[CLSA-2025:1757967705] kernel: Fix of 42 CVEs
Type:
security
Severity:
Important
Release date:
2025-09-15 20:21:49 UTC
Description:
- x86/kvm: Disable kvmclock on all CPUs on shutdown {CVE-2021-47110} - posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() {CVE-2025-38352} - cifs: fix double free race when mount fails in cifs_get_root() {CVE-2022-48919} - aio: mark AIO pseudo-fs noexec {CVE-2016-10044} - cifs: potential buffer overflow in handling symlinks {CVE-2022-49058} - NFSD: fix race between nfsd registration and exports_proc {CVE-2025-38232} - nfsd: register pernet ops last, unregister first {CVE-2025-38232} - net: atm: fix use after free in lec_send() {CVE-2025-22004} - net: atlantic: fix aq_vec index out of range error {CVE-2022-50066} - do_change_type(): refuse to operate on unmounted/not ours mounts {CVE-2025-38498} - net: atm: fix /proc/net/atm/lec handling {CVE-2025-38180} - net: atm: add lec_mutex {CVE-2025-38180} - SUNRPC: make sure cache entry active before cache_show {CVE-2024-53174} - scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() {CVE-2025-38399} - scsi: target: Fix crash during SPEC_I_PT handling {CVE-2025-38399} - mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race {CVE-2025-38085} - drivers:md:fix a potential use-after-free bug {CVE-2022-50022} - ext4: avoid resizing to a partial cluster size {CVE-2022-50020} - HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() {CVE-2025-21928} - net/sched: Abort __tc_modify_qdisc if parent class does not exist {CVE-2025-38457} - misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() {CVE-2022-49788} - dlm: fix plock invalid read {CVE-2022-49407} - net: usb: smsc75xx: Limit packet length to skb->len {CVE-2023-53125} - scsi: libfc: Fix use after free in fc_exch_abts_resp() {CVE-2022-49114} - crypto: algif_hash - fix double free in hash_accept {CVE-2025-38079} - HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} - HID: core: ensure the allocated report buffer can contain the reserved report ID {CVE-2025-38495} - ext4: Fix possible corruption when moving a directory {CVE-2023-53137} - ceph: avoid putting the realm twice when decoding snaps fails {CVE-2022-49770} - vsock/vmci: Clear the vmci transport packet properly when initializing it {CVE-2025-38403} - HID: core: do not bypass hid_hw_raw_request {CVE-2025-38494} - sch_hfsc: make hfsc_qlen_notify() idempotent {CVE-2025-38177} - ext4: check dot and dotdot of dx_root before making dir indexed {CVE-2024-42305} - ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50229} - dm ioctl: prevent potential spectre v1 gadget {CVE-2022-49122} - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too {CVE-2025-37823} - md-raid10: fix KASAN warning {CVE-2022-50211} - scsi: lpfc: Use memcpy() for BIOS version {CVE-2025-38332} - ACPICA: Refuse to evaluate a method if arguments are missing {CVE-2025-38386} - media: cxusb: no longer judge rbuf when the write fails {CVE-2025-38229} - ipc: fix to protect IPCS lookups using RCU {CVE-2025-38212} - ext4: fix off-by-one error in do_split {CVE-2025-23150} - perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init {CVE-2025-37878} - sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() {CVE-2025-38000} - i40e: fix MMIO write access to an invalid page in i40e_clear_hw {CVE-2025-38200}
Updated packages:
  • bpftool-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:e555c3d9b640cbf2a9eaaed3185da1a0a8c01569705070c398b0a4ad564e9dce
  • kernel-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:a829da391927f6702a0d03995f25528679fd21bc1941e410dfaf37d7ecc6a321
  • kernel-debug-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:8b2a22be17319b71f182e0082115409091882160cb1e000945c6d4a73ec3a0ed
  • kernel-debug-devel-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:cea6ebe1863472dceecf44841f2d79378e33d96a1bf3d440759dcab222835cd1
  • kernel-devel-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:f75a8346d497f1495dcb74c189fe1e83d38846c25dbb35f4d63345bcd90053b7
  • kernel-headers-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:f470a9cfab5382b0bcda6f1acb60404d21f7b8d468bd927771a846c8c489290e
  • kernel-tools-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:5844435379ec1e33abb97bf6869a27c3c3e9ca485548bc599b8e60114d391c62
  • kernel-tools-libs-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:f69d0b81f61a0ec78b34959197a7d51d3b636ea193ad718a4a1be081b2d463e5
  • kernel-tools-libs-devel-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:c8cb198b0c9b055e77bc27b336cdcf2b5543baccd492e794fef925bf0d065fd4
  • perf-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:81cd7c07c73fcd62c048806a9aa97d89f259075ea929cae0877a4128d1d30454
  • python-perf-3.10.0-1160.119.1.el7.tuxcare.els24.x86_64.rpm
    sha:e4dfc24db9d88334e48c5a15a666a6567c076eb72ad3efbedb6a6f4fc2fd90f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.