Release date:
2026-08-21 19:33:28 UTC
Description:
- net/sched: serialize qdisc_rtab_list against concurrent get/put {CVE-2026-68138}
- static_call: Replace pointless WARN_ON() in static_call_module_notify() {CVE-2024-49954}
- static_call: Handle module init failure correctly in static_call_del_module() {CVE-2024-50002}
- smb: client: require a full NFS mode SID before reading mode bits {CVE-2026-43350}
- octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() {CVE-2025-39978}
- scsi: core: Fix refcount leak for tagset_refcnt {CVE-2026-23296}
- wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() {CVE-2026-23336}
- smb: client: fix memory leak in cifs_construct_tcon() {CVE-2025-68295}
- sched/deadline: Fix warning in migrate_enable for boosted tasks {CVE-2024-56583}
- nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() {CVE-2025-40261}
- usbnet: Prevents free active kevent {CVE-2025-68312}
- libceph: bound get_version reply decode to front len {CVE-2026-68433}
- neigh: let neigh_xmit take skb ownership {CVE-2026-52981}
- gve: prevent ethtool ops after shutdown {CVE-2025-38735}
- vfs: Don't leak disconnected dentries on umount {CVE-2025-40105}
- NFSD: NFSv4 file creation neglects setting ACL {CVE-2025-68803}
- thermal: intel: int340x: processor: Fix warning during module unload {CVE-2024-50093}
- quota: fix warning in dqgrab() {CVE-2023-54177}
- mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0] {CVE-2026-31458}
- net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change {CVE-2025-71066}
- bpf, skmsg: Fix NULL pointer dereference in sk_psock_skb_ingress_enqueue {CVE-2024-36938}
- net: hv_netvsc: reject RSS hash key programming without RX indirection table {CVE-2026-23054}
- xsk: tighten UMEM headroom validation to account for tailroom and min frame {CVE-2026-43093}
- drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) {CVE-2024-39497}
- bpf: Fix OOB in pcpu_init_value {CVE-2026-53076}
- ftrace: Clean up hash direct_functions on register failures {CVE-2022-49402}
- binfmt_misc: restore write access before closing files opened by open_exec() {CVE-2025-68239}
- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path {CVE-2025-39929}
- wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() {CVE-2026-53102}
- xen: Add support for XenServer 6.1 platform device {CVE-2025-38046}
- i2c: tegra: Do not mark ACPI devices as irq safe {CVE-2024-45029}
- bpf: Add preempt_count_{sub,add} into btf id deny list {CVE-2023-54086}
- libceph: Fix multiplication overflow in decode_new_up_state_weight() {CVE-2026-68158}
- mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose() {CVE-2025-68291}
- net/mlx5: Fix missing lock on sync reset reload {CVE-2024-42268}
- vxlan: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-68432}
- netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels {CVE-2026-23274}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async {CVE-2026-64219}
- mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations {CVE-2026-31394}
- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path {CVE-2026-53096}
- scsi: mpi3mr: Fix possible crash when setting up bsg fails {CVE-2025-21723}
- net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup {CVE-2025-68192}
- net: stream: purge sk_error_queue in sk_stream_kill_queues() {CVE-2022-50838}
- clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context {CVE-2025-21767}
- net: netpoll: fix incorrect refcount handling causing incorrect cleanup {CVE-2025-68245}
- drm/amd/display: Check link_res->hpo_dp_link_enc before using it {CVE-2024-47704}
- crypto: qat - flush misc workqueue during device shutdown {CVE-2025-39721}
- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed {CVE-2026-31698}
- smb: client: split cached_fid bitfields to avoid shared-byte RMW races {CVE-2026-23230}
- net/smc: initialize close_work early to avoid warning {CVE-2024-56641}
- netfilter: nft_ct: add seqadj extension for natted connections {CVE-2025-68206}
- net/sched: sch_netem: fix out-of-bounds access in packet corruption {CVE-2026-31675}
- ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() {CVE-2026-31426}
- bpf: Reject sleepable kprobe_multi programs at attach time {CVE-2026-43010}
- ASoC: soc-core: flush delayed work before removing DAIs and widgets {CVE-2026-43459}
- mm: hugetlb: avoid soft lockup when mprotect to large memory area {CVE-2025-40153}
- mptcp: pm: ADD_ADDR rtx: fix potential data-race {CVE-2026-46137}
- Input: uinput - take event lock when submitting FF request "event"
- smb3: fix lock ordering potential deadlock in cifs_sync_mid_result {CVE-2024-35998}
- drm/i915/gem: Add missing nospec on parallel submit slot {CVE-2026-68269}
- netfilter: ebtables: fix table blob use-after-free {CVE-2023-54243}
- net/mlx5e: xsk: Fix unlocked writing to ICOSQ {CVE-2026-64210}
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU {CVE-2026-68243}
- media: dvb-core: fix wrong reinitialization of ringbuffer on reopen {CVE-2026-23253}
- drm/tegra: nvdec: Fix dma_alloc_coherent error check {CVE-2025-38543}
- tls: Purge async_hold in tls_decrypt_async_wait() {CVE-2026-23414}
- tun: free page on build_skb failure in tun_xdp_one() {CVE-2026-46322}
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c {CVE-2024-56725}
- cpufreq: CPPC: Add u64 casts to avoid overflowing {CVE-2022-49750}
- irqchip/gic-v3: Fix refcount leak in gic_populate_ppi_partitions {CVE-2022-49715}
- ip6_vti: prevent moving the fallback device across netns {CVE-2026-52909}
- spi: fix use-after-free on controller registration failure {CVE-2026-31389}
- ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw() {CVE-2025-22005}
- bpf: Fix stackmap overflow check in __bpf_get_stackid() {CVE-2025-68378}
- bpf: Fix RCU stall in bpf_fd_array_map_clear() {CVE-2026-53083}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() {CVE-2026-53329}
- mm/damon/sysfs-scheme: cleanup access_pattern subdirs on scheme dir setup failure {CVE-2026-23142}
- Squashfs: reject negative file sizes in squashfs_read_inode() {CVE-2025-40200}
- i40e: Fix preempt count leak in napi poll tracepoint {CVE-2026-23313}
- i2c: core: fix adapter deregistration race {CVE-2026-64279}
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC {CVE-2026-64298}
- fuse: re-lock request before returning from fuse_ref_folio() {CVE-2026-64266}
- RDMA/siw: bound Read Response placement to the RREAD length {CVE-2026-64268}
- sctp: don't free the ASCONF's own transport in DEL-IP processing {CVE-2026-64564}
- Input: elan_i2c - prevent division by zero and arithmetic underflow {CVE-2026-64275}
Updated packages:
-
bpftool-7.0.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:9802b882bb08a6a42f4831e8b09e75f22504d9585c50dbf7673111d98d308972
-
kernel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:fda651e8dedaf5d076a8fa3005aed22390610796daf9c3f719bec3b4ac9ddd76
-
kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.11.els12.noarch.rpm
sha:4db02f50cf99a89955f01e94ea578eaefb29e1cf83eadbe75591deba20bea964
-
kernel-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:561da54faf81402f7568f3c269c96e5d60621b179df075e1a3b7254a5c31cd86
-
kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:73e9ad5f601b39c7a2f59e70e8bf3c0f71d5d749d23faa9734a93e4af24b8d40
-
kernel-debug-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:c4fbc1b8414618100508deb8807bfd7656e32756ebc6cff6f69b0041b83f6fb6
-
kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:3e0ab1857bd969fd84bebb8a7c25359a0000622b8f28d7f3fa5506dee2524935
-
kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:3d618d21f07abbedb46a545772049c04c51535f597cb133f78639f4e2ca07b72
-
kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:95d07a33be6fbf94da0547aa8a17c04850495c33936925847fcad01a662b973a
-
kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:1cffa60f70b4f82d566084a43f13d08705a99ef1ef607bd25ec55e7cc1bb77bc
-
kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:40ca03a51f5061ff339e6a63a3d5aa6998142ed9e12e416dd1d018cae2aeff7f
-
kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:4109e8a7222112fd55f3f6a05ee2593287e494e21d8e5708ec5fcd67e3a84231
-
kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:2c3cbff28208b21010d17a3b3d72e4b35f8b384bc28752c79e4a86c5a422c0f9
-
kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:7ca9b41e8de0ad8203d375475ab9eb238c399ffdf5b8472576add3416623718d
-
kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:c10cfbec30ce30db78b5b51d0021a5f6b4e8f1827b70aa9ba3a04aad0309cc9f
-
kernel-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:6911b964ee3ab8fea8e05c5890887e653b302506cce6ed82a51c3c7512d74d3b
-
kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:0cfe865ae4f7fecff77c46ae1577a79be4e450406e78183d717461f666158795
-
kernel-doc-5.14.0-284.1101.el9_2.tuxcare.11.els12.noarch.rpm
sha:d17333519ecbf55c457085e4ed8544a8ecaba817326264f7d8deaa88697c5223
-
kernel-headers-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:c6d46a6f83ce9c9d83a6b170b55592ac14d8abc772b01d01f36c21a2841e8214
-
kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:c1232bb733bdd965f02e8a7274db51703adf3f5d6d43802a0052fa018a6ea0b1
-
kernel-modules-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:24b21786e81be795c0fa121ab3aa8fc8485a422ea065e019a3add4a7125c7b08
-
kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:313c2648c8665aa40fca1a885e36b9a2ba1ddaedd741cc8a0d29d2aad6e8ee2d
-
kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:3000981614bac2f748ef6ad92fcc5782e8b352c0481c9071339b62cff2728577
-
kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:37dee1b4098436744c496e422a63ec145b16cac295817432704538ecae487096
-
kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:565c5b464d7e2e867dfe603f95364fbaf8605762ad07d3cbf5c6bfef12f95cab
-
kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:a6a74b0480290084f3494d25af2aaa37f76bc50be74de5825216fc5ec3c2fe3b
-
kernel-tools-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:b6e6907c1617e755e81415cff9903e3e4cecd882689481616953bb6539e2d146
-
kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:1edbfa4f4686f857f4dd258843884c5e85b60269e837b0c052de24dae0bcfc16
-
kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:ed734c094d4c58cc39a1849c71cbfc1265574c8cb6b3365bc013418e4084bd93
-
kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:7dbf5f2930322fc05542fa75359d31a51e5153bdd964598e45ca1ad88fa3f138
-
libbpf-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
sha:c2ff01cd17aa718f1642d3248e0422acffeef6becc7ef89f711194bc3eee4a8b
-
libbpf-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
sha:64c4e057f90f668f814ceaafbd655f0bedf6984ff209a1b45dca33e990832901
-
libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
sha:7346eb0ae922604b1b2087556bb977aaa0372c83f9e6b69d311d6b20b78edef0
-
libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
sha:813583b6d64ec550e59c4eff9ab9c9668ef1408099ace68bf05378a5f773f75a
-
libbpf-static-1.0.0-2.el9_2.tuxcare.11.els12.i686.rpm
sha:aca73272dc2b780d45f71eab8abf627e01337cde1bed1de1bfc0810484448c6d
-
libbpf-static-1.0.0-2.el9_2.tuxcare.11.els12.x86_64.rpm
sha:3658a3214fcd64c36b4be225fe1cfc77af3bcdfbf0fdb4efdc7609499ef18f47
-
perf-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:23dc22eaf136f827fa60ab30ec342f57fdd5e1ad13a7ad3371a90ffc51ccd083
-
python3-perf-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:778faf5ef2be0d245aecea9b01b7e36aaea03e213aaf28f517201519f8eab5ad
-
rtla-5.14.0-284.1101.el9_2.tuxcare.11.els12.x86_64.rpm
sha:8237e1c2c3373f74a2bce931a7cd248fb5ca0a0434555f681da90c0f21469cf6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.