VYPR

rpm package

almalinux/kernel-rt-64k-debug-core

pkg:rpm/almalinux/kernel-rt-64k-debug-core

Vulnerabilities (698)

  • CVE-2026-63952HigJul 19, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_WRITE When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the implied seal is set after the check that makes sure the memfd can not have any writab

  • CVE-2026-63947HigJul 19, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: fix missing length checks in hidp_input_report() hidp_input_report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data. hidp_recv_int

  • CVE-2026-63946HigJul 19, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_recv_frame reads conn->sk under iso_conn_lock but releases the lock before using sk, with no reference held. A concurrent iso_sock_kill() can free sk in that window

  • CVE-2026-63945HigJul 19, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock iso_sock_close() calls iso_sock_clear_timer() before acquiring lock_sock(sk). iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the soc

  • CVE-2026-63944HigJul 19, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync hci_le_create_cis_sync() dereferences conn->conn_timeout after releasing both rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was obtained from a

  • CVE-2026-63923HigJul 19, 2026
    affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY r

  • CVE-2026-63921HigJul 19, 2026
    affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision l

  • CVE-2026-63919HigJul 19, 2026
    affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until t

  • CVE-2026-63917HigJul 19, 2026
    affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6

  • CVE-2026-63889HigJul 19, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in the ge

  • CVE-2026-63888CriJul 19, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target

  • CVE-2026-63887CriJul 19, 2026
    affected < 6.12.0-211.47.1.el10_2fixed 6.12.0-211.47.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer alloc

  • CVE-2026-63886CriJul 19, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses, passes chap_r directly t

  • CVE-2026-63884HigJul 19, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right pointer.

  • CVE-2026-63879HigJul 19, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. While at it also fix the coding style, e.g. drop the pre-initialized retur

  • CVE-2026-63869HigJul 19, 2026
    affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap When parsing the radiotap header of an injected frame, ieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value directl

  • CVE-2026-63824HigJul 19, 2026
    affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating in

  • CVE-2026-63808CriJul 19, 2026
    affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch r

  • CVE-2026-63801HigJul 19, 2026
    affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to crypto_aead_decrypt(req) without taking a reference on the netns, unlike the encrypt pa

  • CVE-2026-63800CriJul 19, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_put_layout_hdr(lo) is

Page 5 of 35