[CLSA-2026:1781347338] kernel: Fix of 88 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-13 14:51:59 UTC
Description:
- octeontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.c {CVE-2024-56726} - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_common.c {CVE-2024-56679} - USB: chipidea: fix memory leak with using debugfs_lookup() {CVE-2023-53334} - drivers: serial: jsm: fix some leaks in probe {CVE-2022-50312} - drm: amd: display: Fix memory leakage {CVE-2023-53605} - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent {CVE-2026-43026} - net: Drop the lock in skb_may_tx_timestamp() {CVE-2026-43216} - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep {CVE-2026-43381} - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() {CVE-2026-43068} - net: mdio: unexport __init-annotated mdio_bus_init() {CVE-2022-49350} - netfilter: ipset: Rework long task execution when adding/deleting entries {CVE-2023-53549} - ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() {CVE-2023-53275} - thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash {CVE-2022-50494} - can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message {CVE-2026-23307} - usb: image: mdc800: kill download URB on timeout {CVE-2026-43425} - tipc: fix divide-by-zero in tipc_sk_filter_connect() {CVE-2026-43411} - cgroup/cpuset: Fix wrong check in update_parent_subparts_cpumask() {CVE-2023-52942} - net/usb: kalmia: Don't pass act_len in usb_bulk_msg error path {CVE-2023-52703} - usb: typec: tcpci: fix of node refcount leak in tcpci_register_port() {CVE-2022-50246} - bus: mhi: host: Range check CHDBOFF and ERDBOFF {CVE-2023-53598} - hwmon: (coretemp) Simplify platform device handling {CVE-2023-53612} - scsi: mpi3mr: Avoid memcpy field-spanning write WARNING {CVE-2024-36920} - dm crypt: add cond_resched() to dmcrypt_write() {CVE-2023-53051} - xfrm: account XFRMA_IF_ID in aevent size calculation {CVE-2026-43107} - wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he() {CVE-2024-43879} - RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() {CVE-2023-53335} - regulator: check that dummy regulator has been probed before using it {CVE-2025-22008} - HID: prodikeys: Check presence of pm->input_ep82 {CVE-2026-43251} - perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init() {CVE-2022-50510} - wifi: ath11k: fix dfs radar event locking {CVE-2023-52798} - trace/blktrace: fix memory leak with using debugfs_lookup() {CVE-2023-53408} - dm-verity: correctly handle dm_bufio_client_create() failure {CVE-2026-43132} - pstore: ram_core: fix incorrect success return when vmap() fails {CVE-2026-43124} - crypto: af-alg - fix NULL pointer dereference in scatterwalk {CVE-2026-43043} - net: use skb_header_pointer() for TCPv4 GSO frag_off check {CVE-2026-43036} - scsi: mpi3mr: Fix config page DMA memory leak {CVE-2023-53120} - net/mlx5: handle errors in mlx5_chains_create_table() {CVE-2025-21975} - net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx {CVE-2023-53546} - drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() {CVE-2025-37852} - bpf: Prevent decl_tag from being referenced in func_proto arg {CVE-2022-50883} - arm64: set __exception_irq_entry with __irq_entry as a default {CVE-2023-54322} - class: fix possible memory leak in __class_register() {CVE-2022-50578} - ALSA: usb-audio: Stop parsing channels bits when all channels are found. {CVE-2024-27436} - net/mlx5: fix potential memory leak in mlx5e_init_rep_rx {CVE-2023-54106} - net/mlx5: E-Switch, Fix an Oops in error handling code {CVE-2023-53058} - scsi: scsi_dh_alua: Fix memleak for 'qdata' in alua_activate() {CVE-2023-53078} - ice: xsk: disable txq irq before flushing hw {CVE-2023-53102} - selinux: fix memleak in security_read_state_kernel() {CVE-2022-50201} - efi: runtime: Fix potential overflow of soft-reserved region size {CVE-2024-26843} - drm/amdgpu: Fix potential null pointer derefernce {CVE-2023-52814} - ata: libata-core: Fix null pointer dereference on error {CVE-2024-41098} - atm: lec: fix null-ptr-deref in lec_arp_clear_vccs {CVE-2026-23286} - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() {CVE-2026-23304} - drm/amd/display: Fix system hang while resume with TBT monitor {CVE-2024-50003} - netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator {CVE-2026-43085} - KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION {CVE-2026-31590} - l2tp: Drop large packets with UDP encap {CVE-2026-43080} - tun: limit printing rate when illegal packet received by tun dev {CVE-2024-27013} - xfrm: always flush state and policy upon NETDEV_UNREGISTER event {CVE-2026-43167} - KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding {CVE-2026-43315} - xenbus: Use kref to track req lifetime {CVE-2025-37949} - wifi: prevent A-MSDU attacks in mesh networks {CVE-2025-38512} - KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS {CVE-2024-46830} - scsi: smartpqi: Fix disable_managed_interrupts {CVE-2024-26742} - IB/mlx5: Fix init stage error handling to avoid double free of same QP and UAF {CVE-2023-52851} - vhost-vdpa: fix use after free in vhost_vdpa_probe() {CVE-2023-52795} - ndisc: ndisc_send_redirect() cleanup - ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu() - ipv4: use RCU protection in ip_dst_mtu_maybe_forward() - ipv6: icmp: convert to dev_net_rcu() - ipv4: icmp: convert to dev_net_rcu() - ipv4: use RCU protection in __ip_rt_update_pmtu() {CVE-2025-21766} - ipv6: use RCU protection in ip6_default_advmss() {CVE-2025-21765} - fix: ndisc: use RCU protection in ndisc_alloc_skb() {CVE-2025-21764} - neighbour: use RCU protection in __neigh_notify() {CVE-2025-21763} - arp: use RCU protection in arp_xmit() {CVE-2025-21762} - openvswitch: use RCU protection in ovs_vport_cmd_fill_info() {CVE-2025-21761} - ndisc: extend RCU protection in ndisc_send_skb() {CVE-2025-21760} - ipv6: mcast: extend RCU protection in igmp6_send() {CVE-2025-21759} - ipv6: mcast: add RCU protection to mld_newpack() {CVE-2025-21758} - ipv4: use RCU protection in rt_is_expired() - ipv4: use RCU protection in inet_select_addr() - ipv4: add RCU protection to ip4_dst_hoplimit() - flow_dissector: use RCU protection to fetch dev_net() - net: add dev_net_rcu() helper - net: treat possible_net_t net pointer as an RCU one and add read_pnet_rcu() - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress {CVE-2023-52974} - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency {CVE-2024-47696} - perf/x86/amd/core: Always clear status for idx {CVE-2023-53073} - tcp_bpf: fix return value of tcp_bpf_sendmsg() {CVE-2024-46783} - RDMA/umem: Fix double dma_buf_unpin in failure path {CVE-2026-43128} - netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() {CVE-2026-43453} - drm/ttm: Fix a NULL pointer dereference {CVE-2023-53095} - net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak {CVE-2026-43035} - fbcon: check return value of con2fb_acquire_newinfo() {CVE-2026-43123} - ipv4: prevent potential spectre v1 gadget in fib_metrics_match() {CVE-2023-52996} - perf/x86/intel/uncore: Skip discovery table for offline dies {CVE-2026-43079} - mm/page_alloc: clear page->private in free_pages_prepare() {CVE-2026-43303} - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold {CVE-2026-31408} - netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() {CVE-2026-23111} - netfilter: nf_tables: restore set elements when delete set fails {CVE-2024-27012} - drm/amdkfd: Correct the migration DMA map direction {CVE-2024-57897}
Updated packages:
  • bpftool-7.0.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:3069cac74f3f070575fb35eae15bbf9cc1fd79c7768c348b9f71b36b1df02689
  • kernel-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:ac012e32134d98b16b16515b02d132e381b8f0cf8e93de79cdf379f1a62cb67d
  • kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.11.els4.noarch.rpm
    sha:f5942c2d1cc7fed5dffad354c55c89afc50f36bc73f38fcf446f0f18b7774563
  • kernel-core-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:6caf3b2d3e70a3a09fbf6b4602b3eda107877a46729c59fb6c0ddbb090d73ea5
  • kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:0f56b137636beb88382ff4ff70664f7e18a0c7466a17f55392d35ba0820b146d
  • kernel-debug-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:769e2f4b24c066b0e347f4c4f4f9f6a3874299c43f66754e047e5a1295a89c42
  • kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:fa3a79291588a8eb75724e1e2fa61e9a342b8687d9a0e8da764477dce568f278
  • kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:d094ba5f1018d298bc035bebb2ed2d3969ca435277dd42e3631753a9fbbea45b
  • kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:088d646f2f5418cdf1db0b04dd6e4160812f5ceaeb016b722ca14750fa3283d1
  • kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:c61d552ccc73b3f6d15aa35545bce9c2c9c22f4d8e6b82d8c3ecdd27888599c7
  • kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:172cc0fe5ff3179539b2cb9e1c45c6bb693fe1f968e149453efaca45b0a9c6d2
  • kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:b27e078fefea10bdc8cec17e6e9e6eecc7507889b07992e2f645e1ea1be52faa
  • kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:c9a84ec9074fc489948abd928efc2befcb08c09657f432fa9db010d155195800
  • kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:7ca756e77e956bbcc30086d5893a4eaf912c04386ad86ddb0fb4614b8f049097
  • kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:9b835b2d88b904375a56bfb6d337487401141f3cf8db0191f4a706add520e7aa
  • kernel-devel-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:5b3db9f8a6a6fa9ebf8a72f981cb7d2ac8bfda484f8bd9e3faf44151b412a9fb
  • kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:577ce933d92e5b006a62dfb9cff253746aaabe9b7dc0b84d10a047af37b40859
  • kernel-doc-5.14.0-284.1101.el9_2.tuxcare.11.els4.noarch.rpm
    sha:403e11ad598fb709b4d5d45c2fe9b8326d53b398370f83a4839de5300273fd7f
  • kernel-headers-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:3f98ac2f3b819165a0c09140a8e25c415f50277d1c36d70da4e29dc6d7b465c7
  • kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:31fa8e805f00767ec1d245d891adb47145eb442586818df32b49dba6c0bb63b5
  • kernel-modules-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:172d27f916ff4142b6e6f2e095c4c6d23365c9e9cd93723ca536f5ff6c75ce19
  • kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:fc27cf33f296e6c08db3af1d03b1cc32e729b82b4162a75651131dd6d5ea6c18
  • kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:5e2f02e09b77224f9fe9b4784a2d23fa710f4ae4c087405846d8788801f26ba7
  • kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:5b720906b969b4b98a565d37e8b821105e1be01c85acd7ca2102f60b2ab2fa20
  • kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:f943aac3c3027558d90210327eac1b418299cdd2013b6766921eb5e988414d4c
  • kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:8085813fe5450a8a8e8ba6717027a0d431c258a3353b2b902602c27789c96101
  • kernel-tools-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:e244a8f38356f1a319974f9d755756fbbad30a0849edc57b2cc0dbe626608cfe
  • kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:63ea79d4fa6d2ba2d8125eff552a8a48515dc189af59c885955aa46066b197b2
  • kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:7965f831e9fe3ecdb44df290206d19dd8be5d9dc7413d1b2be68597c4d3fa232
  • kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:6dff1cf3cbd91b9d42285a9276e2926e3d4f9182e1ad95e8b16bec374da7dc27
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els4.i686.rpm
    sha:a44352ea0b2443f97a247bac899c70fe480b21100f0c75e31d7a668a5263f765
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:b3466a1b3ca432bd4c5d582b17bcfcb9ab3a1584bcb5e6e3ab35c90acc08a9bc
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els4.i686.rpm
    sha:ab668eb9b2c851d8677e1d512b3b660d9ded2c3df94d62b7def828d2462e52ca
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:f74fd1ff5ab205415194d6c9f0af0ad3bb4218f2eed87bcd6097eb0054af4098
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els4.i686.rpm
    sha:e386f313ece7b9d942a692e0ba69c9984eedc33c3f29db4275eef4a6a4245630
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:03d4f9f16dcf8287503910e6680f28ec66bdd405cde8f4a8f1dab092a0cc5fed
  • perf-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:90b56b5f692189fef94e3507b164d444169101ac9affd379c2de0aa8841793a9
  • python3-perf-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:7d097bb2b4840798c2351416d156f50ebc5cc4114702e38c41a575529156d19a
  • rtla-5.14.0-284.1101.el9_2.tuxcare.11.els4.x86_64.rpm
    sha:3f350c4ab89d160e9d48d074e1947eb6bf6d5994eff20b580f83398ca01588a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.