rpm package
almalinux/kernel-rt-debug-modules
pkg:rpm/almalinux/kernel-rt-debug-modules
Vulnerabilities (1,482)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-89846 | Cri | 9.1 | < 4.18.0-553.167.1.rt7.508.el8_10 | 4.18.0-553.167.1.rt7.508.el8_10 | Sep 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense | |
| CVE-2026-89480 | Hig | 7.5 | < 4.18.0-553.168.1.rt7.509.el8_10 | 4.18.0-553.168.1.rt7.509.el8_10 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the c | |
| CVE-2026-81000 | Hig | 7.8 | < 4.18.0-553.167.1.rt7.508.el8_10 | 4.18.0-553.167.1.rt7.508.el8_10 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to T | |
| CVE-2026-80844 | — | < 4.18.0-553.167.1.rt7.508.el8_10 | 4.18.0-553.167.1.rt7.508.el8_10 | Sep 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of | ||
| CVE-2026-80714 | Cri | 9.8 | < 4.18.0-553.168.1.rt7.509.el8_10 | 4.18.0-553.168.1.rt7.509.el8_10 | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the | |
| CVE-2026-80522 | Hig | 7.8 | < 5.14.0-687.53.1.el9_8 | 5.14.0-687.53.1.el9_8 | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may | |
| CVE-2026-74753 | Hig | 7.8 | < 4.18.0-553.169.1.rt7.510.el8_10 | 4.18.0-553.169.1.rt7.510.el8_10 | Aug 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state and detaches their group relationships. The event's file descriptor can remain open, however | |
| CVE-2026-74581 | Cri | 9.8 | < 5.14.0-687.42.1.el9_8 | 5.14.0-687.42.1.el9_8 | Aug 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacemen | |
| CVE-2026-74556 | Cri | 9.8 | < 4.18.0-553.163.1.rt7.504.el8_10 | 4.18.0-553.163.1.rt7.504.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for | |
| CVE-2026-74518 | Hig | 7.8 | < 5.14.0-687.50.1.el9_8 | 5.14.0-687.50.1.el9_8 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption in allocate_file_region_entries() allocate_file_region_entries() tops up resv->region_cache with freshly allocated file_region descriptors. The allocation uses GFP_KERNEL, so re | |
| CVE-2026-74480 | Cri | 9.8 | < 4.18.0-553.160.1.rt7.501.el8_10 | 4.18.0-553.160.1.rt7.501.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advan | |
| CVE-2026-72329 | Cri | 9.3 | < 4.18.0-553.170.1.rt7.511.el8_10 | 4.18.0-553.170.1.rt7.511.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR-IOV enable path caches VF pci_dev pointers in dpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those entries do not own a reference, because the i | |
| CVE-2026-72298 | Hig | 8.4 | < 4.18.0-553.164.1.rt7.505.el8_10 | 4.18.0-553.164.1.rt7.505.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() qrtr_endpoint_post() validates an incoming packet with if (!size || len != ALIGN(size, 4) + hdrlen) goto err; where size comes from the wire. | |
| CVE-2026-72261 | Hig | 7.8 | < 4.18.0-553.167.1.rt7.508.el8_10 | 4.18.0-553.167.1.rt7.508.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocatio | |
| CVE-2026-72243 | Hig | 8.4 | < 5.14.0-687.49.1.el9_8 | 5.14.0-687.49.1.el9_8 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related permissions on TCP Fast Open Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TC | |
| CVE-2026-72130 | Cri | 9.8 | < 6.12.0-211.50.1.el10_2 | 6.12.0-211.50.1.el10_2 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length after checking only that it is nonzero and matches the transfer length. In the SUCCESS1 and F | |
| CVE-2026-72129 | Cri | 9.8 | < 4.18.0-553.160.1.rt7.501.el8_10 | 4.18.0-553.160.1.rt7.501.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off | |
| CVE-2026-72102 | Hig | 7.8 | < 6.12.0-211.56.1.el10_2 | 6.12.0-211.56.1.el10_2 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm_early_create: fix freeing used table on dm_resume failure If dm_resume fails, the kernel attempts to free table with dm_table_destroy, but the table was already instantiated with dm_swap_table. This commit s | |
| CVE-2026-72099 | Hig | 7.1 | < 4.18.0-553.170.1.rt7.511.el8_10 | 4.18.0-553.170.1.rt7.511.el8_10 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice hash_offset is already incremented in the loop "for (i = 0; i < to_copy; i++, ts--)". Do not increment it again. | |
| CVE-2026-72098 | Cri | 9.8 | < 6.12.0-211.53.1.el10_2 | 6.12.0-211.53.1.el10_2 | Aug 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the p |
- affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense
- affected < 4.18.0-553.168.1.rt7.509.el8_10fixed 4.18.0-553.168.1.rt7.509.el8_10
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the c
- affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to T
- CVE-2026-80844Sep 4, 2026affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10
In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of
- affected < 4.18.0-553.168.1.rt7.509.el8_10fixed 4.18.0-553.168.1.rt7.509.el8_10
In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the
- affected < 5.14.0-687.53.1.el9_8fixed 5.14.0-687.53.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may
- affected < 4.18.0-553.169.1.rt7.510.el8_10fixed 4.18.0-553.169.1.rt7.510.el8_10
In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state and detaches their group relationships. The event's file descriptor can remain open, however
- affected < 5.14.0-687.42.1.el9_8fixed 5.14.0-687.42.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacemen
- affected < 4.18.0-553.163.1.rt7.504.el8_10fixed 4.18.0-553.163.1.rt7.504.el8_10
In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for
- affected < 5.14.0-687.50.1.el9_8fixed 5.14.0-687.50.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption in allocate_file_region_entries() allocate_file_region_entries() tops up resv->region_cache with freshly allocated file_region descriptors. The allocation uses GFP_KERNEL, so re
- affected < 4.18.0-553.160.1.rt7.501.el8_10fixed 4.18.0-553.160.1.rt7.501.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advan
- affected < 4.18.0-553.170.1.rt7.511.el8_10fixed 4.18.0-553.170.1.rt7.511.el8_10
In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR-IOV enable path caches VF pci_dev pointers in dpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those entries do not own a reference, because the i
- affected < 4.18.0-553.164.1.rt7.505.el8_10fixed 4.18.0-553.164.1.rt7.505.el8_10
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() qrtr_endpoint_post() validates an incoming packet with if (!size || len != ALIGN(size, 4) + hdrlen) goto err; where size comes from the wire.
- affected < 4.18.0-553.167.1.rt7.508.el8_10fixed 4.18.0-553.167.1.rt7.508.el8_10
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocatio
- affected < 5.14.0-687.49.1.el9_8fixed 5.14.0-687.49.1.el9_8
In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related permissions on TCP Fast Open Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TC
- affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length after checking only that it is nonzero and matches the transfer length. In the SUCCESS1 and F
- affected < 4.18.0-553.160.1.rt7.501.el8_10fixed 4.18.0-553.160.1.rt7.501.el8_10
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off
- affected < 6.12.0-211.56.1.el10_2fixed 6.12.0-211.56.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: dm_early_create: fix freeing used table on dm_resume failure If dm_resume fails, the kernel attempts to free table with dm_table_destroy, but the table was already instantiated with dm_swap_table. This commit s
- affected < 4.18.0-553.170.1.rt7.511.el8_10fixed 4.18.0-553.170.1.rt7.511.el8_10
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice hash_offset is already incremented in the loop "for (i = 0; i < to_copy; i++, ts--)". Do not increment it again.
- affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the p
Page 1 of 75