rpm package
almalinux/bpftool
pkg:rpm/almalinux/bpftool
Vulnerabilities (1,122)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-68300 | Cri | 9.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk | |
| CVE-2026-68299 | Hig | 7.5 | < 4.18.0-553.170.1.el8_10 | 4.18.0-553.170.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them | |
| CVE-2026-68293 | Hig | 7.1 | < 4.18.0-553.166.1.el8_10 | 4.18.0-553.166.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits | |
| CVE-2026-68273 | Hig | 7.8 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init | |
| CVE-2026-68188 | — | < 4.18.0-553.166.1.el8_10 | 4.18.0-553.166.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia | ||
| CVE-2026-68159 | Cri | 9.8 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t | |
| CVE-2026-68156 | Cri | 9.8 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then | |
| CVE-2026-68155 | Hig | 7.5 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in | |
| CVE-2026-68143 | Hig | 7.8 | < 4.18.0-553.164.1.el8_10 | 4.18.0-553.164.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold | |
| CVE-2026-68121 | Hig | 7.8 | < 4.18.0-553.168.1.el8_10 | 4.18.0-553.168.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid | |
| CVE-2026-68117 | Cri | 9.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves | |
| CVE-2026-68480 | — | < 4.18.0-553.159.1.el8_10 | 4.18.0-553.159.1.el8_10 | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potential | ||
| CVE-2026-64582 | Hig | 7.8 | < 4.18.0-553.166.1.el8_10 | 4.18.0-553.166.1.el8_10 | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->p | |
| CVE-2026-64564 | Cri | 9.8 | < 4.18.0-553.167.1.el8_10 | 4.18.0-553.167.1.el8_10 | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv( | |
| CVE-2026-64563 | Hig | 7.8 | < 4.18.0-553.160.1.el8_10 | 4.18.0-553.160.1.el8_10 | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter | |
| CVE-2026-64556 | Hig | 7.8 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Jul 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT | |
| CVE-2026-17523 | Hig | 7.8 | < 4.18.0-553.156.1.el8_10 | 4.18.0-553.156.1.el8_10 | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq context and removes the hrtimer_tasklet. | |
| CVE-2026-64534 | Cri | 9.8 | < 4.18.0-553.166.1.el8_10 | 4.18.0-553.166.1.el8_10 | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the co | |
| CVE-2026-64530 | Cri | 9.8 | < 4.18.0-553.150.1.el8_10 | 4.18.0-553.150.1.el8_10 | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that h | |
| CVE-2026-64496 | Hig | 7.1 | < 4.18.0-553.154.1.el8_10 | 4.18.0-553.154.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_event_getfd()` creates the event file descriptor with `anon_inode_getfd()`, which allocates a new fd, creates the anonymous file and installs it in the process fd tabl |
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk
- affected < 4.18.0-553.170.1.el8_10fixed 4.18.0-553.170.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them
- affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init
- CVE-2026-68188Aug 10, 2026affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in
- affected < 4.18.0-553.164.1.el8_10fixed 4.18.0-553.164.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold
- affected < 4.18.0-553.168.1.el8_10fixed 4.18.0-553.168.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves
- CVE-2026-68480Aug 6, 2026affected < 4.18.0-553.159.1.el8_10fixed 4.18.0-553.159.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potential
- affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->p
- affected < 4.18.0-553.167.1.el8_10fixed 4.18.0-553.167.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(
- affected < 4.18.0-553.160.1.el8_10fixed 4.18.0-553.160.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT
- affected < 4.18.0-553.156.1.el8_10fixed 4.18.0-553.156.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq context and removes the hrtimer_tasklet.
- affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the co
- affected < 4.18.0-553.150.1.el8_10fixed 4.18.0-553.150.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that h
- affected < 4.18.0-553.154.1.el8_10fixed 4.18.0-553.154.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_event_getfd()` creates the event file descriptor with `anon_inode_getfd()`, which allocates a new fd, creates the anonymous file and installs it in the process fd tabl
Page 2 of 57