rpm package
almalinux/kernel-debug-uki-virt
pkg:rpm/almalinux/kernel-debug-uki-virt
Vulnerabilities (1,096)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-63921 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision l | |
| CVE-2026-63919 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until t | |
| CVE-2026-63917 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6 | |
| CVE-2026-63913 | Hig | 8.2 | < 5.14.0-687.49.1.el9_8 | 5.14.0-687.49.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an | |
| CVE-2026-63889 | Hig | 8.1 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in the ge | |
| CVE-2026-63888 | Cri | 9.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target | |
| CVE-2026-63887 | Cri | 9.8 | < 6.12.0-211.47.1.el10_2 | 6.12.0-211.47.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer alloc | |
| CVE-2026-63886 | Cri | 9.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses, passes chap_r directly t | |
| CVE-2026-63884 | Hig | 7.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right pointer. | |
| CVE-2026-63879 | Hig | 7.8 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. While at it also fix the coding style, e.g. drop the pre-initialized retur | |
| CVE-2026-63869 | Hig | 7.6 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap When parsing the radiotap header of an injected frame, ieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value directl | |
| CVE-2026-63824 | Hig | 7.8 | < 6.12.0-211.51.1.el10_2 | 6.12.0-211.51.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating in | |
| CVE-2026-63823 | Hig | 7.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper | |
| CVE-2026-63808 | Cri | 9.8 | < 6.12.0-211.51.1.el10_2 | 6.12.0-211.51.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch r | |
| CVE-2026-63801 | Hig | 8.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to crypto_aead_decrypt(req) without taking a reference on the netns, unlike the encrypt pa | |
| CVE-2026-63800 | Cri | 9.8 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is | |
| CVE-2026-53399 | Cri | 9.8 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_stateid(). When nfsd4_layo | |
| CVE-2026-53397 | Hig | 7.5 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each call nfs_stream_decode_acl() twice, first for NFS_ACL and then for NFS_DFACL. Each successfu | |
| CVE-2026-53392 | Hig | 7.5 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. The value is used as the count for kzalloc_objs(), and the | |
| CVE-2026-53391 | Hig | 7.5 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then immediately calls strrc |
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision l
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until t
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6
- affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in the ge
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target
- affected < 6.12.0-211.47.1.el10_2fixed 6.12.0-211.47.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer alloc
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses, passes chap_r directly t
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right pointer.
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. While at it also fix the coding style, e.g. drop the pre-initialized retur
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap When parsing the radiotap header of an injected frame, ieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value directl
- affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating in
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper
- affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch r
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to crypto_aead_decrypt(req) without taking a reference on the netns, unlike the encrypt pa
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_stateid(). When nfsd4_layo
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each call nfs_stream_decode_acl() twice, first for NFS_ACL and then for NFS_DFACL. Each successfu
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. The value is used as the count for kzalloc_objs(), and the
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then immediately calls strrc
Page 6 of 55