[CLSA-2026:1789141176] kernel: Fix of 131 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-11 15:41:34 UTC
Description:
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-63829} - USB: legousbtower: fix use-after-free on disconnect race {CVE-2026-64340} - udf: validate sparing table length as an entry count, not a byte count {CVE-2026-64322} - ipv4: igmp: remove multicast group from hash table on device destruction {CVE-2026-64423} - USB: ldusb: fix use-after-free on disconnect race {CVE-2026-64343} - USB: idmouse: fix use-after-free on disconnect race {CVE-2026-64344} - net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers {CVE-2026-74700} - ipvs: clear IPv4 options after rebasing tunnel ICMP errors {CVE-2026-74669} - netfilter: ebt_nflog: pin the NFLOG backend {CVE-2026-74660} - ipv4: fix use-after-free in fib_nhc_update_mtu() {CVE-2026-74656} - ALSA: usx2y: bound the hwdep mmap fault offset {CVE-2026-74641} - ipv6: prevent in6_dev_get() from resurrecting inet6_dev {CVE-2026-74630} - tipc: read le->link under the node lock in tipc_node_link_down() {CVE-2026-74609} - ip6_tunnel: clear skb2->cb[] in ip6ip6_err() {CVE-2026-74597} - bpf, sockmap: Fix sk_redir use-after-free in send verdict {CVE-2026-74589} - sctp: keep chunk->transport in step with the list it is queued on {CVE-2026-74588} - netfilter: nf_tables: make nft_object rhltable per table {CVE-2026-74565} - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write {CVE-2026-74470} - nfs: use nfsi->rwsem to protect traversal of the file lock list {CVE-2026-72472} - geneve: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-68142} - sctp: fix use-after-free of cached ASCONF chunk {CVE-2026-74587} - net/packet: reset the MAC header on the packet-socket transmit path {CVE-2026-74667} - ALSA: usb-audio: fix OOB write on Type II inbound URBs {CVE-2026-74682} - sctp: clear control chunk transport if it is being removed {CVE-2026-74688} - udp: fix potential use-after-free in tunnel segmentation {CVE-2026-74705} - bpf: Preserve pointer state for commuted arithmetic {CVE-2026-74720} - RDMA/siw: bound Read Response placement to the RREAD length {CVE-2026-64268} - libceph: Avoid using invalid osd indices from primary_temp {CVE-2026-80558} - drm/i915: Fix potential UAF in TTM object purge {CVE-2026-63884} - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request {CVE-2026-68363} - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() {CVE-2026-68160} - libceph: Reject monmaps advertising zero monitors {CVE-2026-68155} - sctp: fix auth_hmacs array size in struct sctp_cookie {CVE-2026-68376} - Bluetooth: hci_sync: Protect UUID list traversal {CVE-2026-68189} - net: slip: serialize receive against buffer reallocation {CVE-2026-68143} - libceph: remove debugfs files before client teardown {CVE-2026-68153} - media: rtl2832: fix use-after-free in rtl2832_remove() {CVE-2026-68214} - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid {CVE-2026-68320} - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async {CVE-2026-64219} - pppoe: reload header pointer after dev_hard_header() {CVE-2026-68121} - libceph: Fix multiplication overflow in decode_new_up_state_weight() {CVE-2026-68158} - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() {CVE-2026-74499} - fbdev: Fix invalid page access after closing deferred I/O devices {CVE-2023-52731} - Bluetooth: use RCU for hci_conn_params and iterate safely in hci_sync {CVE-2023-53252} - net_sched: red: fix a race in __red_change() {CVE-2025-38108} - iio: event: Fix event FIFO reset race {CVE-2026-64496} - netfilter: ctnetlink: ensure safe access to master conntrack {CVE-2026-43116} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC {CVE-2026-64298} - openvswitch: fix GSO userspace truncation underflow {CVE-2026-68123} - media: cx23885: add ioremap return check and cleanup {CVE-2026-68226} - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev {CVE-2026-68176} - tracing: Fix resource leak on mmiotrace trace_pipe close {CVE-2026-68175} - bpf: Check validity of link->type in bpf_link_show_fdinfo() {CVE-2024-53099} - bridge: mcast: Fix use-after-free during router port configuration {CVE-2025-38248} - ping: Fix potentail NULL deref for /proc/net/icmp. {CVE-2023-53987} - cifs: fix potential oops in cifs_oplock_break {CVE-2023-54258} - tty: n_gsm: Don't block input queue by waiting MSC {CVE-2025-40071} - nvdimm/bus: Fix potential use after free in asynchronous initialization {CVE-2026-31399} - xen: Add support for XenServer 6.1 platform device {CVE-2025-38046} - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check {CVE-2026-23447} - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead {CVE-2024-47672} - quota: fix warning in dqgrab() {CVE-2023-54177} - scsi: hpsa: Fix possible memory leak in hpsa_init_one() {CVE-2022-50646} - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown {CVE-2026-23454} - ALSA: usb-audio: Use correct version for UAC3 header validation {CVE-2026-23318} - net/mdiobus: Fix potential out-of-bounds read/write access {CVE-2025-38111} - HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure {CVE-2026-43049} - iommu/amd: Avoid stack buffer overflow from kernel cmdline {CVE-2025-38676} - ALSA: usb-audio: Prevent excessive number of frames {CVE-2026-23208} - libceph: fix invalid accesses to ceph_connection_v1_info {CVE-2025-39880} - net_sched: drr: Fix double list add in class with netem as child qdisc {CVE-2025-37915} - wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() {CVE-2026-23315} - vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check {CVE-2023-53543} - net: openvswitch: Fix the dead loop of MPLS parse {CVE-2025-38146} - nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set {CVE-2026-43449} - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() {CVE-2026-68355} - tipc: fix infinite loop in __tipc_nl_compat_dumpit {CVE-2026-68313} - sctp: validate stream count in sctp_process_strreset_inreq() {CVE-2026-68315} - smb/client: handle overlapping allocated ranges in fallocate {CVE-2026-68388} - xfrm: fix stale skb->prev after async crypto steals a GSO segment {CVE-2026-68426} - ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL {CVE-2023-52697} - wifi: mac80211: increase scan_ies_len for S1G {CVE-2025-39957} - drm/tests: helpers: Avoid a driver uaf {CVE-2023-53235} - netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() {CVE-2026-43453} - bpf: Propagate error from htab_lock_bucket() to userspace {CVE-2022-50490} - software node: Correct a OOB check in software_node_get_reference_args() {CVE-2025-38342} - x86/bugs: Flush IBP in ib_prctl_set() {CVE-2023-0045} - xfs: do not propagate ENODATA disk errors into xattr code {CVE-2025-39835} - drm/amdgpu: Add bounds checking to ib_{get,set}_value {CVE-2026-46218} - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() {CVE-2025-39860} - net_sched: qfq: Fix double list add in class with netem as child qdisc {CVE-2025-37913} - kdb: Fix buffer overflow during tab-complete {CVE-2024-39480} - ceph: fix a buffer leak in __ceph_setxattr() {CVE-2026-52962} - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ {CVE-2026-23395} - RDMA/efa: Fix use of completion ctx after free {CVE-2026-31493} - bnxt_en: Fix memory corruption when FW resources change during ifdown {CVE-2025-39810} - bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO {CVE-2022-49961} - Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()' {CVE-2025-38593} - bpf: Fix helper writes to read-only maps {CVE-2024-49861} - bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers {CVE-2023-52621} - ext4: improve error handling from ext4_dirhash() {CVE-2023-53473} - bpf: Check skb->transport_header is set in bpf_skb_check_mtu {CVE-2025-68363} - net: hv_netvsc: reject RSS hash key programming without RX indirection table {CVE-2026-23054} - mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose() {CVE-2025-68291} - futex: Prevent use-after-free during requeue-PI {CVE-2025-39977} - bpf: Fix invalid prog->stats access when update_effective_progs fails {CVE-2025-68742} - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache {CVE-2026-46174} - gve: Fix stats report corruption on queue count change {CVE-2026-23262} - Bluetooth: bnep: reject short frames before parsing {CVE-2026-53253} - arp: use RCU protection in arp_xmit() {CVE-2025-21762} - SUNRPC: make sure cache entry active before cache_show {CVE-2024-53174} - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check {CVE-2026-46006} - drm/amd/display: Use krealloc_array() in dal_vector_reserve() {CVE-2026-53329} - mm/khugepaged: fix ->anon_vma race {CVE-2023-52935} - RDMA/srp: bound SRP_RSP sense copy by the received length {CVE-2026-53186} - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check {CVE-2026-52998} - wifi: mac80211: tear down new links on vif update error path {CVE-2026-64574} - RDMA/rxe: Fix a use-after-free problem in rxe_mmap {CVE-2026-64582} - ipv4: fib: free fib_alias with kfree_rcu() on insert error path {CVE-2026-64572} - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert {CVE-2026-64579} - iommu: disable SVA when CONFIG_X86 is set {CVE-2025-71089} - Bluetooth: MGMT: Protect mgmt_pending list with its own lock {CVE-2025-38117} - IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests {CVE-2023-52474} - ftrace: Also allocate and copy hash for reading of filter files {CVE-2025-39689} - wifi: cfg80211: cancel sched scan results work on unregister {CVE-2026-68414} - ALSA: seq: close a re-opened queue timer in the destructor {CVE-2026-68202} - libceph: refresh auth->authorizer_buf{,_len} after authorizer update {CVE-2026-68156} - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug {CVE-2026-68093} - openvswitch: use RCU protection in ovs_vport_cmd_fill_info() {CVE-2025-21761}
CVEs fixed:
Updated packages:
  • bpftool-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:99290916fd309d40bbbcde23d044ed112cd7bf9b27c21d9737c9b78f1ad63bfc
  • kernel-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:819a392c0035f378d82113aab1002a833a252f974a7ba6ac12d476b0149f666d
  • kernel-core-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:388272ec98294d1a1944d92f873ab2774d78859d92860e1d6da1eb788a833395
  • kernel-cross-headers-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:a6f2696d105c97951851ef815a318f3a5c72e5d305ceafa630eae22b97eb90bf
  • kernel-debug-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:f2e03f9cb2ab0e2a5d7b2a98762efb8c907fb4d78f5582463ea92607c5ae3c7c
  • kernel-debug-core-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:2b8efd4468d0289faca506fcb4509e88c390a76195188a7549780fafd5c5693c
  • kernel-debug-devel-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:e14aadfe19da81c11675b4d3964dd132cb6bd8933b729ade27c484e16c5f3672
  • kernel-debug-modules-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:4666a61637dc88b93ed70446ffc0651d1ea8f662b1547e32cf96042cc387f2a7
  • kernel-debug-modules-extra-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:74974eddd2b778c5c1c4526a53bac61c61afd648b0979f0c2c0e307389e7f3e3
  • kernel-debug-modules-internal-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:814907810a8bee93fc13577f23b6ebd7d542f794e7b39fbd0b10bb8d69b10b84
  • kernel-devel-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:efa8c55327eada92cbe0828da0cfedb5b3d4bda4d13b66715b04aca9d9deacef
  • kernel-headers-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:e38afcf5089e8a992f514f3b5f0a1caee0800deb3c2e7e293bb0720b45ebd90f
  • kernel-ipaclones-internal-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:db8b8c7ff8326e507c4cb2b173f75a92313078f2ee98b8e118a178815603b5c4
  • kernel-modules-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:56c4909494c4008e8be0d9b0cc7587fe59ecac86d23ad337859d32af0c3649fc
  • kernel-modules-extra-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:20cd3c7b903e0a01eeb3f113426054c947fb67b5e5aa5318101a41898d117674
  • kernel-modules-internal-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:04b97609d30d8c973f8c66b5d6a1cd62cee5191d77df8067b2e42ae6c11b646e
  • kernel-selftests-internal-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:899ff3df01d6c37a0c18eb6431204e650960016a8e73a7a2b3f194b37c6041a7
  • kernel-tools-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:a994382b9f0ecc7666bb674fcbe83d2f4322d7c003580f4a78978ae2494c941e
  • kernel-tools-libs-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:8b047a1d0a66b8e1e3d8388b6132482916f394128c7da6123cc4c3c36b21b2e9
  • kernel-tools-libs-devel-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:c42ce7e6d7a3fcebc0952400b6c6dbde157246f73434bde8f08ba4d49acf89c7
  • perf-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:1eab22e39d2d7e71db1cf1e1d60ca10ed950244d07b65b472f0260e9f591ce1a
  • python3-perf-4.18.0-553.6.1.el8_10.tuxcare.els30.x86_64.rpm
    sha:50d38f3807109e115188bcd2821fee459eb3ed367f2765327b092cb6b92afb5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.