[CLSA-2026:1780516677] kernel: Fix of 134 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-09 08:15:27 UTC
Description:
- atm: lec: fix use-after-free in sock_def_readable() {CVE-2026-43050} - ALSA: usb-audio: Use the right limit for PCM OOB check - ALSA: usb-audio: Prevent excessive number of frames {CVE-2026-23208} - xen/privcmd: fix double free via VMA splitting {CVE-2026-31787} - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path {CVE-2026-43328} - cpufreq: governor: Free dbs_data directly when gov->init() fails {CVE-2026-43328} - rcu: Fix rcu_read_unlock() deadloop due to softirq - rcu: Fix racy re-initialization of irq_work causing hangs - RDMA/efa: Fix possible deadlock {CVE-2026-31493} - RDMA/efa: Fix use of completion ctx after free {CVE-2026-31493} - RDMA/efa: Improve admin completion context state machine {CVE-2026-31493} - RDMA/efa: Check stored completion CTX command ID with received one {CVE-2026-31493} - RDMA/efa: Extend admin timeout error print - RDMA/efa: Properly handle unexpected AQ completions {CVE-2026-31493} - rcu: Fix rcu_read_unlock() deadloop due to IRQ work {CVE-2025-39744} - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() {CVE-2026-23455} - rtnetlink: Allocate vfinfo size for VF GUIDs when supported {CVE-2025-22075} - kernel/printk/index.c: fix memory leak with using debugfs_lookup() {CVE-2023-53402} - wifi: iwlwifi: don't warn when if there is a FW error {CVE-2025-38096} - md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() {CVE-2023-53210} - exfat: fix the infinite loop in exfat_readdir() {CVE-2024-57940} - af_netlink: Fix shift out of bounds in group mask calculation {CVE-2022-49197} - xfrm_user: fix info leak in build_mapping() {CVE-2026-43089} - udf: Fix preallocation discarding at indirect extent boundary {CVE-2022-48946} - efi: Do not import certificates from UEFI Secure Boot for T2 Macs {CVE-2022-49357} - kernel/resource: fix kfree() of bootmem memory again {CVE-2022-49190} - smb: client: fix warning in cifs_smb3_do_mount() {CVE-2023-53230} - sctp: Fix null-ptr-deref in reuseport_add_sock(). {CVE-2024-44935} - RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages {CVE-2024-50208} - drm/amdgpu: avoid using null object of framebuffer {CVE-2024-41093} - firmware: cs_dsp: Return error if block header overflows file {CVE-2024-42238} - ata: libata-sff: Ensure that we cannot write outside the allocated buffer {CVE-2025-21738} - net: hinic: fix memory leak when reading function table {CVE-2022-50438} - device property: fix of node refcount leak in fwnode_graph_get_next_endpoint() {CVE-2022-49752} - libceph: fix race between delayed_work() and ceph_monc_stop() {CVE-2024-42232} - usbnet: fix memory leak in error case {CVE-2022-49657} - hwmon: (w83791d) Convert macros to functions to avoid TOCTOU {CVE-2025-71111} - seccomp: Move copy_seccomp() to no failure path. {CVE-2022-50661} - net/mlx5: fs, lock FTE when checking if active {CVE-2024-53121} - nvme-pci: fix freeing of the HMB descriptor table {CVE-2024-56756} - leds: class: Protect brightness_show() with led_cdev->led_access mutex {CVE-2024-56587} - bpf, sockmap: Check for any of tcp_bpf_prots when cloning a listener {CVE-2023-52986} - RDMA/uverbs: Prevent integer overflow issue {CVE-2024-57890} - sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT {CVE-2026-23125} - tracing: Fix memory leak in test_gen_synth_cmd() and test_empty_synth_event() {CVE-2022-49800} - kprobes: Fix check for probe enabled in kill_kprobe() {CVE-2022-50266} - NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 {CVE-2024-26870} - i915/perf: Fix NULL deref bugs with drm_dbg() calls {CVE-2023-52788} - can: mcp251x: fix deadlock in error path of mcp251x_open {CVE-2026-23357} - regmap-irq: Use the new num_config_regs property in regmap_add_irq_chip_fwnode {CVE-2022-50558} - wifi: cfg80211: Set correct chandef when starting CAC {CVE-2024-49937} - netfilter: nf_tables: prevent nf_skb_duplicated corruption {CVE-2024-49952} - can: isotp: fix potential CAN frame reception race in isotp_rcv() {CVE-2022-48830} - bpf: Fix memory leaks in __check_func_call {CVE-2022-49837} - configfs: fix a race in configfs_{,un}register_subsystem() {CVE-2022-48931} - RDMA/mad: Improve handling of timed out WRs of mad agent {CVE-2024-50095} - cifs: Fix connections leak when tlink setup failed {CVE-2022-49822} - usb: atm: cxacru: fix endpoint checking in cxacru_bind() {CVE-2024-41097} - tcp: add sanity checks to rx zerocopy {CVE-2024-26640} - NFSD: Prevent a potential integer overflow {CVE-2024-53146} - bpf, cpumap: Handle skb as well when clean up ptr_ring {CVE-2023-53660} - team: fix null-ptr-deref when team device type is changed {CVE-2023-52574} - fbdev: efifb: Register sysfs groups through driver core {CVE-2024-49925} - bpf: devmap: provide rxq after redirect {CVE-2024-50162} - net: phy: micrel: Allow probing without .driver_data {CVE-2022-49472} - inotify: Avoid reporting event with invalid wd {CVE-2023-54119} - USB: hub: Ignore non-compliant devices with too many configs or interfaces {CVE-2025-21776} - wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode {CVE-2024-58096} - RDMA/irdma: Fix data race on CQP request done {CVE-2023-54292} - fscache: Fix oops due to race with cookie_lru and use_cookie {CVE-2022-48989} - perf/x86/intel/uncore: Fix NULL pointer dereference issue in upi_fill_topology() {CVE-2023-52450} - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c {CVE-2024-56727} - wifi: iwlwifi: fix debug actions order {CVE-2025-38045} - tracing/hist: Fix out-of-bound write on 'action_data.var_ref_idx' {CVE-2022-50553} - net: ipv4: fix one memleak in __inet_del_ifa() {CVE-2023-53995} - exfat: fix memory leak in exfat_load_bitmap() {CVE-2024-50013} - vp_vdpa: fix id_table array not null terminated error {CVE-2024-53110} - intel_th: Fix a resource leak in an error handling path {CVE-2022-50143} - leds: led-class: Only Add LED to leds_list when it is fully ready {CVE-2026-23101} - usb: gadget: core: Check for unset descriptor {CVE-2024-44960} - drm/amdkfd: Fix lock dependency warning with srcu {CVE-2023-52632} - atm: clip: Fix NULL pointer dereference in vcc_sendmsg() {CVE-2025-38458} - PM / devfreq: Check governor before using governor->name {CVE-2025-38609} - tls: fix missing memory barrier in tls_init {CVE-2024-36489} - cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate() {CVE-2025-37830} - wifi: mt76: mt7921s: fix potential hung tasks during chip recovery {CVE-2024-40977} - nvdimm: Fix firmware activation deadlock scenarios {CVE-2022-49446} - wifi: mac80211: sdata can be NULL during AMPDU start {CVE-2022-48875} - can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods {CVE-2022-49024} - wifi: ath10k: Fix memory leak in management tx {CVE-2024-50236} - vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] {CVE-2025-21666} - netdevsim: fix memory leak in nsim_bus_dev_new() {CVE-2022-50772} - fs: relax assertions on failure to encode file handles {CVE-2024-57924} - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c {CVE-2024-56707} - ceph: fix deadlock or deadcode of misusing dget() {CVE-2023-52583} - bpf, verifier: Fix memory leak in array reallocation for stack state {CVE-2022-49878} - ip6_gre: make ip6gre_header() robust {CVE-2025-71098} - ACPICA: Avoid walking the Namespace if start_node is NULL {CVE-2025-71118} - net/mlx5e: kTLS, Fix incorrect page refcounting {CVE-2024-53138} - gve: Clear napi->skb before dev_kfree_skb_any() {CVE-2024-40937} - atm: clip: Fix memory leak of struct clip_vcc. {CVE-2025-38546} - crypto: seqiv - Do not use req->iv after crypto_aead_encrypt {CVE-2025-71131} - xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration {CVE-2024-45006} - irqchip: Fix refcount leak in platform_irqchip_probe {CVE-2023-53610} - CDC-NCM: avoid overflow in sanity checking {CVE-2022-48938} - Bluetooth: Fix crash when replugging CSR fake controllers {CVE-2022-48982} - platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() {CVE-2022-50521} - ptp: Ensure info->enable callback is always set {CVE-2025-21814} - perf/arm_dmc620: Fix hotplug callback leak in dmc620_pmu_init() {CVE-2022-50820} - drm: Fix potential null-ptr-deref due to drmm_mode_config_init() {CVE-2022-50556} - wifi: rtl8xxxu: Fix memory leaks with RTL8723BU, RTL8192EU {CVE-2023-54036} - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() {CVE-2024-40959} - drm/amdgpu: Fix smatch static checker warning {CVE-2024-46835} - svcrdma: Address an integer overflow {CVE-2024-53151} - dma-debug: fix a possible deadlock on radix_lock {CVE-2024-47143} - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check {CVE-2024-41072} - regulator: core: fix use_count leakage when handling boot-on {CVE-2022-50250} - tpm: use try_get_ops() in tpm-space.c {CVE-2022-49286} - ata: libata-transport: fix error handling in ata_tdev_add() {CVE-2022-49823} - padata: Always leave BHs disabled when running ->parallel() {CVE-2022-50382} - can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak {CVE-2026-23108} - serial: core: check uartclk for zero to avoid divide by zero {CVE-2024-43893} - cifs: fix potential memory leaks in session setup {CVE-2023-53008} - tty: fix out-of-bounds access in tty_driver_lookup_tty() {CVE-2023-54198} - nvdimm: Fix memleak of pmu attr_groups in unregister_nvdimm_pmu() {CVE-2023-53697} - HID: logitech-hidpp: Check maxfield in hidpp_get_report_length() {CVE-2026-43136} - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf {CVE-2025-71120} - drm/ioc32: stop speculation on the drm_compat_ioctl path {CVE-2026-31781} - ext4: fix i_disksize exceeding i_size problem in paritally written case {CVE-2023-53270} - wifi: nl80211: fix NULL-ptr deref in offchan check {CVE-2023-53113} - wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback() {CVE-2023-53717} - ASoC: SOF: Add some bounds checking to firmware data {CVE-2024-26927} - regulator: core: Prevent integer underflow {CVE-2022-50582} - power: supply: fix null pointer dereferencing in power_supply_get_battery_info {CVE-2022-50276} - netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() {CVE-2026-43450} - nvdimm/bus: Fix potential use after free in asynchronous initialization {CVE-2026-31399} - crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id {CVE-2025-68724} - nbd: defer config unlock in nbd_genl_connect {CVE-2025-68366} - netfilter: xt_tcpmss: check remaining length before reading optlen {CVE-2026-43190} - netfilter: ip6t_eui64: reject invalid MAC header for all packets {CVE-2026-31685} - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq {CVE-2026-43051} - xfs: fix freemap adjustments when adding xattrs to leaf blocks {CVE-2026-43158} - wifi: brcmfmac: validate bsscfg indices in IF events {CVE-2026-43110}
CVEs fixed:
Updated packages:
  • bpftool-7.0.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:9e440bf473f751f76f522fd0f5e2d84316fe5b90b90399518f6f9c329d24833a
  • kernel-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:8929101b3c09e0fd4727c1b4010366e02ba173588d2492947f675dbdda14569e
  • kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.11.els3.noarch.rpm
    sha:6f32958d91c7afd9acbc6f341e23673de36960d8754a790c1cadc7881e52af6c
  • kernel-core-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:6410a645fba3597930e7ae13f6a61ddd9b00da98325883a587fdc5f138e345e3
  • kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:0033701e3245822c17b0d9a4b52b6bf2bb29a4883ed991a8ff42a6a5d218a7e9
  • kernel-debug-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:14032c059a4a1465847be397ff549aa0a9021ae90a4a5f662f4ac8826c04a316
  • kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:79ac07d289deeb7c5ca3bf3f15a7ea1bc44d17a006697ed3cf36273861415b0b
  • kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:153a228b3c11c9dcaf84a636e433548d40879edc752ba170d26ea603df2434d7
  • kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:4c0777a4e58a81cc3055ebd6c4d0714b18792b3ad62d407f55642f41b5817896
  • kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:05ce8ff229545d5f89231baed3a05cf7836d814a59b818c7a4c6777867cc43c6
  • kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:f56710039590c3289ed1210b51a7ce43b1c19b03664c1f9307c9f4400e12af79
  • kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:ddf4d0b33d6d808c86bfa0b6d4dd136f040b35e77cfc073c0a9ab7e39a0fa191
  • kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:2ec07fd825090e3081c4e635e9b81e917392693aed773742987793746cbbf2a1
  • kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:f105fe20849992112c77a9713505ad7cfb7b8c11d26a122294dc246368bb9eff
  • kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:ee7303007b2c581e403af6123dbb444e79e295db21d964115836165fba039b4f
  • kernel-devel-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:9ee6617f91f911af477cc6bfd29e8eae164fc3817fb68691675bbad561660387
  • kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:005bbd8726ba83d265db5ab949f284ece61d12ad462c4148ea85057077ae5601
  • kernel-doc-5.14.0-284.1101.el9_2.tuxcare.11.els3.noarch.rpm
    sha:ed68391804425bf67fc2a7a527114aa99e8525fb2ea830fd77930aee8c9a022a
  • kernel-headers-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:73376ad843dcd6ce1197297ae7a33e1edd8e5518c34e8f7b5cda3323efbf57c3
  • kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:2399dd0e03fbc1feada1c0ec46a815fe4c6690833949bafdd9dd6c7d23dacfcb
  • kernel-modules-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:a427d4356d120c5b72a2354a7001a80e9b11626223472e5a479d44f16f5f9703
  • kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:d4777380c869c3578470185241e6d9df884bd9e0c1136c2e0932f7a73f59b728
  • kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:340b28d094c68325dd67d686aa6c4b5337339cce7a3c5de2ad8ca02a6a3f8248
  • kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:8305f75e01b3ea28b9b46653a5774472ee2909b87364dd29bba36fcafa477f87
  • kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:2d9173576ddf51b4cbc79d397b7e1e38646cb4860553a7b2bd464415dbb12edd
  • kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:2da4afab942706523bfd3d6a9a0f3d077027b71aaaa53e53662a8812cc3e9cfc
  • kernel-tools-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:ad765f62c0d8e3b49176c63a064b031136473bf7ee19d2e3ea15ff2298f52d98
  • kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:20b95afce1afee9e8e34e18d4500717f538d8509c7295cc24ccf034c8bafaf82
  • kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:8f008d21affc167ed54e5dca27e2c1fe649edfe63cd8914b3b7b404c73ba5b60
  • kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:ee61f7f77eea075341391bcb89b429072c1243e0d1c80feece764eabe6dc89ba
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els3.i686.rpm
    sha:d83b2c52925a312b99f6b1b457768244293bd17c4eff1e11c43981254f4e34aa
  • libbpf-1.0.0-2.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:60a6a7ffb75c4b40b75eec265a8c1b6b3d06bdfdca031b0f90b6df618ba5a443
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els3.i686.rpm
    sha:0de3d52908ff407f73aa074ab6cf9be3503aa61c8e866e8c8a82a010f2475995
  • libbpf-devel-1.0.0-2.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:0a38a45224f0f354d72ce3cc485dffb2fffb077fe28f539b4e85a25fdf5a4dff
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els3.i686.rpm
    sha:28b53f7a2bd87c88822d2a02ece855e54539548786ef179b1f09e2c78910b718
  • libbpf-static-1.0.0-2.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:242b4c492ebe5444f98d8ec820106813046ad52a5a3963dcc9c8e0f72781610f
  • perf-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:0f81d118103d1dafb517c1d303c5cb927d74332066be1aea2b31ae4b9fbd60d8
  • python3-perf-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:62e82b48d1de5f8b428063fb4eb000d27125ead3d81dbee322734a91e27240f8
  • rtla-5.14.0-284.1101.el9_2.tuxcare.11.els3.x86_64.rpm
    sha:51d7e5131fc69a5a3ed5027d5adc4329cc7bc059513f113b74de82f7ac07ba96
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.