VYPR

rpm package

almalinux/kernel-rt-core

pkg:rpm/almalinux/kernel-rt-core

Vulnerabilities (1,515)

  • CVE-2026-97417HigSep 24, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte alignment that the TCP option stream does not

  • CVE-2026-90227HigSep 17, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() Unlike IO_CMD / IO64_CMD, NVME_IOCTL_SUBMIT_IO never calls nvme_cmd_allowed(). Unprivileged callers can thus issue I/O on a partition device or write through

  • CVE-2026-89972CriSep 16, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers

  • CVE-2026-89846CriSep 16, 2026
    affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense

  • CVE-2026-89775CriSep 16, 2026
    affected < 6.12.0-211.61.1.el10_2fixed 6.12.0-211.61.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, th

  • CVE-2026-89481HigSep 11, 2026
    affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a read command nvme_tcp_handle_r2t() does not check the direction of the request the R2T refers to. A malicious controller can send an R2T for a READ and the host

  • CVE-2026-89480HigSep 11, 2026
    affected < 4.18.0-553.168.1.rt7.509.el8_10fixed 4.18.0-553.168.1.rt7.509.el8_10

    In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the c

  • CVE-2026-81000HigSep 11, 2026
    affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10

    In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to T

  • CVE-2026-80921HigSep 9, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb.

  • CVE-2026-80844Sep 4, 2026
    affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10

    In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of

  • CVE-2026-80775Sep 4, 2026
    affected < 5.14.0-687.54.1.el9_8fixed 5.14.0-687.54.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: futex: Fix race on the initial mm->futex.phash.ref allocation futex_hash_allocate() allocates mm->futex.phash.ref without any locking. Commit d9b05321e21e ("futex: Move futex_hash_free() back to __mmput()") mov

  • CVE-2026-80714CriAug 28, 2026
    affected < 4.18.0-553.168.1.rt7.509.el8_10fixed 4.18.0-553.168.1.rt7.509.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the

  • CVE-2026-80522HigAug 26, 2026
    affected < 5.14.0-687.53.1.el9_8fixed 5.14.0-687.53.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may

  • CVE-2026-74753HigAug 26, 2026
    affected < 4.18.0-553.169.1.rt7.510.el8_10fixed 4.18.0-553.169.1.rt7.510.el8_10

    In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state and detaches their group relationships. The event's file descriptor can remain open, however

  • CVE-2026-74746CriAug 26, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while

  • CVE-2026-74744CriAug 26, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the under

  • CVE-2026-74669CriAug 22, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt stil

  • CVE-2026-74581CriAug 21, 2026
    affected < 5.14.0-687.42.1.el9_8fixed 5.14.0-687.42.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacemen

  • CVE-2026-74569CriAug 15, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() sip_help_tcp() stores the size change of each NAT-rewritten SIP message in s16 diff and accumulates it in s16 tdiff, but a single me

  • CVE-2026-74556CriAug 15, 2026
    affected < 4.18.0-553.163.1.rt7.504.el8_10fixed 4.18.0-553.163.1.rt7.504.el8_10

    In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for

Page 1 of 76