chore(deps): rpm updates [security] #2323
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.18.0-553.64.1.el8_10
->4.18.0-553.66.1.el8_10
kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
CVE-2025-37890
More information
Severity
Important
References
kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done
CVE-2025-38052
More information
Severity
Important
References
kernel: crypto: algif_hash - fix double free in hash_accept
CVE-2025-38079
More information
Severity
Important
References
kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
CVE-2025-22020
More information
Severity
Important
References
kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
CVE-2025-21928
More information
Severity
Important
References
kernel: ext4: avoid resizing to a partial cluster size
CVE-2022-50020
More information
Severity
Important
References
kernel: cifs: fix potential double free during failed mount
CVE-2022-49541
More information
Severity
Important
References
kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources
CVE-2024-53150
More information
Severity
Important
References
kernel: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
CVE-2025-21927
More information
Severity
Important
References
kernel: vsock: Keep the binding until socket destruction
CVE-2025-21756
More information
Severity
Important
References
kernel: netfilter: ipset: add missing range check in bitmap_ip_uadt
CVE-2024-53141
More information
Severity
Important
References
kernel: ndisc: use RCU protection in ndisc_alloc_skb()
CVE-2025-21764
More information
Severity
Moderate
References
kernel: tipc: fix use-after-free Read in tipc_named_reinit
CVE-2022-49696
More information
Severity
Moderate
References
kernel: mt76: fix use-after-free by removing a non-RCU wcid pointer
CVE-2022-49328
More information
Severity
Moderate
References
Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c
CVE-2023-1652
More information
Severity
Moderate
References
kernel: blk-mq: don't touch ->tagset in blk_mq_get_sq_hctx
CVE-2022-49377
More information
Severity
Moderate
References
kernel: scsi: libfc: Fix use after free in fc_exch_abts_resp()
CVE-2022-49114
More information
Severity
Moderate
References
kernel: dlm: fix plock invalid read
CVE-2022-49407
More information
Severity
Moderate
References
kernel: Bluetooth: Fix use after free in hci_send_acl
CVE-2022-49111
More information
Severity
Moderate
References
kernel: ipv6: mcast: extend RCU protection in igmp6_send()
CVE-2025-21759
More information
Severity
Important
References
kernel: Squashfs: fix handling and sanity checking of xattr_ids count
CVE-2023-52933
More information
Severity
Important
References
kernel: ext4: ignore xattrs past end
CVE-2025-37738
More information
Severity
Important
References
kernel: um: Fix out-of-bounds read in LDT setup
CVE-2022-49395
More information
Severity
Important
References
kernel: net: atm: fix use after free in lec_send()
CVE-2025-22004
More information
Severity
Important
References
kernel: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
CVE-2025-22121
More information
Severity
Important
References
kernel: net: atlantic: fix aq_vec index out of range error
CVE-2022-50066
More information
Severity
Important
References
kernel: ibmvnic: Use kernel helpers for hex dumps
CVE-2025-22104
More information
Severity
Important
References
kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
CVE-2022-49846
More information
Severity
Important
References
kernel: dm ioctl: prevent potential spectre v1 gadget
CVE-2022-49122
More information
Severity
Important
References
kernel: wifi: iwlwifi: limit printed string from FW file
CVE-2025-21905
More information
Severity
Moderate
References
kernel: media: uvcvideo: Fix double free in error path
CVE-2024-57980
More information
Severity
Moderate
References
kernel: ext4: fix off-by-one error in do_split
CVE-2025-23150
More information
Severity
Moderate
References
kernel: writeback: avoid use-after-free after removing device
CVE-2022-49995
More information
Severity
Moderate
References
kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry
CVE-2025-37958
More information
Severity
Moderate
References
kernel: ext4: avoid journaling sb update on error if journal is destroying
CVE-2025-22113
More information
Severity
Moderate
References
kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources
CVE-2024-53150
More information
Severity
Moderate
References
kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages()
CVE-2024-47745
More information
Severity
Moderate
References
kernel: vsock: Keep the binding until socket destruction
CVE-2025-21756
More information
Severity
Moderate
References
kernel: veth: Fix use after free in XDP_REDIRECT
CVE-2023-53107
More information
Severity
Important
References
kernel: md: fix mddev uaf while iterating all_mddevs list
CVE-2025-22126
More information
Severity
Moderate
References
kernel: bpf: fix OOB devmap writes when deleting elements
CVE-2024-56615
More information
Severity
Moderate
References
kernel: xsk: fix OOB map writes when deleting elements
CVE-2024-56614
More information
Severity
Moderate
References
Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c
CVE-2023-1652
More information
Severity
Important
References
kernel: Squashfs: fix handling and sanity checking of xattr_ids count
CVE-2023-52933
More information
Severity
Moderate
References
kernel: um: Fix out-of-bounds read in LDT setup
CVE-2022-49395
More information
Severity
Moderate
References
kernel: ext4: fix off-by-one error in do_split
CVE-2025-23150
More information
Severity
Important
References
kernel: udmabuf: fix a buf size overflow issue during udmabuf creation
CVE-2025-37803
More information
Severity
Important
References
net/http: Request smuggling due to acceptance of invalid chunked data in net/http
CVE-2025-22871
More information
Severity
Moderate
References
kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry
CVE-2025-37958
More information
Severity
Important
References
kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
CVE-2025-38001
More information
Severity
Important
References
kernel: media: uvcvideo: Fix double free in error path
CVE-2024-57980
More information
Severity
Important
References
kernel: wifi: iwlwifi: limit printed string from FW file
CVE-2025-21905
More information
Severity
Important
References
kernel: ext4: avoid journaling sb update on error if journal is destroying
CVE-2025-22113
More information
Severity
Important
References
kernel: igb: Fix string truncation warnings in igb_set_fw_version
CVE-2024-36010
More information
Severity
Moderate
References
kernel: wifi: ath11k: decrease MHI channel buffer length to 8KB
CVE-2024-35938
More information
Severity
Moderate
References
kernel: tcp: make sure init the accept_queue's spinlocks once
CVE-2024-26614
More information
Severity
Moderate
References
kernel: virtio-blk: fix implicit overflow on virtio_max_dma_size
CVE-2023-52762
More information
Severity
Moderate
References
kernel: asix: fix uninit-value in asix_mdio_read()
CVE-2021-47101
More information
Severity
Moderate
References
kernel: netfilter: nf_tables: reject new basechain after table flag update
CVE-2024-35900
More information
Severity
Moderate
References
kernel: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE
CVE-2024-50192
More information
Severity
Moderate
References
kernel: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
CVE-2024-36902
More information
Severity
Moderate
References
kernel: wifi: mac80211: fix race condition on enabling fast-xmit
CVE-2024-26779
More information
Severity
Moderate
References
kernel: bonding: stop the device in bond_setup_by_slave()
CVE-2023-52784
More information
Severity
Moderate
References
kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init().
CVE-2024-36939
More information
Severity
Moderate
References
kernel: wifi: brcm80211: handle pmk_op allocation failure
CVE-2024-27048
More information
Severity
Moderate
References
kernel: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values
CVE-2024-42114
More information
Severity
Moderate
References
kernel: dev/parport: fix the array out-of-bounds risk
CVE-2024-42301
More information
Severity
Moderate
References
kernel: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
CVE-2024-42070
More information
Severity
Moderate
References
kernel: dma-direct: Leak pages on dma_set_decrypted() failure
CVE-2024-35939
More information
Severity
Moderate
References
kernel: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue
CVE-2024-36004
More information
Severity
Moderate
References
kernel: RDMA/qedr: Fix qedr_create_user_qp error flow
CVE-2024-26743
More information
Severity
Moderate
References