Release Info

Advisory: CLSA-2026:1767864313

OS: AlmaLinux 9.2 ESU

Public date: 2026-01-08 09:25:15.067925

Project: kernel

Version: 7.0.0-284.1101.el9_2.tuxcare.7.els26

Errata link: https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1767864313.html

Changelog

- mm: hugetlb: fix UAF in hugetlb_handle_userfault {CVE-2022-50630} - drm/amdkfd: fix potential kgd_mem UAFs {CVE-2023-53816} - net/mlx5e: Fix deadlock in tc route query code {CVE-2023-53591} - PCI: Fix pci_device_is_present() for VFs by checking PF {CVE-2022-50636} - wifi: ath11k: fix monitor mode bringup crash {CVE-2022-50627} - wifi: mac80211_hwsim: drop short frames {CVE-2023-53321} - scsi: target: iscsi: Fix timeout on deleted connection {CVE-2025-38075} - amdgpu: validate offset_in_bo of drm_amdgpu_gem_va {CVE-2023-53819} - dmaengine: ptdma: check for null desc before calling pt_cmd_callback {CVE-2023-53755} - wifi: mt7601u: fix an integer underflow {CVE-2023-53679} - Bluetooth: hci_event: call disconnect callback before deleting conn {CVE-2023-53673} - firmware: arm_scpi: Ensure scpi_info is not assigned if the probe fails {CVE-2022-50087} - tls: wait for pending async decryptions if tls_strp_msg_hold fails {CVE-2025-40176} - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns {CVE-2025-38499} - net: openvswitch: reject negative ifindex {CVE-2023-53843} - drm/i915: Fix NULL ptr deref by checking new_crtc_state {CVE-2023-53833} - iommu/amd: Improve page fault error reporting {CVE-2023-53789} - media: v4l2-mem2mem: add lock to protect parameter num_rdy {CVE-2023-53519} - Bluetooth: Fix potential use-after-free when clear keys {CVE-2023-53386} - Bluetooth: L2CAP: Fix use-after-free {CVE-2023-53305} - ext4: add bounds checking in get_max_inline_xattr_value_size() {CVE-2023-53285} - ext4: fix use-after-free in ext4_orphan_cleanup {CVE-2022-50673} - cacheinfo: Fix shared_cpu_map to handle shared caches at different levels {CVE-2023-53254} - rxrpc: Make it so that a waiting process can be aborted {CVE-2023-53218} - ip6_vti: fix slab-use-after-free in decode_session6 {CVE-2023-53821} - vxlan: Fix nexthop hash size {CVE-2023-53192} - wifi: mac80211: check S1G action frame size {CVE-2023-53257} - wifi: rtlwifi: Fix global-out-of-bounds bug in _rtl8812ae_phy_set_txpower_limit() {CVE-2022-50279} - dm flakey: fix a crash with invalid table line {CVE-2023-53786} - md/raid10: fix null-ptr-deref in raid10_sync_request {CVE-2023-53832} - md: don't dereference mddev after export_rdev() {CVE-2023-53665} - md: fix 'delete_mutex' deadlock - md: fix duplicate filename for rdev {CVE-2023-53665} - kernfs: Fix UAF in polling when open file is released {CVE-2025-39881} - mptcp: pm: avoid possible UaF when selecting endp {CVE-2024-44974} - mptcp: fix UaF in listener shutdown {CVE-2023-53088} - Bluetooth: MGMT: Fix possible UAFs {CVE-2025-39981} - Bluetooth: hci_sync: fix set_local_name race condition - Bluetooth: MGMT: Fix possible deadlocks {CVE-2024-53207} - tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). {CVE-2025-40186} - e1000e: fix heap overflow in e1000_set_eeprom {CVE-2025-39898} - wifi: cfg80211: fix use-after-free in cmp_bss() {CVE-2025-39864} - nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() {CVE-2025-38724} - usb: xhci: Apply the link chain quirk on NEC isoc endpoints {CVE-2025-22022} - xfrm: xfrm_alloc_spi shouldn't use 0 as SPI {CVE-2025-39965} - xfrm: Duplicate SPI Handling {CVE-2025-39797} - nfsd: release svc_expkey/svc_export with rcu_work {CVE-2024-53216} - NFS: Fix a race when updating an existing write {CVE-2025-39697} - nfs: fold nfs_page_group_lock_subrequests into nfs_lock_and_join_requests - drm/amd/display: Check dce_hwseq before dereferencing it {CVE-2025-38361}

Update

Update command: dnf update kernel*

Packages list

bpftool-7.0.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-abi-stablelists-5.14.0-284.1101.el9_2.tuxcare.7.els26.noarch.rpm kernel-core-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-cross-headers-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-core-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-devel-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-devel-matched-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-modules-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-modules-core-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-modules-extra-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-modules-internal-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-modules-partner-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-debug-uki-virt-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-devel-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-devel-matched-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-doc-5.14.0-284.1101.el9_2.tuxcare.7.els26.noarch.rpm kernel-headers-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-ipaclones-internal-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-modules-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-modules-core-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-modules-extra-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-modules-internal-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-modules-partner-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-selftests-internal-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-tools-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-tools-libs-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-tools-libs-devel-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm kernel-uki-virt-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm libbpf-1.0.0-2.el9_2.tuxcare.7.els26.i686.rpm libbpf-1.0.0-2.el9_2.tuxcare.7.els26.x86_64.rpm libbpf-devel-1.0.0-2.el9_2.tuxcare.7.els26.i686.rpm libbpf-devel-1.0.0-2.el9_2.tuxcare.7.els26.x86_64.rpm libbpf-static-1.0.0-2.el9_2.tuxcare.7.els26.i686.rpm libbpf-static-1.0.0-2.el9_2.tuxcare.7.els26.x86_64.rpm perf-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm python3-perf-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm rtla-5.14.0-284.1101.el9_2.tuxcare.7.els26.x86_64.rpm

CVEs

CVE-2023-53519
CVE-2022-50279
CVE-2023-53665
CVE-2023-53816
CVE-2025-39955
CVE-2022-50087
CVE-2025-40176
CVE-2023-53088
CVE-2023-53821
CVE-2025-39797
CVE-2025-39965
CVE-2022-50636
CVE-2022-50630
CVE-2023-53591
CVE-2025-38075
CVE-2023-53679
CVE-2023-53843
CVE-2022-50673
CVE-2023-53789
CVE-2023-53786
CVE-2024-53216
CVE-2022-50627
CVE-2024-53207
CVE-2025-40186
CVE-2025-22022
CVE-2025-39981
CVE-2023-53819
CVE-2023-53673
CVE-2025-38499
CVE-2023-53257
CVE-2023-53386
CVE-2023-53305
CVE-2023-53833
CVE-2025-38724
CVE-2025-39898
CVE-2025-39864
CVE-2025-38361
CVE-2025-39881
CVE-2025-39697
CVE-2023-53254
CVE-2023-53192
CVE-2023-53218
CVE-2023-53285
CVE-2023-53321
CVE-2023-53755
CVE-2023-53832
CVE-2024-44974