VYPR

rpm package

almalinux/kernel-cross-headers

pkg:rpm/almalinux/kernel-cross-headers

Vulnerabilities (1,561)

  • CVE-2026-72003HigAug 15, 2026
    affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted:

  • CVE-2026-68426CriAug 10, 2026
    affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it

  • CVE-2026-68409HigAug 10, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU: sta_info_free_link(&alloc->inf

  • CVE-2026-68406Aug 10, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range. Reject out-of-range values before using them in the parser capab

  • CVE-2026-68402HigAug 10, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inh

  • CVE-2026-68391HigAug 10, 2026
    affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs

  • CVE-2026-68388CriAug 10, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h

  • CVE-2026-68376HigAug 10, 2026
    affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed

  • CVE-2026-68363Aug 10, 2026
    affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi

  • CVE-2026-68343CriAug 10, 2026
    affected < 5.14.0-687.41.1.el9_8fixed 5.14.0-687.41.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response

  • CVE-2026-68315HigAug 10, 2026
    affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w

  • CVE-2026-68307Aug 10, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery,

  • CVE-2026-68300CriAug 10, 2026
    affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk

  • CVE-2026-68294HigAug 10, 2026
    affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing

  • CVE-2026-68293HigAug 10, 2026
    affected < 4.18.0-553.166.1.el8_10fixed 4.18.0-553.166.1.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits

  • CVE-2026-68273HigAug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init

  • CVE-2026-68267Aug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't

  • CVE-2026-68266HigAug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter's dma_buf->resv. The importer, however, only takes a dma-buf r

  • CVE-2026-68264HigAug 10, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard(

  • CVE-2026-68257HigAug 10, 2026
    affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size m

Page 2 of 79