rpm package
almalinux/kernel-64k-debug-core
pkg:rpm/almalinux/kernel-64k-debug-core
Vulnerabilities (1,134)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-68201 | Hig | 7.8 | < 5.14.0-687.51.1.el9_8 | 5.14.0-687.51.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: drain a slave's callback before its master detaches it snd_timer_close_locked() drains the closing instance's own in-flight callback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a m | |
| CVE-2026-68200 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the | |
| CVE-2026-68193 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx | ||
| CVE-2026-68188 | — | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia | ||
| CVE-2026-68166 | — | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... | ||
| CVE-2026-68159 | Cri | 9.8 | < 5.14.0-687.49.1.el9_8 | 5.14.0-687.49.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t | |
| CVE-2026-68157 | Hig | 7.5 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then | |
| CVE-2026-68156 | Cri | 9.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then | |
| CVE-2026-68155 | Hig | 7.5 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in | |
| CVE-2026-68145 | Hig | 7.8 | < 6.12.0-211.51.1.el10_2 | 6.12.0-211.51.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtra | |
| CVE-2026-68143 | Hig | 7.8 | < 5.14.0-687.48.1.el9_8 | 5.14.0-687.48.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold | |
| CVE-2026-68128 | Hig | 8.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from providing ptype | |
| CVE-2026-68121 | Hig | 7.8 | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid | |
| CVE-2026-68117 | Cri | 9.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves | |
| CVE-2026-68108 | Hig | 8.8 | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calcu | |
| CVE-2026-68086 | — | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream commit 044925f9b565 ("mm: fs: remove filemap_nr_thps*() functions and their users") | ||
| CVE-2026-68480 | — | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potential | ||
| CVE-2026-64597 | Cri | 9.8 | < 5.14.0-687.46.1.el9_8 | 5.14.0-687.46.1.el9_8 | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the pr | |
| CVE-2026-64582 | Hig | 7.8 | < 5.14.0-687.49.1.el9_8 | 5.14.0-687.49.1.el9_8 | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->p | |
| CVE-2026-64564 | Cri | 9.8 | < 5.14.0-687.51.1.el9_8 | 5.14.0-687.51.1.el9_8 | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv( |
- affected < 5.14.0-687.51.1.el9_8fixed 5.14.0-687.51.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: drain a slave's callback before its master detaches it snd_timer_close_locked() drains the closing instance's own in-flight callback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a m
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the
- CVE-2026-68193Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx
- CVE-2026-68188Aug 10, 2026affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia
- CVE-2026-68166Aug 10, 2026affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ...
- affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in
- affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtra
- affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from providing ptype
- affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves
- affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calcu
- CVE-2026-68086Aug 10, 2026affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream commit 044925f9b565 ("mm: fs: remove filemap_nr_thps*() functions and their users")
- CVE-2026-68480Aug 6, 2026affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potential
- affected < 5.14.0-687.46.1.el9_8fixed 5.14.0-687.46.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the pr
- affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->p
- affected < 5.14.0-687.51.1.el9_8fixed 5.14.0-687.51.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(
Page 3 of 57