Submission + - Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities (9to5linux.com)
prisoninmate writes: Linux blog 9to5Linux reports: "The new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel. Most of these security vulnerabilities are smaller, individually scoped fixes, ranging from use-after-free and out-of-bounds access to NULL-pointer bugs across networking, storage, and filesystem drivers. Nonetheless, these may lead to a privilege escalation, denial of service, or information leaks.
The most severe vulnerabilities patched in the new Debian 13 “Trixie” kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root.
CVE-2026-64532 and CVE-2026-64533 are a pair of NTFS3 bugs that could lead to denial-of-service with potential memory corruption or information leak triggered by mounting a crafted NTFS filesystem, and CVE-2026-64534 and CVE-2026-64535 are two flaws in the NVMe-over-TCP target that may lead to denial-of-service."
The most severe vulnerabilities patched in the new Debian 13 “Trixie” kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root.
CVE-2026-64532 and CVE-2026-64533 are a pair of NTFS3 bugs that could lead to denial-of-service with potential memory corruption or information leak triggered by mounting a crafted NTFS filesystem, and CVE-2026-64534 and CVE-2026-64535 are two flaws in the NVMe-over-TCP target that may lead to denial-of-service."