rpm package
almalinux/kernel-debug-core
pkg:rpm/almalinux/kernel-debug-core
Vulnerabilities (1,583)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-72099 | Hig | 7.1 | < 4.18.0-553.170.1.el8_10 | 4.18.0-553.170.1.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice hash_offset is already incremented in the loop "for (i = 0; i < to_copy; i++, ts--)". Do not increment it again. | |
| CVE-2026-72098 | Cri | 9.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the p | |
| CVE-2026-72072 | Hig | 7.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete When an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed the per-SC metadata_dst with metadata_dst_free(), which kfree()s the | |
| CVE-2026-72069 | Cri | 9.8 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock() releases the RCU protection before unlocking the lock. That opens the door for the following UAF scenario: T1 T2 spin_loc | |
| CVE-2026-72045 | Hig | 8.8 | < 5.14.0-687.48.1.el9_8 | 5.14.0-687.48.1.el9_8 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function's LMTLINE physical base | |
| CVE-2026-72003 | Hig | 8.8 | < 5.14.0-687.49.1.el9_8 | 5.14.0-687.49.1.el9_8 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: | |
| CVE-2026-68426 | Cri | 9.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it | |
| CVE-2026-68409 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU: sta_info_free_link(&alloc->inf | |
| CVE-2026-68406 | — | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range. Reject out-of-range values before using them in the parser capab | ||
| CVE-2026-68402 | Hig | 7.1 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inh | |
| CVE-2026-68391 | Hig | 7.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs | |
| CVE-2026-68388 | Cri | 9.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h | |
| CVE-2026-68376 | Hig | 8.1 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed | |
| CVE-2026-68363 | — | < 4.18.0-553.163.1.el8_10 | 4.18.0-553.163.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi | ||
| CVE-2026-68343 | Cri | 9.1 | < 5.14.0-687.41.1.el9_8 | 5.14.0-687.41.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response | |
| CVE-2026-68315 | Hig | 7.5 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w | |
| CVE-2026-68307 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery, | ||
| CVE-2026-68300 | Cri | 9.8 | < 4.18.0-553.162.1.el8_10 | 4.18.0-553.162.1.el8_10 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk | |
| CVE-2026-68299 | Hig | 7.5 | < 6.12.0-211.61.1.el10_2 | 6.12.0-211.61.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them | |
| CVE-2026-68294 | Hig | 8.8 | < 5.14.0-687.48.1.el9_8 | 5.14.0-687.48.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing |
- affected < 4.18.0-553.170.1.el8_10fixed 4.18.0-553.170.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice hash_offset is already incremented in the loop "for (i = 0; i < to_copy; i++, ts--)". Do not increment it again.
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the p
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete When an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed the per-SC metadata_dst with metadata_dst_free(), which kfree()s the
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock() releases the RCU protection before unlocking the lock. That opens the door for the following UAF scenario: T1 T2 spin_loc
- affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function's LMTLINE physical base
- affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted:
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU: sta_info_free_link(&alloc->inf
- CVE-2026-68406Aug 10, 2026affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range. Reject out-of-range values before using them in the parser capab
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inh
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed
- CVE-2026-68363Aug 10, 2026affected < 4.18.0-553.163.1.el8_10fixed 4.18.0-553.163.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi
- affected < 5.14.0-687.41.1.el9_8fixed 5.14.0-687.41.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w
- CVE-2026-68307Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery,
- affected < 4.18.0-553.162.1.el8_10fixed 4.18.0-553.162.1.el8_10
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk
- affected < 6.12.0-211.61.1.el10_2fixed 6.12.0-211.61.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them
- affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing
Page 2 of 80