DSA-6405-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6405-1
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00316.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-459440.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-530050.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-532600.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-533650.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-639700.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-641920.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-642060.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-642270.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-642860.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-642870.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilitiescert-bund
- medium[NEW] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)cert-fr-avis
- medium[NEW] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Servicecert-bund
- highUSN-8618-1: Linux kernel vulnerabilitiesubuntu
- criticalCVE-2026-64551: In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKI…nvd
- highCVE-2026-64550: In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: vali…nvd
- unknownCVE-2026-64549: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bpa10x: avoid O…nvd
- highCVE-2026-64548: In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overf…nvd
- highCVE-2026-64547: In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validat…nvd
- highCVE-2026-64546: In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in …nvd
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31
- unknownDSA-6404-1 expat - security update2026-07-30