[CLSA-2026:1787935638] kernel: Fix of 157 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-29 14:41:43 UTC
Description:
- wifi: brcmfmac: ensure CLM version is null-terminated to prevent stack-out-of-bounds {CVE-2023-53582} - net/sched: accept TCA_STAB only for root qdisc {CVE-2024-50039} - bpf, sockmap: Several fixes to bpf_msg_pop_data {CVE-2024-56720} - net: add more sanity checks to qdisc_pkt_len_init() {CVE-2024-49948} - nvme-tcp: sanitize request list handling {CVE-2025-38264} - smb: client: fix double free of TCP_Server_Info::hostname {CVE-2025-21673} - net/sched: ets: Remove drr class from the active list if it changes to strict {CVE-2025-68815} - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo {CVE-2026-46132} - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send {CVE-2026-45856} - Bluetooth: hci_event: fix potential UAF in SSP passkey handlers {CVE-2026-46056} - bpf: Fix bpf_xdp_store_bytes proto for read-only arg {CVE-2026-45886} - libceph: Fix slab-out-of-bounds access in auth message processing {CVE-2026-46119} - nfsd: never defer requests during idmap lookup {CVE-2026-45983} - openvswitch: cap upcall PID array size and pre-size vport replies {CVE-2026-45840} - procfs: fix missing RCU protection when reading real_parent in do_task_stat() {CVE-2026-46259} - dm mirror: fix integer overflow in create_dirty_log() {CVE-2026-46023} - thermal: core: Fix thermal zone governor cleanup issues {CVE-2026-46021} - tcp: call sk_data_ready() after listener migration {CVE-2026-46015} - dm: fix a buffer overflow in ioctl processing {CVE-2026-46294} - Bluetooth: RFCOMM: validate skb length in MCC handlers {CVE-2026-53254} - xfrm: espintcp: do not reuse an in-progress partial send {CVE-2026-52935} - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() {CVE-2026-53195} - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag {CVE-2026-53218} - netfilter: xt_policy: fix strict mode inbound policy matching {CVE-2026-52920} - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() {CVE-2026-53256} - tipc: fix double-free in tipc_buf_append() {CVE-2026-52993} - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER {CVE-2026-53072} - netfilter: conntrack: remove sprintf usage {CVE-2026-53002} - smb: client: fix krb5 mount with username option {CVE-2026-31392} - netfilter: nft_tunnel: fix use-after-free on object destroy {CVE-2026-53212} - USB: serial: io_ti: fix heap overflow in get_manuf_info() {CVE-2026-53196} - crypto: ccp - copy IV using skcipher ivsize {CVE-2026-53016} - netfilter: conntrack_irc: fix possible out-of-bounds read {CVE-2026-53268} - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN {CVE-2026-53176} - fuse: reject fuse_notify() pagecache ops on directories {CVE-2026-53168} - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls {CVE-2026-53075} - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() {CVE-2026-53239} - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options {CVE-2026-53249} - ipv6: sit: reload inner IPv6 header after GSO offloads {CVE-2026-53228} - uio_hv_generic: Let userspace take care of interrupt mask {CVE-2025-40048} - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove {CVE-2026-52947} - net: guard timestamp cmsgs to real error queue skbs {CVE-2026-53223} - libceph: Fix potential out-of-bounds access in crush_decode() {CVE-2026-52955} - libceph: Fix potential null-ptr-deref in decode_choose_args() {CVE-2026-52957} - netfilter: nft_ct: fix missing expect put in obj eval {CVE-2026-52970} - netfilter: nf_tables: always walk all pending catchall elements {CVE-2026-23278} - crypto: af_alg - Cap AEAD AD length to 0x80000000 {CVE-2026-52972} - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() {CVE-2026-64174} - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr {CVE-2026-53391} - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock {CVE-2026-63945} - pNFS: Fix use-after-free in pnfs_update_layout() {CVE-2026-63800} - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path {CVE-2026-46189} - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() {CVE-2026-46172} - octeontx2-af: Fix PF driver crash with kexec kernel booting {CVE-2026-46249} - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies {CVE-2026-46161} - usb: usblp: fix heap leak in IEEE 1284 device ID via short response {CVE-2026-46151} - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl {CVE-2026-46167} - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission {CVE-2026-46220} - vsock: fix buffer size clamping order {CVE-2026-46234} - sound: ua101: fix division by zero at probe {CVE-2026-46184} - fbcon: Avoid OOB font access if console rotation fails {CVE-2026-46191} - ext4: fix memory leak in ext4_ext_shift_extents() {CVE-2026-45948} - SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path {CVE-2026-45964} - inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails {CVE-2026-46040} - ALSA: ctxfi: Add fallback to default RSR for S/PDIF {CVE-2026-46049} - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES {CVE-2026-46018} - KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 {CVE-2026-45987} - dcache: Limit the minimal number of bucket to two {CVE-2026-43071} - ipmi: Check event message buffer response for bad data {CVE-2026-46128} - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 {CVE-2026-46082} - ipmi:si: Return state to normal if message allocation fails {CVE-2026-46108} - netfilter: reject zero shift in nft_bitwise {CVE-2026-46101} - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access {CVE-2026-31393} - ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() {CVE-2026-46088} - net: remove WARN_ON_ONCE when accessing forward path array {CVE-2026-45847} - scsi: csiostor: Fix dereference of null pointer rn {CVE-2026-45857} - ipvs: skip ipv6 extension headers for csum checks {CVE-2026-45850} - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() {CVE-2026-45839} - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO {CVE-2026-45841} - tipc: fix infinite loop in __tipc_nl_compat_dumpit {CVE-2026-68313} - bpf: fix end-of-list detection in cgroup_storage_get_next_key() {CVE-2026-45838} - slip: reject VJ receive packets on instances with no rstate array {CVE-2026-45842} - sctp: validate stream count in sctp_process_strreset_inreq() {CVE-2026-68315} - smb/client: handle overlapping allocated ranges in fallocate {CVE-2026-68388} - net: openvswitch: fix possible kfree_skb of ERR_PTR {CVE-2026-53227} - netfilter: x_tables: avoid leaking percpu counter pointers {CVE-2026-53219} - xfrm: fix stale skb->prev after async crypto steals a GSO segment {CVE-2026-68426} - vsock/vmci: fix sk_ack_backlog leak on failed handshake {CVE-2026-53181} - bnxt_en: Fix NULL pointer dereference {CVE-2026-53177} - scsi: sg: Resolve soft lockup issue when opening /dev/sgX {CVE-2026-53304} - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() {CVE-2026-43062} - netfilter: nft_ct: drop pending enqueued packets on removal {CVE-2026-43060} - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size {CVE-2026-53136} - xfs: delete attr leaf freemap entries when empty {CVE-2026-43187} - audit: fix incorrect inheritable capability in CAPSET records {CVE-2026-53287} - xprtrdma: Decrement re_receiving on the early exit paths {CVE-2026-43469} - 6lowpan: fix off-by-one in multicast context address compression {CVE-2026-53263} - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr {CVE-2026-53245} - netfilter: synproxy: add mutex to guard hook reference counting {CVE-2026-53269} - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs {CVE-2026-53135} - mailbox: add sanity check for channel array {CVE-2026-53295} - efi: fix NULL-deref in init error path {CVE-2022-48879} - netlabel: validate unlabeled address and mask attribute lengths {CVE-2026-53238} - tracing/histogram: Fix a potential memory leak for kstrdup() {CVE-2022-48768} - drm/amdgpu: Add bounds checking to ib_{get,set}_value {CVE-2026-46218} - drm/amdkfd: validate SVM ioctl nattr against buffer size {CVE-2026-46197} - RDMA/srp: Do not call scsi_done() from srp_abort() {CVE-2023-52515} - Bluetooth: MGMT: validate advertising TLV before type checks {CVE-2026-53255} - vDPA/ifcvf: alloc the mgmt_dev before the adapter {CVE-2022-48706} - pNFS: Handle RPC size limit for layoutcommits - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle - ipmi: Add limits to event and receive message requests {CVE-2026-46177} - nexthop: fix IPv6 route referencing IPv4 nexthop {CVE-2026-53012} - vsock/vmci: fix UAF when peer resets connection during handshake - ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl {CVE-2026-52948} - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() {CVE-2026-52969} - can: af_can: fix NULL pointer dereference in can_rcv_filter {CVE-2022-49863} - nfsd: restore callback functionality for NFSv4.0 - HID: usbhid: fix deadlock in hid_post_reset() {CVE-2026-53037} - netdevsim: zero initialize struct iphdr in dummy sk_buff {CVE-2026-52985} - RDMA/siw: Reject MPA FPDU length underflow before signed receive math - ceph: fix a buffer leak in __ceph_setxattr() {CVE-2026-52962} - platform/x86: dell-wmi-sysman: bound enumeration string aggregation {CVE-2026-53022} - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF {CVE-2026-68398} - block: initialize integrity buffer to zero before writing it to media {CVE-2024-43854} - fs/mount_setattr: always cleanup mount_kattr {CVE-2021-46923} - dm cache: fix null-deref with concurrent writes in passthrough mode {CVE-2026-53064} - net/sched: cls_fw: fix NULL dereference of "old" filters before change() {CVE-2026-53080} - iommu/iova: Fix alloc iova overflows issue {CVE-2023-52910} - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert {CVE-2026-64579} - ipv4: fib: free fib_alias with kfree_rcu() on insert error path {CVE-2026-64572} - nexthop: initialize extack in nh_res_bucket_migrate() {CVE-2026-64576} - wifi: cfg80211: cancel sched scan results work on unregister {CVE-2026-68414} - drm/i915: Fix potential context UAFs {CVE-2023-52913} - wifi: brcmfmac: Fix error pointer dereference {CVE-2026-53093} - Bluetooth: hci_sync: Protect UUID list traversal {CVE-2026-68189} - ALSA: usb-audio: Bound MIDI endpoint descriptor scans {CVE-2026-52963} - net: bonding: fix NULL pointer dereference in bond_do_ioctl() {CVE-2026-53337} - openvswitch: validate MPLS set/set_masked payload length {CVE-2026-31679} - thunderbolt: Clamp XDomain response data copy to allocation size - hwmon: adm1275: Prevent reading uninitialized stack {CVE-2026-72396} - iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() {CVE-2026-68324} - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug {CVE-2026-68093} - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache {CVE-2025-54518} - libbpf: Refactor cleanup in ring_buffer__add {CVE-2022-49030} - libbpf: Handle size overflow for ringbuf mmap {CVE-2022-49030} - cxl/port: Fix use after free of parent_port in cxl_detach_ep() {CVE-2026-31530} - cxl/port: Keep port->uport valid for the entire life of a port {CVE-2026-31530} - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-68142} - net/sched: act_tunnel_key: Defer dst_release to RCU callback {CVE-2026-68377} - net: slip: serialize receive against buffer reallocation {CVE-2026-68143} - libceph: remove debugfs files before client teardown {CVE-2026-68153} - libceph: refresh auth->authorizer_buf{,_len} after authorizer update {CVE-2026-68156} - wifi: cfg80211: bound element ID read when checking non-inheritance {CVE-2026-68402} - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid {CVE-2026-68320} - pppoe: reload header pointer after dev_hard_header() {CVE-2026-68121} - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() {CVE-2026-74499} - Bluetooth: RFCOMM: Fix session UAF in set_termios {CVE-2026-68188} - geneve: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-68142} - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows {CVE-2026-43501} - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request {CVE-2026-68363} - libceph: Reject monmaps advertising zero monitors {CVE-2026-68155} - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() {CVE-2026-68160} - drm/amdgpu/vce: fix integer overflow in image size {CVE-2026-68108} - Input: elan_i2c - validate firmware size before use {CVE-2026-64237} - octeontx2-af: CGX: add bounds check to cgx_speed_mbps index {CVE-2026-64225}
CVEs fixed:
Updated packages:
  • bpftool-7.0.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:6e4ff9deefd16ebdbac08b1aa95aecc46aebb1f4e9ee3a679b2d578127c67a34
  • kernel-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:b779ba79609ea216d129862c112e8665815ce8323e40cb7d0a9fceb9e6a8fa9b
  • kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.11.els13.noarch.rpm
    sha:41d6578d1cc100bb6f82f1ff2675297e07ce1f7c595da79de391ec155bffee52
  • kernel-core-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:2532feb9157abf60d296ef708c19b30947f8e0c413790bcb974c21a4f1020da2
  • kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:efc07d0ac2a6c698df53c49ac4562964686410098c3b0ebeb4910223430583cc
  • kernel-debug-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:88295cdb46cd6eb0701f40aaa5a3e7feb49596468e26647e32e4c6dd97157461
  • kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:8bbb09828dbfc66676bd987ae97ce29954842a3f867228c15e0c4b411c60f99d
  • kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:57066bd6191464548e2830bf7fc7688d3f934e78858b773fb46dd6fd01a27a2e
  • kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:89840ae603abab064987b824c6d8c32608240e804ccbe707f8f92b2de85b0786
  • kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:b2e6278b6c8648af4cf41db79f3da6fac4fd3eefd748bddc74169a42373d1a7c
  • kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:e00a3b7e055be0eac7d2711854f28b74e6c7981c14688b7dde9b2f251714ed52
  • kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:0fea5bfc869a2b37c895f4e7d832a939dd0a0359e474c9f53993d27fb3e7a221
  • kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:a90b19d7d51d613b4102294e776f50c83beebee81ec344eae84ff5f52d1fe555
  • kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:5c1aeec4e64fe79bce44d95f564680bd30d7ea00c79efe94d35548c383d3e38b
  • kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:fcc8d7180a6a0fce512fc03e3f90f6d3e7e2a6230497f73b37c189447d88d5b6
  • kernel-devel-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:e814ff20402191d3e44d0a63b629e65be943734204c4ac4db4d3c5d14a847d6a
  • kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:b642b0de513420da3dc06d658011c5cfa6771263525ba3136c765824992ebd1b
  • kernel-doc-5.14.0-284.1101.el9_2.tuxcare.11.els13.noarch.rpm
    sha:b72ac0c8e6ed570f8655f189758644cd2a5742fec3b941b9a0b6811ced616d85
  • kernel-headers-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:8cd52d8481af00a0107e46763eb0eca2f29e6663811faf0d37d6ac40f4362ad2
  • kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:54aa3e7e5ee68ef25ad20f3a7db4b64930385dd4e3b9f6acbf5fee86314c4baf
  • kernel-modules-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:6db2596573688f7f7f454e690db888cb48004a934b9a5f7f824b6637fd66d749
  • kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:468d063fe64a31616264de20d2635d9d4b5ba3946ad7f26dddbad01371610840
  • kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:301756b923381029d2ab62e0777de7f485a9744e370f8d97f8444142cdfcafc5
  • kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:95aee08db12d19b2c89b7ce3cb2179eb6b4d55a5196447722e83c12d133fb99a
  • kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:d3a51cbc059c8d628323f534f813cc3b06805c4c67cd4f34c9ea77f39e6b58d0
  • kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:a42e58f397029acdd3dc0fc5578d81bc9066efb9df4142162e1f654aaef384df
  • kernel-tools-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:cc5d246f6ba1e348ec236cfb6c1fa263e772647b8a36e12be689339c0acc2b5b
  • kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:284a3d3765203442152b6ffa29ad53f1b7dbfa66b181b4f4091fa291836e8d29
  • kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:18ab0b41a264e494adac0622d24544d86af093eb230da246736df6941dbb8f67
  • kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:e5d45d9dadef8bb71a8c9f017321604945c935e24e8379d04fa39315f8ffc6e9
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els13.i686.rpm
    sha:61842827bc111c8bea8ed94caa7655c16895a923bb05c235e8eda75a762b257b
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:368e63bb41fc1481fc3b0961558f3bd4d5de659aa6458a7d0df0b2e51c2de18f
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els13.i686.rpm
    sha:4bb557779e7d99d8ced9c05444bb12c7f23e164a2147e68ceecae74acfe8ed2f
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:7e3588e84a0a2d0b16f0a062c45eb2216c9ec010c79fd26bb5850cf9df4923ac
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els13.i686.rpm
    sha:58cfce921fc4b4850105e02a7215a73be01075e9b46f2068ede8e069bfa940b7
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:6560b26ce90c2b8a1dceed9e9e87df4fa2edf240907d968213429ba22cb2114f
  • perf-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:f026ffb46a0707db94fb0c1833bbc473667a8caedb1b05ada51678149eea5954
  • python3-perf-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:49153e17d68a4c870041805251e71aa5a37579af419af6449674cad1544a180b
  • rtla-5.14.0-284.1101.el9_2.tuxcare.11.els13.x86_64.rpm
    sha:ea66b14ee2a1a03d683bd9a3e0d7fc4c874523e499358c2e8e02cbfa6341d4a1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.