Advisory: CLSA-2025:1764151168
OS: AlmaLinux 9.2 ESU
Public date: 2025-11-26 09:59:29.993485
Project: kernel
Version: 7.0.0-284.1101.el9_2.tuxcare.7.els24
Errata link: https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1764151168.html
- perf/aux: Fix AUX buffer serialization {CVE-2024-46713} - block: fix uaf for flush rq while iterating tags {CVE-2024-53170} - zram: fix potential UAF of zram table {CVE-2025-21671} - sched: sch_cake: add bounds checks to host bulk flow fairness counts {CVE-2025-21647} - bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors {CVE-2024-56675} - net: openvswitch: fix nested key length validation in the set() action {CVE-2025-37789} - isofs: Prevent the use of too small fid {CVE-2025-37780} - net: ppp: Add bound checking for skb data on ppp_sync_txmung {CVE-2025-37749} - sctp: detect and prevent references to a freed transport in sendmsg {CVE-2025-23142} - ipv6: sr: Fix MAC comparison to be constant-time {CVE-2025-39702} - RDMA/rxe: Fix incomplete state save in rxe_requester {CVE-2023-53539} - crypto: xts - Handle EBUSY correctly {CVE-2023-53494} - Bluetooth: use RCU for hci_conn_params and iterate safely in hci_sync {CVE-2023-53252} - af_unix: Fix data-races around user->unix_inflight. {CVE-2023-53204} - fs: fix UAF/GPF bug in nilfs_mdt_destroy {CVE-2022-50367} - wifi: rtlwifi: remove unused check_buddy_priv {CVE-2024-58072} - wifi: rtlwifi: remove unused dualmac control leftovers - wifi: rtlwifi: remove unused timer and related code - partitions: mac: fix handling of bogus partition table {CVE-2025-21772} - ipmr: do not call mr_mfc_uses_dev() for unres entries {CVE-2025-21719} - wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy() {CVE-2024-58014} - net: mdio: validate parameter addr in mdiobus_get_phy() {CVE-2023-53019} - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control {CVE-2025-39751} - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() {CVE-2025-39730} - net/mlx5e: Check for NOT_READY flag state after locking {CVE-2023-53581} - null_blk: Always check queue mode setting from configfs {CVE-2023-53576} - ip_vti: fix potential slab-use-after-free in decode_session6 {CVE-2023-53559} - rcu-tasks: Avoid pr_info() with spin lock in cblist_init_generic() {CVE-2023-53558} - pstore/ram: Check start of empty przs during init {CVE-2023-53331} - wifi: ath11k: fix memory leak in WMI firmware stats {CVE-2023-53602} - wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta {CVE-2023-53229} - net: ethernet: ti: Fix return type of netcp_ndo_start_xmit() {CVE-2022-50486} - RDMA/core: Make sure "ib_port" is valid when access sysfs node {CVE-2022-50475} - RDMA/rxe: Fix mr->map double free {CVE-2022-50543} - scsi: qla2xxx: Fix end of loop test - scsi: qla2xxx: Fix mem access after free - scsi: qla2xxx: Wait for io return on terminate rport {CVE-2023-53322} - scsi: target: Fix multiple LUN_RESET handling {CVE-2023-53586} - scsi: ses: Fix possible desc_ptr out-of-bounds accesses {CVE-2023-53675} - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses {CVE-2023-53675} - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() {CVE-2023-53675} - scsi: lpfc: Fix buffer free/clear order in deferred receive path {CVE-2025-39841} - nbd: fix incomplete validation of ioctl arg {CVE-2023-53513} - efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare {CVE-2025-39817} - bnxt: avoid overflow in bnxt_get_nvram_directory() {CVE-2023-53661}
Update command: dnf update kernel*
bpftool-7.0.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.7.els24.noarch.rpm kernel-core-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-devel-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-doc-5.14.0-284.1101.el9_2.tuxcare.7.els24.noarch.rpm kernel-headers-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-modules-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-tools-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm libbpf-1.0.0-2.el9_2.tuxcare.7.els24.i686.rpm libbpf-1.0.0-2.el9_2.tuxcare.7.els24.x86_64.rpm libbpf-devel-1.0.0-2.el9_2.tuxcare.7.els24.i686.rpm libbpf-devel-1.0.0-2.el9_2.tuxcare.7.els24.x86_64.rpm libbpf-static-1.0.0-2.el9_2.tuxcare.7.els24.i686.rpm libbpf-static-1.0.0-2.el9_2.tuxcare.7.els24.x86_64.rpm perf-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm python3-perf-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm rtla-5.14.0-284.1101.el9_2.tuxcare.7.els24.x86_64.rpm