Skip to content

chore(deps): rpm updates [security] #2323

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: release-3.21
Choose a base branch
from

Conversation

red-hat-konflux[bot]
Copy link
Contributor

@red-hat-konflux red-hat-konflux bot commented Aug 4, 2025

This PR contains the following updates:

Package Update Change
kernel-headers patch 4.18.0-553.64.1.el8_10 -> 4.18.0-553.66.1.el8_10

kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc

CVE-2025-37890

More information

Severity

Important

References


kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done

CVE-2025-38052

More information

Severity

Important

References


kernel: crypto: algif_hash - fix double free in hash_accept

CVE-2025-38079

More information

Severity

Important

References


kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove

CVE-2025-22020

More information

Severity

Important

References


kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()

CVE-2025-21928

More information

Severity

Important

References


kernel: ext4: avoid resizing to a partial cluster size

CVE-2022-50020

More information

Severity

Important

References


kernel: cifs: fix potential double free during failed mount

CVE-2022-49541

More information

Severity

Important

References


kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources

CVE-2024-53150

More information

Severity

Important

References


kernel: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()

CVE-2025-21927

More information

Severity

Important

References


kernel: vsock: Keep the binding until socket destruction

CVE-2025-21756

More information

Severity

Important

References


kernel: netfilter: ipset: add missing range check in bitmap_ip_uadt

CVE-2024-53141

More information

Severity

Important

References


kernel: ndisc: use RCU protection in ndisc_alloc_skb()

CVE-2025-21764

More information

Severity

Moderate

References


kernel: tipc: fix use-after-free Read in tipc_named_reinit

CVE-2022-49696

More information

Severity

Moderate

References


kernel: mt76: fix use-after-free by removing a non-RCU wcid pointer

CVE-2022-49328

More information

Severity

Moderate

References


Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c

CVE-2023-1652

More information

Severity

Moderate

References


kernel: blk-mq: don't touch ->tagset in blk_mq_get_sq_hctx

CVE-2022-49377

More information

Severity

Moderate

References


kernel: scsi: libfc: Fix use after free in fc_exch_abts_resp()

CVE-2022-49114

More information

Severity

Moderate

References


kernel: dlm: fix plock invalid read

CVE-2022-49407

More information

Severity

Moderate

References


kernel: Bluetooth: Fix use after free in hci_send_acl

CVE-2022-49111

More information

Severity

Moderate

References


kernel: ipv6: mcast: extend RCU protection in igmp6_send()

CVE-2025-21759

More information

Severity

Important

References


kernel: Squashfs: fix handling and sanity checking of xattr_ids count

CVE-2023-52933

More information

Severity

Important

References


kernel: ext4: ignore xattrs past end

CVE-2025-37738

More information

Severity

Important

References


kernel: um: Fix out-of-bounds read in LDT setup

CVE-2022-49395

More information

Severity

Important

References


kernel: net: atm: fix use after free in lec_send()

CVE-2025-22004

More information

Severity

Important

References


kernel: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()

CVE-2025-22121

More information

Severity

Important

References


kernel: net: atlantic: fix aq_vec index out of range error

CVE-2022-50066

More information

Severity

Important

References


kernel: ibmvnic: Use kernel helpers for hex dumps

CVE-2025-22104

More information

Severity

Important

References


kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry()

CVE-2022-49846

More information

Severity

Important

References


kernel: dm ioctl: prevent potential spectre v1 gadget

CVE-2022-49122

More information

Severity

Important

References


kernel: wifi: iwlwifi: limit printed string from FW file

CVE-2025-21905

More information

Severity

Moderate

References


kernel: media: uvcvideo: Fix double free in error path

CVE-2024-57980

More information

Severity

Moderate

References


kernel: ext4: fix off-by-one error in do_split

CVE-2025-23150

More information

Severity

Moderate

References


kernel: writeback: avoid use-after-free after removing device

CVE-2022-49995

More information

Severity

Moderate

References


kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry

CVE-2025-37958

More information

Severity

Moderate

References


kernel: ext4: avoid journaling sb update on error if journal is destroying

CVE-2025-22113

More information

Severity

Moderate

References


kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources

CVE-2024-53150

More information

Severity

Moderate

References


kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages()

CVE-2024-47745

More information

Severity

Moderate

References


kernel: vsock: Keep the binding until socket destruction

CVE-2025-21756

More information

Severity

Moderate

References


kernel: veth: Fix use after free in XDP_REDIRECT

CVE-2023-53107

More information

Severity

Important

References


kernel: md: fix mddev uaf while iterating all_mddevs list

CVE-2025-22126

More information

Severity

Moderate

References


kernel: bpf: fix OOB devmap writes when deleting elements

CVE-2024-56615

More information

Severity

Moderate

References


kernel: xsk: fix OOB map writes when deleting elements

CVE-2024-56614

More information

Severity

Moderate

References


Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c

CVE-2023-1652

More information

Severity

Important

References


kernel: Squashfs: fix handling and sanity checking of xattr_ids count

CVE-2023-52933

More information

Severity

Moderate

References


kernel: um: Fix out-of-bounds read in LDT setup

CVE-2022-49395

More information

Severity

Moderate

References


kernel: ext4: fix off-by-one error in do_split

CVE-2025-23150

More information

Severity

Important

References


kernel: udmabuf: fix a buf size overflow issue during udmabuf creation

CVE-2025-37803

More information

Severity

Important

References


net/http: Request smuggling due to acceptance of invalid chunked data in net/http

CVE-2025-22871

More information

Severity

Moderate

References


kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry

CVE-2025-37958

More information

Severity

Important

References


kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice

CVE-2025-38001

More information

Severity

Important

References


kernel: media: uvcvideo: Fix double free in error path

CVE-2024-57980

More information

Severity

Important

References


kernel: wifi: iwlwifi: limit printed string from FW file

CVE-2025-21905

More information

Severity

Important

References


kernel: ext4: avoid journaling sb update on error if journal is destroying

CVE-2025-22113

More information

Severity

Important

References


kernel: igb: Fix string truncation warnings in igb_set_fw_version

CVE-2024-36010

More information

Severity

Moderate

References


kernel: wifi: ath11k: decrease MHI channel buffer length to 8KB

CVE-2024-35938

More information

Severity

Moderate

References


kernel: tcp: make sure init the accept_queue&#​39;s spinlocks once

CVE-2024-26614

More information

Severity

Moderate

References


kernel: virtio-blk: fix implicit overflow on virtio_max_dma_size

CVE-2023-52762

More information

Severity

Moderate

References


kernel: asix: fix uninit-value in asix_mdio_read()

CVE-2021-47101

More information

Severity

Moderate

References


kernel: netfilter: nf_tables: reject new basechain after table flag update

CVE-2024-35900

More information

Severity

Moderate

References


kernel: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE

CVE-2024-50192

More information

Severity

Moderate

References


kernel: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()

CVE-2024-36902

More information

Severity

Moderate

References


kernel: wifi: mac80211: fix race condition on enabling fast-xmit

CVE-2024-26779

More information

Severity

Moderate

References


kernel: bonding: stop the device in bond_setup_by_slave()

CVE-2023-52784

More information

Severity

Moderate

References


kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init().

CVE-2024-36939

More information

Severity

Moderate

References


kernel: wifi: brcm80211: handle pmk_op allocation failure

CVE-2024-27048

More information

Severity

Moderate

References


kernel: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values

CVE-2024-42114

More information

Severity

Moderate

References


kernel: dev/parport: fix the array out-of-bounds risk

CVE-2024-42301

More information

Severity

Moderate

References


kernel: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers

CVE-2024-42070

More information

Severity

Moderate

References


kernel: dma-direct: Leak pages on dma_set_decrypted() failure

CVE-2024-35939

More information

Severity

Moderate

References


kernel: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue

CVE-2024-36004

More information

Severity

Moderate

References


kernel: RDMA/qedr: Fix qedr_create_user_qp error flow

CVE-2024-26743

More information

Severity

Moderate

References

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot requested review from rhacs-bot and a team as code owners August 4, 2025 17:22
@red-hat-konflux red-hat-konflux bot enabled auto-merge (squash) August 4, 2025 17:23
Copy link
Contributor

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant