rpm package
almalinux/bpftool
pkg:rpm/almalinux/bpftool
Vulnerabilities (1,122)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-64379 | Hig | 7.1 | < 4.18.0-553.157.1.el8_10 | 4.18.0-553.157.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in modefromsid When modefromsid is active, parse_dacl() applies the server-provided sub_auth[2] value from the NFS mode SID to cf_mode without masking to 07777. A | |
| CVE-2026-64320 | Cri | 9.1 | < 4.18.0-553.158.1.el8_10 | 4.18.0-553.158.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then | |
| CVE-2026-64298 | Hig | 7.1 | < 4.18.0-553.159.1.el8_10 | 4.18.0-553.159.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC POSIX requires write permission to truncate a file, so an open() that specifies O_TRUNC must be authorized for write access regardless of the O_ACCMO | |
| CVE-2026-64277 | Hig | 7.8 | < 4.18.0-553.158.1.el8_10 | 4.18.0-553.158.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127). rmi_f3a_map_gp | |
| CVE-2026-64276 | Hig | 7.8 | < 4.18.0-553.158.1.el8_10 | 4.18.0-553.158.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() itera | |
| CVE-2026-64268 | Cri | 9.8 | < 4.18.0-553.159.1.el8_10 | 4.18.0-553.159.1.el8_10 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accum | |
| CVE-2026-64219 | Hig | 7.0 | < 4.18.0-553.156.1.el8_10 | 4.18.0-553.156.1.el8_10 | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[ | |
| CVE-2026-64191 | Hig | 7.8 | < 4.18.0-553.158.1.el8_10 | 4.18.0-553.158.1.el8_10 | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] as the transfer length. The existing check only clamps it to avoid overrunning the | |
| CVE-2026-64189 | Hig | 7.8 | < 4.18.0-553.158.1.el8_10 | 4.18.0-553.158.1.el8_10 | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path of ip_set_dump_do() and ip_set_dump_done() read inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw() of the a | |
| CVE-2026-64117 | Hig | 8.8 | < 4.18.0-553.163.1.el8_10 | 4.18.0-553.163.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb ieee80211_invoke_fast_rx() reads RX status through IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage that ieee80211_rx_mesh_data() r | |
| CVE-2026-64113 | Cri | 9.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to t | |
| CVE-2026-64102 | Cri | 9.8 | < 4.18.0-553.170.1.el8_10 | 4.18.0-553.170.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer can send an iWARP FPDU whose MPA length field (c_hdr->mpa_len, 16 bit big-endian, peer-controlled) is smaller | |
| CVE-2026-64048 | Hig | 7.5 | < 4.18.0-553.157.1.el8_10 | 4.18.0-553.157.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entri | |
| CVE-2026-64034 | Cri | 9.3 | < 4.18.0-553.169.1.el8_10 | 4.18.0-553.169.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-rea | |
| CVE-2026-64018 | Cri | 9.3 | < 4.18.0-553.159.1.el8_10 | 4.18.0-553.159.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memor | |
| CVE-2026-64015 | Hig | 7.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() | |
| CVE-2026-64007 | Cri | 9.8 | < 4.18.0-553.160.1.el8_10 | 4.18.0-553.160.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-s | |
| CVE-2026-64002 | Hig | 7.8 | < 4.18.0-553.164.1.el8_10 | 4.18.0-553.164.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl | |
| CVE-2026-63975 | Hig | 8.8 | < 4.18.0-553.166.1.el8_10 | 4.18.0-553.166.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2cap_chan_del may inva | |
| CVE-2026-63971 | Hig | 7.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another t |
- affected < 4.18.0-553.157.1.el8_10fixed 4.18.0-553.157.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in modefromsid When modefromsid is active, parse_dacl() applies the server-provided sub_auth[2] value from the NFS mode SID to cf_mode without masking to 07777. A
- affected < 4.18.0-553.158.1.el8_10fixed 4.18.0-553.158.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then
- affected < 4.18.0-553.159.1.el8_10fixed 4.18.0-553.159.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC POSIX requires write permission to truncate a file, so an open() that specifies O_TRUNC must be authorized for write access regardless of the O_ACCMO
- affected < 4.18.0-553.158.1.el8_10fixed 4.18.0-553.158.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127). rmi_f3a_map_gp
- affected < 4.18.0-553.158.1.el8_10fixed 4.18.0-553.158.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() itera
- affected < 4.18.0-553.159.1.el8_10fixed 4.18.0-553.159.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accum
- affected < 4.18.0-553.156.1.el8_10fixed 4.18.0-553.156.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[
- affected < 4.18.0-553.158.1.el8_10fixed 4.18.0-553.158.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] as the transfer length. The existing check only clamps it to avoid overrunning the
- affected < 4.18.0-553.158.1.el8_10fixed 4.18.0-553.158.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path of ip_set_dump_do() and ip_set_dump_done() read inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw() of the a
- affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb ieee80211_invoke_fast_rx() reads RX status through IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage that ieee80211_rx_mesh_data() r
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to t
- affected < 4.18.0-553.170.1.el8_10fixed 4.18.0-553.170.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer can send an iWARP FPDU whose MPA length field (c_hdr->mpa_len, 16 bit big-endian, peer-controlled) is smaller
- affected < 4.18.0-553.157.1.el8_10fixed 4.18.0-553.157.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entri
- affected < 4.18.0-553.169.1.el8_10fixed 4.18.0-553.169.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-rea
- affected < 4.18.0-553.159.1.el8_10fixed 4.18.0-553.159.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memor
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc()
- affected < 4.18.0-553.160.1.el8_10fixed 4.18.0-553.160.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-s
- affected < 4.18.0-553.164.1.el8_10fixed 4.18.0-553.164.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl
- affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2cap_chan_del may inva
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another t
Page 3 of 57