rpm package
almalinux/kernel-modules-extra-matched
pkg:rpm/almalinux/kernel-modules-extra-matched
Vulnerabilities (516)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-68307 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery, | ||
| CVE-2026-68299 | Hig | 7.5 | < 6.12.0-211.61.1.el10_2 | 6.12.0-211.61.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them | |
| CVE-2026-68294 | Hig | 8.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing | |
| CVE-2026-68293 | Hig | 7.1 | < 6.12.0-211.58.1.el10_2 | 6.12.0-211.58.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits | |
| CVE-2026-68273 | Hig | 7.8 | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init | |
| CVE-2026-68267 | — | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't | ||
| CVE-2026-68266 | Hig | 7.8 | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter's dma_buf->resv. The importer, however, only takes a dma-buf r | |
| CVE-2026-68264 | Hig | 7.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard( | |
| CVE-2026-68257 | Hig | 7.8 | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size m | |
| CVE-2026-68200 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the | |
| CVE-2026-68193 | — | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx | ||
| CVE-2026-68188 | — | < 6.12.0-211.58.1.el10_2 | 6.12.0-211.58.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia | ||
| CVE-2026-68166 | — | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... | ||
| CVE-2026-68159 | Cri | 9.8 | < 6.12.0-211.58.1.el10_2 | 6.12.0-211.58.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t | |
| CVE-2026-68155 | Hig | 7.5 | < 6.12.0-211.58.1.el10_2 | 6.12.0-211.58.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in | |
| CVE-2026-68145 | Hig | 7.8 | < 6.12.0-211.51.1.el10_2 | 6.12.0-211.51.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtra | |
| CVE-2026-68143 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold | |
| CVE-2026-68128 | Hig | 8.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from providing ptype | |
| CVE-2026-68121 | Hig | 7.8 | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid | |
| CVE-2026-68108 | Hig | 8.8 | < 6.12.0-211.60.1.el10_2 | 6.12.0-211.60.1.el10_2 | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calcu |
- CVE-2026-68307Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt7925_vif_connect_iter() replays firmware state for links tracked in mvif->valid_links. After MLO link changes or MCU timeout recovery,
- affected < 6.12.0-211.61.1.el10_2fixed 6.12.0-211.61.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a sing
- affected < 6.12.0-211.58.1.el10_2fixed 6.12.0-211.58.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits
- affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in the context pstate handling code. The most serious ones are potential use-after-free and NULL pointer dereferences at context init
- CVE-2026-68267Aug 10, 2026affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whitelisting OA registers is a security violation. Set RING_FORCE_TO_NONPRIV_DENY bit in OA nonpriv slots, so that OA registers don't
- affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter's dma_buf->resv. The importer, however, only takes a dma-buf r
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard(
- affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size m
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the
- CVE-2026-68193Aug 10, 2026affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7925_rx_check() and mt7925_queue_rx_skb() dispatch it to mt7925_mac_tx_free() on every bus. mt7925_mac_tx
- CVE-2026-68188Aug 10, 2026affected < 6.12.0-211.58.1.el10_2fixed 6.12.0-211.58.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initia
- CVE-2026-68166Aug 10, 2026affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ...
- affected < 6.12.0-211.58.1.el10_2fixed 6.12.0-211.58.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it t
- affected < 6.12.0-211.58.1.el10_2fixed 6.12.0-211.58.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in
- affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtra
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without hold
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from providing ptype
- affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalid
- affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calcu
Page 2 of 26