VYPR

rpm package

almalinux/kernel-rt

pkg:rpm/almalinux/kernel-rt

Vulnerabilities (1,515)

  • CVE-2026-53143HigJun 25, 2026
    affected < 6.12.0-211.49.1.el10_2fixed 6.12.0-211.49.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These funct

  • CVE-2026-53136HigJun 25, 2026
    affected < 4.18.0-553.156.1.rt7.497.el8_10fixed 4.18.0-553.156.1.rt7.497.el8_10

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when

  • CVE-2026-53131CriJun 25, 2026
    affected < 5.14.0-687.42.1.el9_8fixed 5.14.0-687.42.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)` after either assum

  • CVE-2026-53091HigJun 24, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() do

  • CVE-2026-53075HigJun 24, 2026
    affected < 4.18.0-553.164.1.rt7.505.el8_10fixed 4.18.0-553.164.1.rt7.505.el8_10

    In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_ns, while unattached administrative ioctls operate on current->nsproxy->net_ns.

  • CVE-2026-53073MedJun 24, 2026
    affected < 6.12.0-211.51.1.el10_2fixed 6.12.0-211.51.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to N

  • CVE-2026-53072HigJun 24, 2026
    affected < 6.12.0-211.53.1.el10_2fixed 6.12.0-211.53.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assum

  • CVE-2026-53071HigJun 24, 2026
    affected < 4.18.0-553.146.1.rt7.487.el8_10fixed 4.18.0-553.146.1.rt7.487.el8_10

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the

  • CVE-2026-53062HigJun 24, 2026
    affected < 4.18.0-553.166.1.rt7.507.el8_10fixed 4.18.0-553.166.1.rt7.507.el8_10

    In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: fix missing locks in invalidating cache blocks In passthrough mode, the policy invalidate_mapping operation is called simultaneously from multiple workers, thus it should be protected by a

  • CVE-2026-53059HigJun 24, 2026
    affected < 6.12.0-211.39.1.el10_2fixed 6.12.0-211.39.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit). When

  • CVE-2026-53053HigJun 24, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the original device's devid Currently clone_alias() assumes first argument (pdev) is always the original device pointer. This function is called by pci_for_each_dma_alias() w

  • CVE-2026-53049CriJun 24, 2026
    affected < 4.18.0-553.171.1.rt7.512.el8_10fixed 4.18.0-553.171.1.rt7.512.el8_10

    In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions re

  • CVE-2026-53026HigJun 24, 2026
    affected < 6.12.0-211.50.1.el10_2fixed 6.12.0-211.50.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg In nfsd4_add_rdaccess_to_wrdeleg, if fp->fi_fds[O_RDONLY] is already set by another thread, __nfs4_file_get_access should not be called to

  • CVE-2026-53016HigJun 24, 2026
    affected < 5.14.0-687.25.1.el9_8fixed 5.14.0-687.25.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skcip

  • CVE-2026-53009HigJun 24, 2026
    affected < 6.12.0-211.37.1.el10_2fixed 6.12.0-211.37.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). '

  • CVE-2026-53006CriJun 24, 2026
    affected < 5.14.0-687.30.1.el9_8fixed 5.14.0-687.30.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_

  • CVE-2026-53005HigJun 24, 2026
    affected < 6.12.0-211.60.1.el10_2fixed 6.12.0-211.60.1.el10_2

    In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop all SCM attributes for SOCKMAP. SOCKMAP can hide inflight fd from AF_UNIX GC. When a socket in SOCKMAP receives skb with inflight fd, sk_psock_verdict_data_ready() looks up the mapped socket and

  • CVE-2026-53002CriJun 24, 2026
    affected < 4.18.0-553.160.1.rt7.501.el8_10fixed 4.18.0-553.160.1.rt7.501.el8_10

    In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_co

  • CVE-2026-53000HigJun 24, 2026
    affected < 5.14.0-687.45.1.el9_8fixed 5.14.0-687.45.1.el9_8

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register

  • CVE-2026-52993CriJun 24, 2026
    affected < 4.18.0-553.147.1.rt7.488.el8_10fixed 4.18.0-553.147.1.rt7.488.el8_10

    In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local vari

Page 11 of 76