VYPR

rpm package

almalinux/bpftool

pkg:rpm/almalinux/bpftool

Vulnerabilities (1,122)

  • CVE-2026-89846CriSep 16, 2026
    affected < 4.18.0-553.167.1.el8_10fixed 4.18.0-553.167.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense

  • CVE-2026-89480HigSep 11, 2026
    affected < 4.18.0-553.168.1.el8_10fixed 4.18.0-553.168.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the c

  • CVE-2026-81000HigSep 11, 2026
    affected < 4.18.0-553.167.1.el8_10fixed 4.18.0-553.167.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to T

  • CVE-2026-80844Sep 4, 2026
    affected < 4.18.0-553.167.1.el8_10fixed 4.18.0-553.167.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of

  • CVE-2026-80714CriAug 28, 2026
    affected < 4.18.0-553.168.1.el8_10fixed 4.18.0-553.168.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the

  • CVE-2026-74753HigAug 26, 2026
    affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state and detaches their group relationships. The event's file descriptor can remain open, however

  • CVE-2026-74581CriAug 21, 2026
    affected < 4.18.0-553.159.1.el8_10fixed 4.18.0-553.159.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacemen

  • CVE-2026-74556CriAug 15, 2026
    affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for

  • CVE-2026-74480CriAug 15, 2026
    affected < 4.18.0-553.160.1.el8_10fixed 4.18.0-553.160.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advan

  • CVE-2026-72329CriAug 15, 2026
    affected < 4.18.0-553.170.1.el8_10fixed 4.18.0-553.170.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR-IOV enable path caches VF pci_dev pointers in dpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those entries do not own a reference, because the i

  • CVE-2026-72261HigAug 15, 2026
    affected < 4.18.0-553.167.1.el8_10fixed 4.18.0-553.167.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocatio

  • CVE-2026-72129CriAug 15, 2026
    affected < 4.18.0-553.160.1.el8_10fixed 4.18.0-553.160.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off

  • CVE-2026-72099HigAug 15, 2026
    affected < 4.18.0-553.170.1.el8_10fixed 4.18.0-553.170.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice hash_offset is already incremented in the loop "for (i = 0; i < to_copy; i++, ts--)". Do not increment it again.

  • CVE-2026-72098CriAug 15, 2026
    affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the p

  • CVE-2026-68426CriAug 10, 2026
    affected < 4.18.0-553.164.1.el8_10fixed 4.18.0-553.164.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it

  • CVE-2026-68388CriAug 10, 2026
    affected < 4.18.0-553.157.1.el8_10fixed 4.18.0-553.157.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h

  • CVE-2026-68376HigAug 10, 2026
    affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed

  • CVE-2026-68363Aug 10, 2026
    affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi

  • CVE-2026-68343CriAug 10, 2026
    affected < 4.18.0-553.160.1.el8_10fixed 4.18.0-553.160.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response

  • CVE-2026-68315HigAug 10, 2026
    affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w

Page 1 of 57