rpm package
almalinux/kernel-debug-uki-virt
pkg:rpm/almalinux/kernel-debug-uki-virt
Vulnerabilities (1,121)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-68402 | Hig | 7.1 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inh | |
| CVE-2026-68391 | Hig | 7.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs | |
| CVE-2026-68388 | Cri | 9.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h | |
| CVE-2026-68376 | Hig | 8.1 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed | |
| CVE-2026-68363 | — | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi | ||
| CVE-2026-68343 | Cri | 9.1 | < 5.14.0-687.41.1.el9_8 | 5.14.0-687.41.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response | |
| CVE-2026-68315 | Hig | 7.5 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w | |
| CVE-2026-68307 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery, | ||
| CVE-2026-68300 | Cri | 9.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk | |
| CVE-2026-68294 | Hig | 8.8 | < 5.14.0-687.48.1.el9_8 | 5.14.0-687.48.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing | |
| CVE-2026-68293 | Hig | 7.1 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits | |
| CVE-2026-68273 | Hig | 7.8 | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init | |
| CVE-2026-68267 | — | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't | ||
| CVE-2026-68266 | Hig | 7.8 | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter's dma_buf->resv. The importer, however, only takes a dma-buf r | |
| CVE-2026-68264 | Hig | 7.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard( | |
| CVE-2026-68257 | Hig | 7.8 | < 5.14.0-687.52.1.el9_8 | 5.14.0-687.52.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size m | |
| CVE-2026-68200 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the | |
| CVE-2026-68193 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx | ||
| CVE-2026-68188 | — | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia | ||
| CVE-2026-68166 | — | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... |
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inh
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Use of hci_conn in hci_sync callbacks also needs
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped h
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed
- CVE-2026-68363Aug 10, 2026affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completi
- affected < 5.14.0-687.41.1.el9_8fixed 5.14.0-687.41.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check w
- CVE-2026-68307Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery,
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. sk
- affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits
- affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init
- CVE-2026-68267Aug 10, 2026affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't
- affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter's dma_buf->resv. The importer, however, only takes a dma-buf r
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard(
- affected < 5.14.0-687.52.1.el9_8fixed 5.14.0-687.52.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size m
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the
- CVE-2026-68193Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx
- CVE-2026-68188Aug 10, 2026affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia
- CVE-2026-68166Aug 10, 2026affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ...
Page 2 of 57