[CLSA-2026:1787307395] kernel: Fix of 83 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-21 19:33:28 UTC
Description:
- net/sched: serialize qdisc_rtab_list against concurrent get/put {CVE-2026-68138} - static_call: Replace pointless WARN_ON() in static_call_module_notify() {CVE-2024-49954} - static_call: Handle module init failure correctly in static_call_del_module() {CVE-2024-50002} - smb: client: require a full NFS mode SID before reading mode bits {CVE-2026-43350} - octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() {CVE-2025-39978} - scsi: core: Fix refcount leak for tagset_refcnt {CVE-2026-23296} - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() {CVE-2026-23336} - smb: client: fix memory leak in cifs_construct_tcon() {CVE-2025-68295} - sched/deadline: Fix warning in migrate_enable for boosted tasks {CVE-2024-56583} - nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() {CVE-2025-40261} - usbnet: Prevents free active kevent {CVE-2025-68312} - libceph: bound get_version reply decode to front len {CVE-2026-68433} - neigh: let neigh_xmit take skb ownership {CVE-2026-52981} - gve: prevent ethtool ops after shutdown {CVE-2025-38735} - vfs: Don't leak disconnected dentries on umount {CVE-2025-40105} - NFSD: NFSv4 file creation neglects setting ACL {CVE-2025-68803} - thermal: intel: int340x: processor: Fix warning during module unload {CVE-2024-50093} - quota: fix warning in dqgrab() {CVE-2023-54177} - mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0] {CVE-2026-31458} - net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change {CVE-2025-71066} - bpf, skmsg: Fix NULL pointer dereference in sk_psock_skb_ingress_enqueue {CVE-2024-36938} - net: hv_netvsc: reject RSS hash key programming without RX indirection table {CVE-2026-23054} - xsk: tighten UMEM headroom validation to account for tailroom and min frame {CVE-2026-43093} - drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) {CVE-2024-39497} - bpf: Fix OOB in pcpu_init_value {CVE-2026-53076} - ftrace: Clean up hash direct_functions on register failures {CVE-2022-49402} - binfmt_misc: restore write access before closing files opened by open_exec() {CVE-2025-68239} - smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path {CVE-2025-39929} - wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() {CVE-2026-53102} - xen: Add support for XenServer 6.1 platform device {CVE-2025-38046} - i2c: tegra: Do not mark ACPI devices as irq safe {CVE-2024-45029} - bpf: Add preempt_count_{sub,add} into btf id deny list {CVE-2023-54086} - libceph: Fix multiplication overflow in decode_new_up_state_weight() {CVE-2026-68158} - mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose() {CVE-2025-68291} - net/mlx5: Fix missing lock on sync reset reload {CVE-2024-42268} - vxlan: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-68432} - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels {CVE-2026-23274} - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async {CVE-2026-64219} - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations {CVE-2026-31394} - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path {CVE-2026-53096} - scsi: mpi3mr: Fix possible crash when setting up bsg fails {CVE-2025-21723} - net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup {CVE-2025-68192} - net: stream: purge sk_error_queue in sk_stream_kill_queues() {CVE-2022-50838} - clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context {CVE-2025-21767} - net: netpoll: fix incorrect refcount handling causing incorrect cleanup {CVE-2025-68245} - drm/amd/display: Check link_res->hpo_dp_link_enc before using it {CVE-2024-47704} - crypto: qat - flush misc workqueue during device shutdown {CVE-2025-39721} - crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed {CVE-2026-31698} - smb: client: split cached_fid bitfields to avoid shared-byte RMW races {CVE-2026-23230} - net/smc: initialize close_work early to avoid warning {CVE-2024-56641} - netfilter: nft_ct: add seqadj extension for natted connections {CVE-2025-68206} - net/sched: sch_netem: fix out-of-bounds access in packet corruption {CVE-2026-31675} - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() {CVE-2026-31426} - bpf: Reject sleepable kprobe_multi programs at attach time {CVE-2026-43010} - ASoC: soc-core: flush delayed work before removing DAIs and widgets {CVE-2026-43459} - mm: hugetlb: avoid soft lockup when mprotect to large memory area {CVE-2025-40153} - mptcp: pm: ADD_ADDR rtx: fix potential data-race {CVE-2026-46137} - Input: uinput - take event lock when submitting FF request "event" - smb3: fix lock ordering potential deadlock in cifs_sync_mid_result {CVE-2024-35998} - drm/i915/gem: Add missing nospec on parallel submit slot {CVE-2026-68269} - netfilter: ebtables: fix table blob use-after-free {CVE-2023-54243} - net/mlx5e: xsk: Fix unlocked writing to ICOSQ {CVE-2026-64210} - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU {CVE-2026-68243} - media: dvb-core: fix wrong reinitialization of ringbuffer on reopen {CVE-2026-23253} - drm/tegra: nvdec: Fix dma_alloc_coherent error check {CVE-2025-38543} - tls: Purge async_hold in tls_decrypt_async_wait() {CVE-2026-23414} - tun: free page on build_skb failure in tun_xdp_one() {CVE-2026-46322} - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c {CVE-2024-56725} - cpufreq: CPPC: Add u64 casts to avoid overflowing {CVE-2022-49750} - irqchip/gic-v3: Fix refcount leak in gic_populate_ppi_partitions {CVE-2022-49715} - ip6_vti: prevent moving the fallback device across netns {CVE-2026-52909} - spi: fix use-after-free on controller registration failure {CVE-2026-31389} - ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw() {CVE-2025-22005} - bpf: Fix stackmap overflow check in __bpf_get_stackid() {CVE-2025-68378} - bpf: Fix RCU stall in bpf_fd_array_map_clear() {CVE-2026-53083} - drm/amd/display: Use krealloc_array() in dal_vector_reserve() {CVE-2026-53329} - mm/damon/sysfs-scheme: cleanup access_pattern subdirs on scheme dir setup failure {CVE-2026-23142} - Squashfs: reject negative file sizes in squashfs_read_inode() {CVE-2025-40200} - i40e: Fix preempt count leak in napi poll tracepoint {CVE-2026-23313} - i2c: core: fix adapter deregistration race {CVE-2026-64279} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC {CVE-2026-64298} - fuse: re-lock request before returning from fuse_ref_folio() {CVE-2026-64266} - RDMA/siw: bound Read Response placement to the RREAD length {CVE-2026-64268} - sctp: don't free the ASCONF's own transport in DEL-IP processing {CVE-2026-64564} - Input: elan_i2c - prevent division by zero and arithmetic underflow {CVE-2026-64275}
Updated packages:
  • bpftool-7.0.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:9802b882bb08a6a42f4831e8b09e75f22504d9585c50dbf7673111d98d308972
  • kernel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:fda651e8dedaf5d076a8fa3005aed22390610796daf9c3f719bec3b4ac9ddd76
  • kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.11.els12.noarch.rpm
    sha:4db02f50cf99a89955f01e94ea578eaefb29e1cf83eadbe75591deba20bea964
  • kernel-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:561da54faf81402f7568f3c269c96e5d60621b179df075e1a3b7254a5c31cd86
  • kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:73e9ad5f601b39c7a2f59e70e8bf3c0f71d5d749d23faa9734a93e4af24b8d40
  • kernel-debug-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:c4fbc1b8414618100508deb8807bfd7656e32756ebc6cff6f69b0041b83f6fb6
  • kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:3e0ab1857bd969fd84bebb8a7c25359a0000622b8f28d7f3fa5506dee2524935
  • kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:3d618d21f07abbedb46a545772049c04c51535f597cb133f78639f4e2ca07b72
  • kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:95d07a33be6fbf94da0547aa8a17c04850495c33936925847fcad01a662b973a
  • kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:1cffa60f70b4f82d566084a43f13d08705a99ef1ef607bd25ec55e7cc1bb77bc
  • kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:40ca03a51f5061ff339e6a63a3d5aa6998142ed9e12e416dd1d018cae2aeff7f
  • kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:4109e8a7222112fd55f3f6a05ee2593287e494e21d8e5708ec5fcd67e3a84231
  • kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:2c3cbff28208b21010d17a3b3d72e4b35f8b384bc28752c79e4a86c5a422c0f9
  • kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:7ca9b41e8de0ad8203d375475ab9eb238c399ffdf5b8472576add3416623718d
  • kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:c10cfbec30ce30db78b5b51d0021a5f6b4e8f1827b70aa9ba3a04aad0309cc9f
  • kernel-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:6911b964ee3ab8fea8e05c5890887e653b302506cce6ed82a51c3c7512d74d3b
  • kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:0cfe865ae4f7fecff77c46ae1577a79be4e450406e78183d717461f666158795
  • kernel-doc-5.14.0-284.1101.el9_2.tuxcare.11.els12.noarch.rpm
    sha:d17333519ecbf55c457085e4ed8544a8ecaba817326264f7d8deaa88697c5223
  • kernel-headers-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:c6d46a6f83ce9c9d83a6b170b55592ac14d8abc772b01d01f36c21a2841e8214
  • kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:c1232bb733bdd965f02e8a7274db51703adf3f5d6d43802a0052fa018a6ea0b1
  • kernel-modules-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:24b21786e81be795c0fa121ab3aa8fc8485a422ea065e019a3add4a7125c7b08
  • kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:313c2648c8665aa40fca1a885e36b9a2ba1ddaedd741cc8a0d29d2aad6e8ee2d
  • kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:3000981614bac2f748ef6ad92fcc5782e8b352c0481c9071339b62cff2728577
  • kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:37dee1b4098436744c496e422a63ec145b16cac295817432704538ecae487096
  • kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:565c5b464d7e2e867dfe603f95364fbaf8605762ad07d3cbf5c6bfef12f95cab
  • kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:a6a74b0480290084f3494d25af2aaa37f76bc50be74de5825216fc5ec3c2fe3b
  • kernel-tools-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:b6e6907c1617e755e81415cff9903e3e4cecd882689481616953bb6539e2d146
  • kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:1edbfa4f4686f857f4dd258843884c5e85b60269e837b0c052de24dae0bcfc16
  • kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:ed734c094d4c58cc39a1849c71cbfc1265574c8cb6b3365bc013418e4084bd93
  • kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:7dbf5f2930322fc05542fa75359d31a51e5153bdd964598e45ca1ad88fa3f138
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
    sha:c2ff01cd17aa718f1642d3248e0422acffeef6becc7ef89f711194bc3eee4a8b
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:64c4e057f90f668f814ceaafbd655f0bedf6984ff209a1b45dca33e990832901
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
    sha:7346eb0ae922604b1b2087556bb977aaa0372c83f9e6b69d311d6b20b78edef0
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:813583b6d64ec550e59c4eff9ab9c9668ef1408099ace68bf05378a5f773f75a
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
    sha:aca73272dc2b780d45f71eab8abf627e01337cde1bed1de1bfc0810484448c6d
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:3658a3214fcd64c36b4be225fe1cfc77af3bcdfbf0fdb4efdc7609499ef18f47
  • perf-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:23dc22eaf136f827fa60ab30ec342f57fdd5e1ad13a7ad3371a90ffc51ccd083
  • python3-perf-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:778faf5ef2be0d245aecea9b01b7e36aaea03e213aaf28f517201519f8eab5ad
  • rtla-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
    sha:8237e1c2c3373f74a2bce931a7cd248fb5ca0a0434555f681da90c0f21469cf6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.