageSize: 64 kB [root@dhcp-10-26-1-207 ~]# cat /tmp/test.c : int main(int argc, char **argv) { \tconst char *filename = TEST_XFS_FILENAME; \tint fd = 0; \tvoid *buf = (void *)-1, *p; \tint pgsize = getpagesize(); \tint ret = 0; \tif (pgsize != 0x10000) { \t\tfprintf(stdout, \"System with 64KB base page size is required!\\n\"); \t\treturn -EPERM; \t} \tsystem(\"echo 0 \u003e /sys/devices/virtual/bdi/253:0/read_ahead_kb\"); \tsystem(\"echo 1 \u003e /proc/sys/vm/drop_caches\"); \t/* Open the xfs file */ \tfd = open(filename, O_RDONLY); \tassert(fd \u003e 0); \t/* Create VMA */ \tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0); \tassert(buf != (void *)-1); \tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf); \t/* Populate VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE); \tassert(ret == 0); \tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ); \tassert(ret == 0); \t/* Collapse VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE); \tassert(ret == 0); \tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE); \tif (ret) { \t\tfprintf(stdout, \"Error %d to madvise(MADV_COLLAPSE)\\n\", errno); \t\tgoto out; \t} \t/* Split xarray entry. Write permission is needed */ \tmunmap(buf, TEST_MEM_SIZE); \tbuf = (void *)-1; \tclose(fd); \tfd = open(filename, O_RDWR); \tassert(fd \u003e 0); \tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE, \t\t TEST_MEM_SIZE - pgsize, pgsize); out: \tif (buf != (void *)-1) \t\tmunmap(buf, TEST_MEM_SIZE); \tif (fd \u003e 0) \t\tclose(fd); \treturn ret; } [root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test [root@dhcp-10-26-1-207 ~]# /tmp/test ------------[ cut here ]------------ WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\ nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\ nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\ ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse \\ xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net \\ sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xas_split_alloc+0xf8/0x128 lr : split_huge_page_to_list_to_order+0x1c4/0x780 sp : ffff8000ac32f660 x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0 x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000 x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000 x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8 x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace: xas_split_alloc+0xf8/0x128 split_huge_page_to_list_to_order+0x1c4/0x780 truncate_inode_partial_folio+0xdc/0x160 truncate_inode_pages_range+0x1b4/0x4a8 truncate_pagecache_range+0x84/0xa ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-42317", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "p5Mb3xCHDkUNh497GrLMdg==": { "id": "p5Mb3xCHDkUNh497GrLMdg==", "updater": "debian/updater", "name": "CVE-2026-64345", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev-\u003ekref regardless of the return value. VFS does not call -\u003erelease() for a failed open, so every rejected second open permanently leaks one reference. Move kref_get() into the successful-open branch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64345", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pCu9cCtk/7SjSwDySmAYLQ==": { "id": "pCu9cCtk/7SjSwDySmAYLQ==", "updater": "debian/updater", "name": "CVE-2025-11082", "description": "A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-11082", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pDz4kM39PiixFNvpR9pL2A==": { "id": "pDz4kM39PiixFNvpR9pL2A==", "updater": "debian/updater", "name": "CVE-2023-31439", "description": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31439", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "systemd", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pF+1QuZrEHlKVc2WrF9eCw==": { "id": "pF+1QuZrEHlKVc2WrF9eCw==", "updater": "debian/updater", "name": "CVE-2026-63959", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63959", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pJdb037ioWy4GlzuA61kjg==": { "id": "pJdb037ioWy4GlzuA61kjg==", "updater": "debian/updater", "name": "CVE-2026-68111", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68111", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pLrSNgDWY1XE9frWN9/pEw==": { "id": "pLrSNgDWY1XE9frWN9/pEw==", "updater": "debian/updater", "name": "CVE-2025-68768", "description": "In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit() We have been seeing occasional deadlocks on pernet_ops_rwsem since September in NIPA. The stuck task was usually modprobe (often loading a driver like ipvlan), trying to take the lock as a Writer. lockdep does not track readers for rwsems so the read wasn't obvious from the reports. On closer inspection the Reader holding the lock was conntrack looping forever in nf_conntrack_cleanup_net_list(). Based on past experience with occasional NIPA crashes I looked thru the tests which run before the crash and noticed that the crash follows ip_defrag.sh. An immediate red flag. Scouring thru (de)fragmentation queues reveals skbs sitting around, holding conntrack references. The problem is that since conntrack depends on nf_defrag_ipv6, nf_defrag_ipv6 will load first. Since nf_defrag_ipv6 loads first its netns exit hooks run _after_ conntrack's netns exit hook. Flush all fragment queue SKBs during fqdir_pre_exit() to release conntrack references before conntrack cleanup runs. Also flush the queues in timer expiry handlers when they discover fqdir-\u003edead is set, in case packet sneaks in while we're running the pre_exit flush. The commit under Fixes is not exactly the culprit, but I think previously the timer firing would eventually unblock the spinning conntrack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68768", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pRHfMy/Z0maNYXFcPxZbzA==": { "id": "pRHfMy/Z0maNYXFcPxZbzA==", "updater": "debian/updater", "name": "CVE-2026-46068", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx The bounce buffers are allocated with __get_free_pages() using BOUNCE_BUFFER_ORDER (order 2 = 4 pages), but both the allocation error path and nx842_crypto_free_ctx() release the buffers with free_page(). Use free_pages() with the matching order instead.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46068", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pRxWGmPbo78YrmxmMFHfrg==": { "id": "pRxWGmPbo78YrmxmMFHfrg==", "updater": "debian/updater", "name": "CVE-2026-23191", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are performed outside the cable lock, this may result in UAF when a program attempts to trigger frequently while opening/closing the tied stream, as spotted by fuzzers. For addressing the UAF, this patch changes two things: - It covers the most of code in loopback_check_format() with cable-\u003elock spinlock, and add the proper NULL checks. This avoids already some racy accesses. - In addition, now we try to check the state of the capture PCM stream that may be stopped in this function, which was the major pain point leading to UAF.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23191", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pSsSOHDLn9d/KN98C0jKiA==": { "id": "pSsSOHDLn9d/KN98C0jKiA==", "updater": "debian/updater", "name": "CVE-2026-45382", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps-\u003ePicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45382", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pW3iP9p+y9BBPn5beM2Gdw==": { "id": "pW3iP9p+y9BBPn5beM2Gdw==", "updater": "debian/updater", "name": "CVE-2026-68254", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: require valid min/max vfreq for VRR Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit about it. At worst, a zero min_vfreq could lead to a division by zero in intel_vrr_compute_vmax(). Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68254", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pYy6TvaiCqEs+cKkx32ttQ==": { "id": "pYy6TvaiCqEs+cKkx32ttQ==", "updater": "debian/updater", "name": "CVE-2026-43249", "description": "In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a double-free. Guard the teardown path so only one caller can release the front-end state at a time, preventing the crash. This is a fix for the following double-free: [ 27.052347] Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI [ 27.052357] CPU: 0 UID: 0 PID: 32 Comm: xenwatch Not tainted 6.18.0-02087-g51ab33fc0a8b-dirty #60 PREEMPT(none) [ 27.052363] RIP: e030:xen_9pfs_front_free+0x1d/0x150 [ 27.052368] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 41 55 41 54 55 48 89 fd 48 c7 c7 48 d0 92 85 53 e8 cb cb 05 00 48 8b 45 08 48 8b 55 00 \u003c48\u003e 3b 28 0f 85 f9 28 35 fe 48 3b 6a 08 0f 85 ef 28 35 fe 48 89 42 [ 27.052377] RSP: e02b:ffffc9004016fdd0 EFLAGS: 00010246 [ 27.052381] RAX: 6b6b6b6b6b6b6b6b RBX: ffff88800d66e400 RCX: 0000000000000000 [ 27.052385] RDX: 6b6b6b6b6b6b6b6b RSI: 0000000000000000 RDI: 0000000000000000 [ 27.052389] RBP: ffff88800a887040 R08: 0000000000000000 R09: 0000000000000000 [ 27.052393] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888009e46b68 [ 27.052397] R13: 0000000000000200 R14: 0000000000000000 R15: ffff88800a887040 [ 27.052404] FS: 0000000000000000(0000) GS:ffff88808ca57000(0000) knlGS:0000000000000000 [ 27.052408] CS: e030 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 27.052412] CR2: 00007f9714004360 CR3: 0000000004834000 CR4: 0000000000050660 [ 27.052418] Call Trace: [ 27.052420] \u003cTASK\u003e [ 27.052422] xen_9pfs_front_changed+0x5d5/0x720 [ 27.052426] ? xenbus_otherend_changed+0x72/0x140 [ 27.052430] ? __pfx_xenwatch_thread+0x10/0x10 [ 27.052434] xenwatch_thread+0x94/0x1c0 [ 27.052438] ? __pfx_autoremove_wake_function+0x10/0x10 [ 27.052442] kthread+0xf8/0x240 [ 27.052445] ? __pfx_kthread+0x10/0x10 [ 27.052449] ? __pfx_kthread+0x10/0x10 [ 27.052452] ret_from_fork+0x16b/0x1a0 [ 27.052456] ? __pfx_kthread+0x10/0x10 [ 27.052459] ret_from_fork_asm+0x1a/0x30 [ 27.052463] \u003c/TASK\u003e [ 27.052465] Modules linked in: [ 27.052471] ---[ end trace 0000000000000000 ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43249", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "peqwgDyzcNXXHAaS+9OP/g==": { "id": "peqwgDyzcNXXHAaS+9OP/g==", "updater": "debian/updater", "name": "CVE-2026-43234", "description": "In the Linux kernel, the following vulnerability has been resolved: team: avoid NETDEV_CHANGEMTU event when unregistering slave syzbot is reporting unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 3 ref_tracker: netdev@ffff88807dcf8618 has 1/2 users at __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline] netdev_hold include/linux/netdevice.h:4429 [inline] inetdev_init+0x201/0x4e0 net/ipv4/devinet.c:286 inetdev_event+0x251/0x1610 net/ipv4/devinet.c:1600 notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85 call_netdevice_notifiers_mtu net/core/dev.c:2318 [inline] netif_set_mtu_ext+0x5aa/0x800 net/core/dev.c:9886 netif_set_mtu+0xd7/0x1b0 net/core/dev.c:9907 dev_set_mtu+0x126/0x260 net/core/dev_api.c:248 team_port_del+0xb07/0xcb0 drivers/net/team/team_core.c:1333 team_del_slave drivers/net/team/team_core.c:1936 [inline] team_device_event+0x207/0x5b0 drivers/net/team/team_core.c:2929 notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85 call_netdevice_notifiers_extack net/core/dev.c:2281 [inline] call_netdevice_notifiers net/core/dev.c:2295 [inline] __dev_change_net_namespace+0xcb7/0x2050 net/core/dev.c:12592 do_setlink+0x2ce/0x4590 net/core/rtnetlink.c:3060 rtnl_changelink net/core/rtnetlink.c:3776 [inline] __rtnl_newlink net/core/rtnetlink.c:3935 [inline] rtnl_newlink+0x15a9/0x1be0 net/core/rtnetlink.c:4072 rtnetlink_rcv_msg+0x7d5/0xbe0 net/core/rtnetlink.c:6958 netlink_rcv_skb+0x232/0x4b0 net/netlink/af_netlink.c:2550 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x80f/0x9b0 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1894 problem. Ido Schimmel found steps to reproduce ip link add name team1 type team ip link add name dummy1 mtu 1499 master team1 type dummy ip netns add ns1 ip link set dev dummy1 netns ns1 ip -n ns1 link del dev dummy1 and also found that the same issue was fixed in the bond driver in commit f51048c3e07b (\"bonding: avoid NETDEV_CHANGEMTU event when unregistering slave\"). Let's do similar thing for the team driver, with commit ad7c7b2172c3 (\"net: hold netdev instance lock during sysfs operations\") and commit 303a8487a657 (\"net: s/__dev_set_mtu/__netif_set_mtu/\") also applied.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43234", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pfY3zaK4i7i+hHz4F4Vyrw==": { "id": "pfY3zaK4i7i+hHz4F4Vyrw==", "updater": "debian/updater", "name": "CVE-2026-68213", "description": "In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. rtl2832_sdr_start_streaming() had multiple error paths that hit this trap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six `goto err` paths covering subdev s_power, tuner setup, ADC setup, stream-buffer allocation, urb allocation, and urb submission failures. None of them returned the queued buffers. The original function had no distinct success exit and fell straight through into the err label, which previously only did mutex_unlock and \"return ret\". Adding queued-buffer cleanup at err must therefore be paired with an explicit success return; otherwise every successful start would also drain the buffer queue and kill streaming. Add that success return, then add rtl2832_sdr_cleanup_queued_bufs() at the err label and before each early return. The cleanup helper takes a vb2_buffer_state argument so that the start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as expected by userspace on start_streaming failure) while stop_streaming keeps its existing VB2_BUF_STATE_ERROR semantics. This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\"). The err label still does not roll back power_ctrl(), frontend_ctrl(), the POWER_ON flag, or stream/URB allocations that may have happened before the failing step. Those are pre-existing leaks of a different class and are not addressed here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68213", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pgQbd2pSFJgZhzfneIdMCw==": { "id": "pgQbd2pSFJgZhzfneIdMCw==", "updater": "debian/updater", "name": "CVE-2026-64163", "description": "In the Linux kernel, the following vulnerability has been resolved: test_kprobes: clear kprobes between test runs Running the kprobes sanity tests twice makes all tests fail and eventually crashes the kernel. [root@martin-riscv-1 ~]# echo 1 \u003e /sys/kernel/debug/kunit/kprobes_test/run ... # Totals: pass:5 fail:0 skip:0 total:5 ok 1 kprobes_test [root@martin-riscv-1 ~]# echo 1 \u003e /sys/kernel/debug/kunit/kprobes_test/run ... # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64 Expected 0 == register_kprobe(\u0026kp), but register_kprobe(\u0026kp) == -22 (0xffffffffffffffea) ... Unable to handle kernel paging request ... The testsuite defines several kprobes and kretprobes as static variables that are preserved across test runs. After register_kprobe and unregister_kprobe, a kprobe contains some leftover data that must be cleared before the kprobe can be registered again. The tests are setting symbol_name to define the probe location. Address and flags must be cleared. The existing code clears some of the probes between subsequent tests, but not between two test runs. The leftover data from a previous test run makes the registrations fail in the next run. Move the cleanups for all kprobes into kprobes_test_init, this function is called before each single test (including the first test of a test run).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64163", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "phuKT06g85xsllUzJW4m6Q==": { "id": "phuKT06g85xsllUzJW4m6Q==", "updater": "debian/updater", "name": "CVE-2026-68137", "description": "In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh() x25_kill_by_neigh() walks the global X.25 socket list looking for sockets attached to a terminating neighbour. x25_list_lock protects list membership while the lookup is in progress, but it does not pin a socket's lifetime after the lock is dropped. The function currently drops x25_list_lock before calling lock_sock(s). A concurrent close can run x25_release(), remove the same socket from x25_list, and drop the last socket reference in that window. The neighbour teardown path can then lock or inspect a freed struct sock/struct x25_sock. Take sock_hold(s) while x25_list_lock still proves that the list entry is live, then drop the temporary reference after the socket has been locked, rechecked, and released. Recheck x25_sk(s)-\u003eneighbour after lock_sock(), because another path may have disconnected the socket before this path acquired the socket lock. Restart the list walk after each disconnect because the list lock was dropped and the previous iterator state may no longer be valid. A QEMU/KASAN run against origin/master reproduced a slab-use-after-free in x25_kill_by_neigh().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68137", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "phvXRGzqkL8KUB1+doHwOw==": { "id": "phvXRGzqkL8KUB1+doHwOw==", "updater": "debian/updater", "name": "CVE-2026-68366", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data: \treq-\u003elength = min_t(unsigned int, uvc-\u003eevent_length, data-\u003elength); \t... \tmemcpy(req-\u003ebuf, data-\u003edata, req-\u003elength); req-\u003elength is clamped to uvc-\u003eevent_length, which is taken from the host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to data-\u003elength, which comes from the UVCIOC_SEND_RESPONSE ioctl and is only checked for being negative. The source buffer data-\u003edata is only 60 bytes, so a response with uvc-\u003eevent_length and data-\u003elength both greater than 60 makes memcpy() read past the end of data-\u003edata. Clamp req-\u003elength to sizeof(data-\u003edata) as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68366", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "piBwOKVUN61Uds9fQx9yVw==": { "id": "piBwOKVUN61Uds9fQx9yVw==", "updater": "debian/updater", "name": "CVE-2024-49918", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer This commit addresses a potential null pointer dereference issue in the `dcn32_acquire_idle_pipe_for_head_pipe_in_layer` function. The issue could occur when `head_pipe` is null. The fix adds a check to ensure `head_pipe` is not null before asserting it. If `head_pipe` is null, the function returns NULL to prevent a potential null pointer dereference. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn32/dcn32_resource.c:2690 dcn32_acquire_idle_pipe_for_head_pipe_in_layer() error: we previously assumed 'head_pipe' could be null (see line 2681)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49918", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pkQ3rOcGRLKd/29TT/Sy+w==": { "id": "pkQ3rOcGRLKd/29TT/Sy+w==", "updater": "debian/updater", "name": "CVE-2016-2781", "description": "chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-2781", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pkajBH1lJD3cQ70fN6R9Zw==": { "id": "pkajBH1lJD3cQ70fN6R9Zw==", "updater": "debian/updater", "name": "CVE-2026-49271", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-49271", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pmrDabbkONJKfrgmMjw0zA==": { "id": "pmrDabbkONJKfrgmMjw0zA==", "updater": "debian/updater", "name": "CVE-2025-69649", "description": "GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-69649", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "pnTQqKhpugpRhNDFxnk5kA==": { "id": "pnTQqKhpugpRhNDFxnk5kA==", "updater": "debian/updater", "name": "CVE-2026-55654", "description": "A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-55654", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ppjL8ervQY+FRd+kdVgrBQ==": { "id": "ppjL8ervQY+FRd+kdVgrBQ==", "updater": "debian/updater", "name": "CVE-2023-31082", "description": "An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31082", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q0Qp3076rS1P2dSC+JQopw==": { "id": "q0Qp3076rS1P2dSC+JQopw==", "updater": "debian/updater", "name": "CVE-2023-54141", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Add missing hw_ops-\u003eget_ring_selector() for IPQ5018 During sending data after clients connected, hw_ops-\u003eget_ring_selector() will be called. But for IPQ5018, this member isn't set, and the following NULL pointer exception will be occurred: \t[ 38.840478] 8\u003c--- cut here --- \t[ 38.840517] Unable to handle kernel NULL pointer dereference at virtual address 00000000 \t... \t[ 38.923161] PC is at 0x0 \t[ 38.927930] LR is at ath11k_dp_tx+0x70/0x730 [ath11k] \t... \t[ 39.063264] Process hostapd (pid: 1034, stack limit = 0x801ceb3d) \t[ 39.068994] Stack: (0x856a9a68 to 0x856aa000) \t... \t[ 39.438467] [\u003c7f323804\u003e] (ath11k_dp_tx [ath11k]) from [\u003c7f314e6c\u003e] (ath11k_mac_op_tx+0x80/0x190 [ath11k]) \t[ 39.446607] [\u003c7f314e6c\u003e] (ath11k_mac_op_tx [ath11k]) from [\u003c7f17dbe0\u003e] (ieee80211_handle_wake_tx_queue+0x7c/0xc0 [mac80211]) \t[ 39.456162] [\u003c7f17dbe0\u003e] (ieee80211_handle_wake_tx_queue [mac80211]) from [\u003c7f174450\u003e] (ieee80211_probereq_get+0x584/0x704 [mac80211]) \t[ 39.467443] [\u003c7f174450\u003e] (ieee80211_probereq_get [mac80211]) from [\u003c7f178c40\u003e] (ieee80211_tx_prepare_skb+0x1f8/0x248 [mac80211]) \t[ 39.479334] [\u003c7f178c40\u003e] (ieee80211_tx_prepare_skb [mac80211]) from [\u003c7f179e28\u003e] (__ieee80211_subif_start_xmit+0x32c/0x3d4 [mac80211]) \t[ 39.491053] [\u003c7f179e28\u003e] (__ieee80211_subif_start_xmit [mac80211]) from [\u003c7f17af08\u003e] (ieee80211_tx_control_port+0x19c/0x288 [mac80211]) \t[ 39.502946] [\u003c7f17af08\u003e] (ieee80211_tx_control_port [mac80211]) from [\u003c7f0fc704\u003e] (nl80211_tx_control_port+0x174/0x1d4 [cfg80211]) \t[ 39.515017] [\u003c7f0fc704\u003e] (nl80211_tx_control_port [cfg80211]) from [\u003c808ceac4\u003e] (genl_rcv_msg+0x154/0x340) \t[ 39.526814] [\u003c808ceac4\u003e] (genl_rcv_msg) from [\u003c808cdb74\u003e] (netlink_rcv_skb+0xb8/0x11c) \t[ 39.536446] [\u003c808cdb74\u003e] (netlink_rcv_skb) from [\u003c808ce1d0\u003e] (genl_rcv+0x28/0x34) \t[ 39.544344] [\u003c808ce1d0\u003e] (genl_rcv) from [\u003c808cd234\u003e] (netlink_unicast+0x174/0x274) \t[ 39.551895] [\u003c808cd234\u003e] (netlink_unicast) from [\u003c808cd510\u003e] (netlink_sendmsg+0x1dc/0x440) \t[ 39.559362] [\u003c808cd510\u003e] (netlink_sendmsg) from [\u003c808596e0\u003e] (____sys_sendmsg+0x1a8/0x1fc) \t[ 39.567697] [\u003c808596e0\u003e] (____sys_sendmsg) from [\u003c8085b1a8\u003e] (___sys_sendmsg+0xa4/0xdc) \t[ 39.575941] [\u003c8085b1a8\u003e] (___sys_sendmsg) from [\u003c8085b310\u003e] (sys_sendmsg+0x44/0x74) \t[ 39.583841] [\u003c8085b310\u003e] (sys_sendmsg) from [\u003c80300060\u003e] (ret_fast_syscall+0x0/0x40) \t... \t[ 39.620734] Code: bad PC value \t[ 39.625869] ---[ end trace 8aef983ad3cbc032 ]---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54141", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q165hps53MwmYpTpddoHwg==": { "id": "q165hps53MwmYpTpddoHwg==", "updater": "debian/updater", "name": "CVE-2022-41848", "description": "drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-41848", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q2brSwh5JjiYiRkGkO5mQQ==": { "id": "q2brSwh5JjiYiRkGkO5mQQ==", "updater": "debian/updater", "name": "CVE-2026-59999", "description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-59999", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q59b7LDKqMfkg6R/H6td8w==": { "id": "q59b7LDKqMfkg6R/H6td8w==", "updater": "debian/updater", "name": "CVE-2026-68413", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() The memory allocated in the ipw2100_alloc_device() function is not freed in some of the error paths in ipw2100_pci_init_one(). Fix that by converting the direct return into a goto to the error path return. The error path when pci_enable_device() fails cannot jump to fail, since at this point priv is not set, so perform error handling inline.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68413", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q5t1nltLUU7gVpZnWUIzNQ==": { "id": "q5t1nltLUU7gVpZnWUIzNQ==", "updater": "debian/updater", "name": "CVE-2026-14671", "description": "Type confusion in PostgreSQL module \"refint\" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject \"refint: Remove plan cache.\", without a CVE number. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14671", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q729w5sFLS4RIFtNLkblZw==": { "id": "q729w5sFLS4RIFtNLkblZw==", "updater": "debian/updater", "name": "CVE-2024-57982", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: state: fix out-of-bounds read during lookup lookup and resize can run in parallel. The xfrm_state_hash_generation seqlock ensures a retry, but the hash functions can observe a hmask value that is too large for the new hlist array. rehash does: rcu_assign_pointer(net-\u003exfrm.state_bydst, ndst) [..] net-\u003exfrm.state_hmask = nhashmask; While state lookup does: h = xfrm_dst_hash(net, daddr, saddr, tmpl-\u003ereqid, encap_family); hlist_for_each_entry_rcu(x, net-\u003exfrm.state_bydst + h, bydst) { This is only safe in case the update to state_bydst is larger than net-\u003exfrm.xfrm_state_hmask (or if the lookup function gets serialized via state spinlock again). Fix this by prefetching state_hmask and the associated pointers. The xfrm_state_hash_generation seqlock retry will ensure that the pointer and the hmask will be consistent. The existing helpers, like xfrm_dst_hash(), are now unsafe for RCU side, add lockdep assertions to document that they are only safe for insert side. xfrm_state_lookup_byaddr() uses the spinlock rather than RCU. AFAICS this is an oversight from back when state lookup was converted to RCU, this lock should be replaced with RCU in a future patch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-57982", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q7Ys7sKsyGWeVZYZlY8toA==": { "id": "q7Ys7sKsyGWeVZYZlY8toA==", "updater": "debian/updater", "name": "CVE-2026-68212", "description": "In the Linux kernel, the following vulnerability has been resolved: media: saa7134: Fix a possible memory leak in saa7134_video_init1 In saa7134_video_init1(), the return value of the first saa7134_pgtable_alloc() is not checked. If it fails, the function continues as if successful, leaving the driver with an invalid page table. Additionally, if vb2_queue_init() for the VBI queue fails after the video queue page table has been allocated, the allocated memory is not freed before returning. The second saa7134_pgtable_alloc() also lacks a return value check. Errors occur during device probing before the device is fully registered, the normal cleanup path in saa7134_finidev() is not executed, leading to memory leaks and potential use of uninitialized DMA resources. Check the return value of both saa7134_pgtable_alloc() calls and propagate errors. On failure of any later step, free allocated page tables to avoid memory leaks. Ensure control handlers are also released on error to prevent further resource leakage. Found by code review.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68212", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "q9xVEb6BV7jC4BJzDpa49Q==": { "id": "q9xVEb6BV7jC4BJzDpa49Q==", "updater": "debian/updater", "name": "CVE-2026-64584", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The f_midi driver embeds a work item (midi-\u003ework) whose handler, f_midi_in_work(), dereferences the enclosing struct f_midi through container_of(). This work is armed from two sites: f_midi_complete(), on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA rawmidi output-stream start. Neither f_midi_disable() nor f_midi_unbind() cancels midi-\u003ework. f_midi_disable() only disables the endpoints and drains the in_req_fifo; it does not synchronize the work item, and the sound card is released asynchronously to the final free of the midi object. The midi object is reference-counted (midi-\u003efree_ref) and is freed in f_midi_free() only once both the usb_function reference and the rawmidi private_data reference have been dropped. In f_midi_unbind(), f_midi_disable() runs before the sound card is released, so while the USB endpoints are already disabled the rawmidi device is still usable by an open substream. A concurrent userspace write on such a substream can reach f_midi_in_trigger() and queue midi-\u003ework again after f_midi_disable() has returned. A work item armed this way may still be pending when the last reference drops and f_midi_free() proceeds to kfree(midi), letting f_midi_in_work() dereference the struct after it has been freed, a use-after-free. For this reason cancelling midi-\u003ework in f_midi_disable() would not be sufficient: the ALSA trigger path can rearm the work after disable() returns. Cancelling at the refcount-zero free site is the boundary after which neither arming source can survive, because by then both references that keep the midi object alive have been dropped: the USB endpoints are already disabled and the rawmidi device has been released. Fix this by calling cancel_work_sync(\u0026midi-\u003ework) in the refcount-zero block of f_midi_free(), before the embedded work_struct is freed along with the rest of the structure. opts-\u003elock is a sleeping mutex, so calling cancel_work_sync() under it is permitted, and the handler takes midi-\u003etransmit_lock rather than opts-\u003elock, so no self-deadlock can occur while it waits for a running instance of the work to finish. This issue was found by an in-house static analysis tool.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64584", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qC8C6X96cimg3e6OBu2gcA==": { "id": "qC8C6X96cimg3e6OBu2gcA==", "updater": "debian/updater", "name": "CVE-2025-37833", "description": "In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads Fix niu_try_msix() to not cause a fatal trap on sparc systems. Set PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to work around a bug in the hardware or firmware. For each vector entry in the msix table, niu chips will cause a fatal trap if any registers in that entry are read before that entries' ENTRY_DATA register is written to. Testing indicates writes to other registers are not sufficient to prevent the fatal trap, however the value does not appear to matter. This only needs to happen once after power up, so simply rebooting into a kernel lacking this fix will NOT cause the trap. NON-RESUMABLE ERROR: Reporting on cpu 64 NON-RESUMABLE ERROR: TPC [0x00000000005f6900] \u003cmsix_prepare_msi_desc+0x90/0xa0\u003e NON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff NON-RESUMABLE ERROR: 0000000800000000:0000000000000000:0000000000000000:0000000000000000] NON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff] NON-RESUMABLE ERROR: type [precise nonresumable] NON-RESUMABLE ERROR: attrs [0x02000080] \u003c ASI sp-faulted priv \u003e NON-RESUMABLE ERROR: raddr [0xffffffffffffffff] NON-RESUMABLE ERROR: insn effective address [0x000000c50020000c] NON-RESUMABLE ERROR: size [0x8] NON-RESUMABLE ERROR: asi [0x00] CPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63 Workqueue: events work_for_cpu_fn TSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000 Not tainted TPC: \u003cmsix_prepare_msi_desc+0x90/0xa0\u003e g0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100 g4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000 o0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620 o4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128 RPC: \u003c__pci_enable_msix_range+0x3cc/0x460\u003e l0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020 l4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734 i0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d i4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0 I7: \u003cniu_try_msix.constprop.0+0xc0/0x130 [niu]\u003e Call Trace: [\u003c00000000101888b0\u003e] niu_try_msix.constprop.0+0xc0/0x130 [niu] [\u003c000000001018f840\u003e] niu_get_invariants+0x183c/0x207c [niu] [\u003c00000000101902fc\u003e] niu_pci_init_one+0x27c/0x2fc [niu] [\u003c00000000005ef3e4\u003e] local_pci_probe+0x28/0x74 [\u003c0000000000469240\u003e] work_for_cpu_fn+0x8/0x1c [\u003c000000000046b008\u003e] process_scheduled_works+0x144/0x210 [\u003c000000000046b518\u003e] worker_thread+0x13c/0x1c0 [\u003c00000000004710e0\u003e] kthread+0xb8/0xc8 [\u003c00000000004060c8\u003e] ret_from_fork+0x1c/0x2c [\u003c0000000000000000\u003e] 0x0 Kernel panic - not syncing: Non-resumable error.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37833", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qCasP65HH5s19aqlIVeNSg==": { "id": "qCasP65HH5s19aqlIVeNSg==", "updater": "debian/updater", "name": "CVE-2024-56712", "description": "In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix memory leak on last export_udmabuf() error path In export_udmabuf(), if dma_buf_fd() fails because the FD table is full, a dma_buf owning the udmabuf has already been created; but the error handling in udmabuf_create() will tear down the udmabuf without doing anything about the containing dma_buf. This leaves a dma_buf in memory that contains a dangling pointer; though that doesn't seem to lead to anything bad except a memory leak. Fix it by moving the dma_buf_fd() call out of export_udmabuf() so that we can give it different error handling. Note that the shape of this code changed a lot in commit 5e72b2b41a21 (\"udmabuf: convert udmabuf driver to use folios\"); but the memory leak seems to have existed since the introduction of udmabuf.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56712", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qGTI3SeJ9soW0DAFnYUtXQ==": { "id": "qGTI3SeJ9soW0DAFnYUtXQ==", "updater": "debian/updater", "name": "CVE-2026-23327", "description": "In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() cxl_payload_from_user_allowed() casts and dereferences the input payload without first verifying its size. When a raw mailbox command is sent with an undersized payload (ie: 1 byte for CXL_MBOX_OP_CLEAR_LOG, which expects a 16-byte UUID), uuid_equal() reads past the allocated buffer, triggering a KASAN splat: BUG: KASAN: slab-out-of-bounds in memcmp+0x176/0x1d0 lib/string.c:683 Read of size 8 at addr ffff88810130f5c0 by task syz.1.62/2258 CPU: 2 UID: 0 PID: 2258 Comm: syz.1.62 Not tainted 6.19.0-dirty #3 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 Call Trace: \u003cTASK\u003e __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0xab/0xe0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xce/0x650 mm/kasan/report.c:482 kasan_report+0xce/0x100 mm/kasan/report.c:595 memcmp+0x176/0x1d0 lib/string.c:683 uuid_equal include/linux/uuid.h:73 [inline] cxl_payload_from_user_allowed drivers/cxl/core/mbox.c:345 [inline] cxl_mbox_cmd_ctor drivers/cxl/core/mbox.c:368 [inline] cxl_validate_cmd_from_user drivers/cxl/core/mbox.c:522 [inline] cxl_send_cmd+0x9c0/0xb50 drivers/cxl/core/mbox.c:643 __cxl_memdev_ioctl drivers/cxl/core/memdev.c:698 [inline] cxl_memdev_ioctl+0x14f/0x190 drivers/cxl/core/memdev.c:713 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa8/0x330 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fdaf331ba79 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fdaf1d77038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fdaf3585fa0 RCX: 00007fdaf331ba79 RDX: 00002000000001c0 RSI: 00000000c030ce02 RDI: 0000000000000003 RBP: 00007fdaf33749df R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fdaf3586038 R14: 00007fdaf3585fa0 R15: 00007ffced2af768 \u003c/TASK\u003e Add 'in_size' parameter to cxl_payload_from_user_allowed() and validate the payload is large enough.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23327", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qIDjOygbC4T2PrpwyxD9SQ==": { "id": "qIDjOygbC4T2PrpwyxD9SQ==", "updater": "debian/updater", "name": "CVE-2026-68231", "description": "In the Linux kernel, the following vulnerability has been resolved: media: airspy: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. airspy_start_streaming() returned -ENODEV early when the USB device had been disconnected (s-\u003eudev == NULL) without returning any buffers that buf_queue() had already accepted. Take v4l2_lock first and jump to the existing err_clear_bit label, which already drains s-\u003equeued_bufs via vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking. This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68231", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qIiZiZIZc0OPiHfnmGiEzg==": { "id": "qIiZiZIZc0OPiHfnmGiEzg==", "updater": "debian/updater", "name": "CVE-2023-39328", "description": "A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-39328", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qNFgRdQ/8x4TTxwJoCtMag==": { "id": "qNFgRdQ/8x4TTxwJoCtMag==", "updater": "debian/updater", "name": "CVE-2025-38014", "description": "In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Refactor remove call with idxd_cleanup() helper The idxd_cleanup() helper cleans up perfmon, interrupts, internals and so on. Refactor remove call with the idxd_cleanup() helper to avoid code duplication. Note, this also fixes the missing put_device() for idxd groups, enginces and wqs.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38014", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qOgf95x8MknvgeyA1bCtbw==": { "id": "qOgf95x8MknvgeyA1bCtbw==", "updater": "debian/updater", "name": "CVE-2024-26841", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Update cpu_sibling_map when disabling nonboot CPUs Update cpu_sibling_map when disabling nonboot CPUs by defining \u0026 calling clear_cpu_sibling_map(), otherwise we get such errors on SMT systems: jump label: negative count! WARNING: CPU: 6 PID: 45 at kernel/jump_label.c:263 __static_key_slow_dec_cpuslocked+0xec/0x100 CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340 pc 90000000004c302c ra 90000000004c302c tp 90000001005bc000 sp 90000001005bfd20 a0 000000000000001b a1 900000000224c278 a2 90000001005bfb58 a3 900000000224c280 a4 900000000224c278 a5 90000001005bfb50 a6 0000000000000001 a7 0000000000000001 t0 ce87a4763eb5234a t1 ce87a4763eb5234a t2 0000000000000000 t3 0000000000000000 t4 0000000000000006 t5 0000000000000000 t6 0000000000000064 t7 0000000000001964 t8 000000000009ebf6 u0 9000000001f2a068 s9 0000000000000000 s0 900000000246a2d8 s1 ffffffffffffffff s2 ffffffffffffffff s3 90000000021518c0 s4 0000000000000040 s5 9000000002151058 s6 9000000009828e40 s7 00000000000000b4 s8 0000000000000006 ra: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100 ERA: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100 CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) PRMD: 00000004 (PPLV0 +PIE -PWE) EUEN: 00000000 (-FPE -SXE -ASXE -BTE) ECFG: 00071c1c (LIE=2-4,10-12 VS=7) ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0) PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV) CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340 Stack : 0000000000000000 900000000203f258 900000000179afc8 90000001005bc000 90000001005bf980 0000000000000000 90000001005bf988 9000000001fe0be0 900000000224c280 900000000224c278 90000001005bf8c0 0000000000000001 0000000000000001 ce87a4763eb5234a 0000000007f38000 90000001003f8cc0 0000000000000000 0000000000000006 0000000000000000 4c206e6f73676e6f 6f4c203a656d616e 000000000009ec99 0000000007f38000 0000000000000000 900000000214b000 9000000001fe0be0 0000000000000004 0000000000000000 0000000000000107 0000000000000009 ffffffffffafdabe 00000000000000b4 0000000000000006 90000000004c302c 9000000000224528 00005555939a0c7c 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c ... Call Trace: [\u003c9000000000224528\u003e] show_stack+0x48/0x1a0 [\u003c900000000179afc8\u003e] dump_stack_lvl+0x78/0xa0 [\u003c9000000000263ed0\u003e] __warn+0x90/0x1a0 [\u003c90000000017419b8\u003e] report_bug+0x1b8/0x280 [\u003c900000000179c564\u003e] do_bp+0x264/0x420 [\u003c90000000004c302c\u003e] __static_key_slow_dec_cpuslocked+0xec/0x100 [\u003c90000000002b4d7c\u003e] sched_cpu_deactivate+0x2fc/0x300 [\u003c9000000000266498\u003e] cpuhp_invoke_callback+0x178/0x8a0 [\u003c9000000000267f70\u003e] cpuhp_thread_fun+0xf0/0x240 [\u003c90000000002a117c\u003e] smpboot_thread_fn+0x1dc/0x2e0 [\u003c900000000029a720\u003e] kthread+0x140/0x160 [\u003c9000000000222288\u003e] ret_from_kernel_thread+0xc/0xa4", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26841", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qSRAlDv61oW53IYnp9gUPQ==": { "id": "qSRAlDv61oW53IYnp9gUPQ==", "updater": "debian/updater", "name": "CVE-2026-12912", "description": "A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-12912", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qZ4oRvYnjzMbQXQ9RlFiKg==": { "id": "qZ4oRvYnjzMbQXQ9RlFiKg==", "updater": "debian/updater", "name": "CVE-2026-47714", "description": "libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a `width x height` bitmap. Version 1.22.0 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-47714", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qZUQGxSS2yVcoy0lLq8mQw==": { "id": "qZUQGxSS2yVcoy0lLq8mQw==", "updater": "debian/updater", "name": "CVE-2026-53053", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the original device's devid Currently clone_alias() assumes first argument (pdev) is always the original device pointer. This function is called by pci_for_each_dma_alias() which based on topology decides to send original or alias device details in first argument. This meant that the source devid used to look up and copy the DTE may be incorrect, leading to wrong or stale DTE entries being propagated to alias device. Fix this by passing the original pdev as the opaque data argument to both the direct clone_alias() call and pci_for_each_dma_alias(). Inside clone_alias(), retrieve the original device from data and compute devid from it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53053", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qcrNMjbV5cWUgmRekrRwzw==": { "id": "qcrNMjbV5cWUgmRekrRwzw==", "updater": "debian/updater", "name": "CVE-2026-68115", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68115", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qdg9ZGiyg59EqydNTlb8dQ==": { "id": "qdg9ZGiyg59EqydNTlb8dQ==", "updater": "debian/updater", "name": "CVE-2024-35794", "description": "In the Linux kernel, the following vulnerability has been resolved: dm-raid: really frozen sync_thread during suspend 1) commit f52f5c71f3d4 (\"md: fix stopping sync thread\") remove MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that dm-raid relies on __md_stop_writes() to frozen sync_thread indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in md_stop_writes(), and since stop_sync_thread() is only used for dm-raid in this case, also move stop_sync_thread() to md_stop_writes(). 2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen, it only prevent new sync_thread to start, and it can't stop the running sync thread; In order to frozen sync_thread, after seting the flag, stop_sync_thread() should be used. 3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use it as condition for md_stop_writes() in raid_postsuspend() doesn't look correct. Consider that reentrant stop_sync_thread() do nothing, always call md_stop_writes() in raid_postsuspend(). 4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime, and if MD_RECOVERY_FROZEN is cleared while the array is suspended, new sync_thread can start unexpected. Fix this by disallow raid_message() to change sync_thread status during suspend. Note that after commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), the test shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(), and with previous fixes, the test won't hang there anymore, however, the test will still fail and complain that ext4 is corrupted. And with this patch, the test won't hang due to stop_sync_thread() or fail due to ext4 is corrupted anymore. However, there is still a deadlock related to dm-raid456 that will be fixed in following patches.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35794", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qeBuLmsk7oK4Le8+TUU3sg==": { "id": "qeBuLmsk7oK4Le8+TUU3sg==", "updater": "debian/updater", "name": "CVE-2023-52629", "description": "In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free bug can occur. The details are shown below: (cpu 0) | (cpu 1) switch_drv_remove() | flush_work() | ... | switch_timer // timer | schedule_work(\u0026psw-\u003ework) timer_shutdown_sync() | ... | switch_work_handler // worker kfree(psw) // free | | psw-\u003estate = 0 // use This patch puts timer_shutdown_sync() before flush_work() to mitigate the bugs. As a result, the worker and timer will be stopped safely before the deallocate operations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52629", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qhkvx4CfybVWilBosysd5g==": { "id": "qhkvx4CfybVWilBosysd5g==", "updater": "debian/updater", "name": "CVE-2024-56588", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Create all dump files during debugfs initialization For the current debugfs of hisi_sas, after user triggers dump, the driver allocate memory space to save the register information and create debugfs files to display the saved information. In this process, the debugfs files created after each dump. Therefore, when the dump is triggered while the driver is unbind, the following hang occurs: [67840.853907] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0 [67840.862947] Mem abort info: [67840.865855] ESR = 0x0000000096000004 [67840.869713] EC = 0x25: DABT (current EL), IL = 32 bits [67840.875125] SET = 0, FnV = 0 [67840.878291] EA = 0, S1PTW = 0 [67840.881545] FSC = 0x04: level 0 translation fault [67840.886528] Data abort info: [67840.889524] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [67840.895117] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [67840.900284] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [67840.905709] user pgtable: 4k pages, 48-bit VAs, pgdp=0000002803a1f000 [67840.912263] [00000000000000a0] pgd=0000000000000000, p4d=0000000000000000 [67840.919177] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [67840.996435] pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [67841.003628] pc : down_write+0x30/0x98 [67841.007546] lr : start_creating.part.0+0x60/0x198 [67841.012495] sp : ffff8000b979ba20 [67841.016046] x29: ffff8000b979ba20 x28: 0000000000000010 x27: 0000000000024b40 [67841.023412] x26: 0000000000000012 x25: ffff20202b355ae8 x24: ffff20202b35a8c8 [67841.030779] x23: ffffa36877928208 x22: ffffa368b4972240 x21: ffff8000b979bb18 [67841.038147] x20: ffff00281dc1e3c0 x19: fffffffffffffffe x18: 0000000000000020 [67841.045515] x17: 0000000000000000 x16: ffffa368b128a530 x15: ffffffffffffffff [67841.052888] x14: ffff8000b979bc18 x13: ffffffffffffffff x12: ffff8000b979bb18 [67841.060263] x11: 0000000000000000 x10: 0000000000000000 x9 : ffffa368b1289b18 [67841.067640] x8 : 0000000000000012 x7 : 0000000000000000 x6 : 00000000000003a9 [67841.075014] x5 : 0000000000000000 x4 : ffff002818c5cb00 x3 : 0000000000000001 [67841.082388] x2 : 0000000000000000 x1 : ffff002818c5cb00 x0 : 00000000000000a0 [67841.089759] Call trace: [67841.092456] down_write+0x30/0x98 [67841.096017] start_creating.part.0+0x60/0x198 [67841.100613] debugfs_create_dir+0x48/0x1f8 [67841.104950] debugfs_create_files_v3_hw+0x88/0x348 [hisi_sas_v3_hw] [67841.111447] debugfs_snapshot_regs_v3_hw+0x708/0x798 [hisi_sas_v3_hw] [67841.118111] debugfs_trigger_dump_v3_hw_write+0x9c/0x120 [hisi_sas_v3_hw] [67841.125115] full_proxy_write+0x68/0xc8 [67841.129175] vfs_write+0xd8/0x3f0 [67841.132708] ksys_write+0x70/0x108 [67841.136317] __arm64_sys_write+0x24/0x38 [67841.140440] invoke_syscall+0x50/0x128 [67841.144385] el0_svc_common.constprop.0+0xc8/0xf0 [67841.149273] do_el0_svc+0x24/0x38 [67841.152773] el0_svc+0x38/0xd8 [67841.156009] el0t_64_sync_handler+0xc0/0xc8 [67841.160361] el0t_64_sync+0x1a4/0x1a8 [67841.164189] Code: b9000882 d2800002 d2800023 f9800011 (c85ffc05) [67841.170443] ---[ end trace 0000000000000000 ]--- To fix this issue, create all directories and files during debugfs initialization. In this way, the driver only needs to allocate memory space to save information each time the user triggers dumping.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56588", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qlE/u8JaqdWPOKprjuHfPw==": { "id": "qlE/u8JaqdWPOKprjuHfPw==", "updater": "debian/updater", "name": "CVE-2025-39989", "description": "In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-from-user context Patch series \"mm/hwpoison: Fix regressions in memory failure handling\", v4. ## 1. What am I trying to do: This patchset resolves two critical regressions related to memory failure handling that have appeared in the upstream kernel since version 5.17, as compared to 5.10 LTS. - copyin case: poison found in user page while kernel copying from user space - instr case: poison found while instruction fetching in user space ## 2. What is the expected outcome and why - For copyin case: Kernel can recover from poison found where kernel is doing get_user() or copy_from_user() if those places get an error return and the kernel return -EFAULT to the process instead of crashing. More specifily, MCE handler checks the fixup handler type to decide whether an in kernel #MC can be recovered. When EX_TYPE_UACCESS is found, the PC jumps to recovery code specified in _ASM_EXTABLE_FAULT() and return a -EFAULT to user space. - For instr case: If a poison found while instruction fetching in user space, full recovery is possible. User process takes #PF, Linux allocates a new page and fills by reading from storage. ## 3. What actually happens and why - For copyin case: kernel panic since v5.17 Commit 4c132d1d844a (\"x86/futex: Remove .fixup usage\") introduced a new extable fixup type, EX_TYPE_EFAULT_REG, and later patches updated the extable fixup type for copy-from-user operations, changing it from EX_TYPE_UACCESS to EX_TYPE_EFAULT_REG. It breaks previous EX_TYPE_UACCESS handling when posion found in get_user() or copy_from_user(). - For instr case: user process is killed by a SIGBUS signal due to #CMCI and #MCE race When an uncorrected memory error is consumed there is a race between the CMCI from the memory controller reporting an uncorrected error with a UCNA signature, and the core reporting and SRAR signature machine check when the data is about to be consumed. ### Background: why *UN*corrected errors tied to *C*MCI in Intel platform [1] Prior to Icelake memory controllers reported patrol scrub events that detected a previously unseen uncorrected error in memory by signaling a broadcast machine check with an SRAO (Software Recoverable Action Optional) signature in the machine check bank. This was overkill because it's not an urgent problem that no core is on the verge of consuming that bad data. It's also found that multi SRAO UCE may cause nested MCE interrupts and finally become an IERR. Hence, Intel downgrades the machine check bank signature of patrol scrub from SRAO to UCNA (Uncorrected, No Action required), and signal changed to #CMCI. Just to add to the confusion, Linux does take an action (in uc_decode_notifier()) to try to offline the page despite the UC*NA* signature name. ### Background: why #CMCI and #MCE race when poison is consuming in Intel platform [1] Having decided that CMCI/UCNA is the best action for patrol scrub errors, the memory controller uses it for reads too. But the memory controller is executing asynchronously from the core, and can't tell the difference between a \"real\" read and a speculative read. So it will do CMCI/UCNA if an error is found in any read. Thus: 1) Core is clever and thinks address A is needed soon, issues a speculative read. 2) Core finds it is going to use address A soon after sending the read request 3) The CMCI from the memory controller is in a race with MCE from the core that will soon try to retire the load from address A. Quite often (because speculation has got better) the CMCI from the memory controller is delivered before the core is committed to the instruction reading address A, so the interrupt is taken, and Linux offlines the page (marking it as poison). ## Why user process is killed for instr case Commit 046545a661af (\"mm/hwpoison: fix error page recovered but reported \"not ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39989", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qoXDqpTdCFxrBlCQ121ojw==": { "id": "qoXDqpTdCFxrBlCQ121ojw==", "updater": "debian/updater", "name": "CVE-2026-45949", "description": "In the Linux kernel, the following vulnerability has been resolved: hwrng: core - use RCU and work_struct to fix race condition Currently, hwrng_fill is not cleared until the hwrng_fillfn() thread exits. Since hwrng_unregister() reads hwrng_fill outside the rng_mutex lock, a concurrent hwrng_unregister() may call kthread_stop() again on the same task. Additionally, if hwrng_unregister() is called immediately after hwrng_register(), the stopped thread may have never been executed. Thus, hwrng_fill remains dirty even after hwrng_unregister() returns. In this case, subsequent calls to hwrng_register() will fail to start new threads, and hwrng_unregister() will call kthread_stop() on the same freed task. In both cases, a use-after-free occurs: refcount_t: addition on 0; use-after-free. WARNING: ... at lib/refcount.c:25 refcount_warn_saturate+0xec/0x1c0 Call Trace: kthread_stop+0x181/0x360 hwrng_unregister+0x288/0x380 virtrng_remove+0xe3/0x200 This patch fixes the race by protecting the global hwrng_fill pointer inside the rng_mutex lock, so that hwrng_fillfn() thread is stopped only once, and calls to kthread_run() and kthread_stop() are serialized with the lock held. To avoid deadlock in hwrng_fillfn() while being stopped with the lock held, we convert current_rng to RCU, so that get_current_rng() can read current_rng without holding the lock. To remove the lock from put_rng(), we also delay the actual cleanup into a work_struct. Since get_current_rng() no longer returns ERR_PTR values, the IS_ERR() checks are removed from its callers. With hwrng_fill protected by the rng_mutex lock, hwrng_fillfn() can no longer clear hwrng_fill itself. Therefore, if hwrng_fillfn() returns directly after current_rng is dropped, kthread_stop() would be called on a freed task_struct later. To fix this, hwrng_fillfn() calls schedule() now to keep the task alive until being stopped. The kthread_stop() call is also moved from hwrng_unregister() to drop_current_rng(), ensuring kthread_stop() is called on all possible paths where current_rng becomes NULL, so that the thread would not wait forever.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45949", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qouND1u2rALvXGEiCSfpAw==": { "id": "qouND1u2rALvXGEiCSfpAw==", "updater": "debian/updater", "name": "CVE-2026-68404", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: use wiphy work for socket owner autodisconnect nl80211_netlink_notify() walks the cfg80211 wireless device list when a NETLINK_GENERIC socket is released. If the socket owns a connection, the notifier queues the embedded wdev-\u003edisconnect_wk work item. That work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a NETLINK_URELEASE notifier that already observed conn_owner_nlportid can queue it after that cancel returns. _cfg80211_unregister_wdev() then removes the wdev from the list and waits for RCU readers, but synchronize_net() does not drain work queued by such a reader. Make the autodisconnect work a wiphy_work instead. The callback already needs the wiphy mutex, and wiphy_work runs under that mutex. This lets teardown cancel pending autodisconnect work while holding the mutex, without a cancel_work_sync() vs. worker locking concern. Also cancel the wiphy work after list_del_rcu() and synchronize_net(). Any NETLINK_URELEASE notifier that had already reached the wdev list has then either queued the work and it is removed, or can no longer find the wdev.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68404", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qp6jn4NMCUe5oKGofLit/Q==": { "id": "qp6jn4NMCUe5oKGofLit/Q==", "updater": "debian/updater", "name": "CVE-2025-68322", "description": "In the Linux kernel, the following vulnerability has been resolved: parisc: Avoid crash due to unaligned access in unwinder Guenter Roeck reported this kernel crash on his emulated B160L machine: Starting network: udhcpc: started, v1.36.1 Backtrace: [\u003c104320d4\u003e] unwind_once+0x1c/0x5c [\u003c10434a00\u003e] walk_stackframe.isra.0+0x74/0xb8 [\u003c10434a6c\u003e] arch_stack_walk+0x28/0x38 [\u003c104e5efc\u003e] stack_trace_save+0x48/0x5c [\u003c105d1bdc\u003e] set_track_prepare+0x44/0x6c [\u003c105d9c80\u003e] ___slab_alloc+0xfc4/0x1024 [\u003c105d9d38\u003e] __slab_alloc.isra.0+0x58/0x90 [\u003c105dc80c\u003e] kmem_cache_alloc_noprof+0x2ac/0x4a0 [\u003c105b8e54\u003e] __anon_vma_prepare+0x60/0x280 [\u003c105a823c\u003e] __vmf_anon_prepare+0x68/0x94 [\u003c105a8b34\u003e] do_wp_page+0x8cc/0xf10 [\u003c105aad88\u003e] handle_mm_fault+0x6c0/0xf08 [\u003c10425568\u003e] do_page_fault+0x110/0x440 [\u003c10427938\u003e] handle_interruption+0x184/0x748 [\u003c11178398\u003e] schedule+0x4c/0x190 BUG: spinlock recursion on CPU#0, ifconfig/2420 lock: terminate_lock.2+0x0/0x1c, .magic: dead4ead, .owner: ifconfig/2420, .owner_cpu: 0 While creating the stack trace, the unwinder uses the stack pointer to guess the previous frame to read the previous stack pointer from memory. The crash happens, because the unwinder tries to read from unaligned memory and as such triggers the unalignment trap handler which then leads to the spinlock recursion and finally to a deadlock. Fix it by checking the alignment before accessing the memory.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68322", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qptj7gMK3lgQhRAzWzItJA==": { "id": "qptj7gMK3lgQhRAzWzItJA==", "updater": "debian/updater", "name": "CVE-2026-68203", "description": "In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix cleanup bugs in vivid_init() When platform_device_register() fails in vivid_init(), the embedded struct device in vivid_pdev has already been initialized by device_initialize(), but the failure path jumps to free_output_strings without dropping the device reference for the current platform device: vivid_init() -\u003e platform_device_register(\u0026vivid_pdev) -\u003e device_initialize(\u0026vivid_pdev.dev) -\u003e setup_pdev_dma_masks(\u0026vivid_pdev) -\u003e platform_device_add(\u0026vivid_pdev) This leads to a reference leak when platform_device_register() fails. Fix this by calling platform_device_put() before jumping to the common cleanup path. Also, the unreg_driver label incorrectly calls platform_driver_register() instead of platform_driver_unregister(), which breaks cleanup when workqueue creation fails after successful driver registration. Fix that as well. The reference leak was identified by a static analysis tool I developed and confirmed by manual review. The incorrect cleanup call was found during code inspection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68203", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qrvZPwEn248D72+1ztchmg==": { "id": "qrvZPwEn248D72+1ztchmg==", "updater": "debian/updater", "name": "CVE-2025-39859", "description": "In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog The ptp_ocp_detach() only shuts down the watchdog timer if it is pending. However, if the timer handler is already running, the timer_delete_sync() is not called. This leads to race conditions where the devlink that contains the ptp_ocp is deallocated while the timer handler is still accessing it, resulting in use-after-free bugs. The following details one of the race scenarios. (thread 1) | (thread 2) ptp_ocp_remove() | ptp_ocp_detach() | ptp_ocp_watchdog() if (timer_pending(\u0026bp-\u003ewatchdog))| bp = timer_container_of() timer_delete_sync() | | devlink_free(devlink) //free | | bp-\u003e //use Resolve this by unconditionally calling timer_delete_sync() to ensure the timer is reliably deactivated, preventing any access after free.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39859", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qsIPXyVZhxfTQ3/efdLNnw==": { "id": "qsIPXyVZhxfTQ3/efdLNnw==", "updater": "debian/updater", "name": "CVE-2024-56775", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix handling of plane refcount [Why] The mechanism to backup and restore plane states doesn't maintain refcount, which can cause issues if the refcount of the plane changes in between backup and restore operations, such as memory leaks if the refcount was supposed to go down, or double frees / invalid memory accesses if the refcount was supposed to go up. [How] Cache and re-apply current refcount when restoring plane states.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56775", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "qvI2ZykDyIyLk6Ymml/kug==": { "id": "qvI2ZykDyIyLk6Ymml/kug==", "updater": "debian/updater", "name": "CVE-2026-43215", "description": "In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization. There were still a couple of uses of cifs_tcp_ses_lock to provide tcon fields. In this patch, I've replaced them with tc_lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43215", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "r+SLRw6fkGB8sWuKipdpsg==": { "id": "r+SLRw6fkGB8sWuKipdpsg==", "updater": "debian/updater", "name": "CVE-2025-38029", "description": "In the Linux kernel, the following vulnerability has been resolved: kasan: avoid sleepable page allocation from atomic context apply_to_pte_range() enters the lazy MMU mode and then invokes kasan_populate_vmalloc_pte() callback on each page table walk iteration. However, the callback can go into sleep when trying to allocate a single page, e.g. if an architecutre disables preemption on lazy MMU mode enter. On s390 if make arch_enter_lazy_mmu_mode() -\u003e preempt_enable() and arch_leave_lazy_mmu_mode() -\u003e preempt_disable(), such crash occurs: [ 0.663336] BUG: sleeping function called from invalid context at ./include/linux/sched/mm.h:321 [ 0.663348] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd [ 0.663358] preempt_count: 1, expected: 0 [ 0.663366] RCU nest depth: 0, expected: 0 [ 0.663375] no locks held by kthreadd/2. [ 0.663383] Preemption disabled at: [ 0.663386] [\u003c0002f3284cbb4eda\u003e] apply_to_pte_range+0xfa/0x4a0 [ 0.663405] CPU: 0 UID: 0 PID: 2 Comm: kthreadd Not tainted 6.15.0-rc5-gcc-kasan-00043-gd76bb1ebb558-dirty #162 PREEMPT [ 0.663408] Hardware name: IBM 3931 A01 701 (KVM/Linux) [ 0.663409] Call Trace: [ 0.663410] [\u003c0002f3284c385f58\u003e] dump_stack_lvl+0xe8/0x140 [ 0.663413] [\u003c0002f3284c507b9e\u003e] __might_resched+0x66e/0x700 [ 0.663415] [\u003c0002f3284cc4f6c0\u003e] __alloc_frozen_pages_noprof+0x370/0x4b0 [ 0.663419] [\u003c0002f3284ccc73c0\u003e] alloc_pages_mpol+0x1a0/0x4a0 [ 0.663421] [\u003c0002f3284ccc8518\u003e] alloc_frozen_pages_noprof+0x88/0xc0 [ 0.663424] [\u003c0002f3284ccc8572\u003e] alloc_pages_noprof+0x22/0x120 [ 0.663427] [\u003c0002f3284cc341ac\u003e] get_free_pages_noprof+0x2c/0xc0 [ 0.663429] [\u003c0002f3284cceba70\u003e] kasan_populate_vmalloc_pte+0x50/0x120 [ 0.663433] [\u003c0002f3284cbb4ef8\u003e] apply_to_pte_range+0x118/0x4a0 [ 0.663435] [\u003c0002f3284cbc7c14\u003e] apply_to_pmd_range+0x194/0x3e0 [ 0.663437] [\u003c0002f3284cbc99be\u003e] __apply_to_page_range+0x2fe/0x7a0 [ 0.663440] [\u003c0002f3284cbc9e88\u003e] apply_to_page_range+0x28/0x40 [ 0.663442] [\u003c0002f3284ccebf12\u003e] kasan_populate_vmalloc+0x82/0xa0 [ 0.663445] [\u003c0002f3284cc1578c\u003e] alloc_vmap_area+0x34c/0xc10 [ 0.663448] [\u003c0002f3284cc1c2a6\u003e] __get_vm_area_node+0x186/0x2a0 [ 0.663451] [\u003c0002f3284cc1e696\u003e] __vmalloc_node_range_noprof+0x116/0x310 [ 0.663454] [\u003c0002f3284cc1d950\u003e] __vmalloc_node_noprof+0xd0/0x110 [ 0.663457] [\u003c0002f3284c454b88\u003e] alloc_thread_stack_node+0xf8/0x330 [ 0.663460] [\u003c0002f3284c458d56\u003e] dup_task_struct+0x66/0x4d0 [ 0.663463] [\u003c0002f3284c45be90\u003e] copy_process+0x280/0x4b90 [ 0.663465] [\u003c0002f3284c460940\u003e] kernel_clone+0xd0/0x4b0 [ 0.663467] [\u003c0002f3284c46115e\u003e] kernel_thread+0xbe/0xe0 [ 0.663469] [\u003c0002f3284c4e440e\u003e] kthreadd+0x50e/0x7f0 [ 0.663472] [\u003c0002f3284c38c04a\u003e] __ret_from_fork+0x8a/0xf0 [ 0.663475] [\u003c0002f3284ed57ff2\u003e] ret_from_fork+0xa/0x38 Instead of allocating single pages per-PTE, bulk-allocate the shadow memory prior to applying kasan_populate_vmalloc_pte() callback on a page range.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38029", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "r2VcHWjtXh+g8+PJJuOhrA==": { "id": "r2VcHWjtXh+g8+PJJuOhrA==", "updater": "debian/updater", "name": "CVE-2026-63858", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase. The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list. It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place. Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency. This patch also adapts the event notification path to deal with the list of hook transactions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63858", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "r3qyJwq8y/vEn0Jk2v+zxA==": { "id": "r3qyJwq8y/vEn0Jk2v+zxA==", "updater": "debian/updater", "name": "CVE-2026-23035", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv mlx5e_priv is an unstable structure that can be memset(0) if profile attaching fails. Pass netdev to mlx5e_destroy_netdev() to guarantee it will work on a valid netdev. On mlx5e_remove: Check validity of priv-\u003eprofile, before attempting to cleanup any resources that might be not there. This fixes a kernel oops in mlx5e_remove when switchdev mode fails due to change profile failure. $ devlink dev eswitch set pci/0000:00:03.0 mode switchdev Error: mlx5_core: Failed setting eswitch to offloads. dmesg: workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12 $ devlink dev reload pci/0000:00:03.0 ==\u003e oops BUG: kernel NULL pointer dereference, address: 0000000000000370 PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 15 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc5+ #115 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_dcbnl_dscp_app+0x23/0x100 RSP: 0018:ffffc9000083f8b8 EFLAGS: 00010286 RAX: ffff8881126fc380 RBX: ffff8881015ac400 RCX: ffffffff826ffc45 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8881035109c0 RBP: ffff8881035109c0 R08: ffff888101e3e838 R09: ffff888100264e10 R10: ffffc9000083f898 R11: ffffc9000083f8a0 R12: ffff888101b921a0 R13: ffff888101b921a0 R14: ffff8881015ac9a0 R15: ffff8881015ac400 FS: 00007f789a3c8740(0000) GS:ffff88856aa59000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000370 CR3: 000000010b6c0001 CR4: 0000000000370ef0 Call Trace: \u003cTASK\u003e mlx5e_remove+0x57/0x110 device_release_driver_internal+0x19c/0x200 bus_remove_device+0xc6/0x130 device_del+0x160/0x3d0 ? devl_param_driverinit_value_get+0x2d/0x90 mlx5_detach_device+0x89/0xe0 mlx5_unload_one_devl_locked+0x3a/0x70 mlx5_devlink_reload_down+0xc8/0x220 devlink_reload+0x7d/0x260 devlink_nl_reload_doit+0x45b/0x5a0 genl_family_rcv_msg_doit+0xe8/0x140", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23035", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "r9Y7IJFSuqjglNKfnw8dOw==": { "id": "r9Y7IJFSuqjglNKfnw8dOw==", "updater": "debian/updater", "name": "CVE-2026-64270", "description": "In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer \tstruct mms114_touch touch[MMS114_MAX_TOUCH]; which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes, i.e. 80 bytes. The length of the I2C read into it is taken verbatim from the device: \tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE); \tif (packet_size \u003c= 0) \t\tgoto out; \t... \terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size, \t\t\t(u8 *)touch); packet_size is a single device register byte (0x0F) and the only check is the lower bound packet_size \u003c= 0; it is never bounded against the size of touch[]. A malfunctioning, malicious or counterfeit controller (or an attacker tampering with the I2C bus) can report a packet_size of up to 255, so __mms114_read_reg() writes up to 175 bytes past the end of touch[] on the IRQ-thread stack: a stack out-of-bounds write that can overwrite the stack canary, saved registers and the return address. A well-formed device never reports more than the buffer holds, so reject an oversized packet and drop the report, consistent with the handler's other error paths, rather than reading past the buffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64270", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rFRffA21og/EgJw72V6jLA==": { "id": "rFRffA21og/EgJw72V6jLA==", "updater": "debian/updater", "name": "CVE-2026-56391", "description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56391", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "coreutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rHluYIV74XqfYpOxMHO9Uw==": { "id": "rHluYIV74XqfYpOxMHO9Uw==", "updater": "debian/updater", "name": "CVE-2023-1972", "description": "A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-1972", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rHnR4lOiqYPnpv8M7+IdMw==": { "id": "rHnR4lOiqYPnpv8M7+IdMw==", "updater": "debian/updater", "name": "CVE-2026-64513", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Unconditionally recompute CR8 intercept on PPR update The TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits when the guest's virtual TPR falls under the specified threshold, allowing KVM to inject previously masked interrupts. KVM handles these VM exits in handle_tpr_below_threshold(). Commit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\") optimized this function by calling apic_update_ppr() instead of raising KVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is a pending, deliverable interrupt. However, if there are no new interrupts pending, apic_update_ppr() does not issue the request. Thus, kvm_lapic_update_cr8_intercept() and vmx_update_cr8_intercept() are not called before VM entry, which results in a high, stale TPR_THRESHOLD. This is problematic due to the following sentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM: The following check is performed if the “use TPR shadow” VM-execution control is 1 and the “virtualize APIC accesses” and “virtual-interrupt delivery” VM-execution controls are both 0: the value of bits 3:0 of the TPR threshold VM-execution control field should not be greater than the value of bits 7:4 of VTPR. This error condition is typically not observed when KVM runs on a bare metal system because modern processors support APICv, which enables virtual-interrupt delivery, and which KVM uses when possible. This causes the processor to no longer generate TPR-below-threshold exits and to no longer check TPR_THRESHOLD on entry. However, when running on older platforms, or under nested virtualization on a hypervisor that does not support virtual-interrupt delivery and enforces this check (like Hyper-V) this can cause a VM entry failure with hardware error 0x7, as seen in [1]. Call kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not find a deliverable interrupt (and thus does not raise KVM_REQ_EVENT). Remove calls to kvm_lapic_update_cr8_intercept() on paths that end up in apic_update_ppr(), as they now become redundant. This ensures that any path that updates the guest's PPR also figures out if KVM needs to wait for a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64513", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rL29zskMDhs3jgGi/4V5FA==": { "id": "rL29zskMDhs3jgGi/4V5FA==", "updater": "debian/updater", "name": "CVE-2026-64017", "description": "In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use. Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the driver. This potentially increases a timing window from when a driver wants to freeze its queue to when requests stop being dispatched. That scenario is off the fast path though, and drivers need to appropriately handle requests during a freeze request anyway. The downside is the popped element needs to be individually freed when we performed a bio plug merge. The cached request would have had to be freed later anyway, but this patch does it inline with building the plug list instead of after flushing it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64017", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rM72QABgmf9nL4krapkMSQ==": { "id": "rM72QABgmf9nL4krapkMSQ==", "updater": "debian/updater", "name": "CVE-2025-1377", "description": "A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1377", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rMaA49qwWtSHUzACuwQ1kA==": { "id": "rMaA49qwWtSHUzACuwQ1kA==", "updater": "debian/updater", "name": "CVE-2023-37454", "description": "An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-37454", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rNGDQoozIwLRuTmXHEeY2Q==": { "id": "rNGDQoozIwLRuTmXHEeY2Q==", "updater": "debian/updater", "name": "CVE-2023-3640", "description": "A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-3640", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rSBpBaKVbA5Z4ROUchoGXQ==": { "id": "rSBpBaKVbA5Z4ROUchoGXQ==", "updater": "debian/updater", "name": "CVE-2026-64280", "description": "In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length \u003e\u003e PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64280", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rTJO875dJzTFghGq8UborQ==": { "id": "rTJO875dJzTFghGq8UborQ==", "updater": "debian/updater", "name": "CVE-2025-40354", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix link-\u003eenc NULL pointer access [why] 1.) dc-\u003elinks[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14. 2.) hw_init() access null LINK_ENC for dpia non display_endpoint. (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40354", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rUOuprNv0asp6iYybUFpQA==": { "id": "rUOuprNv0asp6iYybUFpQA==", "updater": "debian/updater", "name": "CVE-2025-39829", "description": "In the Linux kernel, the following vulnerability has been resolved: trace/fgraph: Fix the warning caused by missing unregister notifier This warning was triggered during testing on v6.16: notifier callback ftrace_suspend_notifier_call already registered WARNING: CPU: 2 PID: 86 at kernel/notifier.c:23 notifier_chain_register+0x44/0xb0 ... Call Trace: \u003cTASK\u003e blocking_notifier_chain_register+0x34/0x60 register_ftrace_graph+0x330/0x410 ftrace_profile_write+0x1e9/0x340 vfs_write+0xf8/0x420 ? filp_flush+0x8a/0xa0 ? filp_close+0x1f/0x30 ? do_dup2+0xaf/0x160 ksys_write+0x65/0xe0 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x77/0x7f When writing to the function_profile_enabled interface, the notifier was not unregistered after start_graph_tracing failed, causing a warning the next time function_profile_enabled was written. Fixed by adding unregister_pm_notifier in the exception path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39829", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ralGcrzRAawbxw3toTbgRg==": { "id": "ralGcrzRAawbxw3toTbgRg==", "updater": "debian/updater", "name": "CVE-2025-22125", "description": "In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: don't ignore IO flags If blk-wbt is enabled by default, it's found that raid write performance is quite bad because all IO are throttled by wbt of underlying disks, due to flag REQ_IDLE is ignored. And turns out this behaviour exist since blk-wbt is introduced. Other than REQ_IDLE, other flags should not be ignored as well, for example REQ_META can be set for filesystems, clearing it can cause priority reverse problems; And REQ_NOWAIT should not be cleared as well, because io will wait instead of failing directly in underlying disks. Fix those problems by keep IO flags from master bio. Fises: f51d46d0e7cb (\"md: add support for REQ_NOWAIT\")", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22125", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rcC8CUmqvvy1e5QKJQrBpQ==": { "id": "rcC8CUmqvvy1e5QKJQrBpQ==", "updater": "debian/updater", "name": "CVE-2026-58471", "description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58471", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "wget", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rcPmofVCF5dEf1IjBTTQNQ==": { "id": "rcPmofVCF5dEf1IjBTTQNQ==", "updater": "debian/updater", "name": "CVE-2024-53091", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx As the introduction of the support for vsock and unix sockets in sockmap, tls_sw_has_ctx_tx/rx cannot presume the socket passed in must be IS_ICSK. vsock and af_unix sockets have vsock_sock and unix_sock instead of inet_connection_sock. For these sockets, tls_get_ctx may return an invalid pointer and cause page fault in function tls_sw_ctx_rx. BUG: unable to handle page fault for address: 0000000000040030 Workqueue: vsock-loopback vsock_loopback_work RIP: 0010:sk_psock_strp_data_ready+0x23/0x60 Call Trace: ? __die+0x81/0xc3 ? no_context+0x194/0x350 ? do_page_fault+0x30/0x110 ? async_page_fault+0x3e/0x50 ? sk_psock_strp_data_ready+0x23/0x60 virtio_transport_recv_pkt+0x750/0x800 ? update_load_avg+0x7e/0x620 vsock_loopback_work+0xd0/0x100 process_one_work+0x1a7/0x360 worker_thread+0x30/0x390 ? create_worker+0x1a0/0x1a0 kthread+0x112/0x130 ? __kthread_cancel_work+0x40/0x40 ret_from_fork+0x1f/0x40 v2: - Add IS_ICSK check v3: - Update the commits in Fixes", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53091", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rcUVP72WvBiriS5Y9xSVbA==": { "id": "rcUVP72WvBiriS5Y9xSVbA==", "updater": "debian/updater", "name": "TEMP-0841856-B18BAF", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0841856-B18BAF", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "bash", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rhicS1iAdJ7haynjMu68Lg==": { "id": "rhicS1iAdJ7haynjMu68Lg==", "updater": "debian/updater", "name": "CVE-2018-20673", "description": "The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-20673", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rhxXhWGHnmTccUSB2MF4JQ==": { "id": "rhxXhWGHnmTccUSB2MF4JQ==", "updater": "debian/updater", "name": "CVE-2023-52591", "description": "In the Linux kernel, the following vulnerability has been resolved: reiserfs: Avoid touching renamed directory if parent does not change The VFS will not be locking moved directory if its parent does not change. Change reiserfs rename code to avoid touching renamed directory if its parent does not change as without locking that can corrupt the filesystem.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-52591", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rlIMrSvggt9T2HDIr/N5mg==": { "id": "rlIMrSvggt9T2HDIr/N5mg==", "updater": "debian/updater", "name": "CVE-2016-10505", "description": "NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-10505", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rmKVfK3mgjlQEhH+iHOflg==": { "id": "rmKVfK3mgjlQEhH+iHOflg==", "updater": "debian/updater", "name": "CVE-2026-14679", "description": "Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-14679", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "roEJ3sSQTvxB/BsqtXwWkw==": { "id": "roEJ3sSQTvxB/BsqtXwWkw==", "updater": "debian/updater", "name": "CVE-2024-44951", "description": "In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix TX fifo corruption Sometimes, when a packet is received on channel A at almost the same time as a packet is about to be transmitted on channel B, we observe with a logic analyzer that the received packet on channel A is transmitted on channel B. In other words, the Tx buffer data on channel B is corrupted with data from channel A. The problem appeared since commit 4409df5866b7 (\"serial: sc16is7xx: change EFR lock to operate on each channels\"), which changed the EFR locking to operate on each channel instead of chip-wise. This commit has introduced a regression, because the EFR lock is used not only to protect the EFR registers access, but also, in a very obscure and undocumented way, to protect access to the data buffer, which is shared by the Tx and Rx handlers, but also by each channel of the IC. Fix this regression first by switching to kfifo_out_linear_ptr() in sc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer. Secondly, replace the chip-wise Rx buffer with a separate Rx buffer for each channel.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-44951", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rx8eYzjaW03hO1/BTWCgAA==": { "id": "rx8eYzjaW03hO1/BTWCgAA==", "updater": "debian/updater", "name": "TEMP-0517018-A83CE6", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0517018-A83CE6", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "sysvinit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "rzG+4p1w8Fds+h+0wYwvNg==": { "id": "rzG+4p1w8Fds+h+0wYwvNg==", "updater": "debian/updater", "name": "CVE-2026-68351", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar-\u003ereadbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar-\u003ereadlen, this copies more data than the readbuf was allocated for. Bound the memcpy to min(len - 4, ar-\u003ereadlen) so that the response is still completed -- avoiding repeated restarts from queued garbage -- while preventing an overread past the response buffer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68351", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s/hCdnJizrGpuAbegsTfiQ==": { "id": "s/hCdnJizrGpuAbegsTfiQ==", "updater": "debian/updater", "name": "CVE-2010-5321", "description": "Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761. NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2010-5321", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s/nXcJapIEZ1tDG3K4jPBg==": { "id": "s/nXcJapIEZ1tDG3K4jPBg==", "updater": "debian/updater", "name": "CVE-2026-68236", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: set new_stream to NULL after release In dm_update_crtc_state(), the skip_modeset path releases new_stream via dc_stream_release() but does not set the pointer to NULL. If a later error (e.g., color management failure) triggers the fail label, the error path calls dc_stream_release() again on the same dangling pointer, causing a double release and potential use-after-free. Fix this by setting new_stream to NULL after the initial release. (cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68236", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s37w7PtUSGpx+BxSM/IyNA==": { "id": "s37w7PtUSGpx+BxSM/IyNA==", "updater": "debian/updater", "name": "TEMP-1142904-117334", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-1142904-117334", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "unzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "s54OavJMmxE6M5mPO5T0Pw==": { "id": "s54OavJMmxE6M5mPO5T0Pw==", "updater": "debian/updater", "name": "CVE-2025-39779", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: subpage: keep TOWRITE tag until folio is cleaned btrfs_subpage_set_writeback() calls folio_start_writeback() the first time a folio is written back, and it also clears the PAGECACHE_TAG_TOWRITE tag even if there are still dirty blocks in the folio. This can break ordering guarantees, such as those required by btrfs_wait_ordered_extents(). That ordering breakage leads to a real failure. For example, running generic/464 on a zoned setup will hit the following ASSERT. This happens because the broken ordering fails to flush existing dirty pages before the file size is truncated. assertion failed: !list_empty(\u0026ordered-\u003elist) :: 0, in fs/btrfs/zoned.c:1899 ------------[ cut here ]------------ kernel BUG at fs/btrfs/zoned.c:1899! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 2 UID: 0 PID: 1906169 Comm: kworker/u130:2 Kdump: loaded Not tainted 6.16.0-rc6-BTRFS-ZNS+ #554 PREEMPT(voluntary) Hardware name: Supermicro Super Server/H12SSL-NT, BIOS 2.0 02/22/2021 Workqueue: btrfs-endio-write btrfs_work_helper [btrfs] RIP: 0010:btrfs_finish_ordered_zoned.cold+0x50/0x52 [btrfs] RSP: 0018:ffffc9002efdbd60 EFLAGS: 00010246 RAX: 000000000000004c RBX: ffff88811923c4e0 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffffff827e38b1 RDI: 00000000ffffffff RBP: ffff88810005d000 R08: 00000000ffffdfff R09: ffffffff831051c8 R10: ffffffff83055220 R11: 0000000000000000 R12: ffff8881c2458c00 R13: ffff88811923c540 R14: ffff88811923c5e8 R15: ffff8881c1bd9680 FS: 0000000000000000(0000) GS:ffff88a04acd0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f907c7a918c CR3: 0000000004024000 CR4: 0000000000350ef0 Call Trace: \u003cTASK\u003e ? srso_return_thunk+0x5/0x5f btrfs_finish_ordered_io+0x4a/0x60 [btrfs] btrfs_work_helper+0xf9/0x490 [btrfs] process_one_work+0x204/0x590 ? srso_return_thunk+0x5/0x5f worker_thread+0x1d6/0x3d0 ? __pfx_worker_thread+0x10/0x10 kthread+0x118/0x230 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x205/0x260 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 \u003c/TASK\u003e Consider process A calling writepages() with WB_SYNC_NONE. In zoned mode or for compressed writes, it locks several folios for delalloc and starts writing them out. Let's call the last locked folio folio X. Suppose the write range only partially covers folio X, leaving some pages dirty. Process A calls btrfs_subpage_set_writeback() when building a bio. This function call clears the TOWRITE tag of folio X, whose size = 8K and the block size = 4K. It is following state. 0 4K 8K |/////|/////| (flag: DIRTY, tag: DIRTY) \u003c-----\u003e Process A will write this range. Now suppose process B concurrently calls writepages() with WB_SYNC_ALL. It calls tag_pages_for_writeback() to tag dirty folios with PAGECACHE_TAG_TOWRITE. Since folio X is still dirty, it gets tagged. Then, B collects tagged folios using filemap_get_folios_tag() and must wait for folio X to be written before returning from writepages(). 0 4K 8K |/////|/////| (flag: DIRTY, tag: DIRTY|TOWRITE) However, between tagging and collecting, process A may call btrfs_subpage_set_writeback() and clear folio X's TOWRITE tag. 0 4K 8K | |/////| (flag: DIRTY|WRITEBACK, tag: DIRTY) As a result, process B won't see folio X in its batch, and returns without waiting for it. This breaks the WB_SYNC_ALL ordering requirement. Fix this by using btrfs_subpage_set_writeback_keepwrite(), which retains the TOWRITE tag. We now manually clear the tag only after the folio becomes clean, via the xas operation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39779", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sCWehNOZChMBKr1vk+63og==": { "id": "sCWehNOZChMBKr1vk+63og==", "updater": "debian/updater", "name": "CVE-2025-40064", "description": "In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in __pnet_find_base_ndev(). syzbot reported use-after-free of net_device in __pnet_find_base_ndev(), which was called during connect(). [0] smc_pnet_find_ism_resource() fetches sk_dst_get(sk)-\u003edev and passes down to pnet_find_base_ndev(), where RTNL is held. Then, UAF happened at __pnet_find_base_ndev() when the dev is first used. This means dev had already been freed before acquiring RTNL in pnet_find_base_ndev(). While dev is going away, dst-\u003edev could be swapped with blackhole_netdev, and the dev's refcnt by dst will be released. We must hold dev's refcnt before calling smc_pnet_find_ism_resource(). Also, smc_pnet_find_roce_resource() has the same problem. Let's use __sk_dst_get() and dst_dev_rcu() in the two functions. [0]: BUG: KASAN: use-after-free in __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926 Read of size 1 at addr ffff888036bac33a by task syz.0.3632/18609 CPU: 1 UID: 0 PID: 18609 Comm: syz.0.3632 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595 __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926 pnet_find_base_ndev net/smc/smc_pnet.c:946 [inline] smc_pnet_find_ism_by_pnetid net/smc/smc_pnet.c:1103 [inline] smc_pnet_find_ism_resource+0xef/0x390 net/smc/smc_pnet.c:1154 smc_find_ism_device net/smc/af_smc.c:1030 [inline] smc_find_proposal_devices net/smc/af_smc.c:1115 [inline] __smc_connect+0x372/0x1890 net/smc/af_smc.c:1545 smc_connect+0x877/0xd90 net/smc/af_smc.c:1715 __sys_connect_file net/socket.c:2086 [inline] __sys_connect+0x313/0x440 net/socket.c:2105 __do_sys_connect net/socket.c:2111 [inline] __se_sys_connect net/socket.c:2108 [inline] __x64_sys_connect+0x7a/0x90 net/socket.c:2108 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f47cbf8eba9 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f47ccdb1038 EFLAGS: 00000246 ORIG_RAX: 000000000000002a RAX: ffffffffffffffda RBX: 00007f47cc1d5fa0 RCX: 00007f47cbf8eba9 RDX: 0000000000000010 RSI: 0000200000000280 RDI: 000000000000000b RBP: 00007f47cc011e19 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f47cc1d6038 R14: 00007f47cc1d5fa0 R15: 00007ffc512f8aa8 \u003c/TASK\u003e The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888036bacd00 pfn:0x36bac flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff) raw: 00fff00000000000 ffffea0001243d08 ffff8880b863fdc0 0000000000000000 raw: ffff888036bacd00 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as freed page last allocated via order 2, migratetype Unmovable, gfp_mask 0x446dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_NOWARN|__GFP_RETRY_MAYFAIL|__GFP_COMP), pid 16741, tgid 16741 (syz-executor), ts 343313197788, free_ts 380670750466 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x240/0x2a0 mm/page_alloc.c:1851 prep_new_page mm/page_alloc.c:1859 [inline] get_page_from_freelist+0x21e4/0x22c0 mm/page_alloc.c:3858 __alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5148 alloc_pages_mpol+0x232/0x4a0 mm/mempolicy.c:2416 ___kmalloc_large_node+0x5f/0x1b0 mm/slub.c:4317 __kmalloc_large_node_noprof+0x18/0x90 mm/slub.c:4348 __do_kmalloc_node mm/slub.c:4364 [inline] __kvmalloc_node ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40064", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sDSrA5Cw2PRAVcxX/za76A==": { "id": "sDSrA5Cw2PRAVcxX/za76A==", "updater": "debian/updater", "name": "CVE-2024-26661", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()' In \"u32 otg_inst = pipe_ctx-\u003estream_res.tg-\u003einst;\" pipe_ctx-\u003estream_res.tg could be NULL, it is relying on the caller to ensure the tg is not NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26661", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sDW0EXHPEasW8Uq6gTO+PQ==": { "id": "sDW0EXHPEasW8Uq6gTO+PQ==", "updater": "debian/updater", "name": "CVE-2018-16376", "description": "An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2018-16376", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sFy6XZBsZ1YD59vnMAzJBg==": { "id": "sFy6XZBsZ1YD59vnMAzJBg==", "updater": "debian/updater", "name": "CVE-2024-38950", "description": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38950", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sKvU9EMVvmgu3eX+l3UalA==": { "id": "sKvU9EMVvmgu3eX+l3UalA==", "updater": "debian/updater", "name": "CVE-2026-53078", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path. Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer: - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si-\u003edst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx-\u003etemp.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53078", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sL3KpWpmO+FMS7A9UsXdDg==": { "id": "sL3KpWpmO+FMS7A9UsXdDg==", "updater": "debian/updater", "name": "CVE-2026-43414", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp-\u003efree is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference. qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43414", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sLSWW2qZrLURobO+B3605g==": { "id": "sLSWW2qZrLURobO+B3605g==", "updater": "debian/updater", "name": "CVE-2025-40057", "description": "In the Linux kernel, the following vulnerability has been resolved: ptp: Add a upper bound on max_vclocks syzbot reported WARNING in max_vclocks_store. This occurs when the argument max is too large for kcalloc to handle. Extend the guard to guard against values that are too large for kcalloc", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40057", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sNFHesILBVZ9Xz8u+1R8yw==": { "id": "sNFHesILBVZ9Xz8u+1R8yw==", "updater": "debian/updater", "name": "CVE-2026-68258", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size We weren't checking whether the values provided in the private data in kfd CRIU restore were within bounds. For queue type, add a KFD_QUEUE_TYPE_MAX and ensure the provided type is less than it. For mqd_size, add new function mqd_size_from_queue_type and confirm that the provided mqd_size matches expectations. (cherry picked from commit f19d8086f6644083c913d70bfdeee20e1b6f46a5)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68258", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sT/CdZ9EbhIheJoHHIMlVg==": { "id": "sT/CdZ9EbhIheJoHHIMlVg==", "updater": "debian/updater", "name": "CVE-2026-42250", "description": "bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42250", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "bzip2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sVpyexyrwxYbyqurODQLJQ==": { "id": "sVpyexyrwxYbyqurODQLJQ==", "updater": "debian/updater", "name": "CVE-2024-25260", "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-25260", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "elfutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sXrkHoO8FqgInZBBvNCsaQ==": { "id": "sXrkHoO8FqgInZBBvNCsaQ==", "updater": "debian/updater", "name": "CVE-2026-68195", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus. mt7615_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops-\u003etx_cleanup(). Only the mmio queue ops implement that callback; on the mt7663 USB and SDIO buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker. Same defect as the mt7921 and mt7925 patches in this series. Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for non-mmio devices\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68195", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sc1dlk3LluxR723zHmEQbw==": { "id": "sc1dlk3LluxR723zHmEQbw==", "updater": "debian/updater", "name": "CVE-2026-45942", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: fix e4b bitmap inconsistency reports A bitmap inconsistency issue was observed during stress tests under mixed huge-page workloads. Ext4 reported multiple e4b bitmap check failures like: ext4_mb_complex_scan_group:2508: group 350, 8179 free clusters as per group info. But got 8192 blocks Analysis and experimentation confirmed that the issue is caused by a race condition between page migration and bitmap modification. Although this timing window is extremely narrow, it is still hit in practice: folio_lock ext4_mb_load_buddy __migrate_folio check ref count folio_mc_copy __filemap_get_folio folio_try_get(folio) ...... mb_mark_used ext4_mb_unload_buddy __folio_migrate_mapping folio_ref_freeze folio_unlock The root cause of this issue is that the fast path of load_buddy only increments the folio's reference count, which is insufficient to prevent concurrent folio migration. We observed that the folio migration process acquires the folio lock. Therefore, we can determine whether to take the fast path in load_buddy by checking the lock status. If the folio is locked, we opt for the slow path (which acquires the lock) to close this concurrency window. Additionally, this change addresses the following issues: When the DOUBLE_CHECK macro is enabled to inspect bitmap-related issues, the following error may be triggered: corruption in group 324 at byte 784(6272): f in copy != ff on disk/prealloc Analysis reveals that this is a false positive. There is a specific race window where the bitmap and the group descriptor become momentarily inconsistent, leading to this error report: ext4_mb_load_buddy ext4_mb_load_buddy __filemap_get_folio(create|lock) folio_lock ext4_mb_init_cache folio_mark_uptodate __filemap_get_folio(no lock) ...... mb_mark_used mb_mark_used_double mb_cmp_bitmaps mb_set_bits(e4b-\u003ebd_bitmap) folio_unlock The original logic assumed that since mb_cmp_bitmaps is called when the bitmap is newly loaded from disk, the folio lock would be sufficient to prevent concurrent access. However, this overlooks a specific race condition: if another process attempts to load buddy and finds the folio is already in an uptodate state, it will immediately begin using it without holding folio lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45942", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "scjuuOqx8Qax/3JegyCKcg==": { "id": "scjuuOqx8Qax/3JegyCKcg==", "updater": "debian/updater", "name": "CVE-2026-46175", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by FGGC of node block During FGGC node block migration, fsck may incorrectly treat the migrated node block as fsync-written data. The reproduction scenario: root@vm:/mnt/f2fs# seq 1 2048 | xargs -n 1 ./test_sync // write inline inode and sync root@vm:/mnt/f2fs# rm -f 1 root@vm:/mnt/f2fs# sync root@vm:/mnt/f2fs# f2fs_io gc_range // move data block in sync mode and not write CP SPO, \"fsck --dry-run\" find inode has already checkpointed but still with DENT_BIT_SHIFT set The root cause is that GC does not clear the dentry mark and fsync mark during node block migration, leading fsck to misinterpret them as user-issued fsync writes. In BGGC mode, node block migration is handled by f2fs_sync_node_pages(), which guarantees the dentry and fsync marks are cleared before writing. This patch move the set/clear of the fsync|dentry marks into __write_node_folio to make the logic clearer, and ensures the fsync|dentry mark is cleared in FGGC.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46175", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "seCbnaAzWN2Uub/hJsbccg==": { "id": "seCbnaAzWN2Uub/hJsbccg==", "updater": "debian/updater", "name": "CVE-2026-53005", "description": "In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop all SCM attributes for SOCKMAP. SOCKMAP can hide inflight fd from AF_UNIX GC. When a socket in SOCKMAP receives skb with inflight fd, sk_psock_verdict_data_ready() looks up the mapped socket and enqueue skb to its psock-\u003eingress_skb. Since neither the old nor the new GC can inspect the psock queue, the hidden skb leaks the inflight sockets. Note that this cannot be detected via kmemleak because inflight sockets are linked to a global list. In addition, SOCKMAP redirect breaks the Tarjan-based GC's assumption that unix_edge.successor is always alive, which is no longer true once skb is redirected, resulting in use-after-free below. [0] Moreover, SOCKMAP does not call scm_stat_del() properly, so unix_show_fdinfo() could report an incorrect fd count. sk_msg_recvmsg() does not support any SCM attributes in the first place. Let's drop all SCM attributes before passing skb to the SOCKMAP layer. [0]: BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251) Read of size 8 at addr ffff888125362670 by task kworker/56:1/496 CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 Workqueue: events sk_psock_backlog Call Trace: \u003cTASK\u003e dump_stack_lvl (lib/dump_stack.c:122) print_report (mm/kasan/report.c:379) kasan_report (mm/kasan/report.c:597) unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251) unix_destroy_fpl (net/unix/garbage.c:317) unix_destruct_scm (./include/net/scm.h:80 ./include/net/scm.h:86 net/unix/af_unix.c:1976) sk_psock_backlog (./include/linux/skbuff.h:?) process_scheduled_works (kernel/workqueue.c:?) worker_thread (kernel/workqueue.c:?) kthread (kernel/kthread.c:438) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:258) \u003c/TASK\u003e Allocated by task 955: kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78) __kasan_slab_alloc (mm/kasan/common.c:369) kmem_cache_alloc_noprof (mm/slub.c:4539) sk_prot_alloc (net/core/sock.c:2240) sk_alloc (net/core/sock.c:2301) unix_create1 (net/unix/af_unix.c:1099) unix_create (net/unix/af_unix.c:1169) __sock_create (net/socket.c:1606) __sys_socketpair (net/socket.c:1811) __x64_sys_socketpair (net/socket.c:1863 net/socket.c:1860 net/socket.c:1860) do_syscall_64 (arch/x86/entry/syscall_64.c:?) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Freed by task 496: kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78) kasan_save_free_info (mm/kasan/generic.c:587) __kasan_slab_free (mm/kasan/common.c:287) kmem_cache_free (mm/slub.c:6165) __sk_destruct (net/core/sock.c:2282 net/core/sock.c:2384) sk_psock_destroy (./include/net/sock.h:?) process_scheduled_works (kernel/workqueue.c:?) worker_thread (kernel/workqueue.c:?) kthread (kernel/kthread.c:438) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:258)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53005", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sjk08x30IRw3g2CCIvIBIw==": { "id": "sjk08x30IRw3g2CCIvIBIw==", "updater": "debian/updater", "name": "CVE-2025-8851", "description": "A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8851", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "skb66Jx+vWt5AVpMUcVEdg==": { "id": "skb66Jx+vWt5AVpMUcVEdg==", "updater": "debian/updater", "name": "CVE-2026-32741", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32741", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "sy3ilamsUq1ezzG2K3kdrA==": { "id": "sy3ilamsUq1ezzG2K3kdrA==", "updater": "debian/updater", "name": "CVE-2025-71068", "description": "In the Linux kernel, the following vulnerability has been resolved: svcrdma: bound check rq_pages index in inline path svc_rdma_copy_inline_range indexed rqstp-\u003erq_pages[rc_curpage] without verifying rc_curpage stays within the allocated page array. Add guards before the first use and after advancing to a new page.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71068", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "syYPyXsBtjXISlYg/pYDLg==": { "id": "syYPyXsBtjXISlYg/pYDLg==", "updater": "debian/updater", "name": "CVE-2026-34502", "description": "Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34502", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "apr-util", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t1cDuzMlX117B8LBMX1fYQ==": { "id": "t1cDuzMlX117B8LBMX1fYQ==", "updater": "debian/updater", "name": "CVE-2017-13716", "description": "The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-13716", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t3O7D7jw7OlvBQ0xuLH+cQ==": { "id": "t3O7D7jw7OlvBQ0xuLH+cQ==", "updater": "debian/updater", "name": "CVE-2025-38369", "description": "In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using Running IDXD workloads in a container with the /dev directory mounted can trigger a call trace or even a kernel panic when the parent process of the container is terminated. This issue occurs because, under certain configurations, Docker does not properly propagate the mount replica back to the original mount point. In this case, when the user driver detaches, the WQ is destroyed but it still calls destroy_workqueue() attempting to completes all pending work. It's necessary to check wq-\u003ewq and skip the drain if it no longer exists.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38369", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "t7u6uHAJ/VCFFsPQoc5q9w==": { "id": "t7u6uHAJ/VCFFsPQoc5q9w==", "updater": "debian/updater", "name": "TEMP-1142905-081994", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-1142905-081994", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "unzip", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tC2vRr2PwNrxOJ/kxMcoHQ==": { "id": "tC2vRr2PwNrxOJ/kxMcoHQ==", "updater": "debian/updater", "name": "CVE-2026-23208", "description": "In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Prevent excessive number of frames In this case, the user constructed the parameters with maxpacksize 40 for rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer size for each data URB is maxpacksize * packets, which in this example is 40 * 6 = 240; When the user performs a write operation to send audio data into the ALSA PCM playback stream, the calculated number of frames is packsize[0] * packets = 264, which exceeds the allocated URB buffer size, triggering the out-of-bounds (OOB) issue reported by syzbot [1]. Added a check for the number of single data URB frames when calculating the number of frames to prevent [1]. [1] BUG: KASAN: slab-out-of-bounds in copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487 Write of size 264 at addr ffff88804337e800 by task syz.0.17/5506 Call Trace: copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487 prepare_playback_urb+0x953/0x13d0 sound/usb/pcm.c:1611 prepare_outbound_urb+0x377/0xc50 sound/usb/endpoint.c:333", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23208", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tGzsBkfMtfrEHxSA/TTu3w==": { "id": "tGzsBkfMtfrEHxSA/TTu3w==", "updater": "debian/updater", "name": "CVE-2023-23005", "description": "In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-23005", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tK8NTpgAf2tGi6JtIelJEg==": { "id": "tK8NTpgAf2tGi6JtIelJEg==", "updater": "debian/updater", "name": "CVE-2026-53361", "description": "In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() `- if (!gc_in_progress) `- if (!gc_in_progress) |- gc_in_progress = true | `- queue_work() | unix_gc() \u003c----------------/ | | |- gc_in_progress = true ... `- queue_work() | | `- gc_in_progress = false | | unix_gc() \u003c---------------------------------------------' | ... /* gc_in_progress == false */ | `- gc_in_progress = false unix_peek_fpl() relies on gc_in_progress not to confuse GC by MSG_PEEK. Let's set gc_in_progress to true in unix_gc().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53361", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tQ/cy6+608pCEG8iB+a3xg==": { "id": "tQ/cy6+608pCEG8iB+a3xg==", "updater": "debian/updater", "name": "CVE-2025-38429", "description": "In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer is written Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated before the buffer is written, potentially causing race conditions where the host sees an updated read pointer before the buffer is actually written. Updating rd_offset prematurely can lead to the host accessing an uninitialized or incomplete element, resulting in data corruption. Invoke the buffer write before updating rd_offset to ensure the element is fully written before signaling its availability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38429", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tThsV2ITDYLRgOdGJrS/aQ==": { "id": "tThsV2ITDYLRgOdGJrS/aQ==", "updater": "debian/updater", "name": "CVE-2026-68136", "description": "In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO packet.\") added a flush check to skb_gro_receive(), but skb_gro_receive_list() lacks the same validation. As a result, packets marked with NAPI_GRO_CB(skb)-\u003eflush may still be re-aggregated. This allows already-GRO'd packets with existing frag_list to be re-aggregated into a new GRO session, corrupting the frag_list chain structure. When skb_segment() attempts to unpack these malformed packets, it encounters invalid state and triggers a kernel panic. Scenario (Tethering/Device forwarding): 1. Driver: Generated aggregated packet P1 via LRO with frag_list 2. Dev A: Receives aggregated fraglist packet and flush flag set 3. Dev A: Re-enters GRO, skb_gro_receive_list() is called 4. Missing flush check allows re-aggregation despite flush flag 5. Frag_list chain becomes corrupted (loops or dangling refs) 6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list Root cause in skb_segment(): The check at line ~4891: if (hsize \u003c= 0 \u0026\u0026 i \u003e= nfrags \u0026\u0026 skb_headlen(list_skb) \u0026\u0026 (skb_headlen(list_skb) == len || sg)) { When frag_list is corrupted by double aggregation, when list_skb is a NULL pointer from skb-\u003enext, skb_headlen(list_skb) dereference NULL/corrupted pointers occurs. Call Trace: skb_headlen(NULL skb) skb_segment tcp_gso_segment tcp4_gso_segment inet_gso_segment skb_mac_gso_segment __skb_gso_segment skb_gso_segment validate_xmit_skb validate_xmit_skb_list sch_direct_xmit qdisc_restart __qdisc_run qdisc_run net_tx_action Fix: Add NAPI_GRO_CB(skb)-\u003eflush validation to the early-return check in skb_gro_receive_list(), matching the defensive programming pattern of skb_gro_receive().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68136", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tUnffIqaEOBexSfOy9RSbA==": { "id": "tUnffIqaEOBexSfOy9RSbA==", "updater": "debian/updater", "name": "CVE-2025-66863", "description": "An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66863", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tVih89ImzoM80ZbOBxCm9w==": { "id": "tVih89ImzoM80ZbOBxCm9w==", "updater": "debian/updater", "name": "CVE-2023-50495", "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-50495", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "ncurses", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tXow4avuWZvMPnoVix+ybQ==": { "id": "tXow4avuWZvMPnoVix+ybQ==", "updater": "debian/updater", "name": "CVE-2026-64561", "description": "In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a \"stale\" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is \"fine\", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root pagetables\"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64561", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tYjqt2QuHxyt9AqxIuOaGw==": { "id": "tYjqt2QuHxyt9AqxIuOaGw==", "updater": "debian/updater", "name": "CVE-2025-21651", "description": "In the Linux kernel, the following vulnerability has been resolved: net: hns3: don't auto enable misc vector Currently, there is a time window between misc irq enabled and service task inited. If an interrupte is reported at this time, it will cause warning like below: [ 16.324639] Call trace: [ 16.324641] __queue_delayed_work+0xb8/0xe0 [ 16.324643] mod_delayed_work_on+0x78/0xd0 [ 16.324655] hclge_errhand_task_schedule+0x58/0x90 [hclge] [ 16.324662] hclge_misc_irq_handle+0x168/0x240 [hclge] [ 16.324666] __handle_irq_event_percpu+0x64/0x1e0 [ 16.324667] handle_irq_event+0x80/0x170 [ 16.324670] handle_fasteoi_edge_irq+0x110/0x2bc [ 16.324671] __handle_domain_irq+0x84/0xfc [ 16.324673] gic_handle_irq+0x88/0x2c0 [ 16.324674] el1_irq+0xb8/0x140 [ 16.324677] arch_cpu_idle+0x18/0x40 [ 16.324679] default_idle_call+0x5c/0x1bc [ 16.324682] cpuidle_idle_call+0x18c/0x1c4 [ 16.324684] do_idle+0x174/0x17c [ 16.324685] cpu_startup_entry+0x30/0x6c [ 16.324687] secondary_start_kernel+0x1a4/0x280 [ 16.324688] ---[ end trace 6aa0bff672a964aa ]--- So don't auto enable misc vector when request irq..", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21651", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tYvCYxSwmhDDaN2DBZh/lg==": { "id": "tYvCYxSwmhDDaN2DBZh/lg==", "updater": "debian/updater", "name": "CVE-2024-56729", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: Initialize cfid-\u003etcon before performing network ops Avoid leaking a tcon ref when a lease break races with opening the cached directory. Processing the leak break might take a reference to the tcon in cached_dir_lease_break() and then fail to release the ref in cached_dir_offload_close, since cfid-\u003etcon is still NULL.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56729", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "td4AwwiNo8fDCZzACdpFVg==": { "id": "td4AwwiNo8fDCZzACdpFVg==", "updater": "debian/updater", "name": "CVE-2026-68144", "description": "In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider that pskb_may_pull() might have relocated the skb data, and continue to access the older pointer, causing UAF. Reproduced under KASAN: BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0 Read of size 1 at addr ff11000105510f50 by task repro/157 pep_get_sb+0x234/0x3b0 pipe_handler_do_rcv+0x5f7/0xa10 pep_do_rcv+0x203/0x410 __sk_receive_skb+0x471/0x4a0 phonet_rcv+0x5b3/0x6c0 __netif_receive_skb+0xcc/0x1d0 Refetch the header with skb_header_pointer() after pskb_may_pull(), so the possibly stale pointer is no longer dereferenced. There are better ways to solve this, but, this is the less instrusive one.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68144", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tdmTWMKf4Wd4a94OZjAQWw==": { "id": "tdmTWMKf4Wd4a94OZjAQWw==", "updater": "debian/updater", "name": "CVE-2025-7545", "description": "A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-7545", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tedkwtFcJID1iDvrmjfi+A==": { "id": "tedkwtFcJID1iDvrmjfi+A==", "updater": "debian/updater", "name": "CVE-2025-40075", "description": "In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three dst_dev() with a lockdep enabled helper.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40075", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tf2LLVKK9ztdqJ1EUc9k0A==": { "id": "tf2LLVKK9ztdqJ1EUc9k0A==", "updater": "debian/updater", "name": "CVE-2024-26962", "description": "In the Linux kernel, the following vulnerability has been resolved: dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape For raid456, if reshape is still in progress, then IO across reshape position will wait for reshape to make progress. However, for dm-raid, in following cases reshape will never make progress hence IO will hang: 1) the array is read-only; 2) MD_RECOVERY_WAIT is set; 3) MD_RECOVERY_FROZEN is set; After commit c467e97f079f (\"md/raid6: use valid sector values to determine if an I/O should wait on the reshape\") fix the problem that IO across reshape position doesn't wait for reshape, the dm-raid test shell/lvconvert-raid-reshape.sh start to hang: [root@fedora ~]# cat /proc/979/stack [\u003c0\u003e] wait_woken+0x7d/0x90 [\u003c0\u003e] raid5_make_request+0x929/0x1d70 [raid456] [\u003c0\u003e] md_handle_request+0xc2/0x3b0 [md_mod] [\u003c0\u003e] raid_map+0x2c/0x50 [dm_raid] [\u003c0\u003e] __map_bio+0x251/0x380 [dm_mod] [\u003c0\u003e] dm_submit_bio+0x1f0/0x760 [dm_mod] [\u003c0\u003e] __submit_bio+0xc2/0x1c0 [\u003c0\u003e] submit_bio_noacct_nocheck+0x17f/0x450 [\u003c0\u003e] submit_bio_noacct+0x2bc/0x780 [\u003c0\u003e] submit_bio+0x70/0xc0 [\u003c0\u003e] mpage_readahead+0x169/0x1f0 [\u003c0\u003e] blkdev_readahead+0x18/0x30 [\u003c0\u003e] read_pages+0x7c/0x3b0 [\u003c0\u003e] page_cache_ra_unbounded+0x1ab/0x280 [\u003c0\u003e] force_page_cache_ra+0x9e/0x130 [\u003c0\u003e] page_cache_sync_ra+0x3b/0x110 [\u003c0\u003e] filemap_get_pages+0x143/0xa30 [\u003c0\u003e] filemap_read+0xdc/0x4b0 [\u003c0\u003e] blkdev_read_iter+0x75/0x200 [\u003c0\u003e] vfs_read+0x272/0x460 [\u003c0\u003e] ksys_read+0x7a/0x170 [\u003c0\u003e] __x64_sys_read+0x1c/0x30 [\u003c0\u003e] do_syscall_64+0xc6/0x230 [\u003c0\u003e] entry_SYSCALL_64_after_hwframe+0x6c/0x74 This is because reshape can't make progress. For md/raid, the problem doesn't exist because register new sync_thread doesn't rely on the IO to be done any more: 1) If array is read-only, it can switch to read-write by ioctl/sysfs; 2) md/raid never set MD_RECOVERY_WAIT; 3) If MD_RECOVERY_FROZEN is set, mddev_suspend() doesn't hold 'reconfig_mutex', hence it can be cleared and reshape can continue by sysfs api 'sync_action'. However, I'm not sure yet how to avoid the problem in dm-raid yet. This patch on the one hand make sure raid_message() can't change sync_thread() through raid_message() after presuspend(), on the other hand detect the above 3 cases before wait for IO do be done in dm_suspend(), and let dm-raid requeue those IO.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26962", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tjUOg+P5YgWl5btEGrYxOw==": { "id": "tjUOg+P5YgWl5btEGrYxOw==", "updater": "debian/updater", "name": "CVE-2017-13694", "description": "The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2017-13694", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tl+ldJVpSpeTGWtLbHBFjg==": { "id": "tl+ldJVpSpeTGWtLbHBFjg==", "updater": "debian/updater", "name": "CVE-2024-35945", "description": "In the Linux kernel, the following vulnerability has been resolved: net: phy: phy_device: Prevent nullptr exceptions on ISR If phydev-\u003eirq is set unconditionally, check for valid interrupt handler or fall back to polling mode to prevent nullptr exceptions in interrupt service routine.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35945", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tqFkMROecRC/cxO5FXH2+w==": { "id": "tqFkMROecRC/cxO5FXH2+w==", "updater": "debian/updater", "name": "CVE-2026-6471", "description": "Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6471", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "tr3xh4aSzA1KYajxcVhY0A==": { "id": "tr3xh4aSzA1KYajxcVhY0A==", "updater": "debian/updater", "name": "CVE-2026-43107", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculation xfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then build_aevent() appends attributes including XFRMA_IF_ID when x-\u003eif_id is set. xfrm_aevent_msgsize() does not include space for XFRMA_IF_ID. For states with if_id, build_aevent() can fail with -EMSGSIZE and hit BUG_ON(err \u003c 0) in xfrm_get_ae(), turning a malformed netlink interaction into a kernel panic. Account XFRMA_IF_ID in the size calculation unconditionally and replace the BUG_ON with normal error unwinding.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43107", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u/Ur9qmhT5bd5MffRn9ubw==": { "id": "u/Ur9qmhT5bd5MffRn9ubw==", "updater": "debian/updater", "name": "CVE-2025-21729", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion The rtwdev-\u003escanning flag isn't protected by mutex originally, so cancel_hw_scan can pass the condition, but suddenly hw_scan completion unset the flag and calls ieee80211_scan_completed() that will free local-\u003ehw_scan_req. Then, cancel_hw_scan raises null-ptr-deref and use-after-free. Fix it by moving the check condition to where protected by mutex. KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f] CPU: 2 PID: 6922 Comm: kworker/2:2 Tainted: G OE Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB6WW (2.76 ) 09/10/2019 Workqueue: events cfg80211_conn_work [cfg80211] RIP: 0010:rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core] Code: 00 45 89 6c 24 1c 0f 85 23 01 00 00 48 8b 85 20 ff ff ff 48 8d RSP: 0018:ffff88811fd9f068 EFLAGS: 00010206 RAX: dffffc0000000000 RBX: ffff88811fd9f258 RCX: 0000000000000001 RDX: 0000000000000011 RSI: 0000000000000001 RDI: 0000000000000089 RBP: ffff88811fd9f170 R08: 0000000000000000 R09: 0000000000000000 R10: ffff88811fd9f108 R11: 0000000000000000 R12: ffff88810e47f960 R13: 0000000000000000 R14: 000000000000ffff R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8881d6f00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007531dfca55b0 CR3: 00000001be296004 CR4: 00000000001706e0 Call Trace: \u003cTASK\u003e ? show_regs+0x61/0x73 ? __die_body+0x20/0x73 ? die_addr+0x4f/0x7b ? exc_general_protection+0x191/0x1db ? asm_exc_general_protection+0x27/0x30 ? rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core] ? rtw89_fw_h2c_scan_offload_be+0x458/0x13c3 [rtw89_core] ? __pfx_rtw89_fw_h2c_scan_offload_be+0x10/0x10 [rtw89_core] ? do_raw_spin_lock+0x75/0xdb ? __pfx_do_raw_spin_lock+0x10/0x10 rtw89_hw_scan_offload+0xb5e/0xbf7 [rtw89_core] ? _raw_spin_unlock+0xe/0x24 ? __mutex_lock.constprop.0+0x40c/0x471 ? __pfx_rtw89_hw_scan_offload+0x10/0x10 [rtw89_core] ? __mutex_lock_slowpath+0x13/0x1f ? mutex_lock+0xa2/0xdc ? __pfx_mutex_lock+0x10/0x10 rtw89_hw_scan_abort+0x58/0xb7 [rtw89_core] rtw89_ops_cancel_hw_scan+0x120/0x13b [rtw89_core] ieee80211_scan_cancel+0x468/0x4d0 [mac80211] ieee80211_prep_connection+0x858/0x899 [mac80211] ieee80211_mgd_auth+0xbea/0xdde [mac80211] ? __pfx_ieee80211_mgd_auth+0x10/0x10 [mac80211] ? cfg80211_find_elem+0x15/0x29 [cfg80211] ? is_bss+0x1b7/0x1d7 [cfg80211] ieee80211_auth+0x18/0x27 [mac80211] cfg80211_mlme_auth+0x3bb/0x3e7 [cfg80211] cfg80211_conn_do_work+0x410/0xb81 [cfg80211] ? __pfx_cfg80211_conn_do_work+0x10/0x10 [cfg80211] ? __kasan_check_read+0x11/0x1f ? psi_group_change+0x8bc/0x944 ? __kasan_check_write+0x14/0x22 ? mutex_lock+0x8e/0xdc ? __pfx_mutex_lock+0x10/0x10 ? __pfx___radix_tree_lookup+0x10/0x10 cfg80211_conn_work+0x245/0x34d [cfg80211] ? __pfx_cfg80211_conn_work+0x10/0x10 [cfg80211] ? update_cfs_rq_load_avg+0x3bc/0x3d7 ? sched_clock_noinstr+0x9/0x1a ? sched_clock+0x10/0x24 ? sched_clock_cpu+0x7e/0x42e ? newidle_balance+0x796/0x937 ? __pfx_sched_clock_cpu+0x10/0x10 ? __pfx_newidle_balance+0x10/0x10 ? __kasan_check_read+0x11/0x1f ? psi_group_change+0x8bc/0x944 ? _raw_spin_unlock+0xe/0x24 ? raw_spin_rq_unlock+0x47/0x54 ? raw_spin_rq_unlock_irq+0x9/0x1f ? finish_task_switch.isra.0+0x347/0x586 ? __schedule+0x27bf/0x2892 ? mutex_unlock+0x80/0xd0 ? do_raw_spin_lock+0x75/0xdb ? __pfx___schedule+0x10/0x10 process_scheduled_works+0x58c/0x821 worker_thread+0x4c7/0x586 ? __kasan_check_read+0x11/0x1f kthread+0x285/0x294 ? __pfx_worker_thread+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x29/0x6f ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30 \u003c/TASK\u003e", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21729", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u0KFq8sxSQMQOjkoSQcWGQ==": { "id": "u0KFq8sxSQMQOjkoSQcWGQ==", "updater": "debian/updater", "name": "CVE-2023-31486", "description": "HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-31486", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u5o/Ut47Hjve2qfu2gi2Yw==": { "id": "u5o/Ut47Hjve2qfu2gi2Yw==", "updater": "debian/updater", "name": "CVE-2026-46312", "description": "In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap vb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not see a reason why vb2_dma_sg should behave differently. This avoids hitting `WARN_ON(!(vma-\u003evm_flags \u0026 VM_DONTEXPAND));` in drm_gem_mmap_obj() during mmap() of an imported dma-buf from the out of tree Apple ISP camera capture driver which uses vb2_dma_sg_memops. gst-launch-1.0 v4l2src ! gtk4paintablesink [ 38.201528] ------------[ cut here ]------------ [ 38.202135] WARNING: CPU: 7 PID: 2362 at drivers/gpu/drm/drm_gem.c:1144 drm_gem_mmap_obj+0x1f8/0x210 [ 38.203278] Modules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device uinput nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables qrtr bnep nls_ascii i2c_dev loop fuse dm_multipath nfnetlink brcmfmac_wcc hid_magicmouse hci_bcm4377 brcmfmac brcmutil bluetooth ecdh_generic cfg80211 ecc btrfs xor xor_neon rfkill hid_apple raid6_pq joydev aop_als apple_nvmem_spmi industrialio snd_soc_aop apple_z2 snd_soc_cs42l84 tps6598x snd_soc_tas2764 macsmc_reboot spi_nor macsmc_hwmon rtc_macsmc gpio_macsmc macsmc_power regmap_spmi macsmc_input dockchannel_hid panel_summit appledrm nvme_apple dwc3 snd_soc_macaudio drm_client_lib nvme_core phy_apple_atc hwmon apple_sart apple_dockchannel macsmc apple_rtkit_helper spmi_apple_controller aop apple_wdt mfd_core nvmem_apple_efuses pinctrl_apple_gpio apple_isp apple_dcp videobuf2_dma_sg mux_core spi_apple [ 38.203300] videobuf2_memops i2c_pasemi_platform snd_soc_apple_mca videobuf2_v4l2 videodev clk_apple_nco videobuf2_common snd_pcm_dmaengine adpdrm asahi apple_admac adpdrm_mipi drm_dma_helper pwm_apple i2c_pasemi_core drm_display_helper mc cec apple_dart ofpart apple_soc_cpufreq leds_pwm phram [ 38.217677] CPU: 7 UID: 1000 PID: 2362 Comm: gst-launch-1.0 Tainted: G W 6.17.6+ #asahi-dev PREEMPT(full) [ 38.219040] Tainted: [W]=WARN [ 38.219398] Hardware name: Apple MacBook Pro (13-inch, M2, 2022) (DT) [ 38.220213] pstate: 21400005 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [ 38.221088] pc : drm_gem_mmap_obj+0x1f8/0x210 [ 38.221643] lr : drm_gem_mmap_obj+0x78/0x210 [ 38.222178] sp : ffffc0008dc678e0 [ 38.222579] x29: ffffc0008dc678e0 x28: 0000000000042a97 x27: ffff8000b701b480 [ 38.223465] x26: 00000000000000fb x25: ffffc0008dc67d20 x24: ffffc0008dc67968 [ 38.224402] x23: ffff8000e3ca5600 x22: ffff8000265b7800 x21: ffff80003000c0c0 [ 38.225279] x20: 0000000000000000 x19: ffff8000b68c5200 x18: ffffc0008dc67968 [ 38.226151] x17: 0000000000000000 x16: 0000000000000000 x15: ffffc000810a30a8 [ 38.227042] x14: 00007fff637effff x13: 00005555de91ffff x12: 00007fff63293fff [ 38.227942] x11: 0000000000000000 x10: ffff8000184ecf08 x9 : ffffc0007a1900c8 [ 38.228824] x8 : ffffc0008dc67968 x7 : 0000000000000012 x6 : ffffc0015cf1c000 [ 38.229703] x5 : ffffc0008dc676a0 x4 : ffffc00081a27dc0 x3 : 0000000000000038 [ 38.230607] x2 : 0000000000000003 x1 : 0000000000000003 x0 : 00000000100000fb [ 38.231488] Call trace: [ 38.231806] drm_gem_mmap_obj+0x1f8/0x210 (P) [ 38.232342] drm_gem_mmap+0x140/0x260 [ 38.232813] __mmap_region+0x488/0x9a0 [ 38.233277] mmap_region+0xd0/0x148 [ 38.233703] do_mmap+0x350/0x5c0 [ 38.234148] vm_mmap_pgoff+0x14c/0x200 [ 38.234612] ksys_mmap_pgoff+0x150/0x208 [ 38.235107] __arm64_sys_mmap+0x34/0x50 [ 38.235611] invoke_syscall+0x50/0x120 [ 38.236075] el0_svc_common.constprop.0+0x48/0xf0 [ 38.236680] do_el0_svc+0x24/0x38 [ 38.237113] el0_svc+0x38/0x168 [ 38.237507] el0t_64_sync_handler+0xa0/0xe8 [ 38.238034] el0t_64_sync+0x198/0x1a0 [ 38.238491] ---[ end trace 0000000000000000 ]--- There were discussions in [1] at the end of 2023 that mmap() on imported ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46312", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u7x7ygYe+0lg4dva7NX7RA==": { "id": "u7x7ygYe+0lg4dva7NX7RA==", "updater": "debian/updater", "name": "CVE-2026-31655", "description": "In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled Keep the NOC_HDCP clock always enabled to fix the potential hang caused by the NoC ADB400 port power down handshake.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31655", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u9Iltn6Pyk+xlGjtrBt7hQ==": { "id": "u9Iltn6Pyk+xlGjtrBt7hQ==", "updater": "debian/updater", "name": "CVE-2024-36881", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: reset ptes when close() for wr-protected ones Userfaultfd unregister includes a step to remove wr-protect bits from all the relevant pgtable entries, but that only covered an explicit UFFDIO_UNREGISTER ioctl, not a close() on the userfaultfd itself. Cover that too. This fixes a WARN trace. The only user visible side effect is the user can observe leftover wr-protect bits even if the user close()ed on an userfaultfd when releasing the last reference of it. However hopefully that should be harmless, and nothing bad should happen even if so. This change is now more important after the recent page-table-check patch we merged in mm-unstable (446dd9ad37d0 (\"mm/page_table_check: support userfault wr-protect entries\")), as we'll do sanity check on uffd-wp bits without vma context. So it's better if we can 100% guarantee no uffd-wp bit leftovers, to make sure each report will be valid.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-36881", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "u9eV8+DVR//GBavLQ3uvSA==": { "id": "u9eV8+DVR//GBavLQ3uvSA==", "updater": "debian/updater", "name": "CVE-2026-68445", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and then turn it writable with mprotect(). Validated shader BOs must stay read-only: the validator checks the instructions once and the GPU trusts them afterwards. A writable mapping lets userspace rewrite the code after validation, bypassing the validator. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 already does for its read-only objects.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68445", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uAZ/vVdCFUjRGO/lgTu7Ew==": { "id": "uAZ/vVdCFUjRGO/lgTu7Ew==", "updater": "debian/updater", "name": "CVE-2026-60000", "description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-60000", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uBgGeOGTFkYEcFN9GrAVZQ==": { "id": "uBgGeOGTFkYEcFN9GrAVZQ==", "updater": "debian/updater", "name": "CVE-2019-16232", "description": "drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-16232", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uDMKksa8nEm05P2D+S3qVA==": { "id": "uDMKksa8nEm05P2D+S3qVA==", "updater": "debian/updater", "name": "CVE-2026-11940", "description": "tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11940", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uEC5Qtr12vyf9FN8TJFIpw==": { "id": "uEC5Qtr12vyf9FN8TJFIpw==", "updater": "debian/updater", "name": "CVE-2026-56411", "description": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56411", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uEgJFcCQ1Yyimn97LxvMpg==": { "id": "uEgJFcCQ1Yyimn97LxvMpg==", "updater": "debian/updater", "name": "CVE-2025-38544", "description": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc collision When userspace is using AF_RXRPC to provide a server, it has to preallocate incoming calls and assign to them call IDs that will be used to thread related recvmsg() and sendmsg() together. The preallocated call IDs will automatically be attached to calls as they come in until the pool is empty. To the kernel, the call IDs are just arbitrary numbers, but userspace can use the call ID to hold a pointer to prepared structs. In any case, the user isn't permitted to create two calls with the same call ID (call IDs become available again when the call ends) and EBADSLT should result from sendmsg() if an attempt is made to preallocate a call with an in-use call ID. However, the cleanup in the error handling will trigger both assertions in rxrpc_cleanup_call() because the call isn't marked complete and isn't marked as having been released. Fix this by setting the call state in rxrpc_service_prealloc_one() and then marking it as being released before calling the cleanup function.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38544", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uJaIkdAdssqwBkEXNNs0qg==": { "id": "uJaIkdAdssqwBkEXNNs0qg==", "updater": "debian/updater", "name": "CVE-2026-58010", "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses \u003e instead of \u003e=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-58010", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uLeGXSkRziPc+1wkRZ653A==": { "id": "uLeGXSkRziPc+1wkRZ653A==", "updater": "debian/updater", "name": "CVE-2019-12456", "description": "An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a \"double fetch\" vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-12456", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uMLFKsTN91e1kpaM0hQi8w==": { "id": "uMLFKsTN91e1kpaM0hQi8w==", "updater": "debian/updater", "name": "CVE-2026-22693", "description": "HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-22693", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "harfbuzz", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uNfzK/lUTWl62S8/vMrtaw==": { "id": "uNfzK/lUTWl62S8/vMrtaw==", "updater": "debian/updater", "name": "CVE-2024-26662", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()' 'panel_cntl' structure used to control the display panel could be null, dereferencing it could lead to a null pointer access. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn21/dcn21_hwseq.c:269 dcn21_set_backlight_level() error: we previously assumed 'panel_cntl' could be null (see line 250)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26662", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uR/wRgEeGqBLSPmVdvrr/w==": { "id": "uR/wRgEeGqBLSPmVdvrr/w==", "updater": "debian/updater", "name": "CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-3389", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "gnutls28", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uRTDoRu2o1RYEkr6geNGUA==": { "id": "uRTDoRu2o1RYEkr6geNGUA==", "updater": "debian/updater", "name": "CVE-2026-54241", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54241", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uT3bFChGChX0XV/PpW8+bQ==": { "id": "uT3bFChGChX0XV/PpW8+bQ==", "updater": "debian/updater", "name": "CVE-2025-68236", "description": "In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3) According to UFS specifications, the power-off sequence for a UFS device includes: - Sending an SSU command with Power_Condition=3 and await a response. - Asserting RST_N low. - Turning off REF_CLK. - Turning off VCC. - Turning off VCCQ/VCCQ2. As part of ufs shutdown, after the SSU command completion, asserting hardware reset (HWRST) triggers the device firmware to wake up and execute its reset routine. This routine initializes hardware blocks and takes a few milliseconds to complete. During this time, the ICCQ draws a large current. This large ICCQ current may cause issues for the regulator which is supplying power to UFS, because the turn off request from UFS driver to the regulator framework will be immediately followed by low power mode(LPM) request by regulator framework. This is done by framework because UFS which is the only client is requesting for disable. So if the rail is still in the process of shutting down while ICCQ exceeds LPM current thresholds, and LPM mode is activated in hardware during this state, it may trigger an overcurrent protection (OCP) fault in the regulator. To prevent this, a 10ms delay is added after asserting HWRST. This allows the reset operation to complete while power rails remain active and in high-power mode. Currently there is no way for Host to query whether the reset is completed or not and hence this the delay is based on experiments with Qualcomm UFS controllers across multiple UFS vendors.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-68236", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uT3dvwJpn9tGTvL/XiDyZQ==": { "id": "uT3dvwJpn9tGTvL/XiDyZQ==", "updater": "debian/updater", "name": "CVE-2026-68452", "description": "In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68452", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uTS8BhrtK2N7W+qV8za2Vg==": { "id": "uTS8BhrtK2N7W+qV8za2Vg==", "updater": "debian/updater", "name": "CVE-2026-64571", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() p54_rx_eeprom_readback() copies the requested EEPROM slice out of a device-supplied readback frame without checking that the skb actually holds that many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()\") closed the destination overflow by copying a fixed priv-\u003eeeprom_slice_size (and rejecting a mismatched advertised len), but the source side is still unbounded: nothing verifies the frame is long enough to supply that many bytes. A malicious USB device can send a short frame whose advertised len matches priv-\u003eeeprom_slice_size while the payload is truncated. The equality check passes and memcpy() reads past the end of the skb, leaking adjacent heap: BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) Read of size 1016 at addr ffff88800f077114 by task swapper/0/0 Call Trace: \u003cIRQ\u003e ... __asan_memcpy (mm/kasan/shadow.c:105) p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005) ... \u003c/IRQ\u003e The buggy address belongs to the object at ffff88800f0770c0 which belongs to the cache skbuff_small_head of size 704 The buggy address is located 84 bytes inside of allocated 704-byte region [ffff88800f0770c0, ffff88800f077380) Check that the slice fits in the skb before copying.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64571", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uUeyRpuBJxN4Bn35BikY4w==": { "id": "uUeyRpuBJxN4Bn35BikY4w==", "updater": "debian/updater", "name": "CVE-2008-1687", "description": "The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2008-1687", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "m4", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uWYPETh7SRW4hEs8/1Va9A==": { "id": "uWYPETh7SRW4hEs8/1Va9A==", "updater": "debian/updater", "name": "CVE-2025-21658", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid extent tree [BUG] Syzbot reported a crash with the following call trace: BTRFS info (device loop0): scrub: started on devid 1 BUG: kernel NULL pointer dereference, address: 0000000000000208 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 106e70067 P4D 106e70067 PUD 107143067 PMD 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 1 UID: 0 PID: 689 Comm: repro Kdump: loaded Tainted: G O 6.13.0-rc4-custom+ #206 Tainted: [O]=OOT_MODULE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:find_first_extent_item+0x26/0x1f0 [btrfs] Call Trace: \u003cTASK\u003e scrub_find_fill_first_stripe+0x13d/0x3b0 [btrfs] scrub_simple_mirror+0x175/0x260 [btrfs] scrub_stripe+0x5d4/0x6c0 [btrfs] scrub_chunk+0xbb/0x170 [btrfs] scrub_enumerate_chunks+0x2f4/0x5f0 [btrfs] btrfs_scrub_dev+0x240/0x600 [btrfs] btrfs_ioctl+0x1dc8/0x2fa0 [btrfs] ? do_sys_openat2+0xa5/0xf0 __x64_sys_ioctl+0x97/0xc0 do_syscall_64+0x4f/0x120 entry_SYSCALL_64_after_hwframe+0x76/0x7e \u003c/TASK\u003e [CAUSE] The reproducer is using a corrupted image where extent tree root is corrupted, thus forcing to use \"rescue=all,ro\" mount option to mount the image. Then it triggered a scrub, but since scrub relies on extent tree to find where the data/metadata extents are, scrub_find_fill_first_stripe() relies on an non-empty extent root. But unfortunately scrub_find_fill_first_stripe() doesn't really expect an NULL pointer for extent root, it use extent_root to grab fs_info and triggered a NULL pointer dereference. [FIX] Add an extra check for a valid extent root at the beginning of scrub_find_fill_first_stripe(). The new error path is introduced by 42437a6386ff (\"btrfs: introduce mount option rescue=ignorebadroots\"), but that's pretty old, and later commit b979547513ff (\"btrfs: scrub: introduce helper to find and fill sector info for a scrub_stripe\") changed how we do scrub. So for kernels older than 6.6, the fix will need manual backport.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21658", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uXIQHFI6+ztbjm2wYtFkSQ==": { "id": "uXIQHFI6+ztbjm2wYtFkSQ==", "updater": "debian/updater", "name": "CVE-2026-6845", "description": "A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6845", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uXsz9tYjG7LKTz0a7qH3BQ==": { "id": "uXsz9tYjG7LKTz0a7qH3BQ==", "updater": "debian/updater", "name": "CVE-2026-68102", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix aperture mapping leak amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to always return false, so iounmap(aper_base_kaddr) never runs on normal driver unload, leaving an orphaned entry in the x86 PAT interval tree. On connected_to_cpu hardware, the aperture is mapped write-back (WB) via ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC) over the same range. The WC vs WB conflict causes: ioremap error for 0x..., requested 0x1, got 0x0 amdgpu: discovery failed: -2 Fix by switching to devres-managed mappings so cleanup is guaranteed regardless of drm_dev_enter() state: - connected_to_cpu path: devm_memremap(MEMREMAP_WB). For IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut, returning __va(offset) from the existing kernel direct map. No new ioremap VA or PAT entry is created, so there is nothing to orphan. - dGPU path: devm_ioremap_wc() registers iounmap() as a devres action, guaranteeing cleanup at device_del() time. Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio() since the mapping is now devres-owned. v2: Remove redundant x86_64 guard (Lijo) (cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68102", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uYADkNPHgawO14s3lEkOhA==": { "id": "uYADkNPHgawO14s3lEkOhA==", "updater": "debian/updater", "name": "CVE-2026-68154", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68154", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uaaDC/cqggxU5t4t/B7xZA==": { "id": "uaaDC/cqggxU5t4t/B7xZA==", "updater": "debian/updater", "name": "CVE-2024-26944", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free in do_zone_finish() Shinichiro reported the following use-after-free triggered by the device replace operation in fstests btrfs/070. BTRFS info (device nullb1): scrub: finished on devid 1 with status: 0 ================================================================== BUG: KASAN: slab-use-after-free in do_zone_finish+0x91a/0xb90 [btrfs] Read of size 8 at addr ffff8881543c8060 by task btrfs-cleaner/3494007 CPU: 0 PID: 3494007 Comm: btrfs-cleaner Tainted: G W 6.8.0-rc5-kts #1 Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020 Call Trace: \u003cTASK\u003e dump_stack_lvl+0x5b/0x90 print_report+0xcf/0x670 ? __virt_addr_valid+0x200/0x3e0 kasan_report+0xd8/0x110 ? do_zone_finish+0x91a/0xb90 [btrfs] ? do_zone_finish+0x91a/0xb90 [btrfs] do_zone_finish+0x91a/0xb90 [btrfs] btrfs_delete_unused_bgs+0x5e1/0x1750 [btrfs] ? __pfx_btrfs_delete_unused_bgs+0x10/0x10 [btrfs] ? btrfs_put_root+0x2d/0x220 [btrfs] ? btrfs_clean_one_deleted_snapshot+0x299/0x430 [btrfs] cleaner_kthread+0x21e/0x380 [btrfs] ? __pfx_cleaner_kthread+0x10/0x10 [btrfs] kthread+0x2e3/0x3c0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x31/0x70 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30 \u003c/TASK\u003e Allocated by task 3493983: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 btrfs_alloc_device+0xb3/0x4e0 [btrfs] device_list_add.constprop.0+0x993/0x1630 [btrfs] btrfs_scan_one_device+0x219/0x3d0 [btrfs] btrfs_control_ioctl+0x26e/0x310 [btrfs] __x64_sys_ioctl+0x134/0x1b0 do_syscall_64+0x99/0x190 entry_SYSCALL_64_after_hwframe+0x6e/0x76 Freed by task 3494056: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3f/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x32/0x70 kfree+0x11b/0x320 btrfs_rm_dev_replace_free_srcdev+0xca/0x280 [btrfs] btrfs_dev_replace_finishing+0xd7e/0x14f0 [btrfs] btrfs_dev_replace_by_ioctl+0x1286/0x25a0 [btrfs] btrfs_ioctl+0xb27/0x57d0 [btrfs] __x64_sys_ioctl+0x134/0x1b0 do_syscall_64+0x99/0x190 entry_SYSCALL_64_after_hwframe+0x6e/0x76 The buggy address belongs to the object at ffff8881543c8000 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 96 bytes inside of freed 1024-byte region [ffff8881543c8000, ffff8881543c8400) The buggy address belongs to the physical page: page:00000000fe2c1285 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1543c8 head:00000000fe2c1285 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 flags: 0x17ffffc0000840(slab|head|node=0|zone=2|lastcpupid=0x1fffff) page_type: 0xffffffff() raw: 0017ffffc0000840 ffff888100042dc0 ffffea0019e8f200 dead000000000002 raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff8881543c7f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff8881543c7f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 \u003effff8881543c8000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff8881543c8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff8881543c8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb This UAF happens because we're accessing stale zone information of a already removed btrfs_device in do_zone_finish(). The sequence of events is as follows: btrfs_dev_replace_start btrfs_scrub_dev btrfs_dev_replace_finishing btrfs_dev_replace_update_device_in_mapping_tree \u003c-- devices replaced btrfs_rm_dev_replace_free_srcdev btrfs_free_device \u003c-- device freed cleaner_kthread btrfs_delete_unused_bgs btrfs_zone_finish do_zone_finish \u003c-- refers the freed device The reason for this is that we're using a ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26944", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ucmV7WK26A3Z2691L+x2pw==": { "id": "ucmV7WK26A3Z2691L+x2pw==", "updater": "debian/updater", "name": "CVE-2026-53179", "description": "In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rtw_update_protection rtw_update_protection() is called with a pointer offset into the ies buffer but the full ie_length is passed, causing a potential buffer over-read.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53179", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "udMY5/Ym22m2wauMDwS1ZQ==": { "id": "udMY5/Ym22m2wauMDwS1ZQ==", "updater": "debian/updater", "name": "CVE-2025-21801", "description": "In the Linux kernel, the following vulnerability has been resolved: net: ravb: Fix missing rtnl lock in suspend/resume path Fix the suspend/resume path by ensuring the rtnl lock is held where required. Calls to ravb_open, ravb_close and wol operations must be performed under the rtnl lock to prevent conflicts with ongoing ndo operations. Without this fix, the following warning is triggered: [ 39.032969] ============================= [ 39.032983] WARNING: suspicious RCU usage [ 39.033019] ----------------------------- [ 39.033033] drivers/net/phy/phy_device.c:2004 suspicious rcu_dereference_protected() usage! ... [ 39.033597] stack backtrace: [ 39.033613] CPU: 0 UID: 0 PID: 174 Comm: python3 Not tainted 6.13.0-rc7-next-20250116-arm64-renesas-00002-g35245dfdc62c #7 [ 39.033623] Hardware name: Renesas SMARC EVK version 2 based on r9a08g045s33 (DT) [ 39.033628] Call trace: [ 39.033633] show_stack+0x14/0x1c (C) [ 39.033652] dump_stack_lvl+0xb4/0xc4 [ 39.033664] dump_stack+0x14/0x1c [ 39.033671] lockdep_rcu_suspicious+0x16c/0x22c [ 39.033682] phy_detach+0x160/0x190 [ 39.033694] phy_disconnect+0x40/0x54 [ 39.033703] ravb_close+0x6c/0x1cc [ 39.033714] ravb_suspend+0x48/0x120 [ 39.033721] dpm_run_callback+0x4c/0x14c [ 39.033731] device_suspend+0x11c/0x4dc [ 39.033740] dpm_suspend+0xdc/0x214 [ 39.033748] dpm_suspend_start+0x48/0x60 [ 39.033758] suspend_devices_and_enter+0x124/0x574 [ 39.033769] pm_suspend+0x1ac/0x274 [ 39.033778] state_store+0x88/0x124 [ 39.033788] kobj_attr_store+0x14/0x24 [ 39.033798] sysfs_kf_write+0x48/0x6c [ 39.033808] kernfs_fop_write_iter+0x118/0x1a8 [ 39.033817] vfs_write+0x27c/0x378 [ 39.033825] ksys_write+0x64/0xf4 [ 39.033833] __arm64_sys_write+0x18/0x20 [ 39.033841] invoke_syscall+0x44/0x104 [ 39.033852] el0_svc_common.constprop.0+0xb4/0xd4 [ 39.033862] do_el0_svc+0x18/0x20 [ 39.033870] el0_svc+0x3c/0xf0 [ 39.033880] el0t_64_sync_handler+0xc0/0xc4 [ 39.033888] el0t_64_sync+0x154/0x158 [ 39.041274] ravb 11c30000.ethernet eth0: Link is Down", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21801", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ufTiewnbfOU03vqdmZUHGw==": { "id": "ufTiewnbfOU03vqdmZUHGw==", "updater": "debian/updater", "name": "CVE-2026-46170", "description": "In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free sk if last When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(), and released at the end. If at that moment, it was the last reference being held, the sk would not be freed. sock_put() should then be called instead of __sock_put(). But that's not enough: if it is the last reference, sock_put() will call sk_free(), which will end up calling sk_stop_timer_sync() on the same timer, and waiting indefinitely to finish. So it is needed to mark that the timer is done at the end of the timer handler when it has not been rescheduled, not to call sk_stop_timer_sync() on \"itself\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46170", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uhMnkZEO/VFY8Pl5jKul8Q==": { "id": "uhMnkZEO/VFY8Pl5jKul8Q==", "updater": "debian/updater", "name": "CVE-2026-68344", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM()), and stores a different object as the interface data in each case: a 'struct completion' for a pre-firmware device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a post-firmware one. uea_disconnect() instead tells the two apart by the number of interfaces of the active configuration (a pre-firmware device exposes a single interface, ADI930 has 2 and eagle has 3), and casts the interface data accordingly. Because the two handlers use different criteria, a crafted device that advertises a pre-firmware id together with a multi-interface descriptor (or a post-firmware id with a single interface) makes them disagree: the small 'struct completion' stored by uea_probe() is then passed to usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes instance-\u003eserialize, reading past the end of the allocation: BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80 Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982 ... __mutex_lock+0x152a/0x1b80 usbatm_usb_disconnect+0x70/0x820 uea_disconnect+0x133/0x2c0 usb_unbind_interface+0x1dd/0x9e0 ... which belongs to the cache kmalloc-96 of size 96 The buggy address is located 0 bytes to the right of allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60) Reject such inconsistent descriptors in uea_probe() so that both handlers always make the same pre/post-firmware decision.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68344", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uq//Fq4QaSws9yxxeAr1oQ==": { "id": "uq//Fq4QaSws9yxxeAr1oQ==", "updater": "debian/updater", "name": "CVE-2025-22115", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block group refcount race in btrfs_create_pending_block_groups() Block group creation is done in two phases, which results in a slightly unintuitive property: a block group can be allocated/deallocated from after btrfs_make_block_group() adds it to the space_info with btrfs_add_bg_to_space_info(), but before creation is completely completed in btrfs_create_pending_block_groups(). As a result, it is possible for a block group to go unused and have 'btrfs_mark_bg_unused' called on it concurrently with 'btrfs_create_pending_block_groups'. This causes a number of issues, which were fixed with the block group flag 'BLOCK_GROUP_FLAG_NEW'. However, this fix is not quite complete. Since it does not use the unused_bg_lock, it is possible for the following race to occur: btrfs_create_pending_block_groups btrfs_mark_bg_unused if list_empty // false list_del_init clear_bit else if (test_bit) // true list_move_tail And we get into the exact same broken ref count and invalid new_bgs state for transaction cleanup that BLOCK_GROUP_FLAG_NEW was designed to prevent. The broken refcount aspect will result in a warning like: [1272.943527] refcount_t: underflow; use-after-free. [1272.943967] WARNING: CPU: 1 PID: 61 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110 [1272.944731] Modules linked in: btrfs virtio_net xor zstd_compress raid6_pq null_blk [last unloaded: btrfs] [1272.945550] CPU: 1 UID: 0 PID: 61 Comm: kworker/u32:1 Kdump: loaded Tainted: G W 6.14.0-rc5+ #108 [1272.946368] Tainted: [W]=WARN [1272.946585] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 [1272.947273] Workqueue: btrfs_discard btrfs_discard_workfn [btrfs] [1272.947788] RIP: 0010:refcount_warn_saturate+0xba/0x110 [1272.949532] RSP: 0018:ffffbf1200247df0 EFLAGS: 00010282 [1272.949901] RAX: 0000000000000000 RBX: ffffa14b00e3f800 RCX: 0000000000000000 [1272.950437] RDX: 0000000000000000 RSI: ffffbf1200247c78 RDI: 00000000ffffdfff [1272.950986] RBP: ffffa14b00dc2860 R08: 00000000ffffdfff R09: ffffffff90526268 [1272.951512] R10: ffffffff904762c0 R11: 0000000063666572 R12: ffffa14b00dc28c0 [1272.952024] R13: 0000000000000000 R14: ffffa14b00dc2868 R15: 000001285dcd12c0 [1272.952850] FS: 0000000000000000(0000) GS:ffffa14d33c40000(0000) knlGS:0000000000000000 [1272.953458] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [1272.953931] CR2: 00007f838cbda000 CR3: 000000010104e000 CR4: 00000000000006f0 [1272.954474] Call Trace: [1272.954655] \u003cTASK\u003e [1272.954812] ? refcount_warn_saturate+0xba/0x110 [1272.955173] ? __warn.cold+0x93/0xd7 [1272.955487] ? refcount_warn_saturate+0xba/0x110 [1272.955816] ? report_bug+0xe7/0x120 [1272.956103] ? handle_bug+0x53/0x90 [1272.956424] ? exc_invalid_op+0x13/0x60 [1272.956700] ? asm_exc_invalid_op+0x16/0x20 [1272.957011] ? refcount_warn_saturate+0xba/0x110 [1272.957399] btrfs_discard_cancel_work.cold+0x26/0x2b [btrfs] [1272.957853] btrfs_put_block_group.cold+0x5d/0x8e [btrfs] [1272.958289] btrfs_discard_workfn+0x194/0x380 [btrfs] [1272.958729] process_one_work+0x130/0x290 [1272.959026] worker_thread+0x2ea/0x420 [1272.959335] ? __pfx_worker_thread+0x10/0x10 [1272.959644] kthread+0xd7/0x1c0 [1272.959872] ? __pfx_kthread+0x10/0x10 [1272.960172] ret_from_fork+0x30/0x50 [1272.960474] ? __pfx_kthread+0x10/0x10 [1272.960745] ret_from_fork_asm+0x1a/0x30 [1272.961035] \u003c/TASK\u003e [1272.961238] ---[ end trace 0000000000000000 ]--- Though we have seen them in the async discard workfn as well. It is most likely to happen after a relocation finishes which cancels discard, tears down the block group, etc. Fix this fully by taking the lock arou ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-22115", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "utgx/90cFNFOG7HLlgQMVQ==": { "id": "utgx/90cFNFOG7HLlgQMVQ==", "updater": "debian/updater", "name": "CVE-2026-45859", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation Ulrich reports a regression with nfqueue: If an application did not set the 'F_GSO' capability flag and a gso packet with an unconfirmed nf_conn entry is received all packets are now dropped instead of queued, because the check happens after skb_gso_segment(). In that case, we did have exclusive ownership of the skb and its associated conntrack entry. The elevated use count is due to skb_clone happening via skb_gso_segment(). Move the check so that its peformed vs. the aggregated packet. Then, annotate the individual segments except the first one so we can do a 2nd check at reinject time. For the normal case, where userspace does in-order reinjects, this avoids packet drops: first reinjected segment continues traversal and confirms entry, remaining segments observe the confirmed entry. While at it, simplify nf_ct_drop_unconfirmed(): We only care about unconfirmed entries with a refcnt \u003e 1, there is no need to special-case dying entries. This only happens with UDP. With TCP, the only unconfirmed packet will be the TCP SYN, those aren't aggregated by GRO. Next patch adds a udpgro test case to cover this scenario.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45859", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uuVof/zyt2johcugiudwEQ==": { "id": "uuVof/zyt2johcugiudwEQ==", "updater": "debian/updater", "name": "TEMP-0290435-0B57B5", "description": "", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/TEMP-0290435-0B57B5", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tar", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uvFnRcryNsc38djGoFZELg==": { "id": "uvFnRcryNsc38djGoFZELg==", "updater": "debian/updater", "name": "CVE-2025-1152", "description": "A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-1152", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uvwI+W4eYxKuNvoT3Y077Q==": { "id": "uvwI+W4eYxKuNvoT3Y077Q==", "updater": "debian/updater", "name": "CVE-2025-23133", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: update channel list in reg notifier instead reg worker Currently when ath11k gets a new channel list, it will be processed according to the following steps: 1. update new channel list to cfg80211 and queue reg_work. 2. cfg80211 handles new channel list during reg_work. 3. update cfg80211's handled channel list to firmware by ath11k_reg_update_chan_list(). But ath11k will immediately execute step 3 after reg_work is just queued. Since step 2 is asynchronous, cfg80211 may not have completed handling the new channel list, which may leading to an out-of-bounds write error: BUG: KASAN: slab-out-of-bounds in ath11k_reg_update_chan_list Call Trace: ath11k_reg_update_chan_list+0xbfe/0xfe0 [ath11k] kfree+0x109/0x3a0 ath11k_regd_update+0x1cf/0x350 [ath11k] ath11k_regd_update_work+0x14/0x20 [ath11k] process_one_work+0xe35/0x14c0 Should ensure step 2 is completely done before executing step 3. Thus Wen raised patch[1]. When flag NL80211_REGDOM_SET_BY_DRIVER is set, cfg80211 will notify ath11k after step 2 is done. So enable the flag NL80211_REGDOM_SET_BY_DRIVER then cfg80211 will notify ath11k after step 2 is done. At this time, there will be no KASAN bug during the execution of the step 3. [1] https://patchwork.kernel.org/project/linux-wireless/patch/20230201065313.27203-1-quic_wgong@quicinc.com/ Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-23133", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "uwxCim/b7jTMXTjotGKJxA==": { "id": "uwxCim/b7jTMXTjotGKJxA==", "updater": "debian/updater", "name": "CVE-2026-68164", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow overlapping input ranges for damon_set_regions() damon_set_regions() assumes the input ranges are sorted by the address and don't overlap each other. Hence the assumption was initially to be explicitly validated. But commit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for regions setting\") has mistakenly removed the validation. This can make DAMON behave in unexpected ways. At the best, the monitoring results snapshot will just look weird since there will be overlapping regions. DAMOS will also work weirdly, applying the same action multiple times for overlapping regions, and make DAMOS quota weird. More seriously, depending on the setup and regions updates sequence, negative size regions can be made. It will trigger WARN_ONCE() if the kernel is built with CONFIG_DAMON_DEBUG_SANITY=y. Depending on the monitoring results, the negative size region can further trigger division by zero in damon_merge_two_regions(). Note that some of the consequences including the WARN_ONCE() and the divide by zero depend on commits that were introduced after the root cause commit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for regions setting\"). Fix the problems by checking the assumption and returning an error if the input ranges don't meet the assumption. The issue was discovered [1] by Sashiko.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68164", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v1pFZ/L2vpZW7UoIOvtJ7w==": { "id": "v1pFZ/L2vpZW7UoIOvtJ7w==", "updater": "debian/updater", "name": "CVE-2011-4917", "description": "In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2011-4917", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v2MEiY/DNOR7aWbIhlf+ig==": { "id": "v2MEiY/DNOR7aWbIhlf+ig==", "updater": "debian/updater", "name": "CVE-2026-13757", "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-13757", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "p11-kit", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v8W3uLUipO36H5zJnC42yQ==": { "id": "v8W3uLUipO36H5zJnC42yQ==", "updater": "debian/updater", "name": "CVE-2024-13978", "description": "A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-13978", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "v9vWe3hIDrLLNJbYOtNKRQ==": { "id": "v9vWe3hIDrLLNJbYOtNKRQ==", "updater": "debian/updater", "name": "CVE-2025-39754", "description": "In the Linux kernel, the following vulnerability has been resolved: mm/smaps: fix race between smaps_hugetlb_range and migration smaps_hugetlb_range() handles the pte without holdling ptl, and may be concurrenct with migration, leaing to BUG_ON in pfn_swap_entry_to_page(). The race is as follows. smaps_hugetlb_range migrate_pages huge_ptep_get remove_migration_ptes \t\t\t\t folio_unlock pfn_swap_entry_folio BUG_ON To fix it, hold ptl lock in smaps_hugetlb_range().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39754", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vGwkpBqLshgMfCl70d0myg==": { "id": "vGwkpBqLshgMfCl70d0myg==", "updater": "debian/updater", "name": "CVE-2024-35860", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: support deferring bpf_link dealloc to after RCU grace period BPF link for some program types is passed as a \"context\" which can be used by those BPF programs to look up additional information. E.g., for multi-kprobes and multi-uprobes, link is used to fetch BPF cookie values. Because of this runtime dependency, when bpf_link refcnt drops to zero there could still be active BPF programs running accessing link data. This patch adds generic support to defer bpf_link dealloc callback to after RCU GP, if requested. This is done by exposing two different deallocation callbacks, one synchronous and one deferred. If deferred one is provided, bpf_link_free() will schedule dealloc_deferred() callback to happen after RCU GP. BPF is using two flavors of RCU: \"classic\" non-sleepable one and RCU tasks trace one. The latter is used when sleepable BPF programs are used. bpf_link_free() accommodates that by checking underlying BPF program's sleepable flag, and goes either through normal RCU GP only for non-sleepable, or through RCU tasks trace GP *and* then normal RCU GP (taking into account rcu_trace_implies_rcu_gp() optimization), if BPF program is sleepable. We use this for multi-kprobe and multi-uprobe links, which dereference link during program run. We also preventively switch raw_tp link to use deferred dealloc callback, as upcoming changes in bpf-next tree expose raw_tp link data (specifically, cookie value) to BPF program at runtime as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35860", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vHiy8KO9Yq7S0TDpc4yTgQ==": { "id": "vHiy8KO9Yq7S0TDpc4yTgQ==", "updater": "debian/updater", "name": "CVE-2026-45944", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a \"torn\" entry — where some fields are already zeroed while the 'Present' bit is still set — leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the \"Guidance to Software for Invalidations\" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU. 3. Perform the required cache and context-cache invalidation to ensure hardware no longer has cached references to the entry. 4. Fully zero out the entry only after the invalidation is complete. Also, add a dma_wmb() to context_set_present() to ensure the entry is fully initialized before the 'Present' bit becomes visible.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-45944", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vHuv4/wLhLp07vrdFm5IFQ==": { "id": "vHuv4/wLhLp07vrdFm5IFQ==", "updater": "debian/updater", "name": "CVE-2024-41023", "description": "In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cyclic 30 --timeout 30 --minimize --quiet kmemleak frequently reported a memory leak concerning the task_struct: unreferenced object 0xffff8881305b8000 (size 16136): comm \"stress-ng\", pid 614, jiffies 4294883961 (age 286.412s) object hex dump (first 32 bytes): 02 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 .@.............. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ debug hex dump (first 16 bytes): 53 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 S............... backtrace: [\u003c00000000046b6790\u003e] dup_task_struct+0x30/0x540 [\u003c00000000c5ca0f0b\u003e] copy_process+0x3d9/0x50e0 [\u003c00000000ced59777\u003e] kernel_clone+0xb0/0x770 [\u003c00000000a50befdc\u003e] __do_sys_clone+0xb6/0xf0 [\u003c000000001dbf2008\u003e] do_syscall_64+0x5d/0xf0 [\u003c00000000552900ff\u003e] entry_SYSCALL_64_after_hwframe+0x6e/0x76 The issue occurs in start_dl_timer(), which increments the task_struct reference count and sets a timer. The timer callback, dl_task_timer, is supposed to decrement the reference count upon expiration. However, if enqueue_task_dl() is called before the timer expires and cancels it, the reference count is not decremented, leading to the leak. This patch fixes the reference leak by ensuring the task_struct reference count is properly decremented when the timer is canceled.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-41023", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vQoCKRV0WYdDnzKPcCv6hw==": { "id": "vQoCKRV0WYdDnzKPcCv6hw==", "updater": "debian/updater", "name": "CVE-2026-6879", "description": "`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6879", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vSDZxpLkGafXPiYJDoSc5w==": { "id": "vSDZxpLkGafXPiYJDoSc5w==", "updater": "debian/updater", "name": "CVE-2025-14017", "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-14017", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "curl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vTy7peJhDCvE0j2VylCGPA==": { "id": "vTy7peJhDCvE0j2VylCGPA==", "updater": "debian/updater", "name": "CVE-2026-68304", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning Based on wpa_auth as 1x_256 mode, need to set up \"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X. Or it will happen trace warning when call brcmf_cfg80211_set_pmk(). [ 4481.831101] ------------[ cut here ]------------ [ 4481.831102] WARNING: CPU: 1 PID: 2997 at drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac] [...] [ 4481.831202] Call Trace: [ 4481.831204]  \u003cTASK\u003e [ 4481.831205]  nl80211_set_pmk+0x183/0x250 [cfg80211] [ 4481.831233]  genl_family_rcv_msg_doit+0xea/0x150 [ 4481.831237]  genl_rcv_msg+0x104/0x240 [ 4481.831239]  ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211] [ 4481.831257]  ? genl_family_rcv_msg_doit+0x150/0x150 [ 4481.831259]  netlink_rcv_skb+0x4e/0x100 [ 4481.831261]  genl_rcv+0x24/0x40 [ 4481.831262]  netlink_unicast+0x236/0x380 [ 4481.831264]  netlink_sendmsg+0x250/0x4b0 [ 4481.831266]  sock_sendmsg+0x5c/0x70 [ 4481.831269]  ____sys_sendmsg+0x236/0x2b0 [ 4481.831271]  ? copy_msghdr_from_user+0x6d/0xa0 [ 4481.831272]  ___sys_sendmsg+0x86/0xd0 [ 4481.831274]  ? avc_has_perm+0x8c/0x1a0 [ 4481.831276]  ? preempt_count_add+0x6a/0xa0 [ 4481.831279]  ? sock_has_perm+0x82/0xa0 [ 4481.831280]  __sys_sendmsg+0x57/0xa0 [ 4481.831282]  do_syscall_64+0x38/0x90 [ 4481.831284]  entry_SYSCALL_64_after_hwframe+0x63/0xcd [ 4481.831286] RIP: 0033:0x7fd270d369b4", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68304", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vV1qzf4l+nQIHXosn35mdg==": { "id": "vV1qzf4l+nQIHXosn35mdg==", "updater": "debian/updater", "name": "CVE-2021-45261", "description": "An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2021-45261", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vVKfZgj2ftz4bUN+hvsnmw==": { "id": "vVKfZgj2ftz4bUN+hvsnmw==", "updater": "debian/updater", "name": "CVE-2026-6238", "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6238", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vW7+QMt8GLYlNZ8i61SE4Q==": { "id": "vW7+QMt8GLYlNZ8i61SE4Q==", "updater": "debian/updater", "name": "CVE-2026-32882", "description": "libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-32882", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libheif", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vYXBLgfa++/Y7S8DCCK6kg==": { "id": "vYXBLgfa++/Y7S8DCCK6kg==", "updater": "debian/updater", "name": "CVE-2025-40339", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv-\u003eprt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-40339", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vgQiAROcJccmldely3uVnw==": { "id": "vgQiAROcJccmldely3uVnw==", "updater": "debian/updater", "name": "CVE-2025-39925", "description": "In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 problem, for j1939 protocol did not have NETDEV_UNREGISTER notification handler for undoing changes made by j1939_sk_bind(). Commit 25fe97cb7620 (\"can: j1939: move j1939_priv_put() into sk_destruct callback\") expects that a call to j1939_priv_put() can be unconditionally delayed until j1939_sk_sock_destruct() is called. But we need to call j1939_priv_put() against an extra ref held by j1939_sk_bind() call (as a part of undoing changes made by j1939_sk_bind()) as soon as NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct() is called via j1939_sk_release()). Otherwise, the extra ref on \"struct j1939_priv\" held by j1939_sk_bind() call prevents \"struct net_device\" from dropping the usage count to 1; making it impossible for unregister_netdevice() to continue. [mkl: remove space in front of label]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39925", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vgf0b5TZEtKDqwcBucDIpw==": { "id": "vgf0b5TZEtKDqwcBucDIpw==", "updater": "debian/updater", "name": "CVE-2026-68371", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stores pdev-\u003edev.of_node in a local np variable. This is a borrowed pointer and the probe function does not take a reference to it. The success and error paths nevertheless call of_node_put(np). This drops a reference that is owned by the platform device, and can leave pdev-\u003edev.of_node with an unbalanced reference count. Do not put the borrowed platform device node from omap2430_probe(). References taken for the child MUSB device are handled by the device core, and the ctrl-module phandle reference is still released separately.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68371", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "viHIBVs5uaPlB2vc11zGuA==": { "id": "viHIBVs5uaPlB2vc11zGuA==", "updater": "debian/updater", "name": "CVE-2025-38716", "description": "In the Linux kernel, the following vulnerability has been resolved: hfs: fix general protection fault in hfs_find_init() The hfs_find_init() method can trigger the crash if tree pointer is NULL: [ 45.746290][ T9787] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KAI [ 45.747287][ T9787] KASAN: null-ptr-deref in range [0x0000000000000040-0x0000000000000047] [ 45.748716][ T9787] CPU: 2 UID: 0 PID: 9787 Comm: repro Not tainted 6.16.0-rc3 #10 PREEMPT(full) [ 45.750250][ T9787] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 45.751983][ T9787] RIP: 0010:hfs_find_init+0x86/0x230 [ 45.752834][ T9787] Code: c1 ea 03 80 3c 02 00 0f 85 9a 01 00 00 4c 8d 6b 40 48 c7 45 18 00 00 00 00 48 b8 00 00 00 00 00 fc [ 45.755574][ T9787] RSP: 0018:ffffc90015157668 EFLAGS: 00010202 [ 45.756432][ T9787] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff819a4d09 [ 45.757457][ T9787] RDX: 0000000000000008 RSI: ffffffff819acd3a RDI: ffffc900151576e8 [ 45.758282][ T9787] RBP: ffffc900151576d0 R08: 0000000000000005 R09: 0000000000000000 [ 45.758943][ T9787] R10: 0000000080000000 R11: 0000000000000001 R12: 0000000000000004 [ 45.759619][ T9787] R13: 0000000000000040 R14: ffff88802c50814a R15: 0000000000000000 [ 45.760293][ T9787] FS: 00007ffb72734540(0000) GS:ffff8880cec64000(0000) knlGS:0000000000000000 [ 45.761050][ T9787] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 45.761606][ T9787] CR2: 00007f9bd8225000 CR3: 000000010979a000 CR4: 00000000000006f0 [ 45.762286][ T9787] Call Trace: [ 45.762570][ T9787] \u003cTASK\u003e [ 45.762824][ T9787] hfs_ext_read_extent+0x190/0x9d0 [ 45.763269][ T9787] ? submit_bio_noacct_nocheck+0x2dd/0xce0 [ 45.763766][ T9787] ? __pfx_hfs_ext_read_extent+0x10/0x10 [ 45.764250][ T9787] hfs_get_block+0x55f/0x830 [ 45.764646][ T9787] block_read_full_folio+0x36d/0x850 [ 45.765105][ T9787] ? __pfx_hfs_get_block+0x10/0x10 [ 45.765541][ T9787] ? const_folio_flags+0x5b/0x100 [ 45.765972][ T9787] ? __pfx_hfs_read_folio+0x10/0x10 [ 45.766415][ T9787] filemap_read_folio+0xbe/0x290 [ 45.766840][ T9787] ? __pfx_filemap_read_folio+0x10/0x10 [ 45.767325][ T9787] ? __filemap_get_folio+0x32b/0xbf0 [ 45.767780][ T9787] do_read_cache_folio+0x263/0x5c0 [ 45.768223][ T9787] ? __pfx_hfs_read_folio+0x10/0x10 [ 45.768666][ T9787] read_cache_page+0x5b/0x160 [ 45.769070][ T9787] hfs_btree_open+0x491/0x1740 [ 45.769481][ T9787] hfs_mdb_get+0x15e2/0x1fb0 [ 45.769877][ T9787] ? __pfx_hfs_mdb_get+0x10/0x10 [ 45.770316][ T9787] ? find_held_lock+0x2b/0x80 [ 45.770731][ T9787] ? lockdep_init_map_type+0x5c/0x280 [ 45.771200][ T9787] ? lockdep_init_map_type+0x5c/0x280 [ 45.771674][ T9787] hfs_fill_super+0x38e/0x720 [ 45.772092][ T9787] ? __pfx_hfs_fill_super+0x10/0x10 [ 45.772549][ T9787] ? snprintf+0xbe/0x100 [ 45.772931][ T9787] ? __pfx_snprintf+0x10/0x10 [ 45.773350][ T9787] ? do_raw_spin_lock+0x129/0x2b0 [ 45.773796][ T9787] ? find_held_lock+0x2b/0x80 [ 45.774215][ T9787] ? set_blocksize+0x40a/0x510 [ 45.774636][ T9787] ? sb_set_blocksize+0x176/0x1d0 [ 45.775087][ T9787] ? setup_bdev_super+0x369/0x730 [ 45.775533][ T9787] get_tree_bdev_flags+0x384/0x620 [ 45.775985][ T9787] ? __pfx_hfs_fill_super+0x10/0x10 [ 45.776453][ T9787] ? __pfx_get_tree_bdev_flags+0x10/0x10 [ 45.776950][ T9787] ? bpf_lsm_capable+0x9/0x10 [ 45.777365][ T9787] ? security_capable+0x80/0x260 [ 45.777803][ T9787] vfs_get_tree+0x8e/0x340 [ 45.778203][ T9787] path_mount+0x13de/0x2010 [ 45.778604][ T9787] ? kmem_cache_free+0x2b0/0x4c0 [ 45.779052][ T9787] ? __pfx_path_mount+0x10/0x10 [ 45.779480][ T9787] ? getname_flags.part.0+0x1c5/0x550 [ 45.779954][ T9787] ? putname+0x154/0x1a0 [ 45.780335][ T9787] __x64_sys_mount+0x27b/0x300 [ 45.780758][ T9787] ? __pfx___x64_sys_mount+0x10/0x10 [ 45.781232][ T9787] ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38716", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "via9ORzL8QYeuym0HcD6lg==": { "id": "via9ORzL8QYeuym0HcD6lg==", "updater": "debian/updater", "name": "CVE-2024-38949", "description": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-38949", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vkN7FYaEniQ5g2jNb7NZpg==": { "id": "vkN7FYaEniQ5g2jNb7NZpg==", "updater": "debian/updater", "name": "CVE-2024-10041", "description": "A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-10041", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "pam", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vnP1NtGTRJ4ACQZa+PGWmA==": { "id": "vnP1NtGTRJ4ACQZa+PGWmA==", "updater": "debian/updater", "name": "CVE-2023-53460", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix memory leak in rtw_usb_probe() drivers/net/wireless/realtek/rtw88/usb.c:876 rtw_usb_probe() warn: 'hw' from ieee80211_alloc_hw() not released on lines: 811 Fix this by modifying return to a goto statement.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53460", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vpMXCnh0dDLSciBABeiYWQ==": { "id": "vpMXCnh0dDLSciBABeiYWQ==", "updater": "debian/updater", "name": "CVE-2022-45885", "description": "An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-45885", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vpZ60RLe+1J2lJDPZ4B6fw==": { "id": "vpZ60RLe+1J2lJDPZ4B6fw==", "updater": "debian/updater", "name": "CVE-2026-43239", "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in -\u003equery_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating iface_last_update under iface_lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43239", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vr6U2lQ/hMXF58n2KZKXlQ==": { "id": "vr6U2lQ/hMXF58n2KZKXlQ==", "updater": "debian/updater", "name": "CVE-2026-68100", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl() copies each ACE from the attacker-controlled stored security descriptor verbatim into the response DACL without checking sid.num_subauth. The ACE bytes (including an unchecked num_subauth) originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE with `break` rather than an error, so parse_sec_desc() still returns success and the malformed SD reaches the xattr intact. On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a POSIX access ACL, build_sec_desc() -\u003e set_ntacl_dacl() -\u003e set_posix_acl_entries_dacl() walks the copied ACEs and reads ntace-\u003esid.sub_auth[ntace-\u003esid.num_subauth - 1] with num_subauth taken straight from the stored SD. Since sub_auth[] is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g. 255) drives an out-of-bounds heap read of ~1 KB with an offset fully controlled by an authenticated client. The sibling functions already gate this field: parse_dacl() -- num_subauth == 0 || \u003e SID_MAX_SUB_AUTHORITIES parse_sid() -- num_subauth \u003e SID_MAX_SUB_AUTHORITIES smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES) set_ntacl_dacl() is the lone inconsistent path that omits the check. Add the same num_subauth validation in set_ntacl_dacl() before copying the ACE, matching the gate already enforced by parse_dacl().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68100", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vsd22jqV9sSN27Xj1fhmtA==": { "id": "vsd22jqV9sSN27Xj1fhmtA==", "updater": "debian/updater", "name": "CVE-2026-68441", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains When a TC filter attached to a qdisc filter chain returns TC_ACT_REDIRECT (ex: via an eBPF program calling bpf_redirect() or an act_bpf action), the redirect was silently lost i.e no qdisc classify function handled TC_ACT_REDIRECT, so the packet fell through the switch and was enqueued normally instead of being redirected. This has been broken since bpf_redirect() was introduced for TC in commit 27b29f63058d (\"bpf: add bpf_redirect() helper\"). We got lucky for a long time because bpf_net_context was a per-CPU variable that was always available. commit 401cb7dae813 (\"net: Reference bpf_redirect_info via task_struct on PREEMPT_RT.\") turned bpf_net_context into a task_struct member that is only set up by explicit callers. Without a caller setting it up, bpf_redirect() itself crashes with a NULL pointer dereference in bpf_net_ctx_get_ri(). However, even with bpf_net_context available, TC_ACT_REDIRECT from qdisc filter chains cannot be honored without adding skb_do_redirect() calls to every qdisc classify function, which would require changes across net/sched/. Isolate it to ebpf core where it belongs. Instead, add a tcf_classify_qdisc() inline helper in pkt_cls.h, as a wrapper around tcf_classify() for use by qdisc classify functions and tcf_qevent_handle(). When the classify verdict is TC_ACT_REDIRECT, the wrapper converts it to TC_ACT_SHOT, dropping the packet rather than letting it continue silently. Dropping is preferred over letting the packet through because the user immediately sees packet loss. Silently passing the packet through would hide the problem and leave the user wondering why their redirect is not working. The clsact fast path, tc_run() continues to call tcf_classify() directly and is unaffected: TC_ACT_REDIRECT is returned as-is and handled by sch_handle_egress/ingress() calling skb_do_redirect() as before.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68441", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vv/Nq0/zePjAn4JWE5MOtw==": { "id": "vv/Nq0/zePjAn4JWE5MOtw==", "updater": "debian/updater", "name": "CVE-2026-43170", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Move vbus draw to workqueue context Currently dwc3_gadget_vbus_draw() can be called from atomic context, which in turn invokes power-supply-core APIs. And some these PMIC APIs have operations that may sleep, leading to kernel panic. Fix this by moving the vbus_draw into a workqueue context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43170", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vxmQyPOoTMh1Zx5DCsaQFQ==": { "id": "vxmQyPOoTMh1Zx5DCsaQFQ==", "updater": "debian/updater", "name": "CVE-2023-21264", "description": "In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-21264", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "vyuNHsqRTAlcfL/qtwpSjA==": { "id": "vyuNHsqRTAlcfL/qtwpSjA==", "updater": "debian/updater", "name": "CVE-2026-56211", "description": "A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56211", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "aom", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w1oeUHbRVVOslv73KK3P7Q==": { "id": "w1oeUHbRVVOslv73KK3P7Q==", "updater": "debian/updater", "name": "CVE-2024-58098", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global functions When processing calls to certain helpers, verifier invalidates all packet pointers in a current state. For example, consider the following program: __attribute__((__noinline__)) long skb_pull_data(struct __sk_buff *sk, __u32 len) { return bpf_skb_pull_data(sk, len); } SEC(\"tc\") int test_invalidate_checks(struct __sk_buff *sk) { int *p = (void *)(long)sk-\u003edata; if ((void *)(p + 1) \u003e (void *)(long)sk-\u003edata_end) return TCX_DROP; skb_pull_data(sk, 0); *p = 42; return TCX_PASS; } After a call to bpf_skb_pull_data() the pointer 'p' can't be used safely. See function filter.c:bpf_helper_changes_pkt_data() for a list of such helpers. At the moment verifier invalidates packet pointers when processing helper function calls, and does not traverse global sub-programs when processing calls to global sub-programs. This means that calls to helpers done from global sub-programs do not invalidate pointers in the caller state. E.g. the program above is unsafe, but is not rejected by verifier. This commit fixes the omission by computing field bpf_subprog_info-\u003echanges_pkt_data for each sub-program before main verification pass. changes_pkt_data should be set if: - subprogram calls helper for which bpf_helper_changes_pkt_data returns true; - subprogram calls a global function, for which bpf_subprog_info-\u003echanges_pkt_data should be set. The verifier.c:check_cfg() pass is modified to compute this information. The commit relies on depth first instruction traversal done by check_cfg() and absence of recursive function calls: - check_cfg() would eventually visit every call to subprogram S in a state when S is fully explored; - when S is fully explored: - every direct helper call within S is explored (and thus changes_pkt_data is set if needed); - every call to subprogram S1 called by S was visited with S1 fully explored (and thus S inherits changes_pkt_data from S1). The downside of such approach is that dead code elimination is not taken into account: if a helper call inside global function is dead because of current configuration, verifier would conservatively assume that the call occurs for the purpose of the changes_pkt_data computation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58098", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w3HHZG8nTVYxvXYiyXr1Hw==": { "id": "w3HHZG8nTVYxvXYiyXr1Hw==", "updater": "debian/updater", "name": "CVE-2026-5435", "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-5435", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w5DYnw3Ql//vskdC2DBVgA==": { "id": "w5DYnw3Ql//vskdC2DBVgA==", "updater": "debian/updater", "name": "CVE-2024-26670", "description": "In the Linux kernel, the following vulnerability has been resolved: arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD Currently the ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround isn't quite right, as it is supposed to be applied after the last explicit memory access, but is immediately followed by an LDR. The ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround is used to handle Cortex-A520 erratum 2966298 and Cortex-A510 erratum 3117295, which are described in: * https://developer.arm.com/documentation/SDEN2444153/0600/?lang=en * https://developer.arm.com/documentation/SDEN1873361/1600/?lang=en In both cases the workaround is described as: | If pagetable isolation is disabled, the context switch logic in the | kernel can be updated to execute the following sequence on affected | cores before exiting to EL0, and after all explicit memory accesses: | | 1. A non-shareable TLBI to any context and/or address, including | unused contexts or addresses, such as a `TLBI VALE1 Xzr`. | | 2. A DSB NSH to guarantee completion of the TLBI. The important part being that the TLBI+DSB must be placed \"after all explicit memory accesses\". Unfortunately, as-implemented, the TLBI+DSB is immediately followed by an LDR, as we have: | alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD | \ttlbi\tvale1, xzr | \tdsb\tnsh | alternative_else_nop_endif | alternative_if_not ARM64_UNMAP_KERNEL_AT_EL0 | \tldr\tlr, [sp, #S_LR] | \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp | \teret | alternative_else_nop_endif | | [ ... KPTI exception return path ... ] This patch fixes this by reworking the logic to place the TLBI+DSB immediately before the ERET, after all explicit memory accesses. The ERET is currently in a separate alternative block, and alternatives cannot be nested. To account for this, the alternative block for ARM64_UNMAP_KERNEL_AT_EL0 is replaced with a single alternative branch to skip the KPTI logic, with the new shape of the logic being: | alternative_insn \"b .L_skip_tramp_exit_\\@\", nop, ARM64_UNMAP_KERNEL_AT_EL0 | \t[ ... KPTI exception return path ... ] | .L_skip_tramp_exit_\\@: | | \tldr\tlr, [sp, #S_LR] | \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp | | alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD | \ttlbi\tvale1, xzr | \tdsb\tnsh | alternative_else_nop_endif | \teret The new structure means that the workaround is only applied when KPTI is not in use; this is fine as noted in the documented implications of the erratum: | Pagetable isolation between EL0 and higher level ELs prevents the | issue from occurring. ... and as per the workaround description quoted above, the workaround is only necessary \"If pagetable isolation is disabled\".", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26670", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "w5ixFh9N/z4mFs0nLuh+iA==": { "id": "w5ixFh9N/z4mFs0nLuh+iA==", "updater": "debian/updater", "name": "CVE-2023-23039", "description": "An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-23039", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wIg2Xh802Oj3VZBUTBmY2A==": { "id": "wIg2Xh802Oj3VZBUTBmY2A==", "updater": "debian/updater", "name": "CVE-2026-42767", "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42767", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openssl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wKDPawUoi4V9YbgaK5I6jA==": { "id": "wKDPawUoi4V9YbgaK5I6jA==", "updater": "debian/updater", "name": "CVE-2024-56692", "description": "In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node blkaddr in truncate_node() syzbot reports a f2fs bug as below: ------------[ cut here ]------------ kernel BUG at fs/f2fs/segment.c:2534! RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534 Call Trace: truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909 f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288 f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856 evict+0x4e8/0x9b0 fs/inode.c:723 f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986 f2fs_create+0x357/0x530 fs/f2fs/namei.c:394 lookup_open fs/namei.c:3595 [inline] open_last_lookups fs/namei.c:3694 [inline] path_openat+0x1c03/0x3590 fs/namei.c:3930 do_filp_open+0x235/0x490 fs/namei.c:3960 do_sys_openat2+0x13e/0x1d0 fs/open.c:1415 do_sys_open fs/open.c:1430 [inline] __do_sys_openat fs/open.c:1446 [inline] __se_sys_openat fs/open.c:1441 [inline] __x64_sys_openat+0x247/0x2a0 fs/open.c:1441 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534 The root cause is: on a fuzzed image, blkaddr in nat entry may be corrupted, then it will cause system panic when using it in f2fs_invalidate_blocks(), to avoid this, let's add sanity check on nat blkaddr in truncate_node().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-56692", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wMB5sAuUkEThs0w/PiESyw==": { "id": "wMB5sAuUkEThs0w/PiESyw==", "updater": "debian/updater", "name": "CVE-2024-53114", "description": "In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client A number of Zen4 client SoCs advertise the ability to use virtualized VMLOAD/VMSAVE, but using these instructions is reported to be a cause of a random host reboot. These instructions aren't intended to be advertised on Zen4 client so clear the capability.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-53114", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wOalQ7FUg/Trqlot6vK03Q==": { "id": "wOalQ7FUg/Trqlot6vK03Q==", "updater": "debian/updater", "name": "CVE-2026-68293", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just 12 dwords (48 bytes) of data. mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then memcpy()s that many bytes out of the register, potentially reading past the end of the 'out' buffer. On kernels built with FORTIFY_SOURCE this is caught as a buffer overflow while reading the module EEPROM via ethtool: detected buffer overflow in memcpy kernel BUG at lib/string_helpers.c:1048! RIP: 0010:fortify_panic+0x13/0x20 Call Trace: mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core] mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core] mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core] eeprom_prepare_data+0xf3/0x170 ethnl_default_doit+0xf1/0x3b0 Extend the mcia_reg layout to 32 dwords.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68293", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wOnjjjijWVo2GqwgzbvYSQ==": { "id": "wOnjjjijWVo2GqwgzbvYSQ==", "updater": "debian/updater", "name": "CVE-2025-38246", "description": "In the Linux kernel, the following vulnerability has been resolved: bnxt: properly flush XDP redirect lists We encountered following crash when testing a XDP_REDIRECT feature in production: [56251.579676] list_add corruption. next-\u003eprev should be prev (ffff93120dd40f30), but was ffffb301ef3a6740. (next=ffff93120dd 40f30). [56251.601413] ------------[ cut here ]------------ [56251.611357] kernel BUG at lib/list_debug.c:29! [56251.621082] Oops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI [56251.632073] CPU: 111 UID: 0 PID: 0 Comm: swapper/111 Kdump: loaded Tainted: P O 6.12.33-cloudflare-2025.6. 3 #1 [56251.653155] Tainted: [P]=PROPRIETARY_MODULE, [O]=OOT_MODULE [56251.663877] Hardware name: MiTAC GC68B-B8032-G11P6-GPU/S8032GM-HE-CFR, BIOS V7.020.B10-sig 01/22/2025 [56251.682626] RIP: 0010:__list_add_valid_or_report+0x4b/0xa0 [56251.693203] Code: 0e 48 c7 c7 68 e7 d9 97 e8 42 16 fe ff 0f 0b 48 8b 52 08 48 39 c2 74 14 48 89 f1 48 c7 c7 90 e7 d9 97 48 89 c6 e8 25 16 fe ff \u003c0f\u003e 0b 4c 8b 02 49 39 f0 74 14 48 89 d1 48 c7 c7 e8 e7 d9 97 4c 89 [56251.725811] RSP: 0018:ffff93120dd40b80 EFLAGS: 00010246 [56251.736094] RAX: 0000000000000075 RBX: ffffb301e6bba9d8 RCX: 0000000000000000 [56251.748260] RDX: 0000000000000000 RSI: ffff9149afda0b80 RDI: ffff9149afda0b80 [56251.760349] RBP: ffff9131e49c8000 R08: 0000000000000000 R09: ffff93120dd40a18 [56251.772382] R10: ffff9159cf2ce1a8 R11: 0000000000000003 R12: ffff911a80850000 [56251.784364] R13: ffff93120fbc7000 R14: 0000000000000010 R15: ffff9139e7510e40 [56251.796278] FS: 0000000000000000(0000) GS:ffff9149afd80000(0000) knlGS:0000000000000000 [56251.809133] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [56251.819561] CR2: 00007f5e85e6f300 CR3: 00000038b85e2006 CR4: 0000000000770ef0 [56251.831365] PKRU: 55555554 [56251.838653] Call Trace: [56251.845560] \u003cIRQ\u003e [56251.851943] cpu_map_enqueue.cold+0x5/0xa [56251.860243] xdp_do_redirect+0x2d9/0x480 [56251.868388] bnxt_rx_xdp+0x1d8/0x4c0 [bnxt_en] [56251.877028] bnxt_rx_pkt+0x5f7/0x19b0 [bnxt_en] [56251.885665] ? cpu_max_write+0x1e/0x100 [56251.893510] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.902276] __bnxt_poll_work+0x190/0x340 [bnxt_en] [56251.911058] bnxt_poll+0xab/0x1b0 [bnxt_en] [56251.919041] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.927568] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.935958] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.944250] __napi_poll+0x2b/0x160 [56251.951155] bpf_trampoline_6442548651+0x79/0x123 [56251.959262] __napi_poll+0x5/0x160 [56251.966037] net_rx_action+0x3d2/0x880 [56251.973133] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.981265] ? srso_alias_return_thunk+0x5/0xfbef5 [56251.989262] ? __hrtimer_run_queues+0x162/0x2a0 [56251.996967] ? srso_alias_return_thunk+0x5/0xfbef5 [56252.004875] ? srso_alias_return_thunk+0x5/0xfbef5 [56252.012673] ? bnxt_msix+0x62/0x70 [bnxt_en] [56252.019903] handle_softirqs+0xcf/0x270 [56252.026650] irq_exit_rcu+0x67/0x90 [56252.032933] common_interrupt+0x85/0xa0 [56252.039498] \u003c/IRQ\u003e [56252.044246] \u003cTASK\u003e [56252.048935] asm_common_interrupt+0x26/0x40 [56252.055727] RIP: 0010:cpuidle_enter_state+0xb8/0x420 [56252.063305] Code: dc 01 00 00 e8 f9 79 3b ff e8 64 f7 ff ff 49 89 c5 0f 1f 44 00 00 31 ff e8 a5 32 3a ff 45 84 ff 0f 85 ae 01 00 00 fb 45 85 f6 \u003c0f\u003e 88 88 01 00 00 48 8b 04 24 49 63 ce 4c 89 ea 48 6b f1 68 48 29 [56252.088911] RSP: 0018:ffff93120c97fe98 EFLAGS: 00000202 [56252.096912] RAX: ffff9149afd80000 RBX: ffff9141d3a72800 RCX: 0000000000000000 [56252.106844] RDX: 00003329176c6b98 RSI: ffffffe36db3fdc7 RDI: 0000000000000000 [56252.116733] RBP: 0000000000000002 R08: 0000000000000002 R09: 000000000000004e [56252.126652] R10: ffff9149afdb30c4 R11: 071c71c71c71c71c R12: ffffffff985ff860 [56252.136637] R13: 00003329176c6b98 R14: 0000000000000002 R15: 0000000000000000 [56252.146667] ? cpuidle_enter_state+0xab/0x420 [56252.153909] cpuidle_enter+0x2d/0x40 [56252.160360] do_idle+0x176/0x1c0 [56252.166456 ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38246", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wTS7c0AxSF244WIdQ/+I+A==": { "id": "wTS7c0AxSF244WIdQ/+I+A==", "updater": "debian/updater", "name": "CVE-2026-46153", "description": "In the Linux kernel, the following vulnerability has been resolved: 8021q: delete cleared egress QoS mappings vlan_dev_set_egress_priority() currently keeps cleared egress priority mappings in the hash as tombstones. Repeated set/clear cycles with distinct skb priorities therefore accumulate mapping nodes until device teardown and leak memory. Delete mappings when vlan_prio is cleared instead of keeping tombstones. Now that the egress mapping lists are RCU protected, the node can be unlinked safely and freed after a grace period.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46153", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wZs/M549D013OPgW4vrJnA==": { "id": "wZs/M549D013OPgW4vrJnA==", "updater": "debian/updater", "name": "CVE-2026-8376", "description": "Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-8376", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "perl", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wcariq6PZUM/OyBFO8n8xg==": { "id": "wcariq6PZUM/OyBFO8n8xg==", "updater": "debian/updater", "name": "CVE-2026-33165", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-33165", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "weYaCmbTKCL+KzAIPHVOWg==": { "id": "weYaCmbTKCL+KzAIPHVOWg==", "updater": "debian/updater", "name": "CVE-2026-3713", "description": "A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3713", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "libpng1.6", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wk03AYMKhB6F5bR6XyAsHA==": { "id": "wk03AYMKhB6F5bR6XyAsHA==", "updater": "debian/updater", "name": "CVE-2022-44034", "description": "An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2022-44034", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wkt0wH2J5e6j3zvwUjQ4QA==": { "id": "wkt0wH2J5e6j3zvwUjQ4QA==", "updater": "debian/updater", "name": "CVE-2026-6464", "description": "Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the \"COPY FROM STDIN\" or \"\\copy FROM STDIN\" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. \"COPY FROM\" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6464", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "postgresql-15", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wlPVMVy1Dt3H81fmbPL0kQ==": { "id": "wlPVMVy1Dt3H81fmbPL0kQ==", "updater": "debian/updater", "name": "CVE-2026-43258", "description": "In the Linux kernel, the following vulnerability has been resolved: alpha: fix user-space corruption during memory compaction Alpha systems can suffer sporadic user-space crashes and heap corruption when memory compaction is enabled. Symptoms include SIGSEGV, glibc allocator failures (e.g. \"unaligned tcache chunk\"), and compiler internal errors. The failures disappear when compaction is disabled or when using global TLB invalidation. The root cause is insufficient TLB shootdown during page migration. Alpha relies on ASN-based MM context rollover for instruction cache coherency, but this alone is not sufficient to prevent stale data or instruction translations from surviving migration. Fix this by introducing a migration-specific helper that combines: - MM context invalidation (ASN rollover), - immediate per-CPU TLB invalidation (TBI), - synchronous cross-CPU shootdown when required. The helper is used only by migration/compaction paths to avoid changing global TLB semantics. Additionally, update flush_tlb_other(), pte_clear(), to use READ_ONCE()/WRITE_ONCE() for correct SMP memory ordering. This fixes observed crashes on both UP and SMP Alpha systems.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43258", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wlbPXuepg4Ytqm0bj0dYBQ==": { "id": "wlbPXuepg4Ytqm0bj0dYBQ==", "updater": "debian/updater", "name": "CVE-2026-68229", "description": "In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list entries Cedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the stateless slice control and later uses their indices to look up decode-\u003edpb[] in _cedrus_write_ref_list(). Rejecting such controls in cedrus_try_ctrl() would break existing userspace, since stateless H.264 reference lists may legitimately carry out-of-range indices for missing references. Instead, guard the actual DPB lookup in Cedrus and skip entries whose indices do not fit the fixed V4L2_H264_NUM_DPB_ENTRIES array. This keeps the fix local to the driver use site and avoids out-of-bounds reads from malformed or unsupported reference list entries.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68229", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wmEQj7183akagcy0qXiDCQ==": { "id": "wmEQj7183akagcy0qXiDCQ==", "updater": "debian/updater", "name": "CVE-2026-68106", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd dimensions When width or height is less than 16, width_in_mb or height_in_mb becomes 0, leading to fs_in_mb being 0. This causes a division by zero when calculating num_dpb_buffer in H264 and H264 Perf decode paths. Add validation to reject frames with width \u003c 16 or height \u003c 16 before performing any calculations that depend on these values. V2: Format change - move up all vaiable definitions. V3: Use warn_once to avoid spam. (cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68106", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wrlJJ6sFbDY2toPNxc+sAA==": { "id": "wrlJJ6sFbDY2toPNxc+sAA==", "updater": "debian/updater", "name": "CVE-2026-49346", "description": "libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_image()` call computes the real size using `size_t`, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-49346", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "libde265", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wrnZx9IDlFkjjZFNqfm5BA==": { "id": "wrnZx9IDlFkjjZFNqfm5BA==", "updater": "debian/updater", "name": "CVE-2026-64190", "description": "In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmit during mode change __team_change_mode() clears team-\u003eops with memset() before restoring safe dummy handlers via team_adjust_ops(). A concurrent team_xmit() running under RCU on another CPU can read team-\u003eops.transmit during this window and call a NULL function pointer, crashing the kernel. The race requires a mode change (CAP_NET_ADMIN) concurrent with transmit on the team device. BUG: kernel NULL pointer dereference, address: 0000000000000000 Oops: 0010 [#1] SMP KASAN NOPTI RIP: 0010:0x0 Call Trace: team_xmit (drivers/net/team/team_core.c:1853) dev_hard_start_xmit (net/core/dev.c:3904) __dev_queue_xmit (net/core/dev.c:4871) packet_sendmsg (net/packet/af_packet.c:3109) __sys_sendto (net/socket.c:2265) The original code assumed that no ports means no traffic, so mode changes could freely memset()/memcpy() the ops. AF_PACKET with forced carrier breaks that assumption. Prevent the race instead of making it safe: replace memset()/memcpy() with per-field updates that never touch transmit or receive. Those two handlers are managed solely by team_adjust_ops(), which already installs dummies when tx_en_port_count == 0 (always true during mode change since no ports are present). WRITE_ONCE/READ_ONCE prevent store/load tearing on the handler pointers. synchronize_net() before exit_op() drains in-flight readers that may still reference old mode state from before port removal switched the handlers to dummies.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64190", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wtkule9yShYfYhihK8c/yg==": { "id": "wtkule9yShYfYhihK8c/yg==", "updater": "debian/updater", "name": "CVE-2024-21803", "description": "Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. This issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-21803", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "wwkdl2CLVEKYg/La3pFh0g==": { "id": "wwkdl2CLVEKYg/La3pFh0g==", "updater": "debian/updater", "name": "CVE-2025-71184", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL dereference on root when tracing inode eviction When evicting an inode the first thing we do is to setup tracing for it, which implies fetching the root's id. But in btrfs_evict_inode() the root might be NULL, as implied in the next check that we do in btrfs_evict_inode(). Hence, we either should set the -\u003eroot_objectid to 0 in case the root is NULL, or we move tracing setup after checking that the root is not NULL. Setting the rootid to 0 at least gives us the possibility to trace this call even in the case when the root is NULL, so that's the solution taken here.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-71184", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x1sJYHj1Yii3cb3WNbR0ww==": { "id": "x1sJYHj1Yii3cb3WNbR0ww==", "updater": "debian/updater", "name": "CVE-2019-19814", "description": "In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-19814", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x3ENI1lyHKRf/UfhURYpGA==": { "id": "x3ENI1lyHKRf/UfhURYpGA==", "updater": "debian/updater", "name": "CVE-2026-68259", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT allocate_event_notification_slot has an option to specify an event id to allocate at, used by CRIU. We weren't checking the bounds on that value. Check them. v2: Lower bounds check is unecessary because of idr_alloc already rejecting negative numbers. Upper bounds check should be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might not yet exist (cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68259", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x3ki/oOD8DwpAiHeGtGXsQ==": { "id": "x3ki/oOD8DwpAiHeGtGXsQ==", "updater": "debian/updater", "name": "CVE-2026-11850", "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len \u003c 2, triggering the underflow when the KDC or kadmind reads principal data.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-11850", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "krb5", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x5kJV0vUXZM8gQjTU1an7g==": { "id": "x5kJV0vUXZM8gQjTU1an7g==", "updater": "debian/updater", "name": "CVE-2026-46282", "description": "In the Linux kernel, the following vulnerability has been resolved: iio: frequency: admv1013: fix NULL pointer dereference on str When device_property_read_string() fails, str is left uninitialized but the code falls through to strcmp(str, ...), dereferencing a garbage pointer. Replace manual read/strcmp with device_property_match_property_string() and consolidate the SE mode enums into a single sequential enum, mapping to hardware register values via a switch consistent with other bitfields in the driver. Several cleanup patches have been applied to this driver recently so this will need a manual backport.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46282", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "x6czAHpLprQs9jos235U1w==": { "id": "x6czAHpLprQs9jos235U1w==", "updater": "debian/updater", "name": "CVE-2026-43288", "description": "In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_init() When running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the `DOUBLE_CHECK` macro defined, the following panic is triggered: ================================================================== EXT4-fs error (device vdc): ext4_validate_block_bitmap:423: comm mount: bg 0: bad block bitmap checksum BUG: unable to handle page fault for address: ff110000fa2cc000 PGD 3e01067 P4D 3e02067 PUD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 2386 Comm: mount Tainted: G W 6.18.0-gba65a4e7120a-dirty #1152 PREEMPT(none) RIP: 0010:percpu_counter_add_batch+0x13/0xa0 Call Trace: \u003cTASK\u003e ext4_mark_group_bitmap_corrupted+0xcb/0xe0 ext4_validate_block_bitmap+0x2a1/0x2f0 ext4_read_block_bitmap+0x33/0x50 mb_group_bb_bitmap_alloc+0x33/0x80 ext4_mb_add_groupinfo+0x190/0x250 ext4_mb_init_backend+0x87/0x290 ext4_mb_init+0x456/0x640 __ext4_fill_super+0x1072/0x1680 ext4_fill_super+0xd3/0x280 get_tree_bdev_flags+0x132/0x1d0 vfs_get_tree+0x29/0xd0 vfs_cmd_create+0x59/0xe0 __do_sys_fsconfig+0x4f6/0x6b0 do_syscall_64+0x50/0x1f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e ================================================================== This issue can be reproduced using the following commands: mkfs.ext4 -F -q -b 1024 /dev/sda 5G tune2fs -O quota,project /dev/sda mount /dev/sda /tmp/test With DOUBLE_CHECK defined, mb_group_bb_bitmap_alloc() reads and validates the block bitmap. When the validation fails, ext4_mark_group_bitmap_corrupted() attempts to update sbi-\u003es_freeclusters_counter. However, this percpu_counter has not been initialized yet at this point, which leads to the panic described above. Fix this by moving the execution of ext4_percpu_param_init() to occur before ext4_mb_init(), ensuring the per-CPU counters are initialized before they are used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43288", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xCLaWjPzCBcp97ve36KSvg==": { "id": "xCLaWjPzCBcp97ve36KSvg==", "updater": "debian/updater", "name": "CVE-2026-68369", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: printer: fix infinite loop in printer_read() printer_read() uses the same variable for the requested copy size and the number of bytes actually copied to user space. copy_to_user() returns the number of bytes not copied, so when it fails to copy anything, the computed copied length becomes zero. In that case len, buf, current_rx_bytes and current_rx_buf are left unchanged. If RX data is available and the user buffer remains unwritable, the read loop can repeat indefinitely. Track the copied length separately and return -EFAULT, or the number of bytes already copied, if an iteration makes no progress.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68369", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xDsyjQG9Zgm7g+ZylJSSMw==": { "id": "xDsyjQG9Zgm7g+ZylJSSMw==", "updater": "debian/updater", "name": "CVE-2007-2768", "description": "OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2007-2768", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openssh", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xERS7Vmbh+h18uOunvn0Vg==": { "id": "xERS7Vmbh+h18uOunvn0Vg==", "updater": "debian/updater", "name": "CVE-2024-58095", "description": "In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call Added a read-only check before calling `txBeginAnon` in `extAlloc` and `extRecord`. This prevents modification attempts on a read-only mounted filesystem, avoiding potential errors or crashes. Call trace: txBeginAnon+0xac/0x154 extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78 jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248 __block_write_begin_int+0x580/0x166c fs/buffer.c:2128 __block_write_begin fs/buffer.c:2177 [inline] block_write_begin+0x98/0x11c fs/buffer.c:2236 jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-58095", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xG3XYfxHNvVASsY6AJHqYg==": { "id": "xG3XYfxHNvVASsY6AJHqYg==", "updater": "debian/updater", "name": "CVE-2026-68328", "description": "In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock(). However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource. nfp_resource_acquire() already treats failure to allocate the table mutex as -ENOMEM. Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle. This issue was found by a static analysis checker and confirmed by manual source review.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68328", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xGaIha/H9yzz7QrGLN0uhQ==": { "id": "xGaIha/H9yzz7QrGLN0uhQ==", "updater": "debian/updater", "name": "CVE-2026-63856", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit e2b5499fca55f1a32960a311bbb62e35891eaf73)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63856", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xMNRfv9b++Qx2IGpA34qeA==": { "id": "xMNRfv9b++Qx2IGpA34qeA==", "updater": "debian/updater", "name": "CVE-2025-66382", "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-66382", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "expat", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xPA4Kcui1ANUz/lomxAogQ==": { "id": "xPA4Kcui1ANUz/lomxAogQ==", "updater": "debian/updater", "name": "CVE-2026-31493", "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix use of completion ctx after free On admin queue completion handling, if the admin command completed with error we print data from the completion context. The issue is that we already freed the completion context in polling/interrupts handler which means we print data from context in an unknown state (it might be already used again). Change the admin submission flow so alloc/dealloc of the context will be symmetric and dealloc will be called after any potential use of the context.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31493", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xeEtsv5WJ/XPZImtAV/B2Q==": { "id": "xeEtsv5WJ/XPZImtAV/B2Q==", "updater": "debian/updater", "name": "CVE-2024-26866", "description": "In the Linux kernel, the following vulnerability has been resolved: spi: lpspi: Avoid potential use-after-free in probe() fsl_lpspi_probe() is allocating/disposing memory manually with spi_alloc_host()/spi_alloc_target(), but uses devm_spi_register_controller(). In case of error after the latter call the memory will be explicitly freed in the probe function by spi_controller_put() call, but used afterwards by \"devm\" management outside probe() (spi_unregister_controller() \u003c- devm_spi_unregister() below). Unable to handle kernel NULL pointer dereference at virtual address 0000000000000070 ... Call trace: kernfs_find_ns kernfs_find_and_get_ns sysfs_remove_group sysfs_remove_groups device_remove_attrs device_del spi_unregister_controller devm_spi_unregister release_nodes devres_release_all really_probe driver_probe_device __device_attach_driver bus_for_each_drv __device_attach device_initial_probe bus_probe_device deferred_probe_work_func process_one_work worker_thread kthread ret_from_fork", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26866", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xiMAJpHW80LOtYFONrCzjA==": { "id": "xiMAJpHW80LOtYFONrCzjA==", "updater": "debian/updater", "name": "CVE-2026-6791", "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6791", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "glibc", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xj88t0vf170EWiUK/oDBXA==": { "id": "xj88t0vf170EWiUK/oDBXA==", "updater": "debian/updater", "name": "CVE-2026-64036", "description": "In the Linux kernel, the following vulnerability has been resolved: cgroup/rstat: validate cpu before css_rstat_cpu() access css_rstat_updated() is exposed as a BPF kfunc and accepts a caller-provided cpu argument. The function uses cpu for per-cpu rstat lookups without checking whether it refers to a valid possible CPU. A BPF iter/cgroup program with CAP_BPF and CAP_PERFMON can pass an invalid cpu value. On an unfixed UBSCAN_BOUNDS test kernel, cpu == 0x7fffffff triggers: UBSAN: array-index-out-of-bounds in kernel/cgroup/rstat.c:31:9 index 2147483647 is out of range for type 'long unsigned int [64]' Call Trace: css_rstat_updated bpf_iter_run_prog cgroup_iter_seq_show bpf_seq_read Add cpu validation to the BPF-facing css_rstat_updated() kfunc and move the common implementation to __css_rstat_updated() for in-kernel callers.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64036", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xjRUORCyUNEkviQdyP2FeA==": { "id": "xjRUORCyUNEkviQdyP2FeA==", "updater": "debian/updater", "name": "CVE-2026-31648", "description": "In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() When running stress-ng on my Arm64 machine with v7.0-rc3 kernel, I encountered some very strange crash issues showing up as \"Bad page state\": \" [ 734.496287] BUG: Bad page state in process stress-ng-env pfn:415735fb [ 734.496427] page: refcount:0 mapcount:1 mapping:0000000000000000 index:0x4cf316 pfn:0x415735fb [ 734.496434] flags: 0x57fffe000000800(owner_2|node=1|zone=2|lastcpupid=0x3ffff) [ 734.496439] raw: 057fffe000000800 0000000000000000 dead000000000122 0000000000000000 [ 734.496440] raw: 00000000004cf316 0000000000000000 0000000000000000 0000000000000000 [ 734.496442] page dumped because: nonzero mapcount \" After analyzing this page’s state, it is hard to understand why the mapcount is not 0 while the refcount is 0, since this page is not where the issue first occurred. By enabling the CONFIG_DEBUG_VM config, I can reproduce the crash as well and captured the first warning where the issue appears: \" [ 734.469226] page: refcount:33 mapcount:0 mapping:00000000bef2d187 index:0x81a0 pfn:0x415735c0 [ 734.469304] head: order:5 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 734.469315] memcg:ffff000807a8ec00 [ 734.469320] aops:ext4_da_aops ino:100b6f dentry name(?):\"stress-ng-mmaptorture-9397-0-2736200540\" [ 734.469335] flags: 0x57fffe400000069(locked|uptodate|lru|head|node=1|zone=2|lastcpupid=0x3ffff) ...... [ 734.469364] page dumped because: VM_WARN_ON_FOLIO((_Generic((page + nr_pages - 1), const struct page *: (const struct folio *)_compound_head(page + nr_pages - 1), struct page *: (struct folio *)_compound_head(page + nr_pages - 1))) != folio) [ 734.469390] ------------[ cut here ]------------ [ 734.469393] WARNING: ./include/linux/rmap.h:351 at folio_add_file_rmap_ptes+0x3b8/0x468, CPU#90: stress-ng-mlock/9430 [ 734.469551] folio_add_file_rmap_ptes+0x3b8/0x468 (P) [ 734.469555] set_pte_range+0xd8/0x2f8 [ 734.469566] filemap_map_folio_range+0x190/0x400 [ 734.469579] filemap_map_pages+0x348/0x638 [ 734.469583] do_fault_around+0x140/0x198 ...... [ 734.469640] el0t_64_sync+0x184/0x188 \" The code that triggers the warning is: \"VM_WARN_ON_FOLIO(page_folio(page + nr_pages - 1) != folio, folio)\", which indicates that set_pte_range() tried to map beyond the large folio’s size. By adding more debug information, I found that 'nr_pages' had overflowed in filemap_map_pages(), causing set_pte_range() to establish mappings for a range exceeding the folio size, potentially corrupting fields of pages that do not belong to this folio (e.g., page-\u003e_mapcount). After above analysis, I think the possible race is as follows: CPU 0 CPU 1 filemap_map_pages() ext4_setattr() //get and lock folio with old inode-\u003ei_size next_uptodate_folio() ....... //shrink the inode-\u003ei_size i_size_write(inode, attr-\u003eia_size); //calculate the end_pgoff with the new inode-\u003ei_size file_end = DIV_ROUND_UP(i_size_read(mapping-\u003ehost), PAGE_SIZE) - 1; end_pgoff = min(end_pgoff, file_end); ...... //nr_pages can be overflowed, cause xas.xa_index \u003e end_pgoff end = folio_next_index(folio) - 1; nr_pages = min(end, end_pgoff) - xas.xa_index + 1; ...... //map large folio filemap_map_folio_range() ...... //truncate folios truncate_pagecache(inode, inode-\u003ei_size); To fix this issue, move the 'end_pgoff' calculation before next_uptodate_folio(), so the retrieved folio stays consistent with the file end to avoid ---truncated---", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31648", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xnkuVi8+JWohMGvbl0FkUw==": { "id": "xnkuVi8+JWohMGvbl0FkUw==", "updater": "debian/updater", "name": "CVE-2026-68157", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then dereferences a NULL type_cn and passes an invalid pointer into strcmp(), causing a null-ptr-deref. Skip such malformed parent buckets unless both the bucket name and type name metadata are present. This keeps malformed hierarchy data from crashing locality lookup and safely falls back to \"not local\". [ idryomov: add WARN_ON_ONCE ]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68157", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xriqbRDjo9/OFxZ2ulgl4w==": { "id": "xriqbRDjo9/OFxZ2ulgl4w==", "updater": "debian/updater", "name": "CVE-2026-53024", "description": "In the Linux kernel, the following vulnerability has been resolved: greybus: raw: fix use-after-free if write is called after disconnect If a user writes to the chardev after disconnect has been called, the kernel panics with the following trace (with CONFIG_INIT_ON_FREE_DEFAULT_ON=y): BUG: kernel NULL pointer dereference, address: 0000000000000218 ... Call Trace: \u003cTASK\u003e gb_operation_create_common+0x61/0x180 gb_operation_create_flags+0x28/0xa0 gb_operation_sync_timeout+0x6f/0x100 raw_write+0x7b/0xc7 [gb_raw] vfs_write+0xcf/0x420 ? task_mm_cid_work+0x136/0x220 ksys_write+0x63/0xe0 do_syscall_64+0xa4/0x290 entry_SYSCALL_64_after_hwframe+0x77/0x7f Disconnect calls gb_connection_destroy, which ends up freeing the connection object. When gb_operation_sync is called in the write file operations, its gets a freed connection as parameter and the kernel panics. The gb_connection_destroy cannot be moved out of the disconnect function, as the Greybus subsystem expect all connections belonging to a bundle to be destroyed when disconnect returns. To prevent this bug, use a rw lock to synchronize access between write and disconnect. This guarantees that the write function doesn't try to use a disconnected connection.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53024", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xtYvwG9pXlzZuhCh/01L8w==": { "id": "xtYvwG9pXlzZuhCh/01L8w==", "updater": "debian/updater", "name": "CVE-2023-4010", "description": "A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a logic loophole in its implementation. Due to the inappropriate judgment condition of the goto statement, the function cannot return under the input of a specific malformed descriptor file, so it falls into an endless loop, resulting in a denial of service.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-4010", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xvthDFTRm9NDIq9MylnUog==": { "id": "xvthDFTRm9NDIq9MylnUog==", "updater": "debian/updater", "name": "CVE-2026-43161", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode PCIe endpoints with ATS enabled and passed through to userspace (e.g., QEMU, DPDK) can hard-lock the host when their link drops, either by surprise removal or by a link fault. Commit 4fc82cd907ac (\"iommu/vt-d: Don't issue ATS Invalidation request when device is disconnected\") adds pci_dev_is_disconnected() to devtlb_invalidation_with_pasid() so ATS invalidation is skipped only when the device is being safely removed, but it applies only when Intel IOMMU scalable mode is enabled. With scalable mode disabled or unsupported, a system hard-lock occurs when a PCIe endpoint's link drops because the Intel IOMMU waits indefinitely for an ATS invalidation that cannot complete. Call Trace: qi_submit_sync qi_flush_dev_iotlb __context_flush_dev_iotlb.part.0 domain_context_clear_one_cb pci_for_each_dma_alias device_block_translation blocking_domain_attach_dev iommu_deinit_device __iommu_group_remove_device iommu_release_device iommu_bus_notifier blocking_notifier_call_chain bus_notify device_del pci_remove_bus_device pci_stop_and_remove_bus_device pciehp_unconfigure_device pciehp_disable_slot pciehp_handle_presence_or_link_change pciehp_ist Commit 81e921fd3216 (\"iommu/vt-d: Fix NULL domain on device release\") adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(), which calls qi_flush_dev_iotlb() and can also hard-lock the system when a PCIe endpoint's link drops. Call Trace: qi_submit_sync qi_flush_dev_iotlb __context_flush_dev_iotlb.part.0 intel_context_flush_no_pasid device_pasid_table_teardown pci_pasid_table_teardown pci_for_each_dma_alias intel_pasid_teardown_sm_context intel_iommu_release_device iommu_deinit_device __iommu_group_remove_device iommu_release_device iommu_bus_notifier blocking_notifier_call_chain bus_notify device_del pci_remove_bus_device pci_stop_and_remove_bus_device pciehp_unconfigure_device pciehp_disable_slot pciehp_handle_presence_or_link_change pciehp_ist Sometimes the endpoint loses connection without a link-down event (e.g., due to a link fault); killing the process (virsh destroy) then hard-locks the host. Call Trace: qi_submit_sync qi_flush_dev_iotlb __context_flush_dev_iotlb.part.0 domain_context_clear_one_cb pci_for_each_dma_alias device_block_translation blocking_domain_attach_dev __iommu_attach_device __iommu_device_set_domain __iommu_group_set_domain_internal iommu_detach_group vfio_iommu_type1_detach_group vfio_group_detach_container vfio_group_fops_release __fput pci_dev_is_disconnected() only covers safe-removal paths; pci_device_is_present() tests accessibility by reading vendor/device IDs and internally calls pci_dev_is_disconnected(). On a ConnectX-5 (8 GT/s, x2) this costs ~70 µs. Since __context_flush_dev_iotlb() is only called on {attach,release}_dev paths (not hot), add pci_device_is_present() there to skip inaccessible devices and avoid the hard-lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43161", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xxxPnTr/pbG0N6W/pNDcWQ==": { "id": "xxxPnTr/pbG0N6W/pNDcWQ==", "updater": "debian/updater", "name": "CVE-2026-54371", "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-54371", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "attr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "xy63wlE2Qejaz4vatxOqZA==": { "id": "xy63wlE2Qejaz4vatxOqZA==", "updater": "debian/updater", "name": "CVE-2026-68310", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: guard HE capability lookups mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after checking HE support, then dereference the HE PHY capability returned by mt76_connac_get_he_phy_cap(). That helper can return NULL when no capability entry matches the vif type. Fetch the capability before appending the TLV and skip the HE-specific setup when no matching capability is available.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68310", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y1HQd46JFnDNpDsOnGPiTA==": { "id": "y1HQd46JFnDNpDsOnGPiTA==", "updater": "debian/updater", "name": "CVE-2026-53027", "description": "In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() When a compressed or sparse attribute has its clusters frame-aligned, vcn is rounded down to the frame start using cmask, which can result in vcn != vcn0. In this case, vcn and vcn0 may reside in different attribute segments. The code already handles the case where vcn is in a different segment by loading its runs before allocation. However, it fails to load runs for vcn0 when vcn0 resides in a different segment than vcn. This causes run_lookup_entry() to return SPARSE_LCN for vcn0 since its segment was never loaded into the in-memory run list, triggering the WARN_ON(1). Fix this by adding a missing check for vcn0 after the existing vcn segment check. If vcn0 falls outside the current segment range [svcn, evcn1), find and load the attribute segment containing vcn0 before performing the run lookup. The following scenario triggers the bug: attr_data_get_block_locked() vcn = vcn0 \u0026 cmask \u003c- vcn != vcn0 after frame alignment load runs for vcn segment \u003c- vcn0 segment not loaded! attr_allocate_clusters() \u003c- allocation succeeds run_lookup_entry(vcn0) \u003c- vcn0 not in run -\u003e SPARSE_LCN WARN_ON(1) \u003c- bug fires here!", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53027", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y1e/8gBt80FYuAfr84vIvw==": { "id": "y1e/8gBt80FYuAfr84vIvw==", "updater": "debian/updater", "name": "CVE-2026-31767", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode Stop adjusting the horizontal timing values based on the compression ratio in command mode. Bspec seems to be telling us to do this only in video mode, and this is also how the Windows driver does things. This should also fix a div-by-zero on some machines because the adjusted htotal ends up being so small that we end up with line_time_us==0 when trying to determine the vtotal value in command mode. Note that this doesn't actually make the display on the Huawei Matebook E work, but at least the kernel no longer explodes when the driver loads. (cherry picked from commit 0b475e91ecc2313207196c6d7fd5c53e1a878525)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31767", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y2QOurRj7ZwMObpAZgLNxQ==": { "id": "y2QOurRj7ZwMObpAZgLNxQ==", "updater": "debian/updater", "name": "CVE-2026-68386", "description": "In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject unhashed UDP sockets on sockmap update UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means sk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false. Because sockmap accepts unbound UDP sockets, a BPF program can increment a socket's refcount via lookup. If the socket is subsequently bound, the transition from unbound to bound causes bpf_sk_release() to skip the decrement of the refcount, causing a memory leak. unreferenced object 0xffff88810bc2eb40 (size 1984): comm \"test_progs\", pid 2451, jiffies 4295320596 hex dump (first 32 bytes): 7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00 ................ 02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............ backtrace (crc bdee079d): kmem_cache_alloc_noprof+0x557/0x660 sk_prot_alloc+0x69/0x240 sk_alloc+0x30/0x460 inet_create+0x2ce/0xf80 __sock_create+0x25b/0x5c0 __sys_socket+0x119/0x1d0 __x64_sys_socket+0x72/0xd0 do_syscall_64+0xa1/0x5f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e Instead of special-casing for refcounted sockets, reject unhashed UDP sockets during sockmap updates, as there is no benefit to supporting those. This effectively reverts the commit under Fixes, with two exceptions: 1. sock_map_sk_state_allowed() maintains a fall-through `return true`. 2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash handler for BPF sockmap usage\"), the proto::unhash BPF handler is not reintroduced. Historical note: this issue is related to commit 67312adc96b5 (\"bpf: reject unhashed sockets in bpf_sk_assign\").", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68386", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y4OfweUpVYO2q8iu0jkLbA==": { "id": "y4OfweUpVYO2q8iu0jkLbA==", "updater": "debian/updater", "name": "CVE-2026-68138", "description": "In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no lock. This was only safe because every caller historically held the RTNL mutex, which serialized all rate-table lookups, inserts and frees. That invariant no longer holds. cls_flower sets TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false for it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through tcf_exts_validate_ex() -\u003e tcf_action_init() -\u003e tcf_action_init_1() -\u003e tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each adding a flower filter with a police action carrying the same rate, then race on qdisc_rtab_list and on the non-atomic refcnt, leading to a use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table. qdisc_rtab_list is a single global (not per-netns), so the corrupted object is shared system-wide. BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160 qdisc_put_rtab+0x12f/0x160 tcf_police_init+0xda9/0x1590 tcf_action_init_1+0x460/0x6b0 tcf_action_init+0x439/0xa40 tcf_exts_validate_ex+0x42d/0x550 fl_change+0xddd/0x7da0 tc_new_tfilter+0xaa7/0x2420 rtnetlink_rcv_msg+0x95e/0xe90 which belongs to the cache kmalloc-2k of size 2048 Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The (sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before taking the lock; if a concurrent inserter added an identical table in the meantime the freshly allocated one is freed under the lock, so no duplicate is leaked. qdisc_put_rtab() now decrements the refcount and unlinks under the same lock.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68138", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "y7pmgQLzMRq88J/vS93z2Q==": { "id": "y7pmgQLzMRq88J/vS93z2Q==", "updater": "debian/updater", "name": "CVE-2024-26913", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue [why] odm calculation is missing for pipe split policy determination and cause Underflow/Corruption issue. [how] Add the odm calculation.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26913", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yC4kMoTeidkpBuUtWAJFzQ==": { "id": "yC4kMoTeidkpBuUtWAJFzQ==", "updater": "debian/updater", "name": "CVE-2026-68083", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an absolute path with convert_to_unix_name() and resolves it from AT_FDCWD via start_creating_path(), so a \"..\" component is walked from the real filesystem root and escapes the export. An authenticated client races a missing path component so the rooted open lookup returns -ENOENT (taking the create branch) while the same component is present (a directory) when the create walk runs; the create then resolves \"..\" out of the share. Root the create walk at the share like the lookup and rename paths already are: resolve the parent with vfs_path_parent_lookup(..., LOOKUP_BENEATH, \u0026share_conf-\u003evfs_path) and create the final component with start_creating_noperm(). convert_to_unix_name() then has no callers and is removed.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68083", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yCanNFrkzwkJ63UqSrp79w==": { "id": "yCanNFrkzwkJ63UqSrp79w==", "updater": "debian/updater", "name": "CVE-2026-23240", "description": "In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the tx_work_handler() worker may dereference a freed TLS object. The following is a simple race scenario: cpu0 cpu1 tls_sk_proto_close() tls_sw_cancel_work_tx() tls_write_space() tls_sw_write_space() if (!test_and_set_bit(BIT_TX_SCHEDULED, \u0026tx_ctx-\u003etx_bitmask)) set_bit(BIT_TX_SCHEDULED, \u0026ctx-\u003etx_bitmask); cancel_delayed_work_sync(\u0026ctx-\u003etx_work.work); schedule_delayed_work(\u0026tx_ctx-\u003etx_work.work, 0); To prevent this race condition, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23240", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yFRiUXE6QYAqPVgDGsvzCQ==": { "id": "yFRiUXE6QYAqPVgDGsvzCQ==", "updater": "debian/updater", "name": "CVE-2025-38059", "description": "In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid csum tree [BUG] When trying read-only scrub on a btrfs with rescue=idatacsums mount option, it will crash with the following call trace: BUG: kernel NULL pointer dereference, address: 0000000000000208 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page CPU: 1 UID: 0 PID: 835 Comm: btrfs Tainted: G O 6.15.0-rc3-custom+ #236 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:btrfs_lookup_csums_bitmap+0x49/0x480 [btrfs] Call Trace: \u003cTASK\u003e scrub_find_fill_first_stripe+0x35b/0x3d0 [btrfs] scrub_simple_mirror+0x175/0x290 [btrfs] scrub_stripe+0x5f7/0x6f0 [btrfs] scrub_chunk+0x9a/0x150 [btrfs] scrub_enumerate_chunks+0x333/0x660 [btrfs] btrfs_scrub_dev+0x23e/0x600 [btrfs] btrfs_ioctl+0x1dcf/0x2f80 [btrfs] __x64_sys_ioctl+0x97/0xc0 do_syscall_64+0x4f/0x120 entry_SYSCALL_64_after_hwframe+0x76/0x7e [CAUSE] Mount option \"rescue=idatacsums\" will completely skip loading the csum tree, so that any data read will not find any data csum thus we will ignore data checksum verification. Normally call sites utilizing csum tree will check the fs state flag NO_DATA_CSUMS bit, but unfortunately scrub does not check that bit at all. This results in scrub to call btrfs_search_slot() on a NULL pointer and triggered above crash. [FIX] Check both extent and csum tree root before doing any tree search.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38059", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yHxWeQY4NF97p65Vl25LJA==": { "id": "yHxWeQY4NF97p65Vl25LJA==", "updater": "debian/updater", "name": "CVE-2026-68414", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on unregister cfg80211_sched_scan_results() can queue rdev-\u003esched_scan_res_wk from a driver result notification while a scheduled scan request is present. The work callback recovers the containing cfg80211_registered_device and then locks the wiphy and walks the scheduled-scan request list. wiphy_unregister() already makes the wiphy unreachable and drains rdev work items before cfg80211_dev_free() can release the object, but it does not drain sched_scan_res_wk. A queued or running result work item can therefore cross the unregister/free boundary and access freed rdev state. The buggy scenario involves two paths, with each column showing the order within that path: scheduled-scan result path: unregister/free path: 1. cfg80211_sched_scan_results() 1. interface teardown stops and queues rdev-\u003esched_scan_res_wk. removes the scheduled scan request. 2. cfg80211_wq starts the work 2. wiphy_unregister() drains other item and recovers rdev. rdev work items. 3. The worker locks rdev-\u003ewiphy 3. cfg80211_dev_free() destroys and and walks rdev state. frees rdev. Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev work items. cancel_work_sync() removes a pending result notification and waits for an already running callback, so cfg80211_dev_free() cannot free rdev while this work item is still active. Validation reproduced this kernel report: BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530 Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211] Read of size 8 Call trace: dump_stack_lvl+0x66/0xa0 print_report+0xce/0x630 cfg80211_sched_scan_results_wk+0x4a6/0x530 srso_alias_return_thunk+0x5/0xfbef5 __virt_addr_valid+0x224/0x430 kasan_report+0xac/0xe0 lockdep_hardirqs_on_prepare+0xea/0x1a0 process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212) lock_is_held_type+0x8f/0x100 worker_thread+0x5ad/0xfd0 __kthread_parkme+0xc6/0x200 kthread+0x31e/0x410 trace_hardirqs_on+0x1a/0x170 ret_from_fork+0x576/0x810 __switch_to+0x57e/0xe20 __switch_to_asm+0x33/0x70 ret_from_fork_asm+0x1a/0x30", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68414", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yNXJBhSLoARmyawSPfJ6Kg==": { "id": "yNXJBhSLoARmyawSPfJ6Kg==", "updater": "debian/updater", "name": "CVE-2026-31527", "description": "In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31527", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yOmc2F+SacWrePdm/mxRGA==": { "id": "yOmc2F+SacWrePdm/mxRGA==", "updater": "debian/updater", "name": "CVE-2019-6462", "description": "An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2019-6462", "severity": "low", "normalized_severity": "Medium", "package": { "id": "", "name": "cairo", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yOp5kQck2BSi0PMC4MZ4YQ==": { "id": "yOp5kQck2BSi0PMC4MZ4YQ==", "updater": "debian/updater", "name": "CVE-2026-63854", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-63854", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yVXH9XGqUox0RMMoxgLASA==": { "id": "yVXH9XGqUox0RMMoxgLASA==", "updater": "debian/updater", "name": "CVE-2025-39789", "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The skcipher_walk functions can allocate memory and can fail, so checking for errors is necessary.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39789", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yXuVTfc0mJ3Wo1R5P81UaA==": { "id": "yXuVTfc0mJ3Wo1R5P81UaA==", "updater": "debian/updater", "name": "CVE-2026-53317", "description": "In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: Place upper limit on station AID Any station configured with an AID over 20 causes a firmware crash. This situation occurred in our testing using an AP interface on 7922 hardware, with a modified hostapd, sourced from Mediatek's OpenWRT feeds. In stock hostapd, station AIDs begin counting at 1, and this configuration is prevented with an upper limit on associated stations. However, the modified hostapd began allocation at 65, which caused the firmware to crash. This fix does not allow these AIDs to work, but will prevent the firmware crash. This crash was only seen on IFTYPE_AP interfaces, and the fix does not appear to have an effect on IFTYPE_STATION behavior.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53317", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yc6saAcs8xhmSH0uppstLg==": { "id": "yc6saAcs8xhmSH0uppstLg==", "updater": "debian/updater", "name": "CVE-2026-56288", "description": "GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-56288", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "patch", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ydliNt1/jU+MUM6MVtC2Pg==": { "id": "ydliNt1/jU+MUM6MVtC2Pg==", "updater": "debian/updater", "name": "CVE-2024-26902", "description": "In the Linux kernel, the following vulnerability has been resolved: perf: RISCV: Fix panic on pmu overflow handler (1 \u003c\u003c idx) of int is not desired when setting bits in unsigned long overflowed_ctrs, use BIT() instead. This panic happens when running 'perf record -e branches' on sophgo sg2042. [ 273.311852] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000098 [ 273.320851] Oops [#1] [ 273.323179] Modules linked in: [ 273.326303] CPU: 0 PID: 1475 Comm: perf Not tainted 6.6.0-rc3+ #9 [ 273.332521] Hardware name: Sophgo Mango (DT) [ 273.336878] epc : riscv_pmu_ctr_get_width_mask+0x8/0x62 [ 273.342291] ra : pmu_sbi_ovf_handler+0x2e0/0x34e [ 273.347091] epc : ffffffff80aecd98 ra : ffffffff80aee056 sp : fffffff6e36928b0 [ 273.354454] gp : ffffffff821f82d0 tp : ffffffd90c353200 t0 : 0000002ade4f9978 [ 273.361815] t1 : 0000000000504d55 t2 : ffffffff8016cd8c s0 : fffffff6e3692a70 [ 273.369180] s1 : 0000000000000020 a0 : 0000000000000000 a1 : 00001a8e81800000 [ 273.376540] a2 : 0000003c00070198 a3 : 0000003c00db75a4 a4 : 0000000000000015 [ 273.383901] a5 : ffffffd7ff8804b0 a6 : 0000000000000015 a7 : 000000000000002a [ 273.391327] s2 : 000000000000ffff s3 : 0000000000000000 s4 : ffffffd7ff8803b0 [ 273.398773] s5 : 0000000000504d55 s6 : ffffffd905069800 s7 : ffffffff821fe210 [ 273.406139] s8 : 000000007fffffff s9 : ffffffd7ff8803b0 s10: ffffffd903f29098 [ 273.413660] s11: 0000000080000000 t3 : 0000000000000003 t4 : ffffffff8017a0ca [ 273.421022] t5 : ffffffff8023cfc2 t6 : ffffffd9040780e8 [ 273.426437] status: 0000000200000100 badaddr: 0000000000000098 cause: 000000000000000d [ 273.434512] [\u003cffffffff80aecd98\u003e] riscv_pmu_ctr_get_width_mask+0x8/0x62 [ 273.441169] [\u003cffffffff80076bd8\u003e] handle_percpu_devid_irq+0x98/0x1ee [ 273.447562] [\u003cffffffff80071158\u003e] generic_handle_domain_irq+0x28/0x36 [ 273.454151] [\u003cffffffff8047a99a\u003e] riscv_intc_irq+0x36/0x4e [ 273.459659] [\u003cffffffff80c944de\u003e] handle_riscv_irq+0x4a/0x74 [ 273.465442] [\u003cffffffff80c94c48\u003e] do_irq+0x62/0x92 [ 273.470360] Code: 0420 60a2 6402 5529 0141 8082 0013 0000 0013 0000 (6d5c) b783 [ 273.477921] ---[ end trace 0000000000000000 ]--- [ 273.482630] Kernel panic - not syncing: Fatal exception in interrupt", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26902", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yiXUbBZMQbbOIJqoeHIgUg==": { "id": "yiXUbBZMQbbOIJqoeHIgUg==", "updater": "debian/updater", "name": "CVE-2026-64388", "description": "In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID were also explicitly set. Fix this by checking for posix_extensions in cifs_setattr_nounix() when updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map and set the ownership/group information on the server.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-64388", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yoDPsHBdnYBYvpUe6q83cA==": { "id": "yoDPsHBdnYBYvpUe6q83cA==", "updater": "debian/updater", "name": "CVE-2026-68297", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: fix u16 MTU truncation in media and bearer MTU validation Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied MTU values but only enforce a minimum bound, not a maximum. When a user sets the MTU to a value exceeding U16_MAX (65535), it passes validation but is silently truncated when assigned to u16 fields l-\u003emtu and l-\u003eadvertised_mtu in tipc_link_create(). Values like 65536 (0x10000) truncate to 0, causing a division by zero in tipc_link_set_queue_limits() which computes TIPC_MAX_PUBL / (l-\u003emtu / ITEM_SIZE). Other overflowing values (e.g. 65537-131071) produce small incorrect MTU values, resulting in link malfunction behaviors. Crash stack (triggered as unprivileged user via user namespace): tipc_link_set_queue_limits net/tipc/link.c:2531 tipc_link_create net/tipc/link.c:520 tipc_node_check_dest net/tipc/node.c:1279 tipc_disc_rcv net/tipc/discover.c:252 tipc_rcv net/tipc/node.c:2129 tipc_udp_recv net/tipc/udp_media.c:392 Two independent paths lack the upper bound check: 1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET) 2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET) Fix both by rejecting MTU values above U16_MAX.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68297", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yoNy2I2sbE5vTpot54Noqw==": { "id": "yoNy2I2sbE5vTpot54Noqw==", "updater": "debian/updater", "name": "CVE-2024-49901", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: Assign msm_gpu-\u003epdev earlier to avoid nullptrs There are some cases, such as the one uncovered by Commit 46d4efcccc68 (\"drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails\") where msm_gpu_cleanup() : platform_set_drvdata(gpu-\u003epdev, NULL); is called on gpu-\u003epdev == NULL, as the GPU device has not been fully initialized yet. Turns out that there's more than just the aforementioned path that causes this to happen (e.g. the case when there's speedbin data in the catalog, but opp-supported-hw is missing in DT). Assigning msm_gpu-\u003epdev earlier seems like the least painful solution to this, therefore do so. Patchwork: https://patchwork.freedesktop.org/patch/602742/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-49901", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yp6cTkkawZGD83epsBl2Ow==": { "id": "yp6cTkkawZGD83epsBl2Ow==", "updater": "debian/updater", "name": "CVE-2026-53246", "description": "In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie is parsed and its parameters are later walked by sctp_process_init() using sctp_walk_params(). However, the chunk header length of this cached INIT chunk was not validated against the remaining buffer in the COOKIE_ECHO payload. If the length field is inflated, the parameter walk can run beyond the actual received data, leading to out-of-bounds reads and potential memory corruption during later parameter handling (e.g. STATE_COOKIE processing and kmemdup() copies). Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT chunk length does not exceed the available data in the COOKIE_ECHO buffer before it is used.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53246", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ysl2vdVgh9O8e4G5gfWMJQ==": { "id": "ysl2vdVgh9O8e4G5gfWMJQ==", "updater": "debian/updater", "name": "CVE-2016-9580", "description": "An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2016-9580", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "openjpeg2", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "yzYZsRSpoGNn6ISpW/sHEA==": { "id": "yzYZsRSpoGNn6ISpW/sHEA==", "updater": "debian/updater", "name": "CVE-2024-26876", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/bridge: adv7511: fix crash on irq during probe Moved IRQ registration down to end of adv7511_probe(). If an IRQ already is pending during adv7511_probe (before adv7511_cec_init) then cec_received_msg_ts could crash using uninitialized data: Unable to handle kernel read from unreadable memory at virtual address 00000000000003d5 Internal error: Oops: 96000004 [#1] PREEMPT_RT SMP Call trace: cec_received_msg_ts+0x48/0x990 [cec] adv7511_cec_irq_process+0x1cc/0x308 [adv7511] adv7511_irq_process+0xd8/0x120 [adv7511] adv7511_irq_handler+0x1c/0x30 [adv7511] irq_thread_fn+0x30/0xa0 irq_thread+0x14c/0x238 kthread+0x190/0x1a8", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-26876", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z+0EdNHPSbtJAsK+7Y1ZjQ==": { "id": "z+0EdNHPSbtJAsK+7Y1ZjQ==", "updater": "debian/updater", "name": "CVE-2023-6228", "description": "An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-6228", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z/P7T8+QR8jnNiOGyPUwAQ==": { "id": "z/P7T8+QR8jnNiOGyPUwAQ==", "updater": "debian/updater", "name": "CVE-2025-21872", "description": "In the Linux kernel, the following vulnerability has been resolved: efi: Don't map the entire mokvar table to determine its size Currently, when validating the mokvar table, we (re)map the entire table on each iteration of the loop, adding space as we discover new entries. If the table grows over a certain size, this fails due to limitations of early_memmap(), and we get a failure and traceback: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 0 at mm/early_ioremap.c:139 __early_ioremap+0xef/0x220 ... Call Trace: \u003cTASK\u003e ? __early_ioremap+0xef/0x220 ? __warn.cold+0x93/0xfa ? __early_ioremap+0xef/0x220 ? report_bug+0xff/0x140 ? early_fixup_exception+0x5d/0xb0 ? early_idt_handler_common+0x2f/0x3a ? __early_ioremap+0xef/0x220 ? efi_mokvar_table_init+0xce/0x1d0 ? setup_arch+0x864/0xc10 ? start_kernel+0x6b/0xa10 ? x86_64_start_reservations+0x24/0x30 ? x86_64_start_kernel+0xed/0xf0 ? common_startup_64+0x13e/0x141 \u003c/TASK\u003e ---[ end trace 0000000000000000 ]--- mokvar: Failed to map EFI MOKvar config table pa=0x7c4c3000, size=265187. Mapping the entire structure isn't actually necessary, as we don't ever need more than one entry header mapped at once. Changes efi_mokvar_table_init() to only map each entry header, not the entire table, when determining the table size. Since we're not mapping any data past the variable name, it also changes the code to enforce that each variable name is NUL terminated, rather than attempting to verify it in place.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-21872", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z17t3PbfsUMbWVwOHNYPWQ==": { "id": "z17t3PbfsUMbWVwOHNYPWQ==", "updater": "debian/updater", "name": "CVE-2012-0039", "description": "GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2012-0039", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "glib2.0", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z2Bu+BjK4pQMOBBCKGJjaA==": { "id": "z2Bu+BjK4pQMOBBCKGJjaA==", "updater": "debian/updater", "name": "CVE-2026-23447", "description": "In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the end of the NTB. Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly. Compile-tested only.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-23447", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z2etEwwZ8zYYznKnP9hjUg==": { "id": "z2etEwwZ8zYYznKnP9hjUg==", "updater": "debian/updater", "name": "CVE-2026-68117", "description": "In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock-\u003esk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves sock-\u003esk pointing at the freed object: \tif (tipc_sk_insert(tsk)) { \t\tsk_free(sk); \t\tpr_warn(\"Socket create failed; port number exhausted\\n\"); \t\treturn -EINVAL; \t} This is harmless for plain socket(): the syscall layer clears sock-\u003eops before releasing, so tipc_release() is never called. It is not harmless on the accept() path. tipc_accept() creates the pre-allocated child socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves new_sock-\u003esk dangling and new_sock-\u003eops non-NULL, and do_accept() then fput()s the new file, so __sock_release() -\u003e tipc_release() runs lock_sock(new_sock-\u003esk) on the freed sk -- a use-after-free write of the sk_lock spinlock. tipc_release() already guards this exact \"failed accept() releases a pre-allocated child\" case with \"if (sk == NULL) return 0;\", but the guard is bypassed because tipc_sk_create() left sock-\u003esk non-NULL (dangling) rather than NULL. Clear sock-\u003esk on the failed-insert path so the existing tipc_release() NULL check fires and the use-after-free is avoided. The tipc_sk_insert() failure is reached when the per-netns socket rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M elements) -- i.e. once a netns holds ~2M TIPC sockets every insert returns -E2BIG. BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839) Write of size 8 at addr ffff8880047cdc38 by task init/1 lock_sock_nested (net/core/sock.c:3839) tipc_release (net/tipc/socket.c:638) __sock_release (net/socket.c:710) sock_close (net/socket.c:1501) __fput (fs/file_table.c:512) Allocated by task 1: sk_alloc (net/core/sock.c:2308) tipc_sk_create (net/tipc/socket.c:487) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034) Freed by task 1: __sk_destruct (net/core/sock.c:2391) tipc_sk_create (net/tipc/socket.c:504) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68117", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z2fCL2AfICNwA9BjUi3Dxg==": { "id": "z2fCL2AfICNwA9BjUi3Dxg==", "updater": "debian/updater", "name": "CVE-2026-46324", "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink hooks nft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need to use list_del_rcu(), this list can be walked by concurrent dumpers. Add a new helper and use it consistently.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-46324", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z2iJftUbGjAb9QpTXx8tdg==": { "id": "z2iJftUbGjAb9QpTXx8tdg==", "updater": "debian/updater", "name": "CVE-2026-42216", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-42216", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z4ATwTeQTJHH5b+Mhp9CIw==": { "id": "z4ATwTeQTJHH5b+Mhp9CIw==", "updater": "debian/updater", "name": "CVE-2026-43353", "description": "In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time. However, the function is not serialized and can race with itself. When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring. If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times. Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43353", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "z6sSH26cZGd5xHibpTYF7Q==": { "id": "z6sSH26cZGd5xHibpTYF7Q==", "updater": "debian/updater", "name": "CVE-2026-6846", "description": "A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-6846", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "binutils", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zBi4Vv0a6qBHfmWvyJVErg==": { "id": "zBi4Vv0a6qBHfmWvyJVErg==", "updater": "debian/updater", "name": "CVE-2026-34589", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34589", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zCgR7/0cLZ1DORVb0QZM2A==": { "id": "zCgR7/0cLZ1DORVb0QZM2A==", "updater": "debian/updater", "name": "CVE-2026-52956", "description": "In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This happens without any guarantee that the buffer is large enough to hold this struct. The function parameter ciphertext_len represents the length of the ciphertext to decrypt and is guaranteed to be at most the remaining size of the allocated buffer p. However, this value is not necessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message frame of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold the ciphertext at its end with a ciphertext_len of 8 or less, can trigger an out-of-bounds memory access when accessing hdr-\u003emagic. This patch fixes the issue by adding a check to ensure that the decrypted plaintext in the buffer is large enough to represent at least the ceph_x_encrypt_header.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-52956", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zDrzSYkrjMow2M7l8FVeow==": { "id": "zDrzSYkrjMow2M7l8FVeow==", "updater": "debian/updater", "name": "CVE-2024-35843", "description": "In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Use device rbtree in iopf reporting path The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with device_rbtree_find() to search the device within the probed device rbtree. The I/O page fault is initiated by the device, which does not have any synchronization mechanism with the software to ensure that the device stays in the probed device tree. Theoretically, a device could be released by the IOMMU subsystem after device_rbtree_find() and before iopf_get_dev_fault_param(), which would cause a use-after-free problem. Add a mutex to synchronize the I/O page fault reporting path and the IOMMU release device path. This lock doesn't introduce any performance overhead, as the conflict between I/O page fault reporting and device releasing is very rare.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-35843", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zJmne4UGfnz32Y9xCDqh8Q==": { "id": "zJmne4UGfnz32Y9xCDqh8Q==", "updater": "debian/updater", "name": "CVE-2023-53999", "description": "In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Fix internal port memory leak The flow rule can be splited, and the extra post_act rules are added to post_act table. It's possible to trigger memleak when the rule forwards packets from internal port and over tunnel, in the case that, for example, CT 'new' state offload is allowed. As int_port object is assigned to the flow attribute of post_act rule, and its refcnt is incremented by mlx5e_tc_int_port_get(), but mlx5e_tc_int_port_put() is not called, the refcnt is never decremented, then int_port is never freed. The kmemleak reports the following error: unreferenced object 0xffff888128204b80 (size 64): comm \"handler20\", pid 50121, jiffies 4296973009 (age 642.932s) hex dump (first 32 bytes): 01 00 00 00 19 00 00 00 03 f0 00 00 04 00 00 00 ................ 98 77 67 41 81 88 ff ff 98 77 67 41 81 88 ff ff .wgA.....wgA.... backtrace: [\u003c00000000e992680d\u003e] kmalloc_trace+0x27/0x120 [\u003c000000009e945a98\u003e] mlx5e_tc_int_port_get+0x3f3/0xe20 [mlx5_core] [\u003c0000000035a537f0\u003e] mlx5e_tc_add_fdb_flow+0x473/0xcf0 [mlx5_core] [\u003c0000000070c2cec6\u003e] __mlx5e_add_fdb_flow+0x7cf/0xe90 [mlx5_core] [\u003c000000005cc84048\u003e] mlx5e_configure_flower+0xd40/0x4c40 [mlx5_core] [\u003c000000004f8a2031\u003e] mlx5e_rep_indr_offload.isra.0+0x10e/0x1c0 [mlx5_core] [\u003c000000007df797dc\u003e] mlx5e_rep_indr_setup_tc_cb+0x90/0x130 [mlx5_core] [\u003c0000000016c15cc3\u003e] tc_setup_cb_add+0x1cf/0x410 [\u003c00000000a63305b4\u003e] fl_hw_replace_filter+0x38f/0x670 [cls_flower] [\u003c000000008bc9e77c\u003e] fl_change+0x1fd5/0x4430 [cls_flower] [\u003c00000000e7f766e4\u003e] tc_new_tfilter+0x867/0x2010 [\u003c00000000e101c0ef\u003e] rtnetlink_rcv_msg+0x6fc/0x9f0 [\u003c00000000e1111d44\u003e] netlink_rcv_skb+0x12c/0x360 [\u003c0000000082dd6c8b\u003e] netlink_unicast+0x438/0x710 [\u003c00000000fc568f70\u003e] netlink_sendmsg+0x794/0xc50 [\u003c0000000016e92590\u003e] sock_sendmsg+0xc5/0x190 So fix this by moving int_port cleanup code to the flow attribute free helper, which is used by all the attribute free cases.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-53999", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zLARHi3LgDQgVk9F5LOF8g==": { "id": "zLARHi3LgDQgVk9F5LOF8g==", "updater": "debian/updater", "name": "CVE-2025-48074", "description": "OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-48074", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "openexr", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zLMNfbeOAdf/1PqX2MIsfg==": { "id": "zLMNfbeOAdf/1PqX2MIsfg==", "updater": "debian/updater", "name": "CVE-2026-43036", "description": "In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KMSAN uninit-value warning in gso_features_check() called from netif_skb_features() [1]. gso_features_check() reads iph-\u003efrag_off to decide whether to clear mangleid_features. Accessing the IPv4 header via ip_hdr()/inner_ip_hdr() can rely on skb header offsets that are not always safe for direct dereference on packets injected from PF_PACKET paths. Use skb_header_pointer() for the TCPv4 frag_off check so the header read is robust whether data is already linear or needs copying. [1] https://syzkaller.appspot.com/bug?extid=1543a7d954d9c6d00407", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-43036", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zN3XlOxCBkILB636fP3oCA==": { "id": "zN3XlOxCBkILB636fP3oCA==", "updater": "debian/updater", "name": "CVE-2023-54088", "description": "In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: hold queue_lock when removing blkg-\u003eq_node When blkg is removed from q-\u003eblkg_list from blkg_free_workfn(), queue_lock has to be held, otherwise, all kinds of bugs(list corruption, hard lockup, ..) can be triggered from blkg_destroy_all().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2023-54088", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zO0DTAUP46HiUnxZY7C5hA==": { "id": "zO0DTAUP46HiUnxZY7C5hA==", "updater": "debian/updater", "name": "CVE-2026-31516", "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with netns teardown A XFRM_MSG_NEWSPDINFO request can queue the per-net work item policy_hthresh.work onto the system workqueue. The queued callback, xfrm_hash_rebuild(), retrieves the enclosing struct net via container_of(). If the net namespace is torn down before that work runs, the associated struct net may already have been freed, and xfrm_hash_rebuild() may then dereference stale memory. xfrm_policy_fini() already flushes policy_hash_work during teardown, but it does not synchronize policy_hthresh.work. Synchronize policy_hthresh.work in xfrm_policy_fini() as well, so the queued work cannot outlive the net namespace teardown and access a freed struct net.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-31516", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zOZurysJE2U1emy9T2xB6A==": { "id": "zOZurysJE2U1emy9T2xB6A==", "updater": "debian/updater", "name": "CVE-2026-68255", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response buffer virtio_get_edid_block() validates the read offset only against the device-supplied resp-\u003esize field, never against the fixed-size resp-\u003eedid array. The EDID block index is driven by the device-supplied extension count, so a malicious virtio-gpu backend can advertise a large size together with a high block count and read far past the array into adjacent kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds read / info leak). Also reject any read whose end exceeds the size of the edid array. Conforming EDID responses stay within the array and are unaffected.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68255", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zOjya/MbFb3bR1ErYSGZlQ==": { "id": "zOjya/MbFb3bR1ErYSGZlQ==", "updater": "debian/updater", "name": "CVE-2025-39747", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/msm: Add error handling for krealloc in metadata setup Function msm_ioctl_gem_info_set_metadata() now checks for krealloc failure and returns -ENOMEM, avoiding potential NULL pointer dereference. Explicitly avoids __GFP_NOFAIL due to deadlock risks and allocation constraints. Patchwork: https://patchwork.freedesktop.org/patch/661235/", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-39747", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zPAGkZmePalOvIEfMGZYQA==": { "id": "zPAGkZmePalOvIEfMGZYQA==", "updater": "debian/updater", "name": "CVE-2025-38717", "description": "In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syzbot found a race condition when kcm_unattach(psock) and kcm_release(kcm) are executed at the same time. kcm_unattach() is missing a check of the flag kcm-\u003etx_stopped before calling queue_work(). If the kcm has a reserved psock, kcm_unattach() might get executed between cancel_work_sync() and unreserve_psock() in kcm_release(), requeuing kcm-\u003etx_work right before kcm gets freed in kcm_done(). Remove kcm-\u003etx_stopped and replace it by the less error-prone disable_work_sync().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-38717", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zPZyBg1wZFMz7/V3ogyi9g==": { "id": "zPZyBg1wZFMz7/V3ogyi9g==", "updater": "debian/updater", "name": "CVE-2024-50226", "description": "In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use-after-free, permit out-of-order decoder shutdown In support of investigating an initialization failure report [1], cxl_test was updated to register mock memory-devices after the mock root-port/bus device had been registered. That led to cxl_test crashing with a use-after-free bug with the following signature: cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem0:decoder7.0 @ 0 next: cxl_switch_uport.0 nr_eps: 1 nr_targets: 1 cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem4:decoder14.0 @ 1 next: cxl_switch_uport.0 nr_eps: 2 nr_targets: 1 cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[0] = cxl_switch_dport.0 for mem0:decoder7.0 @ 0 1) cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[1] = cxl_switch_dport.4 for mem4:decoder14.0 @ 1 [..] cxld_unregister: cxl decoder14.0: cxl_region_decode_reset: cxl_region region3: mock_decoder_reset: cxl_port port3: decoder3.0 reset 2) mock_decoder_reset: cxl_port port3: decoder3.0: out of order reset, expected decoder3.1 cxl_endpoint_decoder_release: cxl decoder14.0: [..] cxld_unregister: cxl decoder7.0: 3) cxl_region_decode_reset: cxl_region region3: Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6bc3: 0000 [#1] PREEMPT SMP PTI [..] RIP: 0010:to_cxl_port+0x8/0x60 [cxl_core] [..] Call Trace: \u003cTASK\u003e cxl_region_decode_reset+0x69/0x190 [cxl_core] cxl_region_detach+0xe8/0x210 [cxl_core] cxl_decoder_kill_region+0x27/0x40 [cxl_core] cxld_unregister+0x5d/0x60 [cxl_core] At 1) a region has been established with 2 endpoint decoders (7.0 and 14.0). Those endpoints share a common switch-decoder in the topology (3.0). At teardown, 2), decoder14.0 is the first to be removed and hits the \"out of order reset case\" in the switch decoder. The effect though is that region3 cleanup is aborted leaving it in-tact and referencing decoder14.0. At 3) the second attempt to teardown region3 trips over the stale decoder14.0 object which has long since been deleted. The fix here is to recognize that the CXL specification places no mandate on in-order shutdown of switch-decoders, the driver enforces in-order allocation, and hardware enforces in-order commit. So, rather than fail and leave objects dangling, always remove them. In support of making cxl_region_decode_reset() always succeed, cxl_region_invalidate_memregion() failures are turned into warnings. Crashing the kernel is ok there since system integrity is at risk if caches cannot be managed around physical address mutation events like CXL region destruction. A new device_for_each_child_reverse_from() is added to cleanup port-\u003ecommit_end after all dependent decoders have been disabled. In other words if decoders are allocated 0-\u003e1-\u003e2 and disabled 1-\u003e2-\u003e0 then port-\u003ecommit_end only decrements from 2 after 2 has been disabled, and it decrements all the way to zero since 1 was disabled previously.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50226", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zQ2Rf6aQ16TKQH/8PpQpBg==": { "id": "zQ2Rf6aQ16TKQH/8PpQpBg==", "updater": "debian/updater", "name": "CVE-2025-8177", "description": "A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-8177", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "tiff", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zS4kBiWfhQpglSqbg/NYUw==": { "id": "zS4kBiWfhQpglSqbg/NYUw==", "updater": "debian/updater", "name": "CVE-2026-53358", "description": "In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn-\u003echan_l, which must be done under conn-\u003elock. cleanup_listen() runs under the parent sk_lock, so acquiring conn-\u003elock would invert the established conn-\u003elock -\u003e chan-\u003elock -\u003e sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously. The timeout handler already acquires conn-\u003elock and chan-\u003elock in the correct order. The timer is only armed when chan-\u003econn is still set: if it is already NULL, l2cap_conn_del() has already processed this channel (l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb), so there is nothing left to do. If l2cap_conn_del() races in after the timer is armed, __clear_chan_timer() inside l2cap_chan_del() cancels it; if the timer has already fired, the handler returns harmlessly because chan-\u003econn was cleared.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53358", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zUuWXRAoo66dgq/CBXEmGA==": { "id": "zUuWXRAoo66dgq/CBXEmGA==", "updater": "debian/updater", "name": "CVE-2026-53285", "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED [Why] dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(), which disables local softirqs. The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path, which calls BUG_ON(in_interrupt()) because it's invoked within the FPU-enabled (softirq disabled) region, leading to a kernel crash. [How] Wrap the dc_state_create_phantom_plane() call with the DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during this memory allocation. (cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-53285", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zW0NAmanPbUh3mIYb5jVbQ==": { "id": "zW0NAmanPbUh3mIYb5jVbQ==", "updater": "debian/updater", "name": "CVE-2026-3184", "description": "A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-3184", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zfQNiDqMZk0PW66CHc19Bw==": { "id": "zfQNiDqMZk0PW66CHc19Bw==", "updater": "debian/updater", "name": "CVE-2026-68370", "description": "In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum-\u003efifo_req) that the \"emulated single-request FIFO\" fast-path in dummy_queue() reuses for small IN transfers: it copies the caller's request into it (req-\u003ereq = *_req) and queues it, treating list_empty(\u0026fifo_req.queue) as \"the slot is free\". The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(\u0026req-\u003equeue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req-\u003ecomplete(). But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req-\u003ereq = *_req -- overwriting req-\u003ecomplete while dummy_timer is mid-calling it. The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request's whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(\u0026fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-request giveback sites. The shared slot can no longer be reused until its completion callback has finished.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-68370", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zocj5Xv8ymcJeaZLObOh6w==": { "id": "zocj5Xv8ymcJeaZLObOh6w==", "updater": "debian/updater", "name": "CVE-2026-34191", "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-34191", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "apr-util", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zpnR4DQUSVLOu5w4oXihGg==": { "id": "zpnR4DQUSVLOu5w4oXihGg==", "updater": "debian/updater", "name": "CVE-2026-7210", "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2026-7210", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "python3.11", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zrmO+HE5JByCv0fKZEkTvw==": { "id": "zrmO+HE5JByCv0fKZEkTvw==", "updater": "debian/updater", "name": "CVE-2025-37802", "description": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. This means that ksmbd_durable_scavenger_alive() will try to acquire the mutex while already in a sleeping state. The scheduler warns us by giving the following warning: do not call blocking ops when !TASK_RUNNING; state=2 set at [\u003c0000000061515a6f\u003e] prepare_to_wait_event+0x9f/0x6c0 WARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160 mutex lock is not needed in ksmbd_durable_scavenger_alive().", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-37802", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ztZFbmBHMK5xkfR3cHXb9w==": { "id": "ztZFbmBHMK5xkfR3cHXb9w==", "updater": "debian/updater", "name": "CVE-2024-14040", "description": "In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. Instead of, say, 255:254, we might like to configure something like 1000:999. For these deployments, the 8-bit weight may not be enough. To that end, in this patch increase the next hop weight from u8 to u16. Increasing the width of an integral type can be tricky, because while the code still compiles, the types may not check out anymore, and numerical errors come up. To prevent this, the conversion was done in two steps. First the type was changed from u8 to a single-member structure, which invalidated all uses of the field. This allowed going through them one by one and audit for type correctness. Then the structure was replaced with a vanilla u16 again. This should ensure that no place was missed. The UAPI for configuring nexthop group members is that an attribute NHA_GROUP carries an array of struct nexthop_grp entries: \tstruct nexthop_grp { \t\t__u32\tid;\t /* nexthop id - must exist */ \t\t__u8\tweight; /* weight of this nexthop */ \t\t__u8\tresvd1; \t\t__u16\tresvd2; \t}; The field resvd1 is currently validated and required to be zero. We can lift this requirement and carry high-order bits of the weight in the reserved field: \tstruct nexthop_grp { \t\t__u32\tid;\t /* nexthop id - must exist */ \t\t__u8\tweight; /* weight of this nexthop */ \t\t__u8\tweight_high; \t\t__u16\tresvd2; \t}; Keeping the fields split this way was chosen in case an existing userspace makes assumptions about the width of the weight field, and to sidestep any endianness issues. The weight field is currently encoded as the weight value minus one, because weight of 0 is invalid. This same trick is impossible for the new weight_high field, because zero must mean actual zero. With this in place: - Old userspace is guaranteed to carry weight_high of 0, therefore configuring 8-bit weights as appropriate. When dumping nexthops with 16-bit weight, it would only show the lower 8 bits. But configuring such nexthops implies existence of userspace aware of the extension in the first place. - New userspace talking to an old kernel will work as long as it only attempts to configure 8-bit weights, where the high-order bits are zero. Old kernel will bounce attempts at configuring \u003e8-bit weights. Renaming reserved fields as they are allocated for some purpose is commonly done in Linux. Whoever touches a reserved field is doing so at their own risk. nexthop_grp::resvd1 in particular is currently used by at least strace, however they carry an own copy of UAPI headers, and the conversion should be trivial. A helper is provided for decoding the weight out of the two fields. Forcing a conversion seems preferable to bending backwards and introducing anonymous unions or whatever.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-14040", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "ztbKwpmvdRPX+nuYebgVuw==": { "id": "ztbKwpmvdRPX+nuYebgVuw==", "updater": "debian/updater", "name": "CVE-2025-14104", "description": "A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2025-14104", "severity": "unimportant", "normalized_severity": "Low", "package": { "id": "", "name": "util-linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false }, "zyIwGR4/HmoCcUA8TwohXg==": { "id": "zyIwGR4/HmoCcUA8TwohXg==", "updater": "debian/updater", "name": "CVE-2024-50111", "description": "In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context Unaligned access exception can be triggered in irq-enabled context such as user mode, in this case do_ale() may call get_user() which may cause sleep. Then we will get: BUG: sleeping function called from invalid context at arch/loongarch/kernel/access-helper.h:7 in_atomic(): 0, irqs_disabled(): 1, non_block: 0, pid: 129, name: modprobe preempt_count: 0, expected: 0 RCU nest depth: 0, expected: 0 CPU: 0 UID: 0 PID: 129 Comm: modprobe Tainted: G W 6.12.0-rc1+ #1723 Tainted: [W]=WARN Stack : 9000000105e0bd48 0000000000000000 9000000003803944 9000000105e08000 9000000105e0bc70 9000000105e0bc78 0000000000000000 0000000000000000 9000000105e0bc78 0000000000000001 9000000185e0ba07 9000000105e0b890 ffffffffffffffff 9000000105e0bc78 73924b81763be05b 9000000100194500 000000000000020c 000000000000000a 0000000000000000 0000000000000003 00000000000023f0 00000000000e1401 00000000072f8000 0000007ffbb0e260 0000000000000000 0000000000000000 9000000005437650 90000000055d5000 0000000000000000 0000000000000003 0000007ffbb0e1f0 0000000000000000 0000005567b00490 0000000000000000 9000000003803964 0000007ffbb0dfec 00000000000000b0 0000000000000007 0000000000000003 0000000000071c1d ... Call Trace: [\u003c9000000003803964\u003e] show_stack+0x64/0x1a0 [\u003c9000000004c57464\u003e] dump_stack_lvl+0x74/0xb0 [\u003c9000000003861ab4\u003e] __might_resched+0x154/0x1a0 [\u003c900000000380c96c\u003e] emulate_load_store_insn+0x6c/0xf60 [\u003c9000000004c58118\u003e] do_ale+0x78/0x180 [\u003c9000000003801bc8\u003e] handle_ale+0x128/0x1e0 So enable IRQ if unaligned access exception is triggered in irq-enabled context to fix it.", "issued": "0001-01-01T00:00:00Z", "links": "https://security-tracker.debian.org/tracker/CVE-2024-50111", "severity": "not yet assigned", "normalized_severity": "Unknown", "package": { "id": "", "name": "linux", "version": "", "kind": "source", "normalized_version": "", "cpe": "", "detector": null }, "distribution": { "id": "", "did": "debian", "name": "Debian GNU/Linux", "version": "12 (bookworm)", "version_code_name": "bookworm", "version_id": "12", "arch": "", "cpe": "", "pretty_name": "Debian GNU/Linux 12 (bookworm)" }, "repository": { "cpe": "" }, "fixed_in_version": "", "Self": { "space": "", "name": "" }, "Aliases": null, "Invert": false } }, "package_vulnerabilities": { "+6B10TyZ7Yw1Uati+EDFTg==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "+EvVUYESwvcEspjJuRUM8Q==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "/1xbchBbkMyq0Ur9WaUTgg==": [ "rx8eYzjaW03hO1/BTWCgAA==" ], "0rQO8ev0gA2bMPyvfyRTSg==": [ "ZQePqlHHBA7+hwLcam9ocg==" ], "0zZmFEOjIMpFAeP+24iakA==": [ "HuLcwroM1rTmCRiMq0xq/A==", "DEvkWQMQdNGeGi8iOnJX8g==", "wZs/M549D013OPgW4vrJnA==", "aUsy5n/c6AxyAdYqvDKZAg==", "07URzmvpS7ZEQcLIdrixNA==", "FVeDQej7MCAjLzDoM9qgXg==", "NXu+dXN5KBvsm9u13e7YlA==", "5GKnVDsIRQ4aY8ICcomaOw==", "+42NZLTTWEuGunTe6H5VAQ==", "SnaDJIBcaepGlEY5l0YiZQ==", "eMJT7VG/NT94FNjcwFGj7g==", "PSkg4cwA46LL8z/Lgyf8sg==", "dynHmBSsNbcoeh0tpdlFhg==", "K9HJuYuqoA0oSln39+ncyg==", "u0KFq8sxSQMQOjkoSQcWGQ==", "4QzwilesYlayDLcL7cX9Xg==", "LA1kH936Pv8VoSzyI8d3Tg==" ], "1T4167CC3sXBfikeGTBamA==": [ "mQ7+TqdAO4YZAHkoGQlD8Q==" ], "1d+ozfBeVKodpg99SYjl1A==": [ "2yv1l3MuYdv6baRDFoTAXw==" ], "1ibbew6p8bvI8FxMYegw1g==": [ "sT/CdZ9EbhIheJoHHIMlVg==" ], "2ZcPfrj/S1OihNpEALoqBQ==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "2ZjFWZInqL1yRVL3PtElzg==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "2fLCAY2+SVCQ2VXaZQ3hqg==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "2q4gD1GZAkS/i3n3Sy+/DQ==": [ "PvPOVXZOs5mWfRHbAqRK9Q==", "RHmrG4Tsyn4HRk0mAfBmIg==", "JQ1E3FLXucARkh38lJeV9g==" ], "30Y83yLPxjZH53BgMHRMgg==": [ "2M/vHj3OiKkU7tGWIlYBoQ==", "4K1mbxJj3BNAQaqE7t/g0g==", "VUU74CujbBUJFROehJySAg==", "JoQXSLz122fLIwbOi3oENA==", "vyuNHsqRTAlcfL/qtwpSjA==", "4pmVCkpcFnlXpeO2bi9bvg==" ], "36PkSUqF3oUYJxM3LL7ytg==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "3k4FPwKVTHyfyKjD8kMK+A==": [ "kaqNCfRrzo98RV67uaLNDw==" ], "4HvsO4LmB5qq71OYhAgtsw==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "4j0fN++xbxUCmc5aXfanEw==": [ "ZQePqlHHBA7+hwLcam9ocg==" ], "4uoDWqA6j1h67XvnWkb69Q==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "4xzOAwX8EAP1eOlXGJnUVQ==": [ "MGrbbNsTtAJ91AysbDgiPw==", "obUBIS09Ii79M9cd8FFKpg==", "nxfFlxrPmdAebW4GstXgtg==", "JENS6w0/SSPbnjHI5uhkLg==", "yOmc2F+SacWrePdm/mxRGA==" ], "5uWQa9ljjSF0OokLG8is7A==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "5wydsqQl0bNu0Far4Hwvlg==": [ "kOlCFWKyH7sZJbv3K91zAA==", "9w+bEJrWIFDCRXqCmLqPag==", "0k4T8D9OO0elHgqdOnSGtg==", "Zgn/UYJKK4iGOPjyGoKbxg==", "S1WPfRkh+Ptiwz9FBz1fLw==" ], "5xli1ibcVetek1e+KZM6ow==": [ "/qUM6+rqk8nGECur0ngdlg==", "TXaAGqaslxw3rNhoiJkiZw==" ], "6ATWONUn9Z77FRku437S0A==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "6SJtgGhuLlRhbMpPiqkd3g==": [ "D74mlxiMppsGNMizdZlOXg==" ], "74RbRvv2uTUZVyS/aUST+A==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "7jIzXM6Spac0GoVcshxV2Q==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "7m9Wfd2N4nRasn5qfmA8DQ==": [ "kOlCFWKyH7sZJbv3K91zAA==", "9w+bEJrWIFDCRXqCmLqPag==", "0k4T8D9OO0elHgqdOnSGtg==", "Zgn/UYJKK4iGOPjyGoKbxg==", "S1WPfRkh+Ptiwz9FBz1fLw==" ], "7pVJMzmeLLO4NXWj0YVBag==": [ "N473F11M/P9rXXVHcdmElg==", "mCcaCnP8f52+vu9b5rtNnA==", "Kalz8nPy29l3XQTjNg1oTw==", "xMNRfv9b++Qx2IGpA34qeA==", "AVqsLa8FiT6DFdwPobOf2w==", "3TnfqY55bHsUZcxqm7CvkA==", "ddTPBzeeJYnba7jCapgbAQ==", "PfhjREk4GtBBWbLt/M6Dlw==", "YRihAPX9XQJbgbq8IV5qyQ==", "aBSD9SI0+LjXQAmIuEqC1A==", "LjSRKao8rTYjhGOoAVtUog==", "d59u3XRZGdnK2xtdhx8bMg==", "uEC5Qtr12vyf9FN8TJFIpw==", "cfiD+BYptWNUedEJyRszuw==", "ayNwOwFahcJX8VpuVbGJUw==", "52axsosk1tD0T2LVgOLrtQ==", "9yjo/byOytI0IkYgkukiDQ==", "Cs99NDR/2aWXIUslX4V9Sg==", "eFmZwmd/PF/L5BwzrUL8Bg==", "ZS/gWXbJFn17w55K8PlyRQ==", "GuCBWhZkPdgB6JAffd0vyQ==", "UmInHmlKA0q8kxh6TUPiWQ==", "LR53RfBcaLruNmVIjJlLPg==", "6oQOPW/SOH/HZt4HVN1Sgg==", "UgYbawVYBKlWqMXTnMrkFQ==" ], "80rK+6RM4F9Hot2jSdUHAg==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "8LWvv86uV3cw8wj3q3pMEA==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "8cpRxcbI/vwUuKrU5hjaWw==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "8zBqc6YLv7EX5QenNkOW/g==": [ "kaqNCfRrzo98RV67uaLNDw==" ], "A9S4GbGT4KbqDQ4Rk+9rjw==": [ "5YLhda5cCl4IzztbHPgP+Q==", "RyaU8EhxqdcTWh8ybWTskw==" ], "ADxcp+yqIg7//17igk2iWw==": [ "aTvTtQyFk6amfTAzFmKVQQ==" ], "AEmJ/DcX9k+YTOaY1TPipw==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "AxDgJRPby1Bn5TyQqmbUVA==": [ "rmKVfK3mgjlQEhH+iHOflg==", "tqFkMROecRC/cxO5FXH2+w==", "XHFgJNEJIiIPE15DtoD2KQ==", "jpl1YKH9X76u2ReYrgD2uQ==", "/mMYJM9zN4O/C1HrJJj88A==", "wkt0wH2J5e6j3zvwUjQ4QA==", "3FdoYCjfuaH69GQGMCkueA==", "Tp5o/4SbPLzIMMSn6dmLAw==", "q5t1nltLUU7gVpZnWUIzNQ==", "RvZnPU2cIYuGeiv/rD1odw==", "6Z4TXkcGmyMWqyaCyCnljA==", "Ofi0/2sjxB8nnRkMGdfgiA==", "ecHm30RV2osv+vIdsYl1hg==", "2DgpNYTsr+vLsgB6jUu6qw==", "7AuJGHgHvpeOIE8Xo+9Tiw==", "M0jbZmBvyRuYzBNrvmqEbA==", "ZjN/tXLqyGqAzL0qaRbOdQ==", "WR/jw4xeHrK73fGOrvF1KA==", "mwBbCDmV+BFi1OG3VKzdzg==", "5pSzSEvB4MWtJijvklug6g==", "eyoPFYt1ipSpBRtbyo16hg==", "MCePqVkLQnwVpeYNDE+rBg==", "Eqs0OpFbkAnFRvfxseQQ5g==", "O5i6HOYABXcKKK82h0iOYA==" ], "B5DdwMEMymJ408z76zs2OA==": [ "96cHpmcS0fRAU0scCg6b9g==", "YsKorYDNSlb87ZdIS9kUjQ==", "gJF2RoXEUj/4hrZaYhzyJg==", "mDBfTSXZ1+wA7otb2RysUQ==", "H09h9nd7ZlHJ8LRncQ4cfQ==", "eW+REV5eOe0Z0hdA+hyoQw==", "LJsYhUYv1jp57lU5SMRltg==", "uJaIkdAdssqwBkEXNNs0qg==", "z17t3PbfsUMbWVwOHNYPWQ==", "EAlLhi+f9W1iGlSW/XZEEQ==" ], "BfdRzqdpSloHTsPV0bYqfQ==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "Btnm9wBBF+iO/PtfE/g4Uw==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "C48XyIAaKniO5HPydCvKpg==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "CFG/JDkRv9ezCh1qEKQ8ug==": [ "7XcpF7gQsSGccuF/A656dA==", "+aYX/oRvHl/0BC/uiR5NVA==", "QBFhf4GHFlHTR/5pa1CHXg==" ], "CT3G0GG1+aFkXHFGTSDi3A==": [ "uUeyRpuBJxN4Bn35BikY4w==", "drbuoWX/fF9k6u07fsRX6Q==" ], "CmCZ256ji6DcGmXCpaluIQ==": [ "D74mlxiMppsGNMizdZlOXg==" ], "Crh7PcjcI6TuJynTs7Y4sQ==": [ "MGrbbNsTtAJ91AysbDgiPw==", "obUBIS09Ii79M9cd8FFKpg==", "nxfFlxrPmdAebW4GstXgtg==", "JENS6w0/SSPbnjHI5uhkLg==", "yOmc2F+SacWrePdm/mxRGA==" ], "D4CAttxDppQB4nUjxeAQYg==": [ "kHTcuX2ojk+Ouhq9aqnFmg==", "bkD27G5x4y2TAqhJBzu7xg==" ], "D7pQ2iqeywkQv+e7IPd32g==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "DLENylM5mXuzVt1bbHQcdg==": [ "kOlCFWKyH7sZJbv3K91zAA==", "9w+bEJrWIFDCRXqCmLqPag==", "0k4T8D9OO0elHgqdOnSGtg==", "Zgn/UYJKK4iGOPjyGoKbxg==", "S1WPfRkh+Ptiwz9FBz1fLw==" ], "DMI7vu+hT7nBL5mdHloddg==": [ "OWJa3duCz1A5SfiSYrzr3Q==" ], "DO2gYwj9yFnFCsYsp/BBVA==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "DUfRr94DlcXwFiSA+XKESw==": [ "7rOmgLxcgbnBpJsD3eacKg==", "2lyKtAO8fWwobKAd5ksImw==", "iOyLmeTOvgguVhp+6I7Gmw==", "UqlXj97FrNpj1p9MIGdxxw==", "zpnR4DQUSVLOu5w4oXihGg==", "X2d9l5X1xLpQwAiEXTTewg==", "HhS2mtMKZlbYlHszwIEmdg==", "GT1RFwTTfZX7UTrjVIuvcg==", "bSQHKOOIEu7zn/5UgFOWJw==", "6OnemuwtxINSgBT1Ii+++A==", "/q/1NoaqqY53cTnf3GDbOA==", "vQoCKRV0WYdDnzKPcCv6hw==", "Fv1xZ6eCn6XkYWWsyTGbDw==", "Jr8LE9YgqhUL/qPVlyGCkw==", "uDMKksa8nEm05P2D+S3qVA==", "k5+7SpZcwh35X7eYTNm4mg==", "TqWd5ZUl5sVkYMkHIsu40Q==", "FOCiciYW31UdVFnx5ltZBg==", "oAJV6yKgQS6xMKtIhAlSqg==" ], "Dbw8fwJSQtnZOBPRtWZjAw==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "DcSn3Y7HFbVbRH2l8vXSOw==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "DdG2a7LFFvSXCrM63lYSQQ==": [ "PvPOVXZOs5mWfRHbAqRK9Q==", "RHmrG4Tsyn4HRk0mAfBmIg==", "JQ1E3FLXucARkh38lJeV9g==" ], "DoeL4sQy46KMZZcZaGrPwA==": [ "2xNoBNSp7fweMAQExE+o+Q==", "R6AHXq9kIXOTM2VjUoYfdQ==", "1kpr3WQfwsPlCOJYahwUqg==", "vVKfZgj2ftz4bUN+hvsnmw==", "SOZasT93ZTk1r15AlKIQHw==", "AR1mIh++KWFwOpNBMSCtcg==", "QGrcmtKnV84PkEVV4mmlmg==", "+CL+shtoxDkUb+xwSTpgsg==", "JkDUeWM85AYU2EUC6YsyXw==", "w3HHZG8nTVYxvXYiyXr1Hw==", "xiMAJpHW80LOtYFONrCzjA==", "Nkn4Lx7wFGCCYyHykJcx5Q==", "IeoitvM9lwggrk3KXJzR/A==" ], "Dr0qgUJ7DFtPHxF+bH4bdg==": [ "7rOmgLxcgbnBpJsD3eacKg==", "2lyKtAO8fWwobKAd5ksImw==", "iOyLmeTOvgguVhp+6I7Gmw==", "UqlXj97FrNpj1p9MIGdxxw==", "zpnR4DQUSVLOu5w4oXihGg==", "X2d9l5X1xLpQwAiEXTTewg==", "HhS2mtMKZlbYlHszwIEmdg==", "GT1RFwTTfZX7UTrjVIuvcg==", "bSQHKOOIEu7zn/5UgFOWJw==", "6OnemuwtxINSgBT1Ii+++A==", "/q/1NoaqqY53cTnf3GDbOA==", "vQoCKRV0WYdDnzKPcCv6hw==", "Fv1xZ6eCn6XkYWWsyTGbDw==", "Jr8LE9YgqhUL/qPVlyGCkw==", "uDMKksa8nEm05P2D+S3qVA==", "k5+7SpZcwh35X7eYTNm4mg==", "TqWd5ZUl5sVkYMkHIsu40Q==", "FOCiciYW31UdVFnx5ltZBg==", "oAJV6yKgQS6xMKtIhAlSqg==" ], "EC+JU6AsEvpEEhY498jxOg==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "ET151dfn2MZGHv3vzXEthQ==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "EoG2zpKSlJJwW+MSosZk9w==": [ "ZQePqlHHBA7+hwLcam9ocg==" ], "EyNTk1gqN4KHi+AHyTGTsA==": [ "2xNoBNSp7fweMAQExE+o+Q==", "R6AHXq9kIXOTM2VjUoYfdQ==", "1kpr3WQfwsPlCOJYahwUqg==", "vVKfZgj2ftz4bUN+hvsnmw==", "SOZasT93ZTk1r15AlKIQHw==", "AR1mIh++KWFwOpNBMSCtcg==", "QGrcmtKnV84PkEVV4mmlmg==", "+CL+shtoxDkUb+xwSTpgsg==", "JkDUeWM85AYU2EUC6YsyXw==", "w3HHZG8nTVYxvXYiyXr1Hw==", "xiMAJpHW80LOtYFONrCzjA==", "Nkn4Lx7wFGCCYyHykJcx5Q==", "IeoitvM9lwggrk3KXJzR/A==" ], "F6hFIFBLlsM5E0Jh5GMVew==": [ "aTvTtQyFk6amfTAzFmKVQQ==" ], "FGLgg9hMQpl+MW2W94NfHA==": [ "sT/CdZ9EbhIheJoHHIMlVg==" ], "FUhID3jFFxB1MwHm8UODUA==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "FfB0oKhOP9dQDp61Fjo6EA==": [ "LvYuTk+G9PGeT3CX8knLKQ==", "via9ORzL8QYeuym0HcD6lg==", "9u8cQ+3Wzfyz/hps0KxpaA==", "wrlJJ6sFbDY2toPNxc+sAA==", "pSsSOHDLn9d/KN98C0jKiA==", "j3Jq5DMS3iHLl7p8JZ9cAQ==", "HVLGllsBehzSBhTEViMXWg==", "uRTDoRu2o1RYEkr6geNGUA==", "Ctoz44zltdVfu3psq14Exw==", "sFy6XZBsZ1YD59vnMAzJBg==", "wcariq6PZUM/OyBFO8n8xg==", "3C0sccvTPaFIh87pG5TC1Q==", "Yq9nncpzUr5K0tgMiAx0rw==" ], "GZaXtjtG9UqJe33Ris8hvw==": [ "96cHpmcS0fRAU0scCg6b9g==", "YsKorYDNSlb87ZdIS9kUjQ==", "gJF2RoXEUj/4hrZaYhzyJg==", "mDBfTSXZ1+wA7otb2RysUQ==", "H09h9nd7ZlHJ8LRncQ4cfQ==", "eW+REV5eOe0Z0hdA+hyoQw==", "LJsYhUYv1jp57lU5SMRltg==", "uJaIkdAdssqwBkEXNNs0qg==", "z17t3PbfsUMbWVwOHNYPWQ==", "EAlLhi+f9W1iGlSW/XZEEQ==" ], "GrX0NC3DRB9appRe0ANbeQ==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "GxIFrX03TO2H3bV6/l8Mgw==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "H15dvVf6yrGTTQeCLbwg8w==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "H1jcx9ub/KyuVLut+nrRxQ==": [ "MISSvrkhRBXMQUwT3M+KUQ==", "F1OvjISK96LVSPFgK1ON4Q==", "rM72QABgmf9nL4krapkMSQ==", "LUOZZKY4oeyvXegiWO6Yhg==", "sVpyexyrwxYbyqurODQLJQ==", "NZI2pa2BKL40u6kulzTybA==", "nQ0YMG97Bm6YVHjHJkVM4w==" ], "I1bAbBi99CgH1Fe4vQq8lA==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "IIgYYwpoulHCI9LIpdK3SA==": [ "MGrbbNsTtAJ91AysbDgiPw==", "obUBIS09Ii79M9cd8FFKpg==", "nxfFlxrPmdAebW4GstXgtg==", "JENS6w0/SSPbnjHI5uhkLg==", "yOmc2F+SacWrePdm/mxRGA==" ], "J1M13jv06LUgBQFe/2hBhQ==": [ "96cHpmcS0fRAU0scCg6b9g==", "YsKorYDNSlb87ZdIS9kUjQ==", "gJF2RoXEUj/4hrZaYhzyJg==", "mDBfTSXZ1+wA7otb2RysUQ==", "H09h9nd7ZlHJ8LRncQ4cfQ==", "eW+REV5eOe0Z0hdA+hyoQw==", "LJsYhUYv1jp57lU5SMRltg==", "uJaIkdAdssqwBkEXNNs0qg==", "z17t3PbfsUMbWVwOHNYPWQ==", "EAlLhi+f9W1iGlSW/XZEEQ==" ], "JSIFkKzhU9FvkmcYKQhwAA==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "JSmVKr1KluQ/VM/0yAWB8g==": [ "i5e3aCZ3KFF1VAfPW3LZVQ==", "vV1qzf4l+nQIHXosn35mdg==", "yc6saAcs8xhmSH0uppstLg==", "601t/MM1gE+tOeU7waDd0g==", "/93Mw1QUwTLm8a7eq9zPEw==", "VmgWfo6cc7CWRKYng0D+LQ==" ], "JwsgRUBDkHrNKaGcAJZ/rQ==": [ "vkN7FYaEniQ5g2jNb7NZpg==", "dS8Cxn8/LaNiQCvBYdq7Vg==", "Lc3Tll/o9JPam+3IT/DrKQ==" ], "JyXX6aacgQ9R5u7F789q9w==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "JywcP/qyzW2E6sHDgBtGgQ==": [ "lxUGTdEKAk+ElV/adgJrxA==", "miGlfWYNWZUhM6Uu5lXXWQ==", "Ovas4KEKa7VAli51+uaUcg==", "R/mDXHIDlEeq362SxYMlhg==", "mHbTjMj1rjOIPJCq59mrig==", "Ovox+LFKTyPfDw/8TYho6A==", "kqQebcoRkl7um6sT0akMiw==", "GZouk0sDd/thoSYrZ82zZg==", "mxkBwL2NcQ/jra18Jzk9Vg==" ], "K5LO+DczsLnXcUymG8Ov4Q==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "Kdos9fuXp7Tdirl5OEPk0A==": [ "MGrbbNsTtAJ91AysbDgiPw==", "obUBIS09Ii79M9cd8FFKpg==", "nxfFlxrPmdAebW4GstXgtg==", "JENS6w0/SSPbnjHI5uhkLg==", "yOmc2F+SacWrePdm/mxRGA==" ], "LIR5D4Dte5MOrnhvpHsVrQ==": [ "lkUXzRlvRP1wTsMOeSJoCQ==", "NAl3wEfkqVbijYPDBkjnSA==", "weYaCmbTKCL+KzAIPHVOWg==", "c+Aib934N9AbqiXYLmIOwQ==" ], "M2yshyCx4J0OAFSMphgrFw==": [ "mTD/V/e2oknhxg1DQ/f4hA==" ], "MJc99fNviurhcvfrwqhFnw==": [ "HBrSz1uIhsdeuDCH3ewyoA==", "7dVsv8lPa22N4ojcK5rlYw==" ], "MK+wvMZG5H9N57m0tlxOBQ==": [ "ZmoBlar9F3NrT8PTSCXqLw==", "gFgtzKPw4TudAad/Fcnixg==", "7MNcHEmPDkCtrqXYik1heg==", "c8SYJn1GAxyNkF/7gK0HFg==", "uuVof/zyt2johcugiudwEQ==" ], "MXjHhG8IwQ7T8QqaXIL6BA==": [ "rcUVP72WvBiriS5Y9xSVbA==" ], "MbThVdB9Kwth+Y7uHVZ7aw==": [ "Gg4J4X4MbNfkoXKGRDGfqw==", "49G+2JpyxLGVZgvO4KOVDw==", "oIMZkhmE1zTNLf+KmwFMBw==", "ZOcBwbKbAM2xtrg277utCw==", "lFPS8RnV0dISMcAPV4q8QQ==", "AFIUpz1Y4Fkx6mpVvjmUUA==", "atECatQpyL4OR6Nj8ORK0g==", "XkqmUhavZ8Tr7Mrbp/rI0w==", "N6KFD0gQnZqGoV2GULM/7A==", "f09/sxMi7D7F9rcfxRlDsw==", "73+h9zz0/ADxJTs4lDS2qg==", "Xo30MVWPbFyt6A6zkqyXXw==", "NZV9KIcDUlVYcEXxu9twfg==", "IYakbfCoZsMxgfjVJB5OPQ==", "Ps5MCo5QpzgrRW8/KZMYuA==", "HLibYccak0sZKoSNsE6IZg==", "SAarmoZzBAYwwO6Nw/ABww==", "0MwmAAbL4wOCyh0/b/kddw==", "vSDZxpLkGafXPiYJDoSc5w==", "DnoLLxMGws+PXaby9k1hQw==", "dsSTmk6uj2ELZGZZ+QDrfQ==" ], "NM2r479xc6Vy7ZfeePrYRg==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "NnEYV8lKPl93vYgryCkEwQ==": [ "lkUXzRlvRP1wTsMOeSJoCQ==", "NAl3wEfkqVbijYPDBkjnSA==", "weYaCmbTKCL+KzAIPHVOWg==", "c+Aib934N9AbqiXYLmIOwQ==" ], "Nr51nSGhXANVx6//HdGhXg==": [ "bSOhmLSWdup+bnw7AEzTRw==", "zocj5Xv8ymcJeaZLObOh6w==", "syYPyXsBtjXISlYg/pYDLg==", "+JVQA1F7TvkyaqDQnXuBMg==", "1L8o2LoXsizqmn3etiV0SQ==" ], "OPa+O2qJ8bwSNOa/i8UZrg==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "PPjVsVksOg1xBjerPFAZbA==": [ "D74mlxiMppsGNMizdZlOXg==" ], "PVYbPIfqCsqfnehuqa5Yzw==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "QNQML/EdNKRr8feN6gNQ7Q==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "QNXfg7x0fKp3nkVykQPVdg==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "QiE70L4UggeCJp5Ei3ScLg==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "Qj5vih+YB0oqxjBJX47HcQ==": [ "Gg4J4X4MbNfkoXKGRDGfqw==", "49G+2JpyxLGVZgvO4KOVDw==", "oIMZkhmE1zTNLf+KmwFMBw==", "ZOcBwbKbAM2xtrg277utCw==", "lFPS8RnV0dISMcAPV4q8QQ==", "AFIUpz1Y4Fkx6mpVvjmUUA==", "atECatQpyL4OR6Nj8ORK0g==", "XkqmUhavZ8Tr7Mrbp/rI0w==", "N6KFD0gQnZqGoV2GULM/7A==", "f09/sxMi7D7F9rcfxRlDsw==", "73+h9zz0/ADxJTs4lDS2qg==", "Xo30MVWPbFyt6A6zkqyXXw==", "NZV9KIcDUlVYcEXxu9twfg==", "IYakbfCoZsMxgfjVJB5OPQ==", "Ps5MCo5QpzgrRW8/KZMYuA==", "HLibYccak0sZKoSNsE6IZg==", "SAarmoZzBAYwwO6Nw/ABww==", "0MwmAAbL4wOCyh0/b/kddw==", "vSDZxpLkGafXPiYJDoSc5w==", "DnoLLxMGws+PXaby9k1hQw==", "dsSTmk6uj2ELZGZZ+QDrfQ==" ], "RrvOhWF4pNgkD1EzBzqhHw==": [ "2yv1l3MuYdv6baRDFoTAXw==" ], "SdY6vnz+BkS661rpTNZj9Q==": [ "SWBAXBdd/KEOaPZs2gye7A==", "rFRffA21og/EgJw72V6jLA==", "8MP4w+9DQY+tiSu/rCDGow==", "pkQ3rOcGRLKd/29TT/Sy+w==", "544etN0zC93gGnD8yMmNnQ==" ], "Sqf4aZ2zleKl0J9AxLdThA==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "TSIllJtHNmWZGqpbQMvKDQ==": [ "VIauTgqjmmC3JrXtK9SoKA==", "IckWa2ni3hDgKetUO6msAg==", "IFNW9YBko8LrXi4D/GCQ9A==" ], "TVoY0Z/LyrK88/UqwT1iKQ==": [ "7rOmgLxcgbnBpJsD3eacKg==", "2lyKtAO8fWwobKAd5ksImw==", "iOyLmeTOvgguVhp+6I7Gmw==", "UqlXj97FrNpj1p9MIGdxxw==", "zpnR4DQUSVLOu5w4oXihGg==", "X2d9l5X1xLpQwAiEXTTewg==", "HhS2mtMKZlbYlHszwIEmdg==", "GT1RFwTTfZX7UTrjVIuvcg==", "bSQHKOOIEu7zn/5UgFOWJw==", "6OnemuwtxINSgBT1Ii+++A==", "/q/1NoaqqY53cTnf3GDbOA==", "vQoCKRV0WYdDnzKPcCv6hw==", "Fv1xZ6eCn6XkYWWsyTGbDw==", "Jr8LE9YgqhUL/qPVlyGCkw==", "uDMKksa8nEm05P2D+S3qVA==", "k5+7SpZcwh35X7eYTNm4mg==", "TqWd5ZUl5sVkYMkHIsu40Q==", "FOCiciYW31UdVFnx5ltZBg==", "oAJV6yKgQS6xMKtIhAlSqg==" ], "UGdCvwdFwDgVlrc4KyAStg==": [ "LV6LIlj72s5e2jnkTg5TsA==", "wIg2Xh802Oj3VZBUTBmY2A==" ], "UjugzpaTnXWKhG4OAkEZpw==": [ "vkN7FYaEniQ5g2jNb7NZpg==", "dS8Cxn8/LaNiQCvBYdq7Vg==", "Lc3Tll/o9JPam+3IT/DrKQ==" ], "Vb9RpGB0uEvlFvfuUopE+Q==": [ "MsAjOQqU9HBRH1IUou6UlA==", "IpfbTVt+g1kooJABwZClSw==", "mCd+YBwD6U6filBaB3HE/g==", "v8W3uLUipO36H5zJnC42yQ==", "sjk08x30IRw3g2CCIvIBIw==", "KJIdfpTdRKWkCMfxbS/mUg==", "A5MLttzZQ3XDsFCByj0agw==", "ji/RKwpIMAc9Vv0dRY+IJg==", "4Z81E9P4znFnu7c5edLYhg==", "qSRAlDv61oW53IYnp9gUPQ==", "hoU7b3nCpZ8AGIjXIp7o0A==", "z+0EdNHPSbtJAsK+7Y1ZjQ==", "CZdODvItVtmOQOQwVO8dIg==", "D6W/s3VZQKE8xMh57eUkZw==", "6oeh+EDX7YG2y/U2/jlouw==", "FkO1xyFl3QSN8mmAxDhcqA==", "zQ2Rf6aQ16TKQH/8PpQpBg==", "LWdYqSSWB1E7q9rwDYTSew==", "TCd9g35j6XmK96Itj5MuqA==", "fnopR10wShgmhhhPsuEeJw==" ], "WH0tX6ZQDstQQf37sHDxgA==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "YLnDZQFr2jPrZgUlu5KKAg==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "YQfQT1wRk+YJhnXfvhY46w==": [ "HuLcwroM1rTmCRiMq0xq/A==", "DEvkWQMQdNGeGi8iOnJX8g==", "wZs/M549D013OPgW4vrJnA==", "aUsy5n/c6AxyAdYqvDKZAg==", "07URzmvpS7ZEQcLIdrixNA==", "FVeDQej7MCAjLzDoM9qgXg==", "NXu+dXN5KBvsm9u13e7YlA==", "5GKnVDsIRQ4aY8ICcomaOw==", "+42NZLTTWEuGunTe6H5VAQ==", "SnaDJIBcaepGlEY5l0YiZQ==", "eMJT7VG/NT94FNjcwFGj7g==", "PSkg4cwA46LL8z/Lgyf8sg==", "dynHmBSsNbcoeh0tpdlFhg==", "K9HJuYuqoA0oSln39+ncyg==", "u0KFq8sxSQMQOjkoSQcWGQ==", "4QzwilesYlayDLcL7cX9Xg==", "LA1kH936Pv8VoSzyI8d3Tg==" ], "YR/r5vxq5Kq88OnLa984Eg==": [ "9hXvJPuYbS6CLXFycAJ99w==", "z2Bu+BjK4pQMOBBCKGJjaA==", "hc9IJmOmNudYf6pO7HrB2g==", "1QFm70wnr6bYuRxGyK0OHw==", "TZ6L6I3Cd7+hJR4BXHfHTw==", "vpZ60RLe+1J2lJDPZ4B6fw==", "IVCa8wAzO7odLR515cEXxw==", "Iyl2+BN5OE2iopIsMT0Wsg==", "SmDyXYC0yd+JAF28cyzlyQ==", "7q5Yr5iGk2TjQ1fwpKRx0A==", "cEkDs9u9Cpspxm4MFYaeWQ==", "ipbNqEv3q9WHV7lrDHCung==", "aZ5JnYDYnTmgVCL1meuGtw==", "D1lO466zGDJ2CIR+V5bEmg==", "6Zbh3+Y2tosvSjDcFKP8Aw==", "eMcft8C1+SHqjR2CjpyZMQ==", "RBYBjfXBVxQdpYBUYaRE9Q==", "/SiTRLCQLViYubpilZ0k0Q==", "w5ixFh9N/z4mFs0nLuh+iA==", "iW60tBIRU0UpLCmeaBsyxQ==", "nUTdm61H5wpWvjqAxaXYSg==", "vgf0b5TZEtKDqwcBucDIpw==", "+REan4BC4v//j+uT3WPbNQ==", "dGGcNaPBE98Zf2/IcqDkaA==", "O7qzhTPmuAniGdn3z0AkdQ==", "7apQYQajm57oxazpbOGuzw==", "LQUZVuqaFm5FS1tle9bVrA==", "68eshzTKFcJRqXz/jgAEtA==", "PK1vYjWaZ1mf1KuZmjERPA==", "MsQlQGzt9E1GQg3tm6Z6Xg==", "3Krrzfra6fyC5xAOG8aVdA==", "SDLk5L+DIAztqW2bxjrZsA==", "zyIwGR4/HmoCcUA8TwohXg==", "2UEXWkLtrRPgNGWIp1Hx1A==", "DgELrwVlzyF6LUyCItuo/A==", "+41xmPLBp+GMWuqOpfmZWw==", "3iEhx4hZJtBmBc6kQmlOuQ==", "IuRLsRsG56+n47x1CeHN2g==", "HPnaw8TA8UZeJfoQkXai2g==", "8XxRH9NhjI4C1qTDFVnshA==", "hE5ON6NcQF/ZdeAv4cBeyw==", "dsprIFZqyCzKBLzZu3GFrg==", "ebIgfG/AuFXg1JE3bCfp2g==", "iY0B8c3S8KaeJYJfnX7c7A==", "xPA4Kcui1ANUz/lomxAogQ==", "DSPfaFg7hLhEsc2fToRgLw==", "fGD9z3bMt3Zy2s6flXa9PQ==", "b+yN6F3DrI8g0bS8DE7Ikg==", "+WCO1HEUKIIM9snGdGBm2A==", "Bic4QWky/M3PTMfYe54QyA==", "Cby6yBvWiqge200e7H4cpA==", "2cW+3rxkcATjxvNqtyRwZQ==", "ppjL8ervQY+FRd+kdVgrBQ==", "74TjW2pkixo+XKEdFIUK8A==", "eKnrUNUJQNJOChCt3LUUxg==", "8i7oY8t0v/hqoPfbdjDImQ==", "FepmO5xv4FfIjhOQ4Ibfgg==", "YsKt/LrIX7tM5qDp7LRtvA==", "fwqbK2vWdHEAxL0oK2ZkOA==", "iKw4ydcJcdKtvLNGHH6VHA==", "LicXfFw+HaekF+CWm0dH9A==", "rUOuprNv0asp6iYybUFpQA==", "W0WBVJpOgKZPh97Vdqea9w==", "gIdEieYO/ntsLE6wtAmolw==", "SLBj1tyoPWEZAMUQgU6Bxw==", "+w9hzA4OIRZ7YkoQQCaOOQ==", "jNf5Ky/aCfpj1zuKEL6RhQ==", "KPnqRHuP399EH8xpAsppRQ==", "PtYB7j3KiYHvNfT+z2TDRw==", "X2bZcXn+gYKr8UlsiAMsIQ==", "yNXJBhSLoARmyawSPfJ6Kg==", "YPFxAW99VI7nQ5swWF2Nqg==", "EKglEnYYYfnDpkNpBIJPLA==", "bQkpTmjn4jTZcFsn7mUkdg==", "wmEQj7183akagcy0qXiDCQ==", "I7Gt+2KyC1KdZkKZ23jpSA==", "sKvU9EMVvmgu3eX+l3UalA==", "lwESZdMBFhWpWDqCRMz8Vw==", "gSuQ5dqvcMhkLbF4/1v2/A==", "qlE/u8JaqdWPOKprjuHfPw==", "WBns/fFatdGns4nV2QuIEQ==", "Mgm9HKdYPJAe2Mp7mvmEcA==", "vHiy8KO9Yq7S0TDpc4yTgQ==", "kpNPngHrM4VAz6i1yHUbpg==", "NhLMD1ecB2U1wdghzQvPSA==", "0MTDMTjf9fjVojr+2WUZkA==", "LrXhgDkb+00pghFQVX0J/w==", "PJlk6OySat9b8dMsND5mBg==", "aNtlFmT+qtMf7OWjLlbpiQ==", "7yPUXvIZ9otJoyV9YvQB+A==", "Mw989Y2kuFloF3u0zyM2qw==", "FaQ53XEw5WDkvjBzOQpAIA==", "Po/Ca1qA1mJ+o8NRmnbxbg==", "Cao09ITIaY7Bv2VChcHNSQ==", "HLlE7mJEwNb5ro7Kr4vxZA==", "zOZurysJE2U1emy9T2xB6A==", "QdbJOXOx0QoCor7uxoMzVQ==", "Bbaaaw6EQCYgnB/RTt5DJA==", "dd1K9exjqjFQptWN+pGz8g==", "eJWQkT2e9DpqDKZu/3OPSA==", "C7PpoYskxK6iD21JtQVTfg==", "FCB29/uJidMwx2jZdSpxiA==", "7fFaZxYENGItC+DqHp8ghA==", "YxXrYo+Tio3tXdc6Irqxxg==", "yCanNFrkzwkJ63UqSrp79w==", "j1xnWego+ON5RA1EyBY9Hg==", "E2SmzNbrYzbd3ehJM5ldYQ==", "AlsHKe6pwvjWLCwYVvZHJg==", "BQpEk418T4vUlcMfNVAdmQ==", "Jg7YPBhdd2Y1YRc1lg9K/g==", "jG8/PDXriWa9vWg87ttnrQ==", "b7jIcdQJnfDJcThaGSjCKw==", "xnkuVi8+JWohMGvbl0FkUw==", "fOeXs+kiuyq8k7gYZR0Evg==", "kd9XNSBjIRt8Gh/ZOvPQDA==", "Rp9OSGQipDOR4a9bA2FuVw==", "TPyZYIBowqrU6+m4nrBEHQ==", "WmdYA4n7cWm+dw3CSnfVKw==", "buEdT4BInhnHtAjlzQ/evA==", "z4ATwTeQTJHH5b+Mhp9CIw==", "27nVgKdVp5Z2yN+WIh5Ajg==", "cbSORXfR3xlk/2j/nv5Q1Q==", "FClPDjyyXuDXkVInXpQ8TQ==", "d4ETjtVOtjHfsCmyR87WPA==", "SisGfjGX/TPw7kokQ3wHtQ==", "hbsENkHIOQnmxsyPIblNZQ==", "yoDPsHBdnYBYvpUe6q83cA==", "khK00kzr+C+QKwVhupsvEw==", "iZoWxs61dvDHFXevR0jvWw==", "s54OavJMmxE6M5mPO5T0Pw==", "QYc6DpX2RSeSt/RKd6dG5A==", "R2d8BwjTnNG4x5x8DC2N1A==", "FgYhTgnbuVdz9vvZG/SOpA==", "INNgEif+mrTP5jbRcGV3pQ==", "Bl1L7YkfYfRri1aHtOK8Iw==", "hoc7dG+Mk8W7soxdxHhlhA==", "20rC8H84jJQdDsfgxlWDGQ==", "XaThmJAaKtpx8Mjg3OXeEg==", "BlWzFLDGsRIdIr+8T/estA==", "YW3HoFXarBLE8Jq3Htt1wg==", "tC2vRr2PwNrxOJ/kxMcoHQ==", "vnP1NtGTRJ4ACQZa+PGWmA==", "6ES7hkRcIMPt5iPgfBeemg==", "d8rA+u4msoco+ymnNKq3tA==", "Vv3PxPN9gE/EoER6vTtqlQ==", "Lf0gWAt8cyrMV+1lxEIWlg==", "A5VZss399+5q0Kh9sFgjOQ==", "ImTupm53kNU++C083mygDw==", "uNfzK/lUTWl62S8/vMrtaw==", "JtMhEzdWDI1puPD9shAVng==", "P2lxsKJKPIWm7qQRXm3vKA==", "Wc+Cv0UbBgGLpFfKGy+CJQ==", "wOalQ7FUg/Trqlot6vK03Q==", "zCgR7/0cLZ1DORVb0QZM2A==", "8JDDEQtcQoyLw8fKvkdvtA==", "eSEHklhq8w2Gxt4i9Oe9kA==", "UdaSmnTocU22kiF2dyT8xA==", "IvNyA4RScflkfrHyoUsbww==", "WQgTTwn+g6RZhl4VVAGeqQ==", "HV3kDbwF/ANeXw+eGIqqSA==", "YcAav/frJZCC7Lw5hP+MjA==", "8bJ6TvpmLYG/y2sOhV60fA==", "XUbU+UOP9MU55829zWk52w==", "d1LyvMDT4Er4mayGqstCMw==", "xy63wlE2Qejaz4vatxOqZA==", "B8KsBsV6XL5o0MASDvIxkg==", "JbzslWZ8XhHtjGeJPRHhkA==", "ewHqN0+8nyoWSAsnW89H3g==", "RXvg9/2lKym73IdTnr8C7w==", "MIdBsN6uGjXn5hPMPX7Kzw==", "ydliNt1/jU+MUM6MVtC2Pg==", "sCWehNOZChMBKr1vk+63og==", "l5T8L+VKYOFTQZLSZbrRew==", "PNM3dlozFto46zHKLLUEnQ==", "1Is+R/NfLg3TYOxSDnUaVg==", "5P81961ZqTSY2y9Cipt4Ng==", "41FjDaPjaQzk7tn7JaMlRw==", "IAC/C79xmpc7WEKnnXFbpg==", "gg8om0EaDGmaluF17orLqg==", "tQ/cy6+608pCEG8iB+a3xg==", "rTJO875dJzTFghGq8UborQ==", "V8kRDFippjKvrzP8VaHSbw==", "hSujAslBKEPcDUtT6cHujA==", "hw1aS7NFesUo2f+sJX9NiQ==", "0X9H30gbmWBuPE1VOfDMHQ==", "7JqGXHi6j8X/siNtDOoeCQ==", "v9vWe3hIDrLLNJbYOtNKRQ==", "2GxrERkUMtotDqNjHyQCbg==", "uWYPETh7SRW4hEs8/1Va9A==", "s/hCdnJizrGpuAbegsTfiQ==", "yFRiUXE6QYAqPVgDGsvzCQ==", "xG3XYfxHNvVASsY6AJHqYg==", "tGzsBkfMtfrEHxSA/TTu3w==", "q165hps53MwmYpTpddoHwg==", "2NjwNSG4kcHNhy2M7KLz4w==", "XVEm+2KqBXTjMkwVXx4JzQ==", "wlPVMVy1Dt3H81fmbPL0kQ==", "E+efV15Gp/rLngRKACg3fg==", "JDTAxWidVWpCaBoteYh51g==", "m+XmqJ5VHL/uAOCj13Gx3g==", "peqwgDyzcNXXHAaS+9OP/g==", "q9xVEb6BV7jC4BJzDpa49Q==", "A13dtLHylURUHZNefxlSHg==", "/k9s3Dvh147QROVEXNykPA==", "UiVcHg1u39wxeAduIGVeVQ==", "mv4PinVh5v3tJxVjLXJruQ==", "NuQaIdTAWjK8WtwsvClXbg==", "W68w9FNf3fclCbjmzX4UBw==", "dqjoY6LI7HXbG/ZNHxRFxg==", "R3jTuLGdWUQtcXVXN/W1fw==", "0t6ZhLO4siY+a7KyIW7bQA==", "UeFIZtTayPvdOzvVB41/jA==", "WLo5mNz+nRD5O8r0IuqS6A==", "O+l1d8VG6t1aH2SBfORAMQ==", "H+FYqkEurnu4jymCjwERfA==", "bdwKFQO+8VB6A3n5Lckvuw==", "BE7WNDXAZtKdqmbO+76HPg==", "9uTlw6qkJF9H+PeJLKzcYA==", "ZkKRW+GbeCTumpVfOln0tw==", "QmJiluo6MJGfZS7D1EaJ/Q==", "TGoRkI+VuLFVYEHzjLAL2g==", "8Xzeresx+aYil0U4zoIbPw==", "WBKwh4EgcLSoFYU6H4fS+Q==", "wtkule9yShYfYhihK8c/yg==", "qhkvx4CfybVWilBosysd5g==", "YLkLxk5BFdJfmAIDIUmvjQ==", "ZSjR/M5ho85GTX2Ee3cGUw==", "P8sDnbg5LMrjsP/4Z+0szw==", "vTy7peJhDCvE0j2VylCGPA==", "Awx1BfuojP61w6bh1ny39w==", "Wytddh4/grdOMQGfYqgKuw==", "muQ9JOZI+Lpy3i1Gy2YS9A==", "pW3iP9p+y9BBPn5beM2Gdw==", "vsd22jqV9sSN27Xj1fhmtA==", "rhxXhWGHnmTccUSB2MF4JQ==", "uaaDC/cqggxU5t4t/B7xZA==", "ILz/vDgVPgLngI8Xhmb//g==", "p123ESKFXzhDZdIqbkw/aA==", "1Dy5XyHBfkrD1EQOGZjNFA==", "/47FUb26z0KiPP0KvwhAsA==", "GYeUqbv2q0crIzEsMTVjoA==", "4KipMI43odMoxXzBPDPPTw==", "r2VcHWjtXh+g8+PJJuOhrA==", "/iyMD/CLlrovNCQN6DqV6Q==", "dGkCup6dLBkxUtIMUMHbtQ==", "ejWOPQWvocqi5S9aDnis4A==", "mN2DbEhW6VqTjos2JoPnGg==", "yXuVTfc0mJ3Wo1R5P81UaA==", "u5o/Ut47Hjve2qfu2gi2Yw==", "UUx3cOvsfM1yB1cxpmSDRA==", "MmgZ4Cd3XBWQk/ZvGoOd/g==", "kNbL6Sq5E91SdgHe7lP4dA==", "8EaWp8elgqvtETTn1s9C+A==", "vv/Nq0/zePjAn4JWE5MOtw==", "otDNMIC20yfGt48e132yeQ==", "0tX86Ghr6N4D6ISg4pUM4w==", "b9BwljBVb2STBNXhnDZGew==", "kdRMgKCnW9CeTfNdZwcQkQ==", "gy2AALhX/hsEZnzWIdHdWw==", "kidvWKi8nb4dqsT8EqCASw==", "HPo+h/lLn08f9CNb4yjX9g==", "r+SLRw6fkGB8sWuKipdpsg==", "3I+BoetlmVjDN6jsA7RnYA==", "iXw7N4NbGRzgDoEs3/8Mgw==", "RSK1xJaKXQINWZhrI1wtbg==", "DtV4sdV1hSPQ0AIl8cr61A==", "6u2nND/vhxXQDUUG6S6tPQ==", "HJ9IDZvGKgGm0SpI03Kblw==", "/R+oZfF3C0jFiu9Vh76ooA==", "fbYAG8GGSRzTqm7WqFUn6w==", "GihEukOx/EVvJDmdnw71zw==", "Yv1KmLtUeUjnUz35el07pg==", "g0lNlx+qGIfIvwARrGZIZA==", "7une1X4kNaY52KKvp3/k8Q==", "HAjZuZl9VR4oQ2xpcqiI0g==", "9CEbwXSM4zxlVIlqccQLuA==", "gKT2K6FFmDBgo4l9aOgYBw==", "5Yd8bPgamMhmdpWlFThuzA==", "nDFXJBzen2MLc53jRlGtgw==", "YclsiNNGEgEj+fczIqUMpQ==", "9Vis2TWH9z/j7AjEfl7VGA==", "vpMXCnh0dDLSciBABeiYWQ==", "6ZwesWdsCQ+SFQKouk0D+Q==", "Yq6/Z75fMM5cPYk+D+3Seg==", "QlXZcP/gBAx3ErJ13BXquw==", "9xPy9U3WOy/2+H4t0fpNJw==", "f3MVLCaGFMZhT666w6avPg==", "JqBYA9g+3NYa6CczOXQGhQ==", "3+Zo5MGd6Ee9xwAYwT9nSw==", "h9BaEX+pzwj1f9hCTlIewA==", "GqTJcsBL/Jz1hT2nxRpDEw==", "5MdqoaIOPuW8RSkwuUUkQA==", "cPVrahyl220g0Gp/+c+Ekw==", "Azszg4XRyhbQzS0iD4UYPA==", "1INWm3M2WxieXT2qDaq7PA==", "cX0zpkj0M7q5G5AJpCXepg==", "9VaE7bXXK/xO2n6nA1Zh+g==", "lLwJoWtSVfftOhbbYJ+RRg==", "RySRoRIa3as132RYPgaQ+Q==", "LRmZme+MFDTrTqd0tt9LgA==", "8vil060zSzr5ACC5lwj23w==", "m0UDwMzBwVFEWXmEOBxvUA==", "RHM3pRxZLojreeoTqHcLWA==", "qOgf95x8MknvgeyA1bCtbw==", "GajE3N1YQ6FfS4SAySC7ag==", "msrb9fEz9Kqe2tYzX4cNRg==", "dwFzWQHBBqGTbd9kSgDcoA==", "WLEJTIMl3R9U+oSWIgIMrw==", "ztZFbmBHMK5xkfR3cHXb9w==", "4bp+O/hHtE2TomvTrC9RNw==", "jiLyHD81qvPLMEUaTrdWlQ==", "Fy01J7BLzA/Xpm61ujj0tA==", "VvK7VF34ghwBAlMiD4P5yg==", "MkiM9LdBRncPwjGfHTMgxQ==", "Vbe2XjswKKuAOoU341cwpQ==", "NK1kWadbZSLwkY1aoYnx4w==", "hAcRHS8h0bMTgAczqVlCXw==", "4fAqOoMQkPPDM8f1jeyBNg==", "IL1jRXwy2114/T7QtgavEQ==", "Lo3/+u57vnFiy3iLkojwsg==", "IiNBd3UzYec5KOagj4deCg==", "DUf93g2uSh44oAMP/2IC5g==", "yOp5kQck2BSi0PMC4MZ4YQ==", "2ot4aIu0LulaiafAuekqiQ==", "+uZXDdia4w8YnGrVMyzOtg==", "daGu3oAT3vmj5Wg7ZkBIOQ==", "gH8QEPM8ngOb72/e2psndg==", "SNKDZDO5r13pfUGn0GISlA==", "dIr9Ixsp5HnH41WPm8/HFQ==", "UQvyHOeI4QjGtZnm6T6ljg==", "wMB5sAuUkEThs0w/PiESyw==", "SEvHJqkvVkwfeRKpQlBP3g==", "6gtpOZpKlYN/fTuD2j7uyw==", "21bBfMmtWpw72atVduhNgw==", "uEgJFcCQ1Yyimn97LxvMpg==", "hju8ng9CG1pc4cQuvE/AIw==", "pLrSNgDWY1XE9frWN9/pEw==", "OdUQ3B3TaB6Z7yh9Y747EQ==", "FhmnYUCZZmwMA62xsJ7fxA==", "D+e0V9WHhxi4n8xiC8i18w==", "o5vXQMQiLzL6AxMfR8vX6A==", "1o5lA+NM0aNzCWTeAFzz4Q==", "cTd4017qSU3BkDE+MzazZQ==", "uLeGXSkRziPc+1wkRZ653A==", "c1tgx9s3K6ntVYm7+9+Fhw==", "EJB8Y62Fej4Lt+APLoeA0Q==", "x3ENI1lyHKRf/UfhURYpGA==", "kO53yCiQCcDnlmEzidxYNQ==", "qdg9ZGiyg59EqydNTlb8dQ==", "fC+PYOiejjO7X8tsRGcjvQ==", "vxmQyPOoTMh1Zx5DCsaQFQ==", "mi24MOG36XGGY3jdy9tVog==", "f02LQCCq0NBxbynpJcK7PA==", "kBTtYe13ix5ni1oAgQJaJg==", "qCasP65HH5s19aqlIVeNSg==", "lFQqA2gRtutYweiePnvnDQ==", "+5KO877diVdGAzL6goK/SQ==", "pRxWGmPbo78YrmxmMFHfrg==", "uvwI+W4eYxKuNvoT3Y077Q==", "g19H+ehDjsC8ZfUqpdQz7g==", "A2tELXXEKzN52RK4u1VO4A==", "VRBI4lPXeZDBh7vAlbseMw==", "QMKDT35jYGAcqqClVStulQ==", "hLgns+5VPBgBxKIOHCmUAQ==", "rcPmofVCF5dEf1IjBTTQNQ==", "xeEtsv5WJ/XPZImtAV/B2Q==", "y2QOurRj7ZwMObpAZgLNxQ==", "BycQ8Iao7X8iaC2posSHiw==", "qvI2ZykDyIyLk6Ymml/kug==", "3HM9ZkaDf/qSqto+kg5bSQ==", "cjf0OCUddVeaOOcznR7L+Q==", "+FpneGJ45rNW63+Qsdw/ZQ==", "9NrSuFGpsJVnFc/Q+9zqZA==", "y1HQd46JFnDNpDsOnGPiTA==", "fC/P2jWl2xsImLa95cteRQ==", "GqYY7wlQYv1joWZwNaBehg==", "NAsisJpfKjN1bhnqwGO/dg==", "hwXuy8O1w56Q1F9dXbVfAQ==", "FRliugf8XYS2sR8UKkFcdA==", "10cNbQG657ri8WsAsUhByQ==", "FJpIbicmNxXfM2KinGJfnw==", "Zj7vExxsRx/s2nS5nq7feA==", "GwDIWcE/e/Kt96ryrmbvAw==", "0jSW5utK6X2RgUuKOjtT/g==", "seCbnaAzWN2Uub/hJsbccg==", "wTS7c0AxSF244WIdQ/+I+A==", "K9+A/YujZbKHptbKzfLGDw==", "jyWDLwaa34WPueVKizEYAQ==", "qNFgRdQ/8x4TTxwJoCtMag==", "J8jkPCTciB9Y+QEeYk9/ZA==", "qZUQGxSS2yVcoy0lLq8mQw==", "2gIKJ24NaTvU5hH8MoOEHg==", "gobA70V8S+fBhe3etA88AQ==", "lGk38AMlVf6u9+M+1fHkew==", "xj88t0vf170EWiUK/oDBXA==", "GzbJOUxG2RBo8VcUzgwjjg==", "D3XFmzgwlaUj5224Ty8BXA==", "Fn+CsGgMYWH5eh2+nmnd4g==", "ZxpziBdNrTlF9WyPF0vZ+A==", "wlbPXuepg4Ytqm0bj0dYBQ==", "L2i68tImyqS0x0XbBigK9A==", "8gbN0n+9VnrAx9TxfaZCjg==", "8fvdCdxGOPLTl/QZZmHYXQ==", "/VWikrEHhKeVKspNvUnevA==", "2Y8tgHjdLW66sj5oytXtRg==", "S9khA+AWY8JaldQC0uvPGg==", "8Ye9q4LnyzDb957ctelwBg==", "334T6GRBjc5YGYpYynk7jA==", "NcOCxDESPibyfzi9bB8MWQ==", "njKjXe24Zkq17Blj9of/EA==", "C7tVHOY8u481+kV8QvenfA==", "QOBrzNFBTPjlxOPHaS2UrA==", "lzdlTLkaw2hqoABNUvAwFA==", "+FjM0LpqQllzdfIgyzd3kw==", "56ie/N1k4egyMQTtyui64w==", "u/Ur9qmhT5bd5MffRn9ubw==", "9bLphFFEm/w48fWObkf4Kw==", "1rtxSiqG0YoKdvUs0mjbww==", "lj0olDIEOqoIZRmBl/tcnA==", "BeYK25cFjXVIucBOE9TZxg==", "X+KWCuGLzTBeWttwniMBuA==", "eeINYwTym7iJf+A3+yWIxw==", "5jJsYB8Vm6Wq13rSxq91EA==", "71JlBQez3bAZP4d4xP2Llg==", "PKaiUOTn/Mfy5YjfqxZM9A==", "iIogkXVmWzUQmvCLYwSVyA==", "1OXdOn2y4C9PfQZDckFodQ==", "zJmne4UGfnz32Y9xCDqh8Q==", "9g7xBDIkdEIdlbmN8c78nQ==", "8z+QHi4S4WDm6aWogE6kuw==", "F/fb6BDcJgFpKT7ts1WqjQ==", "CD5zzBd12kSBWciGkqLjZA==", "abuRlaIjMoxp7JxuUe9ZMQ==", "HbRvfbMLW4w7vP8bgDCrkw==", "Rf60dR/Fk4GWivBblGX5uQ==", "xGaIha/H9yzz7QrGLN0uhQ==", "XG93vQK96jZKCPLypcOiZQ==", "fuR5h+zOLXeaugOCtTvDxQ==", "inaCY6PIXgALdUE7MAms4g==", "8l0u4wAMOeupHbUARpHfuw==", "0qAz5+tC5TUL0H7+2lA3xg==", "FlEYOi02huntZhTu3xrArQ==", "YA+baRm92vzKN9/R841SNw==", "Q29O4Bg/VvfVqS3UXQeb5w==", "H/zWlIpN8aMvffie7AG76A==", "/4AjAEsHRRa43cZAeshWvA==", "qeBuLmsk7oK4Le8+TUU3sg==", "/SJ+Rrv1FPQP0mdKaNJOCg==", "7n9MSpyjqSnvfsNTBPI7MQ==", "iShLWfacVbWp+yrwXBiO+A==", "QP+4ZaPTGK0vJoGz0t342Q==", "wKDPawUoi4V9YbgaK5I6jA==", "WDdht+QZQ3xI6LngG1n+jA==", "WIR2HdumojMDCSS6nHR6mg==", "Sg9xJ1gba62NLkd95QOh4A==", "zPAGkZmePalOvIEfMGZYQA==", "GVvZ1pyqS4BMw8vAHqz3pw==", "RZbwexafVJIj0fYiHghpiA==", "7PWa/1p3+m/2Cnct0TMQmg==", "68aTZzXBvZontWtIx/3b4g==", "YlR3u9lZW61NKtn5JlnTOg==", "xERS7Vmbh+h18uOunvn0Vg==", "1v78L0F0y9NkJWyNm5I/Gg==", "pfY3zaK4i7i+hHz4F4Vyrw==", "sy3ilamsUq1ezzG2K3kdrA==", "wwkdl2CLVEKYg/La3pFh0g==", "LQ+t6bZl9RlU5H2tsWen1A==", "EzI+oZVjbP41VkNLC9FD9g==", "2OZ7trlKRLnZsFv1sJvUVg==", "zUuWXRAoo66dgq/CBXEmGA==", "gyC7EL6tB6bwD1BROgqS6w==", "9sEDdvSMwzMV2kaQDYeUkA==", "9pBu5jCd64qlIVwlW2NNSw==", "99HboD4nMyDk4tse/s9C4g==", "7x+psdYzd9mM2qtbmtW+mw==", "8NnG4EWsyzQmd5x6/PohVw==", "0GN6z/4AhTLCs/1UdBBmxw==", "eAkF4gcKeYvDteK2Fky90g==", "pF+1QuZrEHlKVc2WrF9eCw==", "kZ0cFnzel9Dx3vpxtGT7Kg==", "VogRSV/2Imj9EVT5Y+ZWnQ==", "q59b7LDKqMfkg6R/H6td8w==", "mpo3/WeOVY4plMVPjn+etw==", "YJVyMngySk6wihPKJdBk/Q==", "FEuiyn3Aju19ZoBdSagxJg==", "uYADkNPHgawO14s3lEkOhA==", "eW5sSwfH19cOVhqOjFPExA==", "NK0hpvWCXi1qKWF+3Jh4KQ==", "LsID8egvR6MllXOxUPXkwQ==", "0lfDYmZXrLVXyJHmV4fhNg==", "DTqW4x46QrHUeNdsdW0MbA==", "bFiZXYN1LhAR839UCAG4ig==", "v1pFZ/L2vpZW7UoIOvtJ7w==", "7AdvNmaPEJQFk5ZAY+XM1g==", "xriqbRDjo9/OFxZ2ulgl4w==", "XlpyvWfZ026/hB+1UCTGeA==", "uwxCim/b7jTMXTjotGKJxA==", "PoujEHCHWEnkSxht3LvodA==", "m0SyM5ZUWH/WciovBYjlmA==", "tK8NTpgAf2tGi6JtIelJEg==", "A7Yp8lXwx3uwqC6eEl/MIQ==", "VJ3UbesVXW73e03bBBZDRg==", "I2QYqEV869V5y9popmkhNg==", "1RZWxSY70nQZs/BoyJpC7g==", "w5DYnw3Ql//vskdC2DBVgA==", "oV54bC4E88mNdD0K7mJgPQ==", "5YOJRTnjsjCt2E0ARGLcsQ==", "6wR7TzqM+LTXLTLlLsp6BA==", "9hBTSrmMYUQVapaLCp1VhA==", "j9wLU3+UtGm5/f7Rj8ErXg==", "7/erHjcVbxG3II9T3g8TzQ==", "8VV2hxLjCmO9pEMGLA0x9w==", "5BK0I9uVtsTWxIanNlMYUg==", "Z7Zr+aJtnT0rPmKmG4faFw==", "JUvDbSDk41M9/2isiLVsVA==", "XNkZz0xHBwW067x0zzkuWg==", "rNGDQoozIwLRuTmXHEeY2Q==", "q729w5sFLS4RIFtNLkblZw==", "aBoTsVzPtAMF2Qu8j82kjA==", "lKw7TsGs0QExvrzGu983hw==", "dUtIAkfbSAmbKtPLlwkJwA==", "dKgSHf0ATLcRYz460eZ3Cg==", "++HdLGarq5GIso93i+MxpA==", "a+8diPCjyw/R86R6KSI0bw==", "gpWgVqaQmhTigA4n4UKLcw==", "lxpghzTAGPYPM4qIkJMJ5A==", "KIWTfqGvHChaaQEfN6qJjA==", "E2erXXyfGoHicKp15iuNEQ==", "2uOzzZZ2kCVXzbYFBm8+Hw==", "nICJsssx8SRrJtkPaGWSwQ==", "5rlXhvFkSnde6aIX1KftWw==", "7xkpS42Ar82kePpM49ESDQ==", "0MdjxnJHuxg0I0Sa279UwQ==", "L6sfUnRyu2lAMh3ROdPlag==", "/LPnqt/sacv88+z/V9sCnw==", "qoXDqpTdCFxrBlCQ121ojw==", "/6uQNJy+iHLVC38D5Bhy9Q==", "hrRIVmXshFU+iVUyHoT8iA==", "JVgYJrtjksiu+imyHUIFaQ==", "jlrTr1dyDTh1M5CunQeb0w==", "IhzBtHWmglxBKo+mcln/Dw==", "becoMjDxhD0zUVLDpif8cA==", "phvXRGzqkL8KUB1+doHwOw==", "6Tz82TUDik0TIK2cdfoqZg==", "f22/JqHREO/iFR5wVxKZDA==", "b/gb9s3KrIJfPaaNxJoujw==", "Qv2Wv+TjxG5okt+jr01G3g==", "gyst6sbdN8tJ7Od9cn3GJw==", "2TjC60sJ2qX3uuSPiJQTaw==", "oJmCZHz0uc7KgDTvu6vBSQ==", "DTa20HYXjXs/P3Zs9HN/QQ==", "oiZ3IyYpSYlSJn1LdOeXCQ==", "u9Iltn6Pyk+xlGjtrBt7hQ==", "dno/h8+cbyT8NDmhCje7og==", "msiaP6ZPjE6ydV5RJ2powg==", "kM8v6NxzXQPaH6W0rRyY+Q==", "i2AkMMRWwQC/zP2vb2ZDEQ==", "y1e/8gBt80FYuAfr84vIvw==", "frvuZApIP1qQmX+Pqjd9xQ==", "K0pvLWS3Bi17A0Aw8q10eg==", "nnjR/U14S0Gli7ekeQUwIA==", "MJ0OFjy8U2e/bsG70rEfYw==", "T4DqnulOMrKXYCngPGMyDg==", "F4LulQAYnY9rA1Yhcz1gdg==", "NLzrvdj29R1KWzyuO7vGrw==", "wOnjjjijWVo2GqwgzbvYSQ==", "6dBKp35A3yhlTjiBNtzTcw==", "bF08jSMQQwNKtSqSbitR/g==", "0HtM1g1taJ19/JeX7mpPOQ==", "FHdwzMKhciLU2Fxy3C/l9A==", "+0bRxY6TjQIuqDlOK+2izQ==", "msRoLpQ5RRmll+h3oQOUPw==", "gc0jFzxcW25N62GQDKSqMQ==", "IHXe4WyflrmOusIwp8d5Nw==", "AYQU3Kryw6wN3SdT6aXSMg==", "bfUuYbRigpZ1CQq2y/uE9w==", "o2jo+ACRJMvwEfq9dh6AZw==", "8azNbKhH8TuKXpL7oWx0hw==", "D7hEv7Md38UxkdoufM/Uug==", "dlsfp46B9QH8SoQZzW6+/w==", "GbgKUjPpUdUMMrRRtGYntg==", "wk03AYMKhB6F5bR6XyAsHA==", "CLneAUk9k5p+117hZeCApw==", "P2+GI7i9vikUEShC4ve81Q==", "BHVVtbEjnE6kNRkkovl+lw==", "G8YItgV0rZhbyR5nCdBBFA==", "DWmwcDyd4pU5vUlN1XDyCg==", "0llwKVzNKYr3FDiLn1hJfQ==", "eA2NK3nIYMq+exBDZhhXCA==", "9kW5Q4QIU/r33UUcynzNXg==", "6DQLqxaGlg/lwlTdxRMONQ==", "OWtN2QRRD7xZ6IJXy9oe/w==", "P91CMsaALOlJiJxLpiVGpw==", "yHxWeQY4NF97p65Vl25LJA==", "R1MAm+57BqKjyvlSiGGjrw==", "zDrzSYkrjMow2M7l8FVeow==", "jhjhpZEqUsE/GgGdvBBzpw==", "n2hgQh2mltiPUrbZeKTKfw==", "vGwkpBqLshgMfCl70d0myg==", "yVXH9XGqUox0RMMoxgLASA==", "jSmJL+G9oPI6MUI27LQFSg==", "D1lGDgRmVddpsy/krPkJWA==", "ZpA8oyPAdi7/RehnLZhJwQ==", "ONPAYP/p9d2gYGt/OPIPqw==", "XKgaiu1TTiF94OEf06hPHQ==", "C9wNKgQaGWqBeCwo1E9bcQ==", "KbVdO3g9TpKrFW6unwJ3eA==", "9kPxv89eatdt3SCRDIz9QA==", "LSj8enWZZsQGSoQTpJsNLQ==", "b2VPlgx4qj2KQUTqmyJdew==", "boBcfhbBL2Rh/aiBtdXUjQ==", "MWwgjsOk1ofNsK1d5IdecA==", "I/QRd9kPIn5zI7Mx9M0CGg==", "jHQXL8f5Ll8ieaW4clVTQw==", "pYy6TvaiCqEs+cKkx32ttQ==", "zN3XlOxCBkILB636fP3oCA==", "iPYyKUE/vmQTv1il4lqxEg==", "LoNrKFr+U3cMzjwTDABwMg==", "D7yI+RxqvpHcdBC67a88Cg==", "sL3KpWpmO+FMS7A9UsXdDg==", "DQ+fBbiyBgmY3FUEecFZxw==", "WLUVqWxLwr0GY5Xim112wA==", "oldZxrZr+ML2Z5vdlIjivg==", "t3O7D7jw7OlvBQ0xuLH+cQ==", "tr3xh4aSzA1KYajxcVhY0A==", "jcHyaunHiTExlq7AibAZqw==", "nfe3l/Qiy6DgNuk9w1rfsg==", "xvthDFTRm9NDIq9MylnUog==", "0E2oyk9T5Tu1U+CLXaiEEw==", "utgx/90cFNFOG7HLlgQMVQ==", "mtsJHWk1Bpn3p7vhoDLtug==", "p5Mb3xCHDkUNh497GrLMdg==", "p18kTHw6vPdSaxQ1n59IXw==", "yC4kMoTeidkpBuUtWAJFzQ==", "+H/bIsJx0MWpkf9xibMEhA==", "F0G9v3Y1nWxDqdEHKjHhqA==", "o2j1vMVAP/vlfzZZpode4A==", "uT3bFChGChX0XV/PpW8+bQ==", "L6mHELyLIvOeppCFbTEiYA==", "0gA17o48zImKmwnZ3FkTlA==", "B9YYU+s2Cvva7QJUDtHgtA==", "3qkUNBO5aPJqcJSUaSFBCg==", "0L20TVSGH+Xvumc2z925bQ==", "nEDHnAt98ommvxFRwuVpOA==", "uT3dvwJpn9tGTvL/XiDyZQ==", "EEy4+NI4yL8RKqCOZipymw==", "pRHfMy/Z0maNYXFcPxZbzA==", "KGtQEHShm+Nh11YMiqlHfQ==", "ORg9zjoAVr2V+FF+1/aIzg==", "SEepFiQnAZsWEFzEFPs56w==", "tjUOg+P5YgWl5btEGrYxOw==", "sDSrA5Cw2PRAVcxX/za76A==", "nIhEjmVZOLLsxjuIgK19MQ==", "T6jUkybzEGhntULjAsvqfA==", "ZdJ0aFtVMyqkCxjnG6Hd6w==", "joye5blYiU3Lze42WmGVIQ==", "roEJ3sSQTvxB/BsqtXwWkw==", "6Q7cSKnTxu+nzr2vFDnZQg==", "4ywdnWajkUpzJhpgBOXFZA==", "hPf8NZdo1gT8Bb3FUXhP/w==", "jCxEr8JHsUgFjPxyQutQDQ==", "AqPsePg/x9foozdu9m7x0g==", "tf2LLVKK9ztdqJ1EUc9k0A==", "TUuFbo4isqcI/XbM1gY5Rg==", "LWHMtlh7noa7WaBqmptSKA==", "3kIHF9M2LBX4Rx2YoP5boA==", "1URpR/kkS5zJM9sTCGG3pw==", "cw1TUdWPzmOtwmbS1fp9TA==", "PtVDQvqAWTWjVkSW56jMZw==", "dXyvpx0uFAcdUbyal2rtbg==", "XiJI8JQ+WXVm0Ec9LMZ3JA==", "RKjK5hvAP1fD81G9qknIXQ==", "O3dORpbcud/0vqRs7HyGhQ==", "ec8TXpqSyie6lk8Ngt/5pQ==", "RCPRH8WEB/73FUqeKHr/tA==", "sLSWW2qZrLURobO+B3605g==", "oTkz0SJHnY95W0zjomipFw==", "dSdqqjk3yXpPTfjox/jBBg==", "0K3AIfDYtx7QdAwi8fy/tQ==", "j8iy7RKfxZethWyioJYxlw==", "GF6tUVJPrzwKahsYQCql3Q==", "Ot2ALFiZ3eowUTEjMJWYNg==", "rMaA49qwWtSHUzACuwQ1kA==", "8muf76acbZmX8cloC5+CHg==", "HWAHML6vgJHoz8eWpR0Tfg==", "VtJFIoe4RZpuYfcXkn2FAQ==", "qrvZPwEn248D72+1ztchmg==", "ucmV7WK26A3Z2691L+x2pw==", "VgzyFJeiC9rkj6o3g1bF+Q==", "BxmPqE51CJB5JIKaQ3E3/A==", "P3dCGUpIbpcPhfTgvL/rYA==", "RHXquoov8J1zuTpnk4gIEQ==", "sc1dlk3LluxR723zHmEQbw==", "GjZqVvRzaJEGIN3eGK1g9g==", "q0Qp3076rS1P2dSC+JQopw==", "7deukt0nx1nb4gAr399SPA==", "0HOHcobRnpDN9ct7nb9VmQ==", "Lt5HHPW4BE0rSRDcZNrHlQ==", "8s7wZf02zu7kRPi8BEuaOg==", "mqvRSx6ER1B7t4SdSaZBpg==", "l7FhOF2AzGUuX4kVh9umhw==", "r3qyJwq8y/vEn0Jk2v+zxA==", "DgsLnFbbR+zE3+SFeqm4/w==", "qptj7gMK3lgQhRAzWzItJA==", "G9rxX0ybHgw86Jv3kSVS4g==", "U+wbm6D+bKmC0YerxjSEqQ==", "gay3MyHX7w8wsA1EXoF3dQ==", "gBevJICSLIQl0IiTPmQ6qg==", "S4UDJEN31Y9gXebwQEZXnw==", "7FcjXbr6LhyyOlh0vreQ0Q==", "6pA/AAe40mAnWhJupYQJTQ==", "1lREQsvprqgku59eCPwJbA==", "y7pmgQLzMRq88J/vS93z2Q==", "2FzvTR+a3XQlWcXmD/u7sQ==", "CM6brgFmfIaakm9l757eVQ==", "9GMQf3G2BK87x6QUHgjgVg==", "5h5AKXgZ7vJkd6xJ9eKDGQ==", "20WfS86dqjcN43OOzbzJHw==", "phuKT06g85xsllUzJW4m6Q==", "KNBnL8x4YgVUk9a3l4+5tw==", "Uyt1KDdT5GAgyMiaZiypKA==", "X5btFWIXIO7Mm8lNAKiCFw==", "bSGK4tTg10r8DpiEIpZRyA==", "zOjya/MbFb3bR1ErYSGZlQ==", "3sJJdZ2fQt+gHsMLZrLiCA==", "zS4kBiWfhQpglSqbg/NYUw==", "0IZsf9dz4Us+xRLW6BtuLA==", "x1sJYHj1Yii3cb3WNbR0ww==", "izsq1j3LIr6xfhULctXn1Q==", "d3VShHYQEj/Dm98dDAtH8w==", "qC8C6X96cimg3e6OBu2gcA==", "6z/N4Az6vu/Ht80DdvVCEg==", "PA589Yx2mGOwxMg1sXMN0w==", "RrvaRGc6kM93o5B4pizuKg==", "rL29zskMDhs3jgGi/4V5FA==", "u9eV8+DVR//GBavLQ3uvSA==", "lA7ruehTmgKgvtJi2MUvog==", "0r8cGAtKxqmEroQrTr1a5A==", "C2rkTVkGbhSsyKrmiRle6w==", "tXow4avuWZvMPnoVix+ybQ==", "cOsJlkk2OUfZSPuuxDW5xQ==", "tYvCYxSwmhDDaN2DBZh/lg==", "3VkUenslT5nKy0iJQN6Utw==", "RW7pMUOuapy77fLYrIg6pw==", "OaLlKdp4dalc9B0bAvjr/w==", "W8Jcu+Pl8GU+xmEpyPS4Rg==", "ralGcrzRAawbxw3toTbgRg==", "I1DkQsTuELtTHEgBqr+BVg==", "vr6U2lQ/hMXF58n2KZKXlQ==", "nN3RuidIOX87KUHmtXIlYw==", "il7wrKgnv2XFHYQrPt6FUw==", "zO0DTAUP46HiUnxZY7C5hA==", "OudWGxMkT04EAPUlATCyKw==", "fD3V8WvG+u7QpTEDqTMUAw==", "QFJEvbxzg3ctxMvbnApYkA==", "24PxqvKQ7Ck9h0t1w2lO5Q==", "G5V+qv7EnKUSx9A7fkr1ig==", "iVx3xbnEEWX0lvHLuILwkg==", "e8oBnqMThOSsFMwmFoH9HQ==", "Um4hWKnCf0UxAt6EEhGwzQ==", "I5rQJEau/vCfHOUKEwAKEA==", "Diaroq/WqYpF8rJ936nxtw==", "M784aJgm2VrqBMgf0VR0JA==", "VFI2YAPt+wwgNU00tRnLLA==", "SWPowIEYYudHKp5flT9zvA==", "Gx00DehD2xRAI3D63RVOjA==", "15mvvSzVZTLR+G7FdXvygg==", "uq//Fq4QaSws9yxxeAr1oQ==", "2HTtDN23c79rRFsL7WaJ3A==", "53zxUuzjClZZkScYUEBz4w==", "9o4tvTk91flE9SCiUSP70Q==", "+iI+0a0H7BIpaX/3sqTeqg==", "GDwbfYxe5K2nm+263r+ovA==", "gKllHD4ZF3u6+sYpimhiHQ==", "oe29ifZuovUIe0KY+GzIGA==", "Tdhosk8QDFrBzFw1O505sQ==", "EGnO71PPbM9rWb9+S75duw==", "OYZS0g53R8lKkEyzqhKAaw==", "f3CTm99In33LVLjnI20WkA==", "X3TrrLKAzF8VT/gBWvF08A==", "SjOLMJaPaetNB7CJwZwaWA==", "eV+P3z67kBdWDC5tFoPXmw==", "GJrvy9jffG4zI55Mbn9hPQ==", "N0pXiwLCavo/09vFe/8Y+Q==", "scjuuOqx8Qax/3JegyCKcg==", "OyZClLDMbQRE/2KgCJrplA==", "pJdb037ioWy4GlzuA61kjg==", "4Ue0mJ4LvJpt6XGU8X1WSw==", "LWL/yb4swqiUg65uYn6G/w==", "+Plw2tabjfOcVdKKZpp6kQ==", "durgJGXj4cHm6E0amlfNVA==", "q7Ys7sKsyGWeVZYZlY8toA==", "cfv/88ztD/p87G9Py59kmg==", "PASB9dYrqWcXbuomz7pV0Q==", "pgQbd2pSFJgZhzfneIdMCw==", "GBLYo/Hpg17ZmUp20DxbBA==", "6F94GA2WFa6JdVf4FibsZQ==", "aigq+yzTxik8E8CLAWPW4w==", "nmLo+5oFZcZwsNKc/4TkXA==", "PYhpLJ9RKZfyoD9gRqTXHw==", "CdgEydujtCeBhG5XiZmOUg==", "S5XbWbaEYS26ORNQqOThVg==", "zrmO+HE5JByCv0fKZEkTvw==", "TnHi5HWbIX9944L/44v7lw==", "mYbCqE0WYSxXEX/p4j3j/w==", "PxZNCkfZQaCYwxe14mPXGA==", "mAWVuLFcEHWzKwVWF+mmow==", "eAPPNp2r6gp30swyIPgs8A==", "OTrExOT2ykXeHWl52M9Mcg==", "ln1Lq6qzUC1Ys0m8YLemFA==", "865AsH7FNuZXb9d7RiRkFw==", "lD3fwWxRJRf7QGu76Yui/A==", "1FHhd29+E67AOWcm+GUqJQ==", "4HhPzsELhG/UXDb85H5oYg==", "YOjM5JcoxOtI+tIAYob+AA==", "ewtS4cA0J2mjfFxq/QBEkg==", "JeKSqOKLpwhp1P0VSS+TJA==", "bQ14Sxqd6BxYkrJpOMom+g==", "aayQJupbsBVQlIfkLyOZzQ==", "BD42nQToL1fdszU+AsHeUA==", "nQRVDJA8dS+gnrKQ9Z1CkQ==", "uTS8BhrtK2N7W+qV8za2Vg==", "131HLsto66s+BSz7ExU7PQ==", "GtrnpVR3O3zqXqNcQVnSdg==", "am62M/CpkNn2LwlM/A69bA==", "79WMS6tb+GafO7Jnk1cW9A==", "oXhrmejScbhntbL1S6AJTw==", "2k3Srs8A63nD7VMc8eJGDg==", "6nif13v4dYw7gjNbruZ0Rg==", "/kW6pEn0Zy2tehKurgKtPQ==", "o//PejU8uemBRUHDfRoRJA==", "I9owf7FzH3E77Ei9S343oA==", "GMyNpSQdt3P3zg1eWylfrQ==", "RfsugNWfNkQkkeZRRmj6OA==", "+PJ4bIlZWFeM+AWYRfXeKg==", "02rBMXIw8e/W8DLaacuURA==", "SM7H0rz5ObYMAIw/TQYRpQ==", "zLMNfbeOAdf/1PqX2MIsfg==", "vYXBLgfa++/Y7S8DCCK6kg==", "oZ9JVmNUhJ/PNpWTcaxqQA==", "DQTeeBmq/WUyAFVYi9GppQ==", "x5kJV0vUXZM8gQjTU1an7g==", "uXsz9tYjG7LKTz0a7qH3BQ==", "BJSkSr7uOl+9xHp0ryZ62w==", "TGiO4b3FHe8JhZ/HfsRRTQ==", "CDrNE8A4NBsnPAqoIUYOkw==", "Gfnrd/Qq3NY0ytzgSjsjfw==", "WzuogyQu2dsLRYZjLeTWhA==", "aAqnKFLRNriCGQlG3eKWDg==", "iXEcxB2DfPdWKg5BNEWY1Q==", "OER9o99pdjlfsp56JzoqNg==", "fwbh8/ZdzRiNd4UOFeO8kw==", "huYa0W+0g8fZ2PeXYJCMOQ==", "1y4dDNJi+yTWzay2iOe/mQ==", "1Fd2YODU8WjYM3TXmP23Pg==", "XUdSfenojPgi0C3JLdCmEg==", "X/bHAQhdCYw9YE9271HYiQ==", "innhwwtG+k3NRp4Z1S3aPw==", "3jDKPTolYWHmJt68mR0ScA==", "dvz7cMDPMtmwIDAwMwXWkA==", "BUICuyNb/ouszFn+JmeQAw==", "6uzFcJl+4SfrToHOfIjE/g==", "D9VI64lZjFQsFF2NnyKSTw==", "kk0BeSmKqmzGoT7xIOWJaw==", "MIkTRAv/IGPjw1oKbjib+g==", "dl965O/zOjLqXHSSKKeKCg==", "CipgWP1TNrEuX30sXyiVDA==", "+SomP1jA3ScGJcfWiUw9WA==", "TRgfVy4kI8aktXR88Au/ng==", "Nvv3pdW1HxIo+5qMwgrR5g==", "w1oeUHbRVVOslv73KK3P7Q==", "ECNIyveMfVfcwQzGnTen7g==", "d0aaWDMxUoX+Q6AjYLkMvw==", "JqM0nqzbtdEgcyvoIyzloQ==", "Kw0EaPoYj535/n7O8wuTLQ==", "SXstzXJo3ARVPRHH1XkipQ==", "XYrWNG/ZD9L4k6Jv7ONGBA==", "ms6HlDT8WIxnDT/547gqTQ==", "ZCSymtjadlzkXt8CU3F6PA==", "clzVgq3hfrfUfnMH/v6WVA==", "H3+fTqUBus2576Wg9ZAwEQ==", "br7LPYZQDykBoEzkc4rGkg==", "4BExWTUzjM87Vzt6iuYy6g==", "fZVpSeqDPAMZq+eNz0K+JA==", "DDyc4d9FxDQMYN4Q8LEQAA==", "cS7rkbIe2yBX5287dNi5sg==", "2Kd7B1qMo9h48Ei0g8TpUg==", "xtYvwG9pXlzZuhCh/01L8w==", "cFyzieI80PEaY8L5vFgLUg==", "GdrnB+j3VN7L66G2VDQT/w==", "KCR+OKWAEK8jxDXW1fyJcg==", "iuA4+apRQjkon3Iu/gGtXQ==", "B1JjtK21NVnmDCEZc2qsZw==", "inNW/oB7BMbIgnOSCVi/1A==", "BtqbO6KS0TZcYikpFy82Cw==", "lfk6+WpQ1adbnURKkfPv2w==", "lg4ziUlz/8WSEmaAMQG+XA==", "yoNy2I2sbE5vTpot54Noqw==", "dJSdlRZsvhGjIVE5Ol5PvA==", "hHuds3Mc9Bpql1Z9vbWn2g==", "FSIPRFtfRo70nIMzV4j75Q==", "VgbIlYn/yGYWh6cVqQpddA==", "SqunC8KQn/zUdd4jPxGV8g==", "+iuUv0opvq3bo9n8yHMW+g==", "Z70NNghfj3CUDoF3RSOhtA==", "0JY6fbv07QRBiECIH0qRrg==", "e8yl8xEHcBMt6QNxIxnCxw==", "EJ33qgRazVLqeAKxd/8pXw==", "kpPp/LVicTFSGqQuIUP0fQ==", "VWpX5DzXUBXf2CZ3YPlpsw==", "nATdasCaoRj0zKLOYIzA7g==", "Akpq9uDUovUJk/ST/qplwA==", "VLHKht+kiKS6NMvy/MetxA==", "xCLaWjPzCBcp97ve36KSvg==", "f7Zd/PugLsAhu1y1p1pb/Q==", "keb0BYbqks2Jt/xv1VHGMQ==", "kqzISkE3CskWY60zyXu7Og==", "+GZxNvAM2u9WlBgow5l1kQ==", "XEO2N+fKL88Nc+lWd2zGlQ==", "/72eyAw69+s+htVKV47W+A==", "iZX1sSr7/tbc8mtMDlBUxQ==", "lCqUsiwpCWdi15QTuyEemA==", "TtPAUJEPt4ox78QA8ZcSgw==", "54ZbClVVUK2Kye4aOsmx1A==", "TiBB3rhbLcdx2WE3ADGWag==", "sNFHesILBVZ9Xz8u+1R8yw==", "V9t26J6ZUHangNhaOQv5KQ==", "mQUiqOxBu6sTcRb5JQuOcg==", "mmxHxuvoy6NJ2C1Mq41y3Q==", "ENsHyD6BH0uRYy4OOg9ikA==", "biBX6JK0iCfEVUm/Gb3CjQ==", "uBgGeOGTFkYEcFN9GrAVZQ==", "yzYZsRSpoGNn6ISpW/sHEA==", "3Gnrg1HuF80NYk8sDg8vpw==", "9gK+Gqf4Vya04XVvFGXJtw==", "VyBNyzFVuqLQur70rY8brQ==", "IRuMvMA8Fi6mQgkH9s634w==", "VhI3fCsM/ubhXhs9Rae4mQ==", "0PA48EgploV9aVx5eXrXhA==", "Yx94fa+iH+REwbi33a8p6w==", "BfCej9ITNGiYvMRyg3dQRA==", "gMBJpO9BkmdlfyUVgqxitw==", "B0VlhADEhd0NkhsaLhpQSA==", "i/qfmVnfw478DUjEfi5wrQ==", "yp6cTkkawZGD83epsBl2Ow==", "A5edsP7XEH6D4cmvYBsj+w==", "HUcdim+MD+uinTOZqB/5xA==", "J98qdwAtIlFmuTWiWH2dZA==", "f6AXHBxcapnzSbd6qwVDwA==", "7gEkx7h7id09bJ3nUfeoDQ==", "bjHG8/MdZTTG8aCXn6GAlA==", "epW/pSv8hD8g7lw/GzsiZg==", "304DlzeJN7v/P5lwODadIQ==", "dvmQ2v1rsHGGjW3x+eKSvQ==", "IkSL3kbr93i9k/D1z8DQOw==", "piBwOKVUN61Uds9fQx9yVw==", "nUqm8sU2PJyxkU75BauqBQ==", "AepvaOoHpgY77IKxvqCVwA==", "dHzaD2Y00RGnXHcbRlDrUA==", "0MmyGSoo3BjfDz/rvghu0w==", "FthYp8iOz/26jfLVwXB8zw==", "T9d7eiSCgaG9+XuCv6U0qg==", "ez/7MlfWRA47u/CUpm+W6w==", "qIDjOygbC4T2PrpwyxD9SQ==", "8YPiey8As9kb5oGX07GXAQ==", "z/P7T8+QR8jnNiOGyPUwAQ==", "SQFW+PQ31vzHzDdxXe8f8g==", "dg3K65C8jJdIi+d/SalX6w==", "gHf+ohzp2wBUa81nDxLHzQ==", "mQY2cBerKZkBCxSHL8eURg==", "fkPgHfvVMKu1Gs6F8yWv7g==", "apLsRonbFnUs5fqAcBbkRA==", "cCE2kvJ6L+TNVLLtkgOVng==", "2tcTjjafTpV2Ov8GmqFflA==", "Er+X62T35/FYbVBB3GMZvA==", "PgZ2lGBOPfLgmdY25m/o0w==", "ACZllLUORfDLpn3ve8yFBg==", "z2etEwwZ8zYYznKnP9hjUg==", "5gUw7V1UhMnK6YoPfsX5eg==", "DyfgvZwD3+UhyLH1t8vttA==", "7eTva12msMAYR9wW2m9uvA==", "viHIBVs5uaPlB2vc11zGuA==", "MKbNqtVKIsB4Skin5vwLuw==", "IOSxX+ObQIo5oS9dnmmDoA==", "iCypsGLRz0uLfvrJIEyGzA==", "tedkwtFcJID1iDvrmjfi+A==", "e9wCn09MX9e/m/J6umidJA==", "Z7jfyTdh0hmn3U15zwBAjA==", "XwcGNCaKGppyE8H0de1PKQ==", "evy4OzzM2ENIuS4DaluP/g==", "DJp7nKlC0fmEasL8DScwkw==", "G2iV9eBpaZfZ03f0d0t/rA==", "n1G51+pDWdZffLujptzXqQ==", "gKmkpT34vBHPSq1IVRTgvQ==", "VIIHXNAx40tfWxKjUYoXug==", "F8iw2hivo7VOfY6T6lVssg==", "nfQRE3FnBHWnn4FiLmrVoA==", "l0KK0xXzbXVKX6MCmaR4mA==", "qsIPXyVZhxfTQ3/efdLNnw==", "bSFklTcH++Qe4N7ocEMvdg==", "zfQNiDqMZk0PW66CHc19Bw==", "r9Y7IJFSuqjglNKfnw8dOw==", "EWhxjOpXqq00D0eBpMcpRQ==", "Z2k8gTGRE3tRnaa6C7ph1Q==", "DOO695SndYXuHis5ZYF2fg==", "K9Vsb61vzm4QbCVaTbr4Ag==", "kuhXZolaYNXAtDpu9lnamQ==", "2+1Rq6lvyXFZLzYVLzQGHg==", "R5eHMXQhuB92WB0MreSz4A==", "AqeVD5NxLS+weKkPZyFjMg==", "UnZ1Z5jaCJ5t0Ylihj7qQw==", "xjRUORCyUNEkviQdyP2FeA==", "Qq49by++IUkNs52HRvz21w==", "gyVItLDvKyiNCqhC3vwT0Q==", "/gOLZIgdoycagHU6KFi2aQ==", "7MfZgzd25Q7NVpvV5hOlMA==", "2fU9DFSbokep7QHBQAIDEA==", "D03Adkd0D6klk/oxgxcglg==", "qouND1u2rALvXGEiCSfpAw==", "+pBS1yXkx77P7vOf8YUZWQ==", "m1TezlMZQnewh2w+eeh1Pg==", "awprMKbVrDulQWYe0doRPQ==", "lTH6RQt00L2k/ovUGND4sA==", "13jIQw5H6nkLwOd5/nXpCQ==", "9c20tP8YyQIYlvInrc9qUg==", "D1By26h2T5U+g0sTT5l5FQ==", "Gn+PhE9phsL43pvVHeJqsg==", "j+HKy5fI+gwanQcT0VJVzw==", "0OtsAnxTbW0/IiNAzGzOSw==", "KsWYpAXrfuC7trSFJnEVxQ==", "+MC1LzBYIrxJU1ofAGLHLw==", "nHnLyc0i3LGGWSzAPhyYKw==", "WxIKMZNzfMhN/POQQ+P6fQ==", "T8SIyFnp0mpbb+kcuicFvw==", "y4OfweUpVYO2q8iu0jkLbA==", "a/h8Yn1UYQgMp+F/8tbQPw==", "CZMZO0J+3/q6iPxizT+6tQ==", "CssqY71pYe1Q3wka2HbNKQ==", "DTKWI1xT2s8d7ZdCcH14Dg==", "kBdlZauBxTfq+9SvHKQRIA==", "U2VEKQWR5OWfSqtkBGXqmA==", "sXrkHoO8FqgInZBBvNCsaQ==", "5iXA2QPCrnbK5zJICgTGpA==", "XeDhNbWrPP/57TKkZGU/9w==", "6D1DnfX30dlWWva3QgMcTw==", "m2kTWYyEXt2b8Y+bpHExMw==", "dNm7m8S2foMYQ6OzUGB8fA==", "7kwW3ItNyNKm5qVpmNIbIw==", "99x4WEH1muHpRR25VdE5CQ==", "s/nXcJapIEZ1tDG3K4jPBg==", "Phm8YvjUIERay7fC4vhmgA==", "aNNHQzxgcXugfFwv/DN3Ag==", "fI1cxD6IkyVtdqUWMiiHAg==", "fI/7lxwm3vQ3N/j0g7Qz4g==", "cCGIxICmrHrqqkgDQC8qVA==", "qcrNMjbV5cWUgmRekrRwzw==", "fCfk1NFnDb8OiVjOSfRa6Q==", "ML4iV/fRl+h1v0CFzdyy1A==", "TaiMhQEJ3Q6BZYv48dLzKA==", "1WJj58mYAh64tk3XzeRGcA==", "YBoIkY5E236Ku4x1vswMrQ==", "OGb2T1usqCHtg55ESExGbA==", "+LRjWXj/kMRxvO5AwDDNng==", "kvTVIa5bq/R/nK1M8mwXTQ==", "5g0m2i3mcd+wd2w7F0Wv4Q==", "na/ugY9lH08smavOJFuCMw==", "22wLUSnOfslxJaWCytMpKg==", "Ceca9Wrlp9YR4qlWnU8ocw==", "YpBqEuxGaKPIJ0A0P+PjUA==", "B/9cE6Ouzx84LJq7Bh1ZUA==", "8d4vfFuZtB02pD0yhIbT8g==", "lxbSICKaJJFo0IPqGvWzRg==", "Lx+kSp9vjsGhL+UyYXuS7A==", "oE5rFIgE+cUQmwp2YVokrw==", "tl+ldJVpSpeTGWtLbHBFjg==", "p1l5BO+8RYtfzObLk3HHFw==", "81GjLIh5V5cQwLLndqjzDg==", "PF8BPDtAFqhzfwgGoGNhcQ==", "kq6Qe3EeFnn/jFkC4GiCWA==", "lr3UWI+X5MYZjlxk+Wat/w==", "2oxlB1EOQ09AptLb1N+Vtw==", "rSBpBaKVbA5Z4ROUchoGXQ==", "UPXbqUFGE1PJo7+PrKvZ+A==", "j7/3bA8hjorM6rPdwZBKqw==", "MsbFZkmfoWEAxb2Qnj1CHw==", "SjxxlwRlBvhzJ+EIPQg+2A==", "Dvyktamg43GwH2r9Vyku/g==", "Q2V4OQGLyygD4mA4BeUHwg==", "josbSdjNIEYt2YuT3t31lA==", "4mF8/FakY1sQvyJ5OVbHOA==", "FudvHFdemDy5PhXvCA5sUg==", "FwYFV0OFCW//qyPsOZ72+g==", "wrnZx9IDlFkjjZFNqfm5BA==", "2cydAg9zvkUhWdDZ3rvr3g==", "0EtUZyNBUfLwjGZbPM2VIw==", "qp6jn4NMCUe5oKGofLit/Q==", "axu/TKv6CR+vYzn6x+QHGw==", "2HyLq00ETIjilxA0P7tDoA==", "1cAGedmPqnVqnE6FUIK/pQ==", "SldwWsd7f71t2sTT4le4NA==", "U0DvYYTZagIO6ldE+WrquQ==", "iaZLD1oLC/nOU24rKE4c5Q==", "ozPRwqwtgPcs1i1CZrMe7A==", "iXfwRorHjxpSQP/Y3LKYmw==", "VhutE6CSNp92DtQ53GCh4A==", "/REASQvEPfhjbb5nEMfVnA==", "IJDoATEPeUuA9XUXGUVO/g==", "zPZyBg1wZFMz7/V3ogyi9g==", "ZwjT/nBmdsy72TmavWU8dw==", "u7x7ygYe+0lg4dva7NX7RA==", "axvi+bbvad2fAYBT2fF1/A==", "FYe7Wa0fVzI7RmAJoXf+VQ==", "CBXpgXWZVGhSJGbFah0a1w==", "+Dpp4Bh7n/kRZxDGgTot4g==", "Y6U2P92fk05LBVYfzYisoQ==", "4wUIkilM6I3qGUwBON8lSw==", "IvtNhBs9EBdfQJVcaS8g/Q==", "9qs74TofCJ6nuFrBMs8T/Q==", "7ItuePxGlND/Uf0/PTPlTw==", "jwCtKZlExxG3oKjYCyqGAg==", "lbq4vh2+ZnForhi6QFyAFA==", "o+J4rA1seQs4hgsSwwbzQg==", "rzG+4p1w8Fds+h+0wYwvNg==", "ECGZX1xSn5skLpWJCsWTpA==", "ufTiewnbfOU03vqdmZUHGw==", "L8aIsY3YbUYD/sR0L1FHbA==", "SZAMdkdOi2w2C22zR27Q3g==", "W14SH0dlFhsWPGHnK1aCZw==", "vgQiAROcJccmldely3uVnw==", "YtV7YaLA+7ggXlLHn+OtFQ==", "Xvvhh6iAcEx/QtBYxuBfzw==", "Tc7Jjf4+kp5gWgBaBH6IHQ==", "td4AwwiNo8fDCZzACdpFVg==", "7CspTksKQHFn5A13jATrGA==", "62mRq4C9D2Fi3b6rCkQTcw==", "3lax9jHcdE4WSI3FQmqtaQ==", "5GhYAEdTvNxvxVlGZr2DUw==", "nKoGjNh27GCeUMT2dK/Gdg==", "k68Qrm+GmbkyaCk2lSsCEg==", "dBAGfhWDcEAx2Uc8DY0PeA==", "6/WrFYuWPwgl9mKfkUaCJA==", "h4QHAJEWozjnyL48yC+Q2A==", "jAT5nCGVIS6apnWN5nWkJg==", "QDHl1wjJ/hhM0L8lwX+C3Q==", "o0ecraUnR3jJvtQR7V8UVw==", "+ZsvZzBtKkBP0sJejGpg/Q==", "z2fCL2AfICNwA9BjUi3Dxg==", "cTXu3OaxY8CyhRj30KQ3nA==", "TTAW99m397pPNBpmG2HcRw==", "x6czAHpLprQs9jos235U1w==", "6S0eyEO6j+/5Oru/7o8ifw==", "apNb4s14qtsrQ/p0KNYftw==", "EYn2BjEWyvSrwQm3hD7uvg==", "PmbS8KA5GseS80O/YimnuQ==", "PqqxmFVRtD8Y5XIsEOgprQ==", "0MrCDPmbl4IB1C1qt/dJNw==", "NnyA5h91xhCGj/V12bkyNQ==", "c78r6gYTO3VN8WrBjUSEOQ==", "V8iS57FCTRiSUW3SJu20mw==", "NPKsnmhsUE2/wNe5Pb3DLQ==", "/mOKp220qBx69vW8tihtwQ==", "b25sK2nK3uR0z9nGZBhD8g==", "ZT6BPilZ5dCEdgXwljpiUg==", "/iNADhKp6vmMCCjkrsQJCg==", "tYjqt2QuHxyt9AqxIuOaGw==", "jRZ1mZCh6vaS3zFUu7kTfQ==", "udMY5/Ym22m2wauMDwS1ZQ==", "Rqd9TLIcblEe/+yGz2R3dA==", "XoEp9DT2Gi2ed605R4lXUQ==", "jvXo8L+w0I5IeZJsE5sQ8Q==", "Pi59oKxtylAGg/MHtN0qBA==", "LeJ94r+TvuBTyjiQvoh/+A==", "V+U5FRF3lAEjle3LkhTGnQ==", "2Rj37iOfBDGFAoEcyBe2Wg==", "c5zsAjQ64TJlVMAw69YoFg==", "bXtl+n71538U32lxPZ+WzQ==", "gAHDj/wjeA1RlKJMa+beqg==", "kfLGxTKoKicnK/rNfBjRJg==", "VYlkYCaZtG2x/9LY6YoOwQ==", "Xe5HZ8wO+kGA+Q95DAIHAw==", "TqzX5XqesrQCHwYXN5ag3g==", "CK0gQPCPQM+aEJCCq53cDA==", "f52mHBMxaML8BIIi27ptmw==", "UhU7m296KGnSD1zZRSq/jA==", "6J3s3ytYuZnXwt5lQIqlhA==", "Mu99OY+ZuIj2ySoksh3ThQ==", "o2NMtZKjIaTGadvHG5mp6Q==", "7pmzE7cjlb0lYdvy2/02Zw==", "c0sBmQCRvVCT7737MQwU/Q==", "+SXw0I//F1BclxmXEGpShg==", "S4XcHs/PjEW7QI+5zc1r6Q==", "8wnXl2a51yIxn7LxSeinXA==", "dASWaRulk6HSMFrYTrSg/g==", "XvaFhekmoVjuOn94KgTfyA==", "bq3rksXgiXoV6AuXVj+nKg==", "9idvVOsyaQdFcV+qdxfyoQ==", "esFy+BTeKuM/9GkyYe9/tw==", "aXQ9/hjqCHUJVtN4KDB0uQ==", "dK5VsavHbrJfcH/kIwHYaQ==", "d4Wj41RNFZ7ktyiP6AmZ3g==", "5lZx/k7YcLQIp3NEG7huZg==", "rHnR4lOiqYPnpv8M7+IdMw==", "tThsV2ITDYLRgOdGJrS/aQ==", "qGTI3SeJ9soW0DAFnYUtXQ==", "YwhOz+GeBIjFXWub1Yuf1Q==", "Aj16ChfAS29bZiI21jI7Vw==", "uhMnkZEO/VFY8Pl5jKul8Q==", "/7VBddfR6qwo6S8sjY5kGA==", "1NI5gDrOF88LHCi6AdglUQ==", "SSVSuTL0VIq15KhNLh5h8Q==", "O3Czql5c0ZzfDAtbZXKSfA==", "kKJMMvyEOKqokJ0bzYC2Cw==", "vHuv4/wLhLp07vrdFm5IFQ==", "/1k9RtYbBTAP1KTpcUZZbg==", "aULCDyTTvZjPfzCejfrcxQ==", "Ko56RywS/QY4DPnvHjCF8w==", "KD6Eqcfq8aH0K5cooWIvRA==", "c+mqOc/mqFarsH0PO+qZHA==", "XvR107GSrc+xeR3HWE/qEg==", "kn5p/OUsWwHeiiKEcjDSmw==", "yiXUbBZMQbbOIJqoeHIgUg==", "cWQ9Gv0TkIKOhqjDE5i5IA==", "VBhzdEYeRcywtNKzXlcEJw==", "l/LCnnKtIXI6QIMXQyAmyg==", "QRArYIgl58N8Ovzgvjnhbg==", "+f6yn1AEEkdjdgoOCMF2Tg==", "CSDuo5+yBjRvBzy9+2BbuA==", "gIEQo5B1M9YN4hmFor01HQ==" ], "YnPSos1SroYgrNVto6+i2w==": [ "hNTPziyPr0zH92JXPH3A5Q==", "uMLFKsTN91e1kpaM0hQi8w==" ], "Z4PEfJvMbj4dqTXnsp95Aw==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "ZTVtM/3ZWA9Gl2UwxERsuA==": [ "rmKVfK3mgjlQEhH+iHOflg==", "tqFkMROecRC/cxO5FXH2+w==", "XHFgJNEJIiIPE15DtoD2KQ==", "jpl1YKH9X76u2ReYrgD2uQ==", "/mMYJM9zN4O/C1HrJJj88A==", "wkt0wH2J5e6j3zvwUjQ4QA==", "3FdoYCjfuaH69GQGMCkueA==", "Tp5o/4SbPLzIMMSn6dmLAw==", "q5t1nltLUU7gVpZnWUIzNQ==", "RvZnPU2cIYuGeiv/rD1odw==", "6Z4TXkcGmyMWqyaCyCnljA==", "Ofi0/2sjxB8nnRkMGdfgiA==", "ecHm30RV2osv+vIdsYl1hg==", "2DgpNYTsr+vLsgB6jUu6qw==", "7AuJGHgHvpeOIE8Xo+9Tiw==", "M0jbZmBvyRuYzBNrvmqEbA==", "ZjN/tXLqyGqAzL0qaRbOdQ==", "WR/jw4xeHrK73fGOrvF1KA==", "mwBbCDmV+BFi1OG3VKzdzg==", "5pSzSEvB4MWtJijvklug6g==", "eyoPFYt1ipSpBRtbyo16hg==", "MCePqVkLQnwVpeYNDE+rBg==", "Eqs0OpFbkAnFRvfxseQQ5g==", "O5i6HOYABXcKKK82h0iOYA==" ], "Zc22Q3iFIPZ+epg2FdgpvA==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "ZfVnnJy7oaL9gSdtJaq2cQ==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "ZrenMRS4ooimSw7HXEAolA==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "aEtzpfwMbCldfN1nMySS/Q==": [ "MsAjOQqU9HBRH1IUou6UlA==", "IpfbTVt+g1kooJABwZClSw==", "mCd+YBwD6U6filBaB3HE/g==", "v8W3uLUipO36H5zJnC42yQ==", "sjk08x30IRw3g2CCIvIBIw==", "KJIdfpTdRKWkCMfxbS/mUg==", "A5MLttzZQ3XDsFCByj0agw==", "ji/RKwpIMAc9Vv0dRY+IJg==", "4Z81E9P4znFnu7c5edLYhg==", "qSRAlDv61oW53IYnp9gUPQ==", "hoU7b3nCpZ8AGIjXIp7o0A==", "z+0EdNHPSbtJAsK+7Y1ZjQ==", "CZdODvItVtmOQOQwVO8dIg==", "D6W/s3VZQKE8xMh57eUkZw==", "6oeh+EDX7YG2y/U2/jlouw==", "FkO1xyFl3QSN8mmAxDhcqA==", "zQ2Rf6aQ16TKQH/8PpQpBg==", "LWdYqSSWB1E7q9rwDYTSew==", "TCd9g35j6XmK96Itj5MuqA==", "fnopR10wShgmhhhPsuEeJw==" ], "aZVh1+7qlPGF1Mzt+c+CWw==": [ "niZVkyT1xeY52WsrQOz+8Q==", "29RQTKk7QHtywy1FBm7cYw==" ], "actKaDb3xYrYFwmm8ud9yA==": [ "niZVkyT1xeY52WsrQOz+8Q==", "29RQTKk7QHtywy1FBm7cYw==" ], "aeGWMCgnauz71afUV6KWIg==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "bRgs7+GRebE8GepCiTgVUg==": [ "UrZKzZ/sKVqQmTDnQ47I9g==", "45wOtea4pyEVfVs+5FQItQ==", "pDz4kM39PiixFNvpR9pL2A==", "IiHIqbVmvG4EG9wLjhDnjQ==", "09nI6dXLoEtf+3xPpjxkqQ==" ], "bh8ssVhS9Y+kH8SHn/gSBw==": [ "vkN7FYaEniQ5g2jNb7NZpg==", "dS8Cxn8/LaNiQCvBYdq7Vg==", "Lc3Tll/o9JPam+3IT/DrKQ==" ], "c5tjU1eTINvwTj7oRd+r4w==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "cKuouhxzNwqPCwYlA0+RvA==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "cdMtaom6+kBauoZ8sh47yQ==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "cjiQfFpqlL6r2yX1yzvy2g==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "doTtw5XfITX5mpS5AWcHgg==": [ "MsAjOQqU9HBRH1IUou6UlA==", "IpfbTVt+g1kooJABwZClSw==", "mCd+YBwD6U6filBaB3HE/g==", "v8W3uLUipO36H5zJnC42yQ==", "sjk08x30IRw3g2CCIvIBIw==", "KJIdfpTdRKWkCMfxbS/mUg==", "A5MLttzZQ3XDsFCByj0agw==", "ji/RKwpIMAc9Vv0dRY+IJg==", "4Z81E9P4znFnu7c5edLYhg==", "qSRAlDv61oW53IYnp9gUPQ==", "hoU7b3nCpZ8AGIjXIp7o0A==", "z+0EdNHPSbtJAsK+7Y1ZjQ==", "CZdODvItVtmOQOQwVO8dIg==", "D6W/s3VZQKE8xMh57eUkZw==", "6oeh+EDX7YG2y/U2/jlouw==", "FkO1xyFl3QSN8mmAxDhcqA==", "zQ2Rf6aQ16TKQH/8PpQpBg==", "LWdYqSSWB1E7q9rwDYTSew==", "TCd9g35j6XmK96Itj5MuqA==", "fnopR10wShgmhhhPsuEeJw==" ], "e62g+eBZRfYBs6yG5WT/QA==": [ "Gg4J4X4MbNfkoXKGRDGfqw==", "49G+2JpyxLGVZgvO4KOVDw==", "oIMZkhmE1zTNLf+KmwFMBw==", "ZOcBwbKbAM2xtrg277utCw==", "lFPS8RnV0dISMcAPV4q8QQ==", "AFIUpz1Y4Fkx6mpVvjmUUA==", "atECatQpyL4OR6Nj8ORK0g==", "XkqmUhavZ8Tr7Mrbp/rI0w==", "N6KFD0gQnZqGoV2GULM/7A==", "f09/sxMi7D7F9rcfxRlDsw==", "73+h9zz0/ADxJTs4lDS2qg==", "Xo30MVWPbFyt6A6zkqyXXw==", "NZV9KIcDUlVYcEXxu9twfg==", "IYakbfCoZsMxgfjVJB5OPQ==", "Ps5MCo5QpzgrRW8/KZMYuA==", "HLibYccak0sZKoSNsE6IZg==", "SAarmoZzBAYwwO6Nw/ABww==", "0MwmAAbL4wOCyh0/b/kddw==", "vSDZxpLkGafXPiYJDoSc5w==", "DnoLLxMGws+PXaby9k1hQw==", "dsSTmk6uj2ELZGZZ+QDrfQ==" ], "etBHHpaJIkAd+r+FzrnQYQ==": [ "64hLJutN1wNAcS1ep0rAsA==", "OiYs2+zugavnJ0RPGp7q3g==", "UgtteC8anOFnYyiPGfCwSQ==", "f3vaferRpevg8b0DyptSqw==", "gVMCgMuPTTEnybcY++CgSw==", "DMCt/mrj+Z0rWRq22nL0ZQ==" ], "fNp2jCSWjymcyaSrauohUQ==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "fXX1mg9IUP1aOVFN1izlsA==": [ "iSKNzZ2VWxhWfx0M40PIwQ==", "FQizKMX/v1MT9QGLib3ifw==", "LgJ7oWqdNk4cJQzVzTFMRQ==", "80CwuXka1gaqTKme6aYJTA==", "AOC74CEOMieqF4QnNIHpHw==", "QmzF0n9xqyFZOW62FA1/qQ==", "hPYi8glMBvStMRV421SnXQ==", "qIiZiZIZc0OPiHfnmGiEzg==", "RROy+89qj73l90OV1VglGg==", "rlIMrSvggt9T2HDIr/N5mg==", "Mc/PcK7PUGXHVZGur/JxKQ==", "ysl2vdVgh9O8e4G5gfWMJQ==", "sDW0EXHPEasW8Uq6gTO+PQ==" ], "fjmjfd8Z1obPxEblTqtW3A==": [ "Gg4J4X4MbNfkoXKGRDGfqw==", "49G+2JpyxLGVZgvO4KOVDw==", "oIMZkhmE1zTNLf+KmwFMBw==", "ZOcBwbKbAM2xtrg277utCw==", "lFPS8RnV0dISMcAPV4q8QQ==", "AFIUpz1Y4Fkx6mpVvjmUUA==", "atECatQpyL4OR6Nj8ORK0g==", "XkqmUhavZ8Tr7Mrbp/rI0w==", "N6KFD0gQnZqGoV2GULM/7A==", "f09/sxMi7D7F9rcfxRlDsw==", "73+h9zz0/ADxJTs4lDS2qg==", "Xo30MVWPbFyt6A6zkqyXXw==", "NZV9KIcDUlVYcEXxu9twfg==", "IYakbfCoZsMxgfjVJB5OPQ==", "Ps5MCo5QpzgrRW8/KZMYuA==", "HLibYccak0sZKoSNsE6IZg==", "SAarmoZzBAYwwO6Nw/ABww==", "0MwmAAbL4wOCyh0/b/kddw==", "vSDZxpLkGafXPiYJDoSc5w==", "DnoLLxMGws+PXaby9k1hQw==", "dsSTmk6uj2ELZGZZ+QDrfQ==" ], "g4NDzTQtw6KVo/DkE5yxgA==": [ "2xNoBNSp7fweMAQExE+o+Q==", "R6AHXq9kIXOTM2VjUoYfdQ==", "1kpr3WQfwsPlCOJYahwUqg==", "vVKfZgj2ftz4bUN+hvsnmw==", "SOZasT93ZTk1r15AlKIQHw==", "AR1mIh++KWFwOpNBMSCtcg==", "QGrcmtKnV84PkEVV4mmlmg==", "+CL+shtoxDkUb+xwSTpgsg==", "JkDUeWM85AYU2EUC6YsyXw==", "w3HHZG8nTVYxvXYiyXr1Hw==", "xiMAJpHW80LOtYFONrCzjA==", "Nkn4Lx7wFGCCYyHykJcx5Q==", "IeoitvM9lwggrk3KXJzR/A==" ], "gPUUPwC35o/YYWvMKRT3jQ==": [ "v2MEiY/DNOR7aWbIhlf+ig==", "nCU1KSyyHi3FvXLK34YLSg==" ], "gQ6Px92HfjNtE1SIyFrTNw==": [ "LV6LIlj72s5e2jnkTg5TsA==", "wIg2Xh802Oj3VZBUTBmY2A==" ], "gTvrCykxbI1a3Gcl7E0P9Q==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "iLiEn2koQeeimUI4OL8oGg==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "iwRi5YipcVuzlYupn5b+jg==": [ "OWJa3duCz1A5SfiSYrzr3Q==" ], "k0OfjdCQeCK/OovAA207Pg==": [ "7XcpF7gQsSGccuF/A656dA==", "+aYX/oRvHl/0BC/uiR5NVA==", "QBFhf4GHFlHTR/5pa1CHXg==" ], "kFXNoZ7znmAHcjIm9e1ZjQ==": [ "6tqG15NFTj8WQy8yBxg3gA==", "jNYd/zgCFBkDRlsDFtS4MQ==", "mOwqF5f1oo/f3Hy4A5hQEA==", "9hmYdgk6YhZjkk5kRAej1A==", "vW7+QMt8GLYlNZ8i61SE4Q==", "ka7CS6AmNsxHCjw2UdKtvg==", "4hLcUQApc7re7Y2zeJnb0Q==", "qZ4oRvYnjzMbQXQ9RlFiKg==", "pkajBH1lJD3cQ70fN6R9Zw==", "W7Ne/UdSHmg7xt0DK0wdtg==", "EnkqWTVrWXoijqIWOFr68w==", "Wl81NablfKtwVAL4vOotQg==", "fVbaDjJ+wmNFZEEpBOAEqw==", "Rj9IqPmKRJYSLzoR0SyLLw==", "NNeGSUp8UIMc5elm+qOY6g==", "O6rYT5lpJicjJDJhxGauhQ==", "WSHmH2/QOPqnJ/tYpBj0sA==", "2TIb7FMvCnflY0kS4ZA16g==", "5c4woM08z/CQiVzL2RiBWw==", "5C5sqkZA+SZJZWBO+v3goA==", "skb66Jx+vWt5AVpMUcVEdg==", "YF8OfaM1DSxNuPCgGIsTTQ==" ], "kSEV+mUKUgo2G6fUzNc4Xw==": [ "5aGW1SB62ChYqvixvhftXg==", "/NbVFv0WYTS4IOv3EHzDgA==", "FeWrBJujMl45wBsMuJwWow==", "Ty07MJmxlxMtrmptnF2X2A==", "gt5sb+F8Vt96IRL1gx4D9g==", "PtgAAlJUo6Q894aXIicfNw==" ], "knCuFHAKZKhlQzlL5X/4GA==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "kuFVsliIpJiDywtMew9a2Q==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "l+d8apBfkzYeHMLDsiDPfA==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "lSvWkavUDMv8SqOHTq017g==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "ldxG14V6EBIxhDObD0C6XA==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "lnKrfDFZYbpH3rjpRabl0g==": [ "+/SIYxDzhjXzas1XPY8Vww==" ], "m4X0sD8xf1gD4Z26V7ni2g==": [ "ZQePqlHHBA7+hwLcam9ocg==" ], "mWPGBAGgpAZ6v4RXC0mAXg==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "munkvrAt8cZg1PdJDw+QAg==": [ "D74mlxiMppsGNMizdZlOXg==" ], "nLtBe1D/LMWpe8qyvoTEQg==": [ "LV6LIlj72s5e2jnkTg5TsA==", "wIg2Xh802Oj3VZBUTBmY2A==" ], "nfBx6td713hSJbdgrWWi7g==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "nmKloy3CkYM0SIICJVg+lg==": [ "HuLcwroM1rTmCRiMq0xq/A==", "DEvkWQMQdNGeGi8iOnJX8g==", "wZs/M549D013OPgW4vrJnA==", "aUsy5n/c6AxyAdYqvDKZAg==", "07URzmvpS7ZEQcLIdrixNA==", "FVeDQej7MCAjLzDoM9qgXg==", "NXu+dXN5KBvsm9u13e7YlA==", "5GKnVDsIRQ4aY8ICcomaOw==", "+42NZLTTWEuGunTe6H5VAQ==", "SnaDJIBcaepGlEY5l0YiZQ==", "eMJT7VG/NT94FNjcwFGj7g==", "PSkg4cwA46LL8z/Lgyf8sg==", "dynHmBSsNbcoeh0tpdlFhg==", "K9HJuYuqoA0oSln39+ncyg==", "u0KFq8sxSQMQOjkoSQcWGQ==", "4QzwilesYlayDLcL7cX9Xg==", "LA1kH936Pv8VoSzyI8d3Tg==" ], "nsXhakxka4aH9ndfG/DcZw==": [ "pCu9cCtk/7SjSwDySmAYLQ==", "uXIQHFI6+ztbjm2wYtFkSQ==", "S7ffVdT0arMe7/C4MSXpWQ==", "ekhzxIHRTH4nfurC7aQlwQ==", "USv5GnXR+OJ5oCOuiw09/Q==", "jxeBZQT0rZDcUDj8Kd0PtQ==", "RxrW7ydW11PIaDYyAYKVTg==", "jcvnkSTQb1UhujW6CRJ4uA==", "J+BMNtoyQOWexo7hrmq3rA==", "je6ZqfWg3ctmGtEqprl3eg==", "mcxEec0DnlmZz3+CmevTKg==", "mjzU8fYHUEmYm86e389JVw==", "NQ2dAoiyDdaP6k9PNV2Zmg==", "z6sSH26cZGd5xHibpTYF7Q==", "rHluYIV74XqfYpOxMHO9Uw==", "R9EvNzu5a78IhkYE+ovVXg==", "4rNBEHiXgqYlYhIDoP5zSA==", "Dv8HkcDBMS+SJaMU3YocwA==", "5xeM1k+VvYcU/xV+hgDtwA==", "JcUD7/ApkvlfO47KVpD1zw==", "S3qfKrj3et4RUCaKB10piw==", "ajXQ+t6g/zl5c5KwrQ6iCw==", "mmtl2ec/o09W0FXFeHnmQg==", "OmC3nNLL/7/oGa15psUdDQ==", "A0op+L+JbMa3xmsB6bfM0Q==", "L24+fTbM1h+Y5XH0k90XrQ==", "T7H5goqWimRhJ6/lmz/14A==", "tdmTWMKf4Wd4a94OZjAQWw==", "6p8Hozv8P/sKC+WoYVsDKQ==", "pmrDabbkONJKfrgmMjw0zA==", "tUnffIqaEOBexSfOy9RSbA==", "+NN/IoxjMxchzwn/MMxhPQ==", "0QszTeXFRafC+y9Bl5KyMw==", "Te4WUvO8GpV/xKQSiWprnQ==", "6SfR7C92OMaKw1U/fAorwA==", "9VoBuFaXdnhHPgibGyhpfA==", "j9y+IM7NanO51P1/fIO3nw==", "M4tbiBn7IwzJ1ZmsEQrp+A==", "JVCst7rPc5C+mXRLD/3i7A==", "i+rrqjPcomFeN8diE7L33A==", "eg0zr8Uw6LmL6IroDlS7wQ==", "YIFdVIZNby7xlEcg9enH4A==", "uvFnRcryNsc38djGoFZELg==", "i1s4S05MBwRzcUxGMEEy+A==", "UJIAglRfS3rNJeKQfo5kOA==", "rhicS1iAdJ7haynjMu68Lg==", "PqUWqiKg/hRVx15iUfBtvg==", "t1cDuzMlX117B8LBMX1fYQ==", "HkgQtDnxOCfhb030V2ZyYg==", "c/x21M6pcU8su1V/zbVNTQ==", "kBrSwqqu9R+58yY5supBMg==", "X8WzV6hUi6GZYWa/shwqXg==", "gmmLCpwndlyXmMBrnZn0Lw==", "dGQe1jlLm01G2RlSenIKgg==", "aXiSjOT7d8P3PHD3zq8S+w==", "fOZ09WQ2S529qRiEbktTWA==", "B/seqlJe9e/N8mUU5WStLg==", "U+y6NfYK1BUAIqPDEbxONA==", "DVtv7ccp2q3OpewgYQvjSQ==", "ndJ5GEAWepa3cRd6DbKPJw==", "FqN9MEddiJrhptEcz05UTg==", "KT/XSjqNnGmyUjZ4EXYXeA==" ], "oJVJhm4h5O0CE9d/wGyW6w==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "oVNzYxanlnKcVn1aOfjY0g==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "oZB7NQXsGwhpn+1reikgKg==": [ "D74mlxiMppsGNMizdZlOXg==" ], "oa2Klvjpg54cEHv2U+uMyg==": [ "vkN7FYaEniQ5g2jNb7NZpg==", "dS8Cxn8/LaNiQCvBYdq7Vg==", "Lc3Tll/o9JPam+3IT/DrKQ==" ], "ow72bVQfBucqWn9Lpanhfw==": [ "96cHpmcS0fRAU0scCg6b9g==", "YsKorYDNSlb87ZdIS9kUjQ==", "gJF2RoXEUj/4hrZaYhzyJg==", "mDBfTSXZ1+wA7otb2RysUQ==", "H09h9nd7ZlHJ8LRncQ4cfQ==", "eW+REV5eOe0Z0hdA+hyoQw==", "LJsYhUYv1jp57lU5SMRltg==", "uJaIkdAdssqwBkEXNNs0qg==", "z17t3PbfsUMbWVwOHNYPWQ==", "EAlLhi+f9W1iGlSW/XZEEQ==" ], "pbeJdaGLL/qpemruqH9rXg==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "pfF+qwLjBmQwroRuGF5i9Q==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "pqXSQwt50vUG+o+dld9Maw==": [ "uR/wRgEeGqBLSPmVdvrr/w==" ], "pzWPbMb0u08oeR+ebbcTtA==": [ "VbYu/WOg75Vb8/1JanN0hA==", "MTPA2fuSLOyzUIakkBHnzA==", "KLJBylkG3Wsrc5iZ+g9zLw==", "zBi4Vv0a6qBHfmWvyJVErg==", "6wB3SHb/Pw3K2aEF5Qy/JQ==", "auQHeL2oNVf2NwdOBO/agQ==", "Z3tjpgDGCLjk3Ec4HecEQQ==", "0TmZZ5LEd0yAayUm31rvqA==", "TwSGWkGdJQxHand5kiwizg==", "7Qb81tXMISyKPC7YEKlyZg==", "zLARHi3LgDQgVk9F5LOF8g==", "T5ISGm5LbVeRDQDfUYF1oA==", "fJ/sIb8ANcg6WDYkQtkeAg==", "nXMMuqzw9RtwcJ6EHriBaw==", "VUn+MKhO9qXlulJ0JJY/og==", "fIOBZLi+PdPMNcRduPMSyQ==", "z2iJftUbGjAb9QpTXx8tdg==", "O+eHWF1ryUlCFVMNqM1DDQ==", "8hXgdgR3MyuUTqBbTATxRA==", "Es8gDnTR4NlprvEhI8DsyQ==", "JyMCBwsAlUJ+0nV0dZZ1Vw==" ], "qljM0gjNc4JfErPeE+a4Mg==": [ "H1V1G2DPgYUppmsrLKmg5A==", "uAZ/vVdCFUjRGO/lgTu7Ew==", "l/kNLokvToElk8R5OEG1Hw==", "hvrnL6/SCX8xDjTn++W9GA==", "+jA2qUkOg/IukdQQNgzQEg==", "O4I5OUkDRdIqJ5Q9vidfxA==", "9LQ7cgc2lvnSN3tA95Jgmw==", "8rwOy6z2QofRrkprYBngOw==", "4sWuzq5lKkghOSNsQUHWjw==", "hUVvVaAQhwSwgFrBD1MdTg==", "EqGiuiFVwruyN8bfEkimAA==", "iEDMueHFmszLRMIGHWZmww==", "xDsyjQG9Zgm7g+ZylJSSMw==", "UAWZPxzzQwGwhDNr0CGk9g==", "MVI9YH7/7TuqWPhRsSRp2A==", "f/he7Poe7++v+chxeZckAw==", "pnTQqKhpugpRhNDFxnk5kA==", "q2brSwh5JjiYiRkGkO5mQQ==", "Ad7lED91xtuO5R2vruVbvw==", "5vQpVW4vLgKPy4ui5REMvw==", "7ApekoO6bPDdCOudsP0VLg==" ], "qvtCTIsiRY8AFQ+wciQxjA==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "rXBH8p7w0o7P+QqmKYI5cw==": [ "VbYu/WOg75Vb8/1JanN0hA==", "MTPA2fuSLOyzUIakkBHnzA==", "KLJBylkG3Wsrc5iZ+g9zLw==", "zBi4Vv0a6qBHfmWvyJVErg==", "6wB3SHb/Pw3K2aEF5Qy/JQ==", "auQHeL2oNVf2NwdOBO/agQ==", "Z3tjpgDGCLjk3Ec4HecEQQ==", "0TmZZ5LEd0yAayUm31rvqA==", "TwSGWkGdJQxHand5kiwizg==", "7Qb81tXMISyKPC7YEKlyZg==", "zLARHi3LgDQgVk9F5LOF8g==", "T5ISGm5LbVeRDQDfUYF1oA==", "fJ/sIb8ANcg6WDYkQtkeAg==", "nXMMuqzw9RtwcJ6EHriBaw==", "VUn+MKhO9qXlulJ0JJY/og==", "fIOBZLi+PdPMNcRduPMSyQ==", "z2iJftUbGjAb9QpTXx8tdg==", "O+eHWF1ryUlCFVMNqM1DDQ==", "8hXgdgR3MyuUTqBbTATxRA==", "Es8gDnTR4NlprvEhI8DsyQ==", "JyMCBwsAlUJ+0nV0dZZ1Vw==" ], "rkyfCtkobwjj2Asc5nC2cA==": [ "UrZKzZ/sKVqQmTDnQ47I9g==", "45wOtea4pyEVfVs+5FQItQ==", "pDz4kM39PiixFNvpR9pL2A==", "IiHIqbVmvG4EG9wLjhDnjQ==", "09nI6dXLoEtf+3xPpjxkqQ==" ], "s04lFaf8GISBWleGLKMYSg==": [ "lxUGTdEKAk+ElV/adgJrxA==", "miGlfWYNWZUhM6Uu5lXXWQ==", "Ovas4KEKa7VAli51+uaUcg==", "R/mDXHIDlEeq362SxYMlhg==", "mHbTjMj1rjOIPJCq59mrig==", "Ovox+LFKTyPfDw/8TYho6A==", "kqQebcoRkl7um6sT0akMiw==", "GZouk0sDd/thoSYrZ82zZg==", "mxkBwL2NcQ/jra18Jzk9Vg==" ], "s0EZjv2nVvc8F2tzbZWnLg==": [ "DjJF3Cvfh4VoqiOq+lbgBA==" ], "s3tOAOa/dusIyn91E3m9dQ==": [ "gKs+7YLrqwmMe1IHwKZE4A==", "TKbTlc4iN8EYX5qKd3EbZA==", "gtf6IZ1G6pyIA4U2B7AsmQ==", "n0V5sg2R2RKEdXaGiJ1trQ==", "DKLM8rvwKJ6+fHZ/qapkKQ==", "UCJ0Wb2hKTJ6hH+buyeBOQ==", "VG2kMas1/Gt7kIoRyvIsOQ==", "Opk4oLLMvcTmHz8OjJT6ig==", "dbr/eJTKVL+PlwpJky5WYQ==", "Vd6ZTfdSpcn12KBePvRLWQ==", "f+L/NxbWRWtyU7efEy5kwA==", "NgS+u6TtkDzJT8fQO9+/4g==", "YsLoHuuQxyXnuNuD6BKbDg==", "fgbOPWAFsTd3RMyFiveWZg==" ], "saTNJ4JLYjq2syxwkWSJ3w==": [ "7rOmgLxcgbnBpJsD3eacKg==", "2lyKtAO8fWwobKAd5ksImw==", "iOyLmeTOvgguVhp+6I7Gmw==", "UqlXj97FrNpj1p9MIGdxxw==", "zpnR4DQUSVLOu5w4oXihGg==", "X2d9l5X1xLpQwAiEXTTewg==", "HhS2mtMKZlbYlHszwIEmdg==", "GT1RFwTTfZX7UTrjVIuvcg==", "bSQHKOOIEu7zn/5UgFOWJw==", "6OnemuwtxINSgBT1Ii+++A==", "/q/1NoaqqY53cTnf3GDbOA==", "vQoCKRV0WYdDnzKPcCv6hw==", "Fv1xZ6eCn6XkYWWsyTGbDw==", "Jr8LE9YgqhUL/qPVlyGCkw==", "uDMKksa8nEm05P2D+S3qVA==", "k5+7SpZcwh35X7eYTNm4mg==", "TqWd5ZUl5sVkYMkHIsu40Q==", "FOCiciYW31UdVFnx5ltZBg==", "oAJV6yKgQS6xMKtIhAlSqg==" ], "tR8RKPSydOIs4d7KfihmaA==": [ "96cHpmcS0fRAU0scCg6b9g==", "YsKorYDNSlb87ZdIS9kUjQ==", "gJF2RoXEUj/4hrZaYhzyJg==", "mDBfTSXZ1+wA7otb2RysUQ==", "H09h9nd7ZlHJ8LRncQ4cfQ==", "eW+REV5eOe0Z0hdA+hyoQw==", "LJsYhUYv1jp57lU5SMRltg==", "uJaIkdAdssqwBkEXNNs0qg==", "z17t3PbfsUMbWVwOHNYPWQ==", "EAlLhi+f9W1iGlSW/XZEEQ==" ], "uZRVQPPNGjtjKkLQKoY9Cw==": [ "2xNoBNSp7fweMAQExE+o+Q==", "R6AHXq9kIXOTM2VjUoYfdQ==", "1kpr3WQfwsPlCOJYahwUqg==", "vVKfZgj2ftz4bUN+hvsnmw==", "SOZasT93ZTk1r15AlKIQHw==", "AR1mIh++KWFwOpNBMSCtcg==", "QGrcmtKnV84PkEVV4mmlmg==", "+CL+shtoxDkUb+xwSTpgsg==", "JkDUeWM85AYU2EUC6YsyXw==", "w3HHZG8nTVYxvXYiyXr1Hw==", "xiMAJpHW80LOtYFONrCzjA==", "Nkn4Lx7wFGCCYyHykJcx5Q==", "IeoitvM9lwggrk3KXJzR/A==" ], "uotq0WJi2CaJg4+oE5qZFw==": [ "mTD/V/e2oknhxg1DQ/f4hA==" ], "uyyQsF78T1CHrA0TO3N6tA==": [ "tVih89ImzoM80ZbOBxCm9w==", "J2eGA05DEwryfnUENIziAw==", "ABdl7tHgbWbJkXgHXYjkaA==" ], "vnAoEPoqD8sCFdu/1HyFTg==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "vrwg5TC0wZPqmwcGBbnmpA==": [ "t7u6uHAJ/VCFFsPQoc5q9w==", "JCBjk0sch/mgIqnyRjXsZw==", "k4fnMU3FBc/o62cw/deQ3A==", "s37w7PtUSGpx+BxSM/IyNA==" ], "wNKNI+lzZqD8WQpcAM3nlg==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "wlUScb5LLgsHluTsMm3QGw==": [ "iSKNzZ2VWxhWfx0M40PIwQ==", "FQizKMX/v1MT9QGLib3ifw==", "LgJ7oWqdNk4cJQzVzTFMRQ==", "80CwuXka1gaqTKme6aYJTA==", "AOC74CEOMieqF4QnNIHpHw==", "QmzF0n9xqyFZOW62FA1/qQ==", "hPYi8glMBvStMRV421SnXQ==", "qIiZiZIZc0OPiHfnmGiEzg==", "RROy+89qj73l90OV1VglGg==", "rlIMrSvggt9T2HDIr/N5mg==", "Mc/PcK7PUGXHVZGur/JxKQ==", "ysl2vdVgh9O8e4G5gfWMJQ==", "sDW0EXHPEasW8Uq6gTO+PQ==" ], "xOYvqnnLEnYNo3LYgrwOMg==": [ "/HEhjSedxSIiGuLqKxMtww==", "Hq2KZaE/Uj/paNzirKIsyA==", "JF+sYH11Tbao/uQQ3R4oJQ==", "jHHTwsFpYzooo5vrSwGKhA==" ], "xOybpUB1yOVytErftRFyQQ==": [ "N473F11M/P9rXXVHcdmElg==", "mCcaCnP8f52+vu9b5rtNnA==", "Kalz8nPy29l3XQTjNg1oTw==", "xMNRfv9b++Qx2IGpA34qeA==", "AVqsLa8FiT6DFdwPobOf2w==", "3TnfqY55bHsUZcxqm7CvkA==", "ddTPBzeeJYnba7jCapgbAQ==", "PfhjREk4GtBBWbLt/M6Dlw==", "YRihAPX9XQJbgbq8IV5qyQ==", "aBSD9SI0+LjXQAmIuEqC1A==", "LjSRKao8rTYjhGOoAVtUog==", "d59u3XRZGdnK2xtdhx8bMg==", "uEC5Qtr12vyf9FN8TJFIpw==", "cfiD+BYptWNUedEJyRszuw==", "ayNwOwFahcJX8VpuVbGJUw==", "52axsosk1tD0T2LVgOLrtQ==", "9yjo/byOytI0IkYgkukiDQ==", "Cs99NDR/2aWXIUslX4V9Sg==", "eFmZwmd/PF/L5BwzrUL8Bg==", "ZS/gWXbJFn17w55K8PlyRQ==", "GuCBWhZkPdgB6JAffd0vyQ==", "UmInHmlKA0q8kxh6TUPiWQ==", "LR53RfBcaLruNmVIjJlLPg==", "6oQOPW/SOH/HZt4HVN1Sgg==", "UgYbawVYBKlWqMXTnMrkFQ==" ], "xkYVRT04r3WxTy3oo/fXzQ==": [ "x3ki/oOD8DwpAiHeGtGXsQ==", "bV7JkNyzTIO5N9GIRXxGug==", "RCTFNcTWXhvQB4avl+clNw==", "Czqm8H7741oaglDeK6CQXw==" ], "xn3p89bkGlD/HFM/zmmZTQ==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ], "xvFdzctIUU+pgbZNN5yUYQ==": [ "SmqMtlvlVJyhJeSdEeHrGw==", "Z7pBeVnuOVlWlFYmFAqamg==", "4v9AfyCA9lnPveBYKs2uUQ==", "N+fzYkC09CSzgvWTQBy8Aw==", "AS9W4vbMqGdpKVw9iOwZAQ==", "KxKTzhkAQv+z2VKOGo/8bA==", "rcC8CUmqvvy1e5QKJQrBpQ==" ], "y7fV0ey1tXsmdYkL7TASCw==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "yDNUD3wG3wsxr/KwdyEmpA==": [ "HuLcwroM1rTmCRiMq0xq/A==", "DEvkWQMQdNGeGi8iOnJX8g==", "wZs/M549D013OPgW4vrJnA==", "aUsy5n/c6AxyAdYqvDKZAg==", "07URzmvpS7ZEQcLIdrixNA==", "FVeDQej7MCAjLzDoM9qgXg==", "NXu+dXN5KBvsm9u13e7YlA==", "5GKnVDsIRQ4aY8ICcomaOw==", "+42NZLTTWEuGunTe6H5VAQ==", "SnaDJIBcaepGlEY5l0YiZQ==", "eMJT7VG/NT94FNjcwFGj7g==", "PSkg4cwA46LL8z/Lgyf8sg==", "dynHmBSsNbcoeh0tpdlFhg==", "K9HJuYuqoA0oSln39+ncyg==", "u0KFq8sxSQMQOjkoSQcWGQ==", "4QzwilesYlayDLcL7cX9Xg==", "LA1kH936Pv8VoSzyI8d3Tg==" ], "yKlKN1Y5OU0/iEuHPCOKlw==": [ "xxxPnTr/pbG0N6W/pNDcWQ==" ], "ypha8g8Z4b071lSnccTVsQ==": [ "kHTcuX2ojk+Ouhq9aqnFmg==", "bkD27G5x4y2TAqhJBzu7xg==" ], "z3pzHZFRSYY1FGGY1OapeA==": [ "dEb3nK/PwybHr3KGCX3LoA==" ], "zBPaU1mMhx5jfMwCeUFl1w==": [ "4QfchxeDhLyOBwQdywbhbg==", "lngFfpAJvbin9hXK0qoQYg==", "4hTsMj8hVKY9LmF0edFYCQ==", "zW0NAmanPbUh3mIYb5jVbQ==", "ztbKwpmvdRPX+nuYebgVuw==", "GWR1J92TJBEfZUdv9nbrxw==", "mxiTANJZC5hMGOWhQIq9Wg==" ], "zS2GG5MD4wD3w6JwVU9pkA==": [ "VIauTgqjmmC3JrXtK9SoKA==", "IckWa2ni3hDgKetUO6msAg==", "IFNW9YBko8LrXi4D/GCQ9A==" ], "zgvSJIUhIFalYguys+yFgA==": [ "sT/CdZ9EbhIheJoHHIMlVg==" ], "zwCQDqDNfLrjHOe2yydsXQ==": [ "g0ZIb1T8gqxy9GnBZHrs4w==" ] }, "enrichments": { "message/vnd.clair.map.vulnerability; enricher=clair.cvss schema=https://csrc.nist.gov/schema/nvd/api/2.0/cve_api_json_2.0.schema": [ { "++HdLGarq5GIso93i+MxpA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+0bRxY6TjQIuqDlOK+2izQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+41xmPLBp+GMWuqOpfmZWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+42NZLTTWEuGunTe6H5VAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "+5KO877diVdGAzL6goK/SQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+CL+shtoxDkUb+xwSTpgsg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "+Dpp4Bh7n/kRZxDGgTot4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+FjM0LpqQllzdfIgyzd3kw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "+H/bIsJx0MWpkf9xibMEhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+LRjWXj/kMRxvO5AwDDNng==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "+MC1LzBYIrxJU1ofAGLHLw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+NN/IoxjMxchzwn/MMxhPQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+Plw2tabjfOcVdKKZpp6kQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+REan4BC4v//j+uT3WPbNQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+SomP1jA3ScGJcfWiUw9WA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+WCO1HEUKIIM9snGdGBm2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+ZsvZzBtKkBP0sJejGpg/Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+f6yn1AEEkdjdgoOCMF2Tg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "+jA2qUkOg/IukdQQNgzQEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "+w9hzA4OIRZ7YkoQQCaOOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/4AjAEsHRRa43cZAeshWvA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "/6uQNJy+iHLVC38D5Bhy9Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/72eyAw69+s+htVKV47W+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/7VBddfR6qwo6S8sjY5kGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "/HEhjSedxSIiGuLqKxMtww==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "/NbVFv0WYTS4IOv3EHzDgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N", "baseScore": 4.2, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "/R+oZfF3C0jFiu9Vh76ooA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/SJ+Rrv1FPQP0mdKaNJOCg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/SiTRLCQLViYubpilZ0k0Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/gOLZIgdoycagHU6KFi2aQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/iyMD/CLlrovNCQN6DqV6Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/kW6pEn0Zy2tehKurgKtPQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "/mOKp220qBx69vW8tihtwQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "/q/1NoaqqY53cTnf3GDbOA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "/qUM6+rqk8nGECur0ngdlg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "02rBMXIw8e/W8DLaacuURA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "09nI6dXLoEtf+3xPpjxkqQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "0EtUZyNBUfLwjGZbPM2VIw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0HOHcobRnpDN9ct7nb9VmQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0HtM1g1taJ19/JeX7mpPOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0IZsf9dz4Us+xRLW6BtuLA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0JY6fbv07QRBiECIH0qRrg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0MTDMTjf9fjVojr+2WUZkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0MmyGSoo3BjfDz/rvghu0w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0MrCDPmbl4IB1C1qt/dJNw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0MwmAAbL4wOCyh0/b/kddw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "0OtsAnxTbW0/IiNAzGzOSw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0TmZZ5LEd0yAayUm31rvqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "0X9H30gbmWBuPE1VOfDMHQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0jSW5utK6X2RgUuKOjtT/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0qAz5+tC5TUL0H7+2lA3xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "0t6ZhLO4siY+a7KyIW7bQA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "0tX86Ghr6N4D6ISg4pUM4w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "10cNbQG657ri8WsAsUhByQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "13jIQw5H6nkLwOd5/nXpCQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1Dy5XyHBfkrD1EQOGZjNFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1FHhd29+E67AOWcm+GUqJQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1INWm3M2WxieXT2qDaq7PA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1Is+R/NfLg3TYOxSDnUaVg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1OXdOn2y4C9PfQZDckFodQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1QFm70wnr6bYuRxGyK0OHw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1o5lA+NM0aNzCWTeAFzz4Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1v78L0F0y9NkJWyNm5I/Gg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "1y4dDNJi+yTWzay2iOe/mQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2+1Rq6lvyXFZLzYVLzQGHg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "20WfS86dqjcN43OOzbzJHw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "27nVgKdVp5Z2yN+WIh5Ajg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "29RQTKk7QHtywy1FBm7cYw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2FzvTR+a3XQlWcXmD/u7sQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2GxrERkUMtotDqNjHyQCbg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2HyLq00ETIjilxA0P7tDoA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2Kd7B1qMo9h48Ei0g8TpUg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "2M/vHj3OiKkU7tGWIlYBoQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2NjwNSG4kcHNhy2M7KLz4w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2OZ7trlKRLnZsFv1sJvUVg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2Rj37iOfBDGFAoEcyBe2Wg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2TjC60sJ2qX3uuSPiJQTaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2UEXWkLtrRPgNGWIp1Hx1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2cW+3rxkcATjxvNqtyRwZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2cydAg9zvkUhWdDZ3rvr3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2fU9DFSbokep7QHBQAIDEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2gIKJ24NaTvU5hH8MoOEHg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2k3Srs8A63nD7VMc8eJGDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2ot4aIu0LulaiafAuekqiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2oxlB1EOQ09AptLb1N+Vtw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2uOzzZZ2kCVXzbYFBm8+Hw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "2yv1l3MuYdv6baRDFoTAXw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3+Zo5MGd6Ee9xwAYwT9nSw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3Gnrg1HuF80NYk8sDg8vpw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3HM9ZkaDf/qSqto+kg5bSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3I+BoetlmVjDN6jsA7RnYA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3VkUenslT5nKy0iJQN6Utw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "3iEhx4hZJtBmBc6kQmlOuQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3jDKPTolYWHmJt68mR0ScA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3lax9jHcdE4WSI3FQmqtaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "3sJJdZ2fQt+gHsMLZrLiCA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "41FjDaPjaQzk7tn7JaMlRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "49G+2JpyxLGVZgvO4KOVDw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4HhPzsELhG/UXDb85H5oYg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "4QfchxeDhLyOBwQdywbhbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4QzwilesYlayDLcL7cX9Xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.4, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "4Z81E9P4znFnu7c5edLYhg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4bp+O/hHtE2TomvTrC9RNw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4pmVCkpcFnlXpeO2bi9bvg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "4sWuzq5lKkghOSNsQUHWjw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 9.4, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "4v9AfyCA9lnPveBYKs2uUQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "4wUIkilM6I3qGUwBON8lSw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "4ywdnWajkUpzJhpgBOXFZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "53zxUuzjClZZkScYUEBz4w==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "54ZbClVVUK2Kye4aOsmx1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "5C5sqkZA+SZJZWBO+v3goA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "5GKnVDsIRQ4aY8ICcomaOw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5P81961ZqTSY2y9Cipt4Ng==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5c4woM08z/CQiVzL2RiBWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5gUw7V1UhMnK6YoPfsX5eg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5h5AKXgZ7vJkd6xJ9eKDGQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "5rlXhvFkSnde6aIX1KftWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "5vQpVW4vLgKPy4ui5REMvw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "baseScore": 6.8, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "5xeM1k+VvYcU/xV+hgDtwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "601t/MM1gE+tOeU7waDd0g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "62mRq4C9D2Fi3b6rCkQTcw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "68aTZzXBvZontWtIx/3b4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "68eshzTKFcJRqXz/jgAEtA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "6ES7hkRcIMPt5iPgfBeemg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6F94GA2WFa6JdVf4FibsZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6J3s3ytYuZnXwt5lQIqlhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6Q7cSKnTxu+nzr2vFDnZQg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6S0eyEO6j+/5Oru/7o8ifw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6SfR7C92OMaKw1U/fAorwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "6Zbh3+Y2tosvSjDcFKP8Aw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "6ZwesWdsCQ+SFQKouk0D+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6oQOPW/SOH/HZt4HVN1Sgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "6oeh+EDX7YG2y/U2/jlouw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "6tqG15NFTj8WQy8yBxg3gA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "6wB3SHb/Pw3K2aEF5Qy/JQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "6z/N4Az6vu/Ht80DdvVCEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7/erHjcVbxG3II9T3g8TzQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "71JlBQez3bAZP4d4xP2Llg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "74TjW2pkixo+XKEdFIUK8A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "79WMS6tb+GafO7Jnk1cW9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7AdvNmaPEJQFk5ZAY+XM1g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "7ApekoO6bPDdCOudsP0VLg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "7CspTksKQHFn5A13jATrGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7FcjXbr6LhyyOlh0vreQ0Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7JqGXHi6j8X/siNtDOoeCQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7MNcHEmPDkCtrqXYik1heg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "7MfZgzd25Q7NVpvV5hOlMA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7PWa/1p3+m/2Cnct0TMQmg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7deukt0nx1nb4gAr399SPA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7fFaZxYENGItC+DqHp8ghA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7gEkx7h7id09bJ3nUfeoDQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7kwW3ItNyNKm5qVpmNIbIw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7pmzE7cjlb0lYdvy2/02Zw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "7q5Yr5iGk2TjQ1fwpKRx0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "7une1X4kNaY52KKvp3/k8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "7xkpS42Ar82kePpM49ESDQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "80CwuXka1gaqTKme6aYJTA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "81GjLIh5V5cQwLLndqjzDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8JDDEQtcQoyLw8fKvkdvtA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8MP4w+9DQY+tiSu/rCDGow==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "8VV2hxLjCmO9pEMGLA0x9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8Xzeresx+aYil0U4zoIbPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8YPiey8As9kb5oGX07GXAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8azNbKhH8TuKXpL7oWx0hw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8bJ6TvpmLYG/y2sOhV60fA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8d4vfFuZtB02pD0yhIbT8g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8fvdCdxGOPLTl/QZZmHYXQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8gbN0n+9VnrAx9TxfaZCjg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8i7oY8t0v/hqoPfbdjDImQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8l0u4wAMOeupHbUARpHfuw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8muf76acbZmX8cloC5+CHg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8s7wZf02zu7kRPi8BEuaOg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "8vil060zSzr5ACC5lwj23w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8wnXl2a51yIxn7LxSeinXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "8z+QHi4S4WDm6aWogE6kuw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "96cHpmcS0fRAU0scCg6b9g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9CEbwXSM4zxlVIlqccQLuA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9GMQf3G2BK87x6QUHgjgVg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9LQ7cgc2lvnSN3tA95Jgmw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "9NrSuFGpsJVnFc/Q+9zqZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9VaE7bXXK/xO2n6nA1Zh+g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9Vis2TWH9z/j7AjEfl7VGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9VoBuFaXdnhHPgibGyhpfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9g7xBDIkdEIdlbmN8c78nQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9hBTSrmMYUQVapaLCp1VhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9hXvJPuYbS6CLXFycAJ99w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9idvVOsyaQdFcV+qdxfyoQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9uTlw6qkJF9H+PeJLKzcYA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "9xPy9U3WOy/2+H4t0fpNJw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "A0op+L+JbMa3xmsB6bfM0Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "A13dtLHylURUHZNefxlSHg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N", "baseScore": 1.9, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "A2tELXXEKzN52RK4u1VO4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "A5edsP7XEH6D4cmvYBsj+w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "A7Yp8lXwx3uwqC6eEl/MIQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ACZllLUORfDLpn3ve8yFBg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AOC74CEOMieqF4QnNIHpHw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AR1mIh++KWFwOpNBMSCtcg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "AVqsLa8FiT6DFdwPobOf2w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AYQU3Kryw6wN3SdT6aXSMg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Ad7lED91xtuO5R2vruVbvw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "AepvaOoHpgY77IKxvqCVwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AlsHKe6pwvjWLCwYVvZHJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "AqPsePg/x9foozdu9m7x0g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "AqeVD5NxLS+weKkPZyFjMg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "B1JjtK21NVnmDCEZc2qsZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "B8KsBsV6XL5o0MASDvIxkg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "B9YYU+s2Cvva7QJUDtHgtA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BD42nQToL1fdszU+AsHeUA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BE7WNDXAZtKdqmbO+76HPg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BJSkSr7uOl+9xHp0ryZ62w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BeYK25cFjXVIucBOE9TZxg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BlWzFLDGsRIdIr+8T/estA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BxmPqE51CJB5JIKaQ3E3/A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "BycQ8Iao7X8iaC2posSHiw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "C2rkTVkGbhSsyKrmiRle6w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "C7PpoYskxK6iD21JtQVTfg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CD5zzBd12kSBWciGkqLjZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CDrNE8A4NBsnPAqoIUYOkw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "CK0gQPCPQM+aEJCCq53cDA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "CLneAUk9k5p+117hZeCApw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "CSDuo5+yBjRvBzy9+2BbuA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "CZdODvItVtmOQOQwVO8dIg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CipgWP1TNrEuX30sXyiVDA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Cs99NDR/2aWXIUslX4V9Sg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "CssqY71pYe1Q3wka2HbNKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "D+e0V9WHhxi4n8xiC8i18w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "D1lGDgRmVddpsy/krPkJWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "D3XFmzgwlaUj5224Ty8BXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "D6W/s3VZQKE8xMh57eUkZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "D7hEv7Md38UxkdoufM/Uug==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "D7yI+RxqvpHcdBC67a88Cg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "D9VI64lZjFQsFF2NnyKSTw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DJp7nKlC0fmEasL8DScwkw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "DKLM8rvwKJ6+fHZ/qapkKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "DOO695SndYXuHis5ZYF2fg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DSPfaFg7hLhEsc2fToRgLw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DTa20HYXjXs/P3Zs9HN/QQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DTqW4x46QrHUeNdsdW0MbA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DUf93g2uSh44oAMP/2IC5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DVtv7ccp2q3OpewgYQvjSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "DgELrwVlzyF6LUyCItuo/A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DtV4sdV1hSPQ0AIl8cr61A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Dvyktamg43GwH2r9Vyku/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "DyfgvZwD3+UhyLH1t8vttA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "E+efV15Gp/rLngRKACg3fg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "E2SmzNbrYzbd3ehJM5ldYQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EAlLhi+f9W1iGlSW/XZEEQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EJ33qgRazVLqeAKxd/8pXw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EJB8Y62Fej4Lt+APLoeA0Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ENsHyD6BH0uRYy4OOg9ikA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "EYn2BjEWyvSrwQm3hD7uvg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Er+X62T35/FYbVBB3GMZvA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Es8gDnTR4NlprvEhI8DsyQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "F0G9v3Y1nWxDqdEHKjHhqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "F1OvjISK96LVSPFgK1ON4Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "F4LulQAYnY9rA1Yhcz1gdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "F8iw2hivo7VOfY6T6lVssg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "FClPDjyyXuDXkVInXpQ8TQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FHdwzMKhciLU2Fxy3C/l9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FJpIbicmNxXfM2KinGJfnw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FQizKMX/v1MT9QGLib3ifw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FRliugf8XYS2sR8UKkFcdA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FSIPRFtfRo70nIMzV4j75Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "FYe7Wa0fVzI7RmAJoXf+VQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FeWrBJujMl45wBsMuJwWow==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "FepmO5xv4FfIjhOQ4Ibfgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FkO1xyFl3QSN8mmAxDhcqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FlEYOi02huntZhTu3xrArQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Fn+CsGgMYWH5eh2+nmnd4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "FthYp8iOz/26jfLVwXB8zw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "G2iV9eBpaZfZ03f0d0t/rA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "G5V+qv7EnKUSx9A7fkr1ig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "G8YItgV0rZhbyR5nCdBBFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "G9rxX0ybHgw86Jv3kSVS4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GBLYo/Hpg17ZmUp20DxbBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GF6tUVJPrzwKahsYQCql3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GJrvy9jffG4zI55Mbn9hPQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GVvZ1pyqS4BMw8vAHqz3pw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GYeUqbv2q0crIzEsMTVjoA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GZouk0sDd/thoSYrZ82zZg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "GajE3N1YQ6FfS4SAySC7ag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GdrnB+j3VN7L66G2VDQT/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Gfnrd/Qq3NY0ytzgSjsjfw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GjZqVvRzaJEGIN3eGK1g9g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "GqTJcsBL/Jz1hT2nxRpDEw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "GuCBWhZkPdgB6JAffd0vyQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "H+FYqkEurnu4jymCjwERfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "H/zWlIpN8aMvffie7AG76A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "H09h9nd7ZlHJ8LRncQ4cfQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "baseScore": 8.6, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "HBrSz1uIhsdeuDCH3ewyoA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "HJ9IDZvGKgGm0SpI03Kblw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "HhS2mtMKZlbYlHszwIEmdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "Hq2KZaE/Uj/paNzirKIsyA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "HuLcwroM1rTmCRiMq0xq/A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "I2QYqEV869V5y9popmkhNg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "I5rQJEau/vCfHOUKEwAKEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "I9owf7FzH3E77Ei9S343oA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IAC/C79xmpc7WEKnnXFbpg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IFNW9YBko8LrXi4D/GCQ9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "IHXe4WyflrmOusIwp8d5Nw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "IL1jRXwy2114/T7QtgavEQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IOSxX+ObQIo5oS9dnmmDoA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IRuMvMA8Fi6mQgkH9s634w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "IVCa8wAzO7odLR515cEXxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IckWa2ni3hDgKetUO6msAg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "IeoitvM9lwggrk3KXJzR/A==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "IiHIqbVmvG4EG9wLjhDnjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "IiNBd3UzYec5KOagj4deCg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IkSL3kbr93i9k/D1z8DQOw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "IuRLsRsG56+n47x1CeHN2g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "IvtNhBs9EBdfQJVcaS8g/Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Iyl2+BN5OE2iopIsMT0Wsg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "J+BMNtoyQOWexo7hrmq3rA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "J2eGA05DEwryfnUENIziAw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "J98qdwAtIlFmuTWiWH2dZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JVCst7rPc5C+mXRLD/3i7A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JVgYJrtjksiu+imyHUIFaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JbzslWZ8XhHtjGeJPRHhkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JcUD7/ApkvlfO47KVpD1zw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "JqM0nqzbtdEgcyvoIyzloQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JtMhEzdWDI1puPD9shAVng==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "JyMCBwsAlUJ+0nV0dZZ1Vw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "K9+A/YujZbKHptbKzfLGDw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "K9HJuYuqoA0oSln39+ncyg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "K9Vsb61vzm4QbCVaTbr4Ag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KIWTfqGvHChaaQEfN6qJjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KJIdfpTdRKWkCMfxbS/mUg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "KLJBylkG3Wsrc5iZ+g9zLw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "KNBnL8x4YgVUk9a3l4+5tw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KT/XSjqNnGmyUjZ4EXYXeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Kalz8nPy29l3XQTjNg1oTw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KbVdO3g9TpKrFW6unwJ3eA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Ko56RywS/QY4DPnvHjCF8w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "KsWYpAXrfuC7trSFJnEVxQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Kw0EaPoYj535/n7O8wuTLQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "L24+fTbM1h+Y5XH0k90XrQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "L2i68tImyqS0x0XbBigK9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "L6sfUnRyu2lAMh3ROdPlag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "L8aIsY3YbUYD/sR0L1FHbA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LA1kH936Pv8VoSzyI8d3Tg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "LQ+t6bZl9RlU5H2tsWen1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LR53RfBcaLruNmVIjJlLPg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LRmZme+MFDTrTqd0tt9LgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LUOZZKY4oeyvXegiWO6Yhg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LWHMtlh7noa7WaBqmptSKA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LeJ94r+TvuBTyjiQvoh/+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LgJ7oWqdNk4cJQzVzTFMRQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LjSRKao8rTYjhGOoAVtUog==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "Lo3/+u57vnFiy3iLkojwsg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LrXhgDkb+00pghFQVX0J/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "LsID8egvR6MllXOxUPXkwQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "M4tbiBn7IwzJ1ZmsEQrp+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MGrbbNsTtAJ91AysbDgiPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MISSvrkhRBXMQUwT3M+KUQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "MIdBsN6uGjXn5hPMPX7Kzw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "MIkTRAv/IGPjw1oKbjib+g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MKbNqtVKIsB4Skin5vwLuw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MTPA2fuSLOyzUIakkBHnzA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MVI9YH7/7TuqWPhRsSRp2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "MWwgjsOk1ofNsK1d5IdecA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Mc/PcK7PUGXHVZGur/JxKQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MmgZ4Cd3XBWQk/ZvGoOd/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MsAjOQqU9HBRH1IUou6UlA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MsQlQGzt9E1GQg3tm6Z6Xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "MsbFZkmfoWEAxb2Qnj1CHw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Mu99OY+ZuIj2ySoksh3ThQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Mw989Y2kuFloF3u0zyM2qw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "N0pXiwLCavo/09vFe/8Y+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NAl3wEfkqVbijYPDBkjnSA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NK0hpvWCXi1qKWF+3Jh4KQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "NLzrvdj29R1KWzyuO7vGrw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NQ2dAoiyDdaP6k9PNV2Zmg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NZI2pa2BKL40u6kulzTybA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NgS+u6TtkDzJT8fQO9+/4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "NhLMD1ecB2U1wdghzQvPSA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Nkn4Lx7wFGCCYyHykJcx5Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Nvv3pdW1HxIo+5qMwgrR5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O+eHWF1ryUlCFVMNqM1DDQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O3Czql5c0ZzfDAtbZXKSfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O6rYT5lpJicjJDJhxGauhQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "O7qzhTPmuAniGdn3z0AkdQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OER9o99pdjlfsp56JzoqNg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OGb2T1usqCHtg55ESExGbA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ONPAYP/p9d2gYGt/OPIPqw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ORg9zjoAVr2V+FF+1/aIzg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "OTrExOT2ykXeHWl52M9Mcg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OWJa3duCz1A5SfiSYrzr3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "OWtN2QRRD7xZ6IJXy9oe/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OYZS0g53R8lKkEyzqhKAaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OaLlKdp4dalc9B0bAvjr/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OdUQ3B3TaB6Z7yh9Y747EQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OmC3nNLL/7/oGa15psUdDQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Ot2ALFiZ3eowUTEjMJWYNg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Ovox+LFKTyPfDw/8TYho6A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "OyZClLDMbQRE/2KgCJrplA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "P2+GI7i9vikUEShC4ve81Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "P2lxsKJKPIWm7qQRXm3vKA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "P3dCGUpIbpcPhfTgvL/rYA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "P8sDnbg5LMrjsP/4Z+0szw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PF8BPDtAFqhzfwgGoGNhcQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PK1vYjWaZ1mf1KuZmjERPA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PNM3dlozFto46zHKLLUEnQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "PYhpLJ9RKZfyoD9gRqTXHw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PfhjREk4GtBBWbLt/M6Dlw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Pi59oKxtylAGg/MHtN0qBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PmbS8KA5GseS80O/YimnuQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Po/Ca1qA1mJ+o8NRmnbxbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PoujEHCHWEnkSxht3LvodA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PqqxmFVRtD8Y5XIsEOgprQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PtVDQvqAWTWjVkSW56jMZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PtYB7j3KiYHvNfT+z2TDRw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "PtgAAlJUo6Q894aXIicfNw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "PvPOVXZOs5mWfRHbAqRK9Q==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "PxZNCkfZQaCYwxe14mPXGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Q29O4Bg/VvfVqS3UXQeb5w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.6, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QDHl1wjJ/hhM0L8lwX+C3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QGrcmtKnV84PkEVV4mmlmg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QOBrzNFBTPjlxOPHaS2UrA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QP+4ZaPTGK0vJoGz0t342Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QRArYIgl58N8Ovzgvjnhbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "QlXZcP/gBAx3ErJ13BXquw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Qq49by++IUkNs52HRvz21w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R1MAm+57BqKjyvlSiGGjrw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R2d8BwjTnNG4x5x8DC2N1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R3jTuLGdWUQtcXVXN/W1fw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R5eHMXQhuB92WB0MreSz4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "R6AHXq9kIXOTM2VjUoYfdQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "RBYBjfXBVxQdpYBUYaRE9Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RCPRH8WEB/73FUqeKHr/tA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RCTFNcTWXhvQB4avl+clNw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "RHM3pRxZLojreeoTqHcLWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "RHXquoov8J1zuTpnk4gIEQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RROy+89qj73l90OV1VglGg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RSK1xJaKXQINWZhrI1wtbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "RZbwexafVJIj0fYiHghpiA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Rp9OSGQipDOR4a9bA2FuVw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "RxrW7ydW11PIaDYyAYKVTg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "RySRoRIa3as132RYPgaQ+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "S3qfKrj3et4RUCaKB10piw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "S4UDJEN31Y9gXebwQEZXnw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "S5XbWbaEYS26ORNQqOThVg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "S7ffVdT0arMe7/C4MSXpWQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "S9khA+AWY8JaldQC0uvPGg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "SNKDZDO5r13pfUGn0GISlA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SWPowIEYYudHKp5flT9zvA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SXstzXJo3ARVPRHH1XkipQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SZAMdkdOi2w2C22zR27Q3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SisGfjGX/TPw7kokQ3wHtQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SjOLMJaPaetNB7CJwZwaWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SjxxlwRlBvhzJ+EIPQg+2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "SmDyXYC0yd+JAF28cyzlyQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "SqunC8KQn/zUdd4jPxGV8g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "T5ISGm5LbVeRDQDfUYF1oA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "T6jUkybzEGhntULjAsvqfA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "T7H5goqWimRhJ6/lmz/14A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "T9d7eiSCgaG9+XuCv6U0qg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TCd9g35j6XmK96Itj5MuqA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TGoRkI+VuLFVYEHzjLAL2g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TKbTlc4iN8EYX5qKd3EbZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "TPyZYIBowqrU6+m4nrBEHQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TXaAGqaslxw3rNhoiJkiZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "TZ6L6I3Cd7+hJR4BXHfHTw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TaiMhQEJ3Q6BZYv48dLzKA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Te4WUvO8GpV/xKQSiWprnQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TiBB3rhbLcdx2WE3ADGWag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "TqzX5XqesrQCHwYXN5ag3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Ty07MJmxlxMtrmptnF2X2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "U2VEKQWR5OWfSqtkBGXqmA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UQvyHOeI4QjGtZnm6T6ljg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UUx3cOvsfM1yB1cxpmSDRA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UeFIZtTayPvdOzvVB41/jA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UgYbawVYBKlWqMXTnMrkFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UhU7m296KGnSD1zZRSq/jA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UiVcHg1u39wxeAduIGVeVQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Um4hWKnCf0UxAt6EEhGwzQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UnZ1Z5jaCJ5t0Ylihj7qQw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "UqlXj97FrNpj1p9MIGdxxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "UrZKzZ/sKVqQmTDnQ47I9g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "Uyt1KDdT5GAgyMiaZiypKA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "V8iS57FCTRiSUW3SJu20mw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "V8kRDFippjKvrzP8VaHSbw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "VFI2YAPt+wwgNU00tRnLLA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VG2kMas1/Gt7kIoRyvIsOQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VIIHXNAx40tfWxKjUYoXug==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "VIauTgqjmmC3JrXtK9SoKA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "VJ3UbesVXW73e03bBBZDRg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "VLHKht+kiKS6NMvy/MetxA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VRBI4lPXeZDBh7vAlbseMw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VUn+MKhO9qXlulJ0JJY/og==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "VWpX5DzXUBXf2CZ3YPlpsw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Vbe2XjswKKuAOoU341cwpQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Vd6ZTfdSpcn12KBePvRLWQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VgzyFJeiC9rkj6o3g1bF+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VhutE6CSNp92DtQ53GCh4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VmgWfo6cc7CWRKYng0D+LQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VogRSV/2Imj9EVT5Y+ZWnQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "VtJFIoe4RZpuYfcXkn2FAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N", "baseScore": 3.4, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "Vv3PxPN9gE/EoER6vTtqlQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "VvK7VF34ghwBAlMiD4P5yg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "W0WBVJpOgKZPh97Vdqea9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "W7Ne/UdSHmg7xt0DK0wdtg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WDdht+QZQ3xI6LngG1n+jA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "WIR2HdumojMDCSS6nHR6mg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WLEJTIMl3R9U+oSWIgIMrw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WQgTTwn+g6RZhl4VVAGeqQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "WxIKMZNzfMhN/POQQ+P6fQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "WzuogyQu2dsLRYZjLeTWhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "X+KWCuGLzTBeWttwniMBuA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "X/bHAQhdCYw9YE9271HYiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XEO2N+fKL88Nc+lWd2zGlQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XKgaiu1TTiF94OEf06hPHQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XUdSfenojPgi0C3JLdCmEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XVEm+2KqBXTjMkwVXx4JzQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XYrWNG/ZD9L4k6Jv7ONGBA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XiJI8JQ+WXVm0Ec9LMZ3JA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XvR107GSrc+xeR3HWE/qEg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XvaFhekmoVjuOn94KgTfyA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Xvvhh6iAcEx/QtBYxuBfzw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "XwcGNCaKGppyE8H0de1PKQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "YA+baRm92vzKN9/R841SNw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "YF8OfaM1DSxNuPCgGIsTTQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YIFdVIZNby7xlEcg9enH4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YJVyMngySk6wihPKJdBk/Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YPFxAW99VI7nQ5swWF2Nqg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "YW3HoFXarBLE8Jq3Htt1wg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YcAav/frJZCC7Lw5hP+MjA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YlR3u9lZW61NKtn5JlnTOg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Yq6/Z75fMM5cPYk+D+3Seg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "Yq9nncpzUr5K0tgMiAx0rw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YsKorYDNSlb87ZdIS9kUjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "YsLoHuuQxyXnuNuD6BKbDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "YtV7YaLA+7ggXlLHn+OtFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Z2k8gTGRE3tRnaa6C7ph1Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Z3tjpgDGCLjk3Ec4HecEQQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "Z70NNghfj3CUDoF3RSOhtA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Z7Zr+aJtnT0rPmKmG4faFw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Z7pBeVnuOVlWlFYmFAqamg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "ZCSymtjadlzkXt8CU3F6PA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "Zj7vExxsRx/s2nS5nq7feA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "ZkKRW+GbeCTumpVfOln0tw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ZwjT/nBmdsy72TmavWU8dw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aAqnKFLRNriCGQlG3eKWDg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aNNHQzxgcXugfFwv/DN3Ag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aULCDyTTvZjPfzCejfrcxQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aXQ9/hjqCHUJVtN4KDB0uQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aXiSjOT7d8P3PHD3zq8S+w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "aZ5JnYDYnTmgVCL1meuGtw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "abuRlaIjMoxp7JxuUe9ZMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "apLsRonbFnUs5fqAcBbkRA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "apNb4s14qtsrQ/p0KNYftw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "awprMKbVrDulQWYe0doRPQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "axu/TKv6CR+vYzn6x+QHGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ayNwOwFahcJX8VpuVbGJUw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "b+yN6F3DrI8g0bS8DE7Ikg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "b/gb9s3KrIJfPaaNxJoujw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "b2VPlgx4qj2KQUTqmyJdew==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "b7jIcdQJnfDJcThaGSjCKw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "b9BwljBVb2STBNXhnDZGew==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bQ14Sxqd6BxYkrJpOMom+g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "bQkpTmjn4jTZcFsn7mUkdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bSFklTcH++Qe4N7ocEMvdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bSGK4tTg10r8DpiEIpZRyA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bSQHKOOIEu7zn/5UgFOWJw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bXtl+n71538U32lxPZ+WzQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "bfUuYbRigpZ1CQq2y/uE9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "biBX6JK0iCfEVUm/Gb3CjQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "bkD27G5x4y2TAqhJBzu7xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "buEdT4BInhnHtAjlzQ/evA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "c/x21M6pcU8su1V/zbVNTQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "c5zsAjQ64TJlVMAw69YoFg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "c78r6gYTO3VN8WrBjUSEOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cEkDs9u9Cpspxm4MFYaeWQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cPVrahyl220g0Gp/+c+Ekw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "cS7rkbIe2yBX5287dNi5sg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cTXu3OaxY8CyhRj30KQ3nA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cTd4017qSU3BkDE+MzazZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cWQ9Gv0TkIKOhqjDE5i5IA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "cbSORXfR3xlk/2j/nv5Q1Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "clzVgq3hfrfUfnMH/v6WVA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "cw1TUdWPzmOtwmbS1fp9TA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d1LyvMDT4Er4mayGqstCMw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d3VShHYQEj/Dm98dDAtH8w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.7, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d4Wj41RNFZ7ktyiP6AmZ3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "d59u3XRZGdnK2xtdhx8bMg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L", "baseScore": 6.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "LOW" } ], "dASWaRulk6HSMFrYTrSg/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dGQe1jlLm01G2RlSenIKgg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dHzaD2Y00RGnXHcbRlDrUA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "dIr9Ixsp5HnH41WPm8/HFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dK5VsavHbrJfcH/kIwHYaQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dNm7m8S2foMYQ6OzUGB8fA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dUtIAkfbSAmbKtPLlwkJwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dXyvpx0uFAcdUbyal2rtbg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "daGu3oAT3vmj5Wg7ZkBIOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dbr/eJTKVL+PlwpJky5WYQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dd1K9exjqjFQptWN+pGz8g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ddTPBzeeJYnba7jCapgbAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dno/h8+cbyT8NDmhCje7og==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "dqjoY6LI7HXbG/ZNHxRFxg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "e8yl8xEHcBMt6QNxIxnCxw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "e9wCn09MX9e/m/J6umidJA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eA2NK3nIYMq+exBDZhhXCA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eAPPNp2r6gp30swyIPgs8A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eFmZwmd/PF/L5BwzrUL8Bg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "eJWQkT2e9DpqDKZu/3OPSA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eKnrUNUJQNJOChCt3LUUxg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eMcft8C1+SHqjR2CjpyZMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "eSEHklhq8w2Gxt4i9Oe9kA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eV+P3z67kBdWDC5tFoPXmw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eW+REV5eOe0Z0hdA+hyoQw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "eW5sSwfH19cOVhqOjFPExA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ebIgfG/AuFXg1JE3bCfp2g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "eg0zr8Uw6LmL6IroDlS7wQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ekhzxIHRTH4nfurC7aQlwQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "esFy+BTeKuM/9GkyYe9/tw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "evy4OzzM2ENIuS4DaluP/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ewHqN0+8nyoWSAsnW89H3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "f+L/NxbWRWtyU7efEy5kwA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "f/he7Poe7++v+chxeZckAw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "f22/JqHREO/iFR5wVxKZDA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "f3CTm99In33LVLjnI20WkA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "f3MVLCaGFMZhT666w6avPg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "f3vaferRpevg8b0DyptSqw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fD3V8WvG+u7QpTEDqTMUAw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fGD9z3bMt3Zy2s6flXa9PQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fI1cxD6IkyVtdqUWMiiHAg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "fIOBZLi+PdPMNcRduPMSyQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "fOZ09WQ2S529qRiEbktTWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fOeXs+kiuyq8k7gYZR0Evg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fZVpSeqDPAMZq+eNz0K+JA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fgbOPWAFsTd3RMyFiveWZg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fnopR10wShgmhhhPsuEeJw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "frvuZApIP1qQmX+Pqjd9xQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "fuR5h+zOLXeaugOCtTvDxQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "g0ZIb1T8gqxy9GnBZHrs4w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gBevJICSLIQl0IiTPmQ6qg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gH8QEPM8ngOb72/e2psndg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "gHf+ohzp2wBUa81nDxLHzQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "gIEQo5B1M9YN4hmFor01HQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gIdEieYO/ntsLE6wtAmolw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gJF2RoXEUj/4hrZaYhzyJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gKT2K6FFmDBgo4l9aOgYBw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "gKllHD4ZF3u6+sYpimhiHQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gKs+7YLrqwmMe1IHwKZE4A==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gVMCgMuPTTEnybcY++CgSw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gay3MyHX7w8wsA1EXoF3dQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gc0jFzxcW25N62GQDKSqMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gobA70V8S+fBhe3etA88AQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gpWgVqaQmhTigA4n4UKLcw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gt5sb+F8Vt96IRL1gx4D9g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "gy2AALhX/hsEZnzWIdHdWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hHuds3Mc9Bpql1Z9vbWn2g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hLgns+5VPBgBxKIOHCmUAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hNTPziyPr0zH92JXPH3A5Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hPYi8glMBvStMRV421SnXQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "hbsENkHIOQnmxsyPIblNZQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N", "baseScore": 2.5, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "hoU7b3nCpZ8AGIjXIp7o0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "hoc7dG+Mk8W7soxdxHhlhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "huYa0W+0g8fZ2PeXYJCMOQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "hvrnL6/SCX8xDjTn++W9GA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "hw1aS7NFesUo2f+sJX9NiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "i/qfmVnfw478DUjEfi5wrQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "i5e3aCZ3KFF1VAfPW3LZVQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iCypsGLRz0uLfvrJIEyGzA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iEDMueHFmszLRMIGHWZmww==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "iIogkXVmWzUQmvCLYwSVyA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iKw4ydcJcdKtvLNGHH6VHA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iOyLmeTOvgguVhp+6I7Gmw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "iShLWfacVbWp+yrwXBiO+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iVx3xbnEEWX0lvHLuILwkg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "iXfwRorHjxpSQP/Y3LKYmw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iY0B8c3S8KaeJYJfnX7c7A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iZX1sSr7/tbc8mtMDlBUxQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "iaZLD1oLC/nOU24rKE4c5Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "il7wrKgnv2XFHYQrPt6FUw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "inNW/oB7BMbIgnOSCVi/1A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "inaCY6PIXgALdUE7MAms4g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "innhwwtG+k3NRp4Z1S3aPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ipbNqEv3q9WHV7lrDHCung==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "j7/3bA8hjorM6rPdwZBKqw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "j8iy7RKfxZethWyioJYxlw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "j9wLU3+UtGm5/f7Rj8ErXg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jAT5nCGVIS6apnWN5nWkJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "jG8/PDXriWa9vWg87ttnrQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jHHTwsFpYzooo5vrSwGKhA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jSmJL+G9oPI6MUI27LQFSg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jcvnkSTQb1UhujW6CRJ4uA==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "je6ZqfWg3ctmGtEqprl3eg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jhjhpZEqUsE/GgGdvBBzpw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jiLyHD81qvPLMEUaTrdWlQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jlrTr1dyDTh1M5CunQeb0w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "joye5blYiU3Lze42WmGVIQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jvXo8L+w0I5IeZJsE5sQ8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jwCtKZlExxG3oKjYCyqGAg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jxeBZQT0rZDcUDj8Kd0PtQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "jyWDLwaa34WPueVKizEYAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "k4fnMU3FBc/o62cw/deQ3A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "baseScore": 3.3, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "kBTtYe13ix5ni1oAgQJaJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kBdlZauBxTfq+9SvHKQRIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kHTcuX2ojk+Ouhq9aqnFmg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kKJMMvyEOKqokJ0bzYC2Cw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kM8v6NxzXQPaH6W0rRyY+Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kO53yCiQCcDnlmEzidxYNQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kZ0cFnzel9Dx3vpxtGT7Kg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kaqNCfRrzo98RV67uaLNDw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "kd9XNSBjIRt8Gh/ZOvPQDA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "keb0BYbqks2Jt/xv1VHGMQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kfLGxTKoKicnK/rNfBjRJg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kidvWKi8nb4dqsT8EqCASw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kk0BeSmKqmzGoT7xIOWJaw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kpNPngHrM4VAz6i1yHUbpg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kq6Qe3EeFnn/jFkC4GiCWA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "kqzISkE3CskWY60zyXu7Og==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "kvTVIa5bq/R/nK1M8mwXTQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "l/LCnnKtIXI6QIMXQyAmyg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "l/kNLokvToElk8R5OEG1Hw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "l0KK0xXzbXVKX6MCmaR4mA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "l5T8L+VKYOFTQZLSZbrRew==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lCqUsiwpCWdi15QTuyEemA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lD3fwWxRJRf7QGu76Yui/A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lKw7TsGs0QExvrzGu983hw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lTH6RQt00L2k/ovUGND4sA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lbq4vh2+ZnForhi6QFyAFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "lfk6+WpQ1adbnURKkfPv2w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lj0olDIEOqoIZRmBl/tcnA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ln1Lq6qzUC1Ys0m8YLemFA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lngFfpAJvbin9hXK0qoQYg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "lr3UWI+X5MYZjlxk+Wat/w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "lxpghzTAGPYPM4qIkJMJ5A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "m+XmqJ5VHL/uAOCj13Gx3g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "m0UDwMzBwVFEWXmEOBxvUA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mCcaCnP8f52+vu9b5rtNnA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "baseScore": 2.5, "baseSeverity": "LOW", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "mCd+YBwD6U6filBaB3HE/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mHbTjMj1rjOIPJCq59mrig==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mN2DbEhW6VqTjos2JoPnGg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mQ7+TqdAO4YZAHkoGQlD8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mQUiqOxBu6sTcRb5JQuOcg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mQY2cBerKZkBCxSHL8eURg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mTD/V/e2oknhxg1DQ/f4hA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mcxEec0DnlmZz3+CmevTKg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ], "mi24MOG36XGGY3jdy9tVog==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mmtl2ec/o09W0FXFeHnmQg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "mmxHxuvoy6NJ2C1Mq41y3Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mpo3/WeOVY4plMVPjn+etw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ms6HlDT8WIxnDT/547gqTQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "msRoLpQ5RRmll+h3oQOUPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "msiaP6ZPjE6ydV5RJ2powg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "mtsJHWk1Bpn3p7vhoDLtug==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "muQ9JOZI+Lpy3i1Gy2YS9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nATdasCaoRj0zKLOYIzA7g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "nEDHnAt98ommvxFRwuVpOA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nHnLyc0i3LGGWSzAPhyYKw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "nICJsssx8SRrJtkPaGWSwQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "nIhEjmVZOLLsxjuIgK19MQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nKoGjNh27GCeUMT2dK/Gdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "nN3RuidIOX87KUHmtXIlYw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nQ0YMG97Bm6YVHjHJkVM4w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "na/ugY9lH08smavOJFuCMw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ndJ5GEAWepa3cRd6DbKPJw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "niZVkyT1xeY52WsrQOz+8Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "njKjXe24Zkq17Blj9of/EA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "nmLo+5oFZcZwsNKc/4TkXA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nnjR/U14S0Gli7ekeQUwIA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "nxfFlxrPmdAebW4GstXgtg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "o+J4rA1seQs4hgsSwwbzQg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "o0ecraUnR3jJvtQR7V8UVw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "o2j1vMVAP/vlfzZZpode4A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "o2jo+ACRJMvwEfq9dh6AZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "o5vXQMQiLzL6AxMfR8vX6A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oJmCZHz0uc7KgDTvu6vBSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oV54bC4E88mNdD0K7mJgPQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oXhrmejScbhntbL1S6AJTw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oZ9JVmNUhJ/PNpWTcaxqQA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "obUBIS09Ii79M9cd8FFKpg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oe29ifZuovUIe0KY+GzIGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "oldZxrZr+ML2Z5vdlIjivg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ozPRwqwtgPcs1i1CZrMe7A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "p123ESKFXzhDZdIqbkw/aA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "p18kTHw6vPdSaxQ1n59IXw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "p1l5BO+8RYtfzObLk3HHFw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "pCu9cCtk/7SjSwDySmAYLQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "pDz4kM39PiixFNvpR9pL2A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "pRHfMy/Z0maNYXFcPxZbzA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "pRxWGmPbo78YrmxmMFHfrg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "peqwgDyzcNXXHAaS+9OP/g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "piBwOKVUN61Uds9fQx9yVw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "pkQ3rOcGRLKd/29TT/Sy+w==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "pmrDabbkONJKfrgmMjw0zA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ppjL8ervQY+FRd+kdVgrBQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "q165hps53MwmYpTpddoHwg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.2, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "q2brSwh5JjiYiRkGkO5mQQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE" } ], "q729w5sFLS4RIFtNLkblZw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qC8C6X96cimg3e6OBu2gcA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qCasP65HH5s19aqlIVeNSg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qGTI3SeJ9soW0DAFnYUtXQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qNFgRdQ/8x4TTxwJoCtMag==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qOgf95x8MknvgeyA1bCtbw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qdg9ZGiyg59EqydNTlb8dQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qhkvx4CfybVWilBosysd5g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qlE/u8JaqdWPOKprjuHfPw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qoXDqpTdCFxrBlCQ121ojw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "qrvZPwEn248D72+1ztchmg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "qsIPXyVZhxfTQ3/efdLNnw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "r+SLRw6fkGB8sWuKipdpsg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rHluYIV74XqfYpOxMHO9Uw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rM72QABgmf9nL4krapkMSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rMaA49qwWtSHUzACuwQ1kA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rNGDQoozIwLRuTmXHEeY2Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "rUOuprNv0asp6iYybUFpQA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ralGcrzRAawbxw3toTbgRg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rcC8CUmqvvy1e5QKJQrBpQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH" } ], "rcPmofVCF5dEf1IjBTTQNQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rhicS1iAdJ7haynjMu68Lg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "rlIMrSvggt9T2HDIr/N5mg==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "roEJ3sSQTvxB/BsqtXwWkw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "s/hCdnJizrGpuAbegsTfiQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "s54OavJMmxE6M5mPO5T0Pw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "sDW0EXHPEasW8Uq6gTO+PQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "sy3ilamsUq1ezzG2K3kdrA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "t1cDuzMlX117B8LBMX1fYQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "t3O7D7jw7OlvBQ0xuLH+cQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "tC2vRr2PwNrxOJ/kxMcoHQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "tGzsBkfMtfrEHxSA/TTu3w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tQ/cy6+608pCEG8iB+a3xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tVih89ImzoM80ZbOBxCm9w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tYjqt2QuHxyt9AqxIuOaGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tYvCYxSwmhDDaN2DBZh/lg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tdmTWMKf4Wd4a94OZjAQWw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "tf2LLVKK9ztdqJ1EUc9k0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tjUOg+P5YgWl5btEGrYxOw==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "tl+ldJVpSpeTGWtLbHBFjg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "tr3xh4aSzA1KYajxcVhY0A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "u0KFq8sxSQMQOjkoSQcWGQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.1, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "u5o/Ut47Hjve2qfu2gi2Yw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "u7x7ygYe+0lg4dva7NX7RA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uAZ/vVdCFUjRGO/lgTu7Ew==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uBgGeOGTFkYEcFN9GrAVZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.1, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uEgJFcCQ1Yyimn97LxvMpg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uJaIkdAdssqwBkEXNNs0qg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uLeGXSkRziPc+1wkRZ653A==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "uWYPETh7SRW4hEs8/1Va9A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uaaDC/cqggxU5t4t/B7xZA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "ucmV7WK26A3Z2691L+x2pw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "udMY5/Ym22m2wauMDwS1ZQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ufTiewnbfOU03vqdmZUHGw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uq//Fq4QaSws9yxxeAr1oQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "uvFnRcryNsc38djGoFZELg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 3.7, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" } ], "uvwI+W4eYxKuNvoT3Y077Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "v1pFZ/L2vpZW7UoIOvtJ7w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" } ], "v9vWe3hIDrLLNJbYOtNKRQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vGwkpBqLshgMfCl70d0myg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vHuv4/wLhLp07vrdFm5IFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vV1qzf4l+nQIHXosn35mdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vgQiAROcJccmldely3uVnw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "viHIBVs5uaPlB2vc11zGuA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vnP1NtGTRJ4ACQZa+PGWmA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vpMXCnh0dDLSciBABeiYWQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.0, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "vv/Nq0/zePjAn4JWE5MOtw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "vxmQyPOoTMh1Zx5DCsaQFQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "w1oeUHbRVVOslv73KK3P7Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "w5DYnw3Ql//vskdC2DBVgA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "w5ixFh9N/z4mFs0nLuh+iA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H", "baseScore": 5.7, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wKDPawUoi4V9YbgaK5I6jA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wMB5sAuUkEThs0w/PiESyw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wOnjjjijWVo2GqwgzbvYSQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wTS7c0AxSF244WIdQ/+I+A==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wZs/M549D013OPgW4vrJnA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wcariq6PZUM/OyBFO8n8xg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wk03AYMKhB6F5bR6XyAsHA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wrnZx9IDlFkjjZFNqfm5BA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "wtkule9yShYfYhihK8c/yg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "wwkdl2CLVEKYg/La3pFh0g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "x1sJYHj1Yii3cb3WNbR0ww==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "x5kJV0vUXZM8gQjTU1an7g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "x6czAHpLprQs9jos235U1w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xERS7Vmbh+h18uOunvn0Vg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xMNRfv9b++Qx2IGpA34qeA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xPA4Kcui1ANUz/lomxAogQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "xeEtsv5WJ/XPZImtAV/B2Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xtYvwG9pXlzZuhCh/01L8w==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.6, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "xvthDFTRm9NDIq9MylnUog==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "y1HQd46JFnDNpDsOnGPiTA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "y1e/8gBt80FYuAfr84vIvw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "y7pmgQLzMRq88J/vS93z2Q==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "yFRiUXE6QYAqPVgDGsvzCQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yNXJBhSLoARmyawSPfJ6Kg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "yOmc2F+SacWrePdm/mxRGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yVXH9XGqUox0RMMoxgLASA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yXuVTfc0mJ3Wo1R5P81UaA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yc6saAcs8xhmSH0uppstLg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ydliNt1/jU+MUM6MVtC2Pg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "yoNy2I2sbE5vTpot54Noqw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "ysl2vdVgh9O8e4G5gfWMJQ==": [ { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "yzYZsRSpoGNn6ISpW/sHEA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "z/P7T8+QR8jnNiOGyPUwAQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "z2Bu+BjK4pQMOBBCKGJjaA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "z2iJftUbGjAb9QpTXx8tdg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 9.1, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zBi4Vv0a6qBHfmWvyJVErg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zLARHi3LgDQgVk9F5LOF8g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zLMNfbeOAdf/1PqX2MIsfg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zOjya/MbFb3bR1ErYSGZlQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zPAGkZmePalOvIEfMGZYQA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 4.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zPZyBg1wZFMz7/V3ogyi9g==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "zQ2Rf6aQ16TKQH/8PpQpBg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ], "zUuWXRAoo66dgq/CBXEmGA==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zW0NAmanPbUh3mIYb5jVbQ==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" } ], "zpnR4DQUSVLOu5w4oXihGg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zrmO+HE5JByCv0fKZEkTvw==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ], "zyIwGR4/HmoCcUA8TwohXg==": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" } ] } ] }, "PackageNotVulnerable": {} }