VYPR

rpm package

almalinux/kernel-64k-debug-modules-core

pkg:rpm/almalinux/kernel-64k-debug-modules-core

Vulnerabilities (1,125)

  • CVE-2026-68193Aug 10, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx

  • CVE-2026-68188Aug 10, 2026
    affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia

  • CVE-2026-68166Aug 10, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ...

  • CVE-2026-68159CriAug 10, 2026
    affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t

  • CVE-2026-68157HigAug 10, 2026
    affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then

  • CVE-2026-68156CriAug 10, 2026
    affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then

  • CVE-2026-68155HigAug 10, 2026
    affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in

  • CVE-2026-68145HigAug 10, 2026
    affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtra

  • CVE-2026-68143HigAug 10, 2026
    affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold

  • CVE-2026-68128HigAug 10, 2026
    affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from providing ptype

  • CVE-2026-68121HigAug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid

  • CVE-2026-68117CriAug 10, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves

  • CVE-2026-68108HigAug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calcu

  • CVE-2026-68086Aug 10, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream commit 044925f9b565 ("mm: fs: remove filemap_nr_thps*() functions and their users")

  • CVE-2026-68480Aug 6, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potential

  • CVE-2026-64597CriAug 6, 2026
    affected < 5.14.0-687.46.1.el9_8fixed 5.14.0-687.46.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the pr

  • CVE-2026-64582HigAug 5, 2026
    affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->p

  • CVE-2026-64564CriAug 4, 2026
    affected < 5.14.0-687.51.1.el9_8fixed 5.14.0-687.51.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(

  • CVE-2026-64563HigAug 4, 2026
    affected < 5.14.0-687.46.1.el9_8fixed 5.14.0-687.46.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter

  • CVE-2026-64560HigJul 29, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_time

Page 3 of 57