rpm package
almalinux/kernel-rt-64k-debug-devel
pkg:rpm/almalinux/kernel-rt-64k-debug-devel
Vulnerabilities (755)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-64042 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. | |
| CVE-2026-64037 | Cri | 9.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled When the TLC notification disables AMSDU for a TID, the MLD driver sets max_tid_amsdu_len to the sentinel value 1. The TSO segmentation | |
| CVE-2026-64034 | Cri | 9.3 | < 5.14.0-687.46.1.el9_8 | 5.14.0-687.46.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-rea | |
| CVE-2026-64029 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Serialize UMP output teardown with event_input seq_ump_process_event() borrows client->out_rfile.output without synchronizing with the first-open and last-close transition in seq_ump_client_open() an | |
| CVE-2026-64018 | Cri | 9.3 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memor | |
| CVE-2026-64017 | Hig | 7.8 | < 5.14.0-687.31.1.el9_8 | 5.14.0-687.31.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freei | |
| CVE-2026-64015 | Hig | 7.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() | |
| CVE-2026-64007 | Cri | 9.8 | < 5.14.0-687.41.1.el9_8 | 5.14.0-687.41.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-s | |
| CVE-2026-64002 | Hig | 7.8 | < 5.14.0-687.44.1.el9_8 | 5.14.0-687.44.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl | |
| CVE-2026-63975 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2cap_chan_del may inva | |
| CVE-2026-63971 | Hig | 7.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another t | |
| CVE-2026-63952 | Hig | 8.4 | < 6.12.0-211.49.1.el10_2 | 6.12.0-211.49.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_WRITE When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the implied seal is set after the check that makes sure the memfd can not have any writab | |
| CVE-2026-63947 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: fix missing length checks in hidp_input_report() hidp_input_report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data. hidp_recv_int | |
| CVE-2026-63946 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_recv_frame reads conn->sk under iso_conn_lock but releases the lock before using sk, with no reference held. A concurrent iso_sock_kill() can free sk in that window | |
| CVE-2026-63945 | Hig | 7.8 | < 5.14.0-687.47.1.el9_8 | 5.14.0-687.47.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock iso_sock_close() calls iso_sock_clear_timer() before acquiring lock_sock(sk). iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the soc | |
| CVE-2026-63944 | Hig | 8.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync hci_le_create_cis_sync() dereferences conn->conn_timeout after releasing both rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was obtained from a | |
| CVE-2026-63923 | Hig | 8.8 | < 5.14.0-687.48.1.el9_8 | 5.14.0-687.48.1.el9_8 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY r | |
| CVE-2026-63921 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision l | |
| CVE-2026-63919 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until t | |
| CVE-2026-63917 | Hig | 8.8 | < 6.12.0-211.55.1.el10_2 | 6.12.0-211.55.1.el10_2 | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6 |
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting.
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled When the TLC notification disables AMSDU for a TID, the MLD driver sets max_tid_amsdu_len to the sentinel value 1. The TSO segmentation
- affected < 5.14.0-687.46.1.el9_8fixed 5.14.0-687.46.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-rea
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Serialize UMP output teardown with event_input seq_ump_process_event() borrows client->out_rfile.output without synchronizing with the first-open and last-close transition in seq_ump_client_open() an
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memor
- affected < 5.14.0-687.31.1.el9_8fixed 5.14.0-687.31.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freei
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc()
- affected < 5.14.0-687.41.1.el9_8fixed 5.14.0-687.41.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-s
- affected < 5.14.0-687.44.1.el9_8fixed 5.14.0-687.44.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2cap_chan_del may inva
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another t
- affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_WRITE When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the implied seal is set after the check that makes sure the memfd can not have any writab
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: fix missing length checks in hidp_input_report() hidp_input_report() reads keyboard and mouse payload data from an skb without first verifying that skb->len contains enough data. hidp_recv_int
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_recv_frame reads conn->sk under iso_conn_lock but releases the lock before using sk, with no reference held. A concurrent iso_sock_kill() can free sk in that window
- affected < 5.14.0-687.47.1.el9_8fixed 5.14.0-687.47.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock iso_sock_close() calls iso_sock_clear_timer() before acquiring lock_sock(sk). iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the soc
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync hci_le_create_cis_sync() dereferences conn->conn_timeout after releasing both rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was obtained from a
- affected < 5.14.0-687.48.1.el9_8fixed 5.14.0-687.48.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/ octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY r
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision l
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until t
- affected < 6.12.0-211.55.1.el10_2fixed 6.12.0-211.55.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6
Page 6 of 38