[CLSA-2026:1789037015] kernel: Fix of 51 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-10 10:44:39 UTC
Description:
- net: openvswitch: fix skb leak on flow key update failure during ct {CVE-2026-74464} - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error {CVE-2026-74456} - wifi: mwifiex: fix permanently busy scans after multiple roam iterations {CVE-2026-68469} - drm/amdgpu/gfx8: drop unecessary BUG_ON() {CVE-2026-68430} - sctp: auth: verify auth requirement when auth_chunk is NULL {CVE-2026-68300} - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL {CVE-2026-68184} - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read {CVE-2026-68351} - wifi: carl9170: fix buffer overflow in rx_stream failover path {CVE-2026-68349} - wifi: carl9170: fix OOB read from off-by-two in TX status handler {CVE-2026-68350} - net: sit: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72061} - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72055} - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72054} - net: ipip: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72053} - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72051} - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-63829} - usb: free iso schedules on failed submit {CVE-2026-64348} - smb: client: restrict implied bcc[0] exemption to responses without data area {CVE-2026-64448} - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes {CVE-2026-64422} - netfilter: ebtables: terminate table name before find_table_lock() {CVE-2026-64411} - netfilter: ebtables: zero chainstack array {CVE-2026-64413} - USB: idmouse: fix use-after-free on disconnect race {CVE-2026-64344} - USB: iowarrior: fix use-after-free on disconnect race {CVE-2026-64341} - udf: validate VAT header length against the VAT inode size {CVE-2026-64323} - udf: validate sparing table length as an entry count, not a byte count {CVE-2026-64322} - can: bcm: track a single source interface for ANYDEV timeout/throttle ops {CVE-2026-72115} - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() {CVE-2026-72117} - can: bcm: fix stale rx/tx ops after device removal {CVE-2026-72116} - can: bcm: add missing device refcount for CAN filter removal {CVE-2026-72113} - scsi: libiscsi: Move ehwait initialization to iscsi_session_setup() {CVE-2021-47328} - sctp: validate cookie AUTH state before use {CVE-2026-74752} - drm/amdgpu: reject oversized IBs with per-ring packet limits {CVE-2026-80576} - libceph: Avoid using invalid osd indices from primary_temp {CVE-2026-80558} - can: bcm: restore op->flags assignment lost in the bcm_tx_lock backport {CVE-2025-38004} - can: bcm: fix CAN frame rx/tx statistics {CVE-2026-72118} - can: bcm: add locking when updating filter and timer values {CVE-2026-72121} - can: bcm: fix out-of-bounds frame read introduced by the bcm_tx_lock backport {CVE-2025-38004} - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() {CVE-2026-72308} - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure {CVE-2026-72122} - can: bcm: fix warning in bcm_connect/proc_register {CVE-2026-72113} - ipv4: fix use-after-free in fib_nhc_update_mtu() {CVE-2026-74656} - perf/core: Fix group leader use-after-free after sibling detach {CVE-2026-74637} - sctp: fix use-after-free of cached ASCONF chunk {CVE-2026-74587} - sctp: clear control chunk transport if it is being removed {CVE-2026-74688} - ALSA: usb-audio: fix OOB write on Type II inbound URBs {CVE-2026-74682} - ALSA: usx2y: bound the hwdep mmap fault offset {CVE-2026-74641} - enic: fix tx_hang_reset use-after-free on device removal {CVE-2026-74725} - udp: fix potential use-after-free in tunnel segmentation {CVE-2026-74705} - ip6_tunnel: clear skb2->cb[] in ip6ip6_err() {CVE-2026-74597} - ipv6: prevent in6_dev_get() from resurrecting inet6_dev {CVE-2026-74630} - vhost: reset the vring metadata cache on vring reconfiguration {CVE-2026-74580} - PCI: serialize driver_override to fix use-after-free in pci_match_device() {CVE-2026-53120} - iommu/vt-d: Clear Present bit before tearing down context entry {CVE-2026-45944} - ipmi: Add limits to event and receive message requests {CVE-2026-46177} - RDMA/srp: bound SRP_RSP sense copy by the received length {CVE-2026-53186} - ext4: improve error handling from ext4_dirhash() {CVE-2023-53473} - scsi: iscsi: Fix conn use after free during resets {CVE-2021-47328}
Updated packages:
  • bpftool-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:0622e8fc38e2680a97a19580377a893ac1a13fe2c764e985d2c3a8e5f9ef4781
  • kernel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:3cfb04c9e6edef17f412a976bed52881b3c44dfde69ef21b0d24d47b2164ced4
  • kernel-debug-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:ed8f2b8ef850fe674258896b5231853de7b44a52d4f32478149ec0917f6f8157
  • kernel-debug-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:b9d48c81428753c88bb6f80b8ea535f0feb69f506c9f986f97a37f3389de96a7
  • kernel-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:236d9e11bbecdfcf00562a4d24299a9a31ffcf75af3f409ebf9dc3d360571b57
  • kernel-doc-3.10.0-1160.156.1.el7.tuxcare.els4.noarch.rpm
    sha:b2eb0524bcd4506a520577fa24e0dff2516bcd54f2a9961aacadbef408652651
  • kernel-headers-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:dc344a013321cba17f92f5cdf9392978bff4ead0fbd0d11f9a3c6b1542691a5a
  • kernel-tools-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:722ca533afa6e2a3a2ac67406bd59233e14c0b5d1538c1276d3abd18b1472cfb
  • kernel-tools-libs-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:f94d6818996257cf8c86fb41e54af1583eee60faf21c1a370559d42f64c9f788
  • kernel-tools-libs-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:56121f81544b71f2dcaff184772b1e38c9fcd579042ec40243f3bbabd28d1e6f
  • perf-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:f053ebb11babb6d3379e92a2da77c52eca93c5c8e4e0d382ce3df9d9f8ee930c
  • python-perf-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
    sha:76e481c59ea3f034333582f8b1bd96c14460cb773e6bd1d653f77e6ba4df4b8a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.