Release date:
2026-09-10 11:31:59 UTC
Description:
- net: openvswitch: fix skb leak on flow key update failure during ct {CVE-2026-74464}
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error {CVE-2026-74456}
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations {CVE-2026-68469}
- drm/amdgpu/gfx8: drop unecessary BUG_ON() {CVE-2026-68430}
- sctp: auth: verify auth requirement when auth_chunk is NULL {CVE-2026-68300}
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL {CVE-2026-68184}
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read {CVE-2026-68351}
- wifi: carl9170: fix buffer overflow in rx_stream failover path {CVE-2026-68349}
- wifi: carl9170: fix OOB read from off-by-two in TX status handler {CVE-2026-68350}
- net: sit: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72061}
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72055}
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72054}
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72053}
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-72051}
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink {CVE-2026-63829}
- usb: free iso schedules on failed submit {CVE-2026-64348}
- smb: client: restrict implied bcc[0] exemption to responses without data area {CVE-2026-64448}
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes {CVE-2026-64422}
- netfilter: ebtables: terminate table name before find_table_lock() {CVE-2026-64411}
- netfilter: ebtables: zero chainstack array {CVE-2026-64413}
- USB: idmouse: fix use-after-free on disconnect race {CVE-2026-64344}
- USB: iowarrior: fix use-after-free on disconnect race {CVE-2026-64341}
- udf: validate VAT header length against the VAT inode size {CVE-2026-64323}
- udf: validate sparing table length as an entry count, not a byte count {CVE-2026-64322}
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops {CVE-2026-72115}
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() {CVE-2026-72117}
- can: bcm: fix stale rx/tx ops after device removal {CVE-2026-72116}
- can: bcm: add missing device refcount for CAN filter removal {CVE-2026-72113}
- scsi: libiscsi: Move ehwait initialization to iscsi_session_setup() {CVE-2021-47328}
- sctp: validate cookie AUTH state before use {CVE-2026-74752}
- drm/amdgpu: reject oversized IBs with per-ring packet limits {CVE-2026-80576}
- libceph: Avoid using invalid osd indices from primary_temp {CVE-2026-80558}
- can: bcm: restore op->flags assignment lost in the bcm_tx_lock backport {CVE-2025-38004}
- can: bcm: fix CAN frame rx/tx statistics {CVE-2026-72118}
- can: bcm: add locking when updating filter and timer values {CVE-2026-72121}
- can: bcm: fix out-of-bounds frame read introduced by the bcm_tx_lock backport {CVE-2025-38004}
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() {CVE-2026-72308}
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure {CVE-2026-72122}
- can: bcm: fix warning in bcm_connect/proc_register {CVE-2026-72113}
- ipv4: fix use-after-free in fib_nhc_update_mtu() {CVE-2026-74656}
- perf/core: Fix group leader use-after-free after sibling detach {CVE-2026-74637}
- sctp: fix use-after-free of cached ASCONF chunk {CVE-2026-74587}
- sctp: clear control chunk transport if it is being removed {CVE-2026-74688}
- ALSA: usb-audio: fix OOB write on Type II inbound URBs {CVE-2026-74682}
- ALSA: usx2y: bound the hwdep mmap fault offset {CVE-2026-74641}
- enic: fix tx_hang_reset use-after-free on device removal {CVE-2026-74725}
- udp: fix potential use-after-free in tunnel segmentation {CVE-2026-74705}
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() {CVE-2026-74597}
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev {CVE-2026-74630}
- vhost: reset the vring metadata cache on vring reconfiguration {CVE-2026-74580}
- PCI: serialize driver_override to fix use-after-free in pci_match_device() {CVE-2026-53120}
- iommu/vt-d: Clear Present bit before tearing down context entry {CVE-2026-45944}
- ipmi: Add limits to event and receive message requests {CVE-2026-46177}
- RDMA/srp: bound SRP_RSP sense copy by the received length {CVE-2026-53186}
- ext4: improve error handling from ext4_dirhash() {CVE-2023-53473}
- scsi: iscsi: Fix conn use after free during resets {CVE-2021-47328}
Updated packages:
-
bpftool-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:0622e8fc38e2680a97a19580377a893ac1a13fe2c764e985d2c3a8e5f9ef4781
-
kernel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:3cfb04c9e6edef17f412a976bed52881b3c44dfde69ef21b0d24d47b2164ced4
-
kernel-debug-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:ed8f2b8ef850fe674258896b5231853de7b44a52d4f32478149ec0917f6f8157
-
kernel-debug-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:b9d48c81428753c88bb6f80b8ea535f0feb69f506c9f986f97a37f3389de96a7
-
kernel-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:236d9e11bbecdfcf00562a4d24299a9a31ffcf75af3f409ebf9dc3d360571b57
-
kernel-doc-3.10.0-1160.156.1.el7.tuxcare.els4.noarch.rpm
sha:b2eb0524bcd4506a520577fa24e0dff2516bcd54f2a9961aacadbef408652651
-
kernel-headers-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:dc344a013321cba17f92f5cdf9392978bff4ead0fbd0d11f9a3c6b1542691a5a
-
kernel-tools-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:722ca533afa6e2a3a2ac67406bd59233e14c0b5d1538c1276d3abd18b1472cfb
-
kernel-tools-libs-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:f94d6818996257cf8c86fb41e54af1583eee60faf21c1a370559d42f64c9f788
-
kernel-tools-libs-devel-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:56121f81544b71f2dcaff184772b1e38c9fcd579042ec40243f3bbabd28d1e6f
-
perf-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:f053ebb11babb6d3379e92a2da77c52eca93c5c8e4e0d382ce3df9d9f8ee930c
-
python-perf-3.10.0-1160.156.1.el7.tuxcare.els4.x86_64.rpm
sha:76e481c59ea3f034333582f8b1bd96c14460cb773e6bd1d653f77e6ba4df4b8a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.