[CLSA-2026:1788170774] kernel: Fix of 132 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-31 10:08:23 UTC
Description:
- sctp: fix potential deadlock on &net->sctp.addr_wq_lock {CVE-2024-0639} - sctp: delay auto_asconf init until binding the first addr {CVE-2021-23133} - netfilter: nf_log: validate MAC header was set before dumping it {CVE-2026-52942} - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check {CVE-2026-52998} - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check {CVE-2026-46006} - btrfs: fix use-after-free when attempting to join an aborted transaction {CVE-2025-21753} - btrfs: qgroup: fix race between quota disable and quota rescan ioctl {CVE-2025-39759} - team: fix header_ops type confusion with non-Ethernet ports {CVE-2026-31502} - xfrm: Fix dev use-after-free in xfrm async resumption {CVE-2026-72463} - xfrm: hold dev ref until after transport_finish NF_HOOK {CVE-2026-31663} - xen/privcmd: restrict usage in unprivileged domU {CVE-2026-31788} - xen/privcmd: add IOCTL_PRIVCMD_RESTRICT {CVE-2026-31788} - Bluetooth: L2CAP: make l2cap_connect() return void {CVE-2024-36013} - btrfs: fix incorrect splitting in btrfs_drop_extent_map_range {CVE-2023-54121} - netfilter: nf_conntrack: defer invalid log until after unlock {CVE-2026-74624} - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call {CVE-2026-74730} - dm cache: fix flushing uninitialized delayed_work on cache_ctr error {CVE-2024-50280} - audit: fix recursive locking deadlock in audit_dupe_exe() {CVE-2026-68096} - RDMA/rxe: Reject unknown opcodes before ICRC processing {CVE-2026-46133} - Bluetooth: bnep: reject short frames before parsing {CVE-2026-53253} - net: pull headers in qdisc_pkt_len_segs_init() {CVE-2026-53091} - inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP {CVE-2026-46266} - Bluetooth: RFCOMM: validate skb length in MCC handlers {CVE-2026-53254} - sched, cpuset: Fix dl_cpu_busy() panic due to empty cs->cpus_allowed {CVE-2022-50103} - btrfs: qgroup: fix race between quota disable and quota rescan ioctl {CVE-2025-39759} - fanotify: fix false positive on permission events {CVE-2026-46150} - HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() {CVE-2025-38103} - ext4: fix e4b bitmap inconsistency reports {CVE-2026-45942} - Bluetooth: serialize accept_q access {CVE-2026-52918} - ALSA: usb-audio: Add sanity check for OOB writes at silencing {CVE-2026-43279} - RDMA/bnxt_re: zero shared page before exposing to userspace {CVE-2026-74584} - sctp: keep chunk->transport in step with the list it is queued on {CVE-2026-74588} - ipvs: clear IPv4 options after rebasing tunnel ICMP errors {CVE-2026-74669} - wifi: cfg80211: Partial revert "wifi: cfg80211: Fix use after free for wext" {CVE-2023-53153} - net/sched: cls_route: fix fastmap use-after-free on filter {CVE-2026-74583} - nfs: use nfsi->rwsem to protect traversal of the file lock list {CVE-2026-72472} - Bluetooth: RFCOMM: Fix session UAF in set_termios {CVE-2026-68188} - drm/amdgpu/vce: fix integer overflow in image size {CVE-2026-68108} - ALSA: seq: close a re-opened queue timer in the destructor {CVE-2026-68202} - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() {CVE-2026-74499} - USB: serial: io_edgeport: cap received transmit credits {CVE-2026-68365} - net: slip: serialize receive against buffer reallocation {CVE-2026-68143} - wifi: cfg80211: cancel sched scan results work on unregister {CVE-2026-68414} - sctp: fix auth_hmacs array size in struct sctp_cookie {CVE-2026-68376} - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid {CVE-2026-68320} - pppoe: reload header pointer after dev_hard_header() {CVE-2026-68121} - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() {CVE-2026-68160} - libceph: refresh auth->authorizer_buf{,_len} after authorizer update {CVE-2026-68156} - libceph: remove debugfs files before client teardown {CVE-2026-68153} - libceph: Fix multiplication overflow in decode_new_up_state_weight() {CVE-2026-68158} - libceph: reject zero bucket types in crush_decode {CVE-2026-68154} - libceph: bound get_version reply decode to front len {CVE-2026-68433} - libceph: Reject monmaps advertising zero monitors {CVE-2026-68155} - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug {CVE-2026-68093} - hwmon: adm1275: Prevent reading uninitialized stack {CVE-2026-72396} - fuse: re-lock request before returning from fuse_ref_folio() {CVE-2026-64266} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC {CVE-2026-64298} - perf/x86/amd: Check event before enable to avoid GPF {CVE-2025-68798} - xen: Add support for XenServer 6.1 platform device {CVE-2025-38046} - openvswitch: fix GSO userspace truncation underflow {CVE-2026-68123} - RDMA/rxe: Fix a use-after-free problem in rxe_mmap {CVE-2026-64582} - btrfs: reject free space cache with more entries than pages {CVE-2026-64567} - media: cx23885: add ioremap return check and cleanup {CVE-2026-68226} - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev {CVE-2026-68176} - scsi: hpsa: Fix possible memory leak in hpsa_init_one() {CVE-2022-50646} - netfilter: ebtables: fix table blob use-after-free {CVE-2023-54243} - nfsd: provide locking for v4_end_grace {CVE-2026-22980} - dm cache: Fix UAF in destroy() {CVE-2022-50496} - xhci: Remove device endpoints from bandwidth list when freeing the device {CVE-2022-50470} - dm btree remove: fix use after free in rebalance_children() {CVE-2021-47600} - drm: Fix use-after-free read in drm_getunique() {CVE-2021-47280} - smb: client: fix krb5 mount with username option {CVE-2026-31392} - sctp: validate embedded INIT chunk and address list lengths in cookie {CVE-2026-53224} - rbd: avoid use-after-free in do_rbd_add() when rbd_dev_create() fails {CVE-2023-53307} - libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() {CVE-2026-52956} - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path {CVE-2026-46189} - bonding: alb: fix UAF in rlb_arp_recv during bond up/down {CVE-2026-45970} - ipv6: prevent possible UaF in addrconf_permanent_addr() {CVE-2026-43339} - scsi: megaraid_sas: Fix invalid node index {CVE-2025-38239} - netfilter: ctnetlink: ensure safe access to master conntrack {CVE-2026-43116} - netfilter: require Ethernet MAC header before using eth_hdr() {CVE-2026-53131} - bpf, net: add skb_mac_header_len helper {CVE-2026-53131} - gfs2: Fix use-after-free in iomap inline data write path {CVE-2026-45984} - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache {CVE-2026-46174} - crypto: pcrypt - Fix handling of MAY_BACKLOG requests {CVE-2026-43493} - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() {CVE-2026-46149} - netfilter: xt_policy: fix strict mode inbound policy matching {CVE-2026-52920} - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction {CVE-2025-38211} - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency {CVE-2024-47696} - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs {CVE-2024-42285} - ceph: only d_add() negative dentries when they are unhashed {CVE-2026-46052} - ipvs: clear the svc scheduler ptr early on edit {CVE-2026-53270} - kernfs: fix use-after-free in __kernfs_remove {CVE-2022-50432} - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls {CVE-2026-53075} - Bluetooth: MGMT: validate advertising TLV before type checks {CVE-2026-53255} - Bluetooth: mgmt: Fix slab-out-of-bounds in tlv_data_is_valid {CVE-2026-53255} - gfs2: Fix slab-use-after-free in qd_put {CVE-2026-45861} - ipv6: sit: reload inner IPv6 header after GSO offloads {CVE-2026-53228} - Bluetooth: SMP: force responder MITM requirements before building the pairing response {CVE-2026-43334} - ipv6: mcast: Fix use-after-free when processing MLD queries {CVE-2026-53275} - netfilter: conntrack_irc: fix possible out-of-bounds read {CVE-2026-53268} - netfilter: conntrack: remove sprintf usage {CVE-2026-53002} - netfilter: nf_conntrack_sip: don't use simple_strtoul {CVE-2026-52986} - dm cache policy smq: check allocation under invalidate lock {CVE-2026-53265} - dm cache policy smq: fix missing locks in invalidating cache blocks {CVE-2026-53062} - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send {CVE-2026-45856} - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() {CVE-2026-53256} - Bluetooth: hci_event: fix potential UAF in SSP passkey handlers {CVE-2026-46056} - libceph: Fix potential null-ptr-deref in decode_choose_args() {CVE-2026-52957} - wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() {CVE-2022-50551} - HID: multitouch: Add NULL check in mt_input_configured {CVE-2024-58020} - HID: multitouch: Correct devm device reference for hidinput input_dev name {CVE-2023-53454} - net/sched: act_api: use RCU with deferred freeing for action lifecycle {CVE-2026-53264} - sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing {CVE-2026-53246} - perf/core: Prevent VMA split of buffer mappings {CVE-2025-38563} - ice: fix double-free of tx_buf skb {CVE-2026-53009} - procfs: fix missing RCU protection when reading real_parent in do_task_stat() {CVE-2026-46259} - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv {CVE-2026-46043} - Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() {CVE-2024-36013} - ndisc: use RCU protection in ndisc_alloc_skb() {CVE-2025-21764} - Bluetooth: Fix use after free in hci_send_acl {CVE-2022-49111} - scsi: megaraid_sas: Fix invalid node index {CVE-2025-38239} - Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock {CVE-2026-31500} - ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size {CVE-2023-53265} - bonding: limit BOND_MODE_8023AD to Ethernet devices {CVE-2026-23099} - wifi: cfg80211: Fix use after free for wext {CVE-2023-53153} - ubi: ensure that VID header offset + VID header size <= alloc, size {CVE-2023-53265} - btrfs: reserve enough transaction items for qgroup ioctls {CVE-2026-43338} - ACPICA: Fix error code path in acpi_ds_call_control_method() {CVE-2022-50411} - drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 {CVE-2023-52818} - scsi: mpt3sas: Fix kernel panic during drive powercycle test {CVE-2021-47565} - mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() {CVE-2026-43281} - wifi: mac80211: Fix UAF in ieee80211_scan_rx() {CVE-2022-49934} - drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers() {CVE-2022-50185} - iavf: Fix use-after-free in free_netdev {CVE-2023-53556} - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf {CVE-2023-53524} - ALSA: usb-audio: Use correct version for UAC3 header validation {CVE-2026-23318} - nvdimm/bus: Fix potential use after free in asynchronous initialization {CVE-2026-31399} - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress {CVE-2023-52974} - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet {CVE-2026-53112} - media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init {CVE-2022-49478} - staging: rtl8712: fix use-after-free in rtl8712_dl_fw {CVE-2021-47479} - usbnet: Fix linkwatch use-after-free on disconnect {CVE-2022-50220} - kernel.spec: debrand and drop every per-vendor conditional — one build for centos7/rhel7/ol7 - kernel.spec: build the noarch kernel-doc package in the normal pass - kernel.spec: replace vendor secure-boot certs with the tuxcare ones we sign with
CVEs fixed:
Updated packages:
  • bpftool-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:42663df63b385021c878174273d470b69b4561d77cabf548834ef9cb4a4fd033
  • kernel-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:542022b05b4b96464a214770900cec5ec63c29887af6c5106fa632c003c20a00
  • kernel-debug-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:ccaaa7fb5193141564facf9b4e3e1be564c09d058f6a1dc68757567ef81000f0
  • kernel-debug-devel-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:f44e4631d165a4ac0e49da26c6034755c920de68f234dac4a3fb418c1e2a3401
  • kernel-devel-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:f5b8356437b3ab9a4ecb099c6cb20b748e600ac1efa4da3ef5228614c5b75e7c
  • kernel-doc-3.10.0-1160.156.1.el7.tuxcare.els3.noarch.rpm
    sha:0a7015f6c3866163f2bf22670e328b1f732dd1f8693c1628e4a3adce9a64fc92
  • kernel-headers-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:99dc3e4e7fc1a72389564af7d98c5d8d3f5cdc82bc26a17e9a2f25e68c20834f
  • kernel-tools-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:672ea30755f41da823948a97a882bf95108022038e6e90c42b8fe19483a9412d
  • kernel-tools-libs-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:7a3846083d9cfabb73bc87b3e0c38f3fe19c1ddc66c15cf550143347cda6b3ea
  • kernel-tools-libs-devel-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:cee4707fc560322f074a70a2986fe0f9974f80e4194b1616c583c4d9b7cd4811
  • perf-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:fc5fff5d475806b21cd326b248d8ecf7513c57af95a6abd354c9fac8374c9f46
  • python-perf-3.10.0-1160.156.1.el7.tuxcare.els3.x86_64.rpm
    sha:8341730e51b90a083f17780767302b949c92b78112a2d9d626157753a526cf99
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.