[CLSA-2026:1787304608] kernel-uek: Fix of 35 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-21 15:12:07 UTC
Description:
- Rebased onto Oracle UEK base 5.4.17-2136.357.2.el7uek - sctp: don't free the ASCONF's own transport in DEL-IP processing {CVE-2026-64564} - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison {CVE-2026-53309} - ocfs2/dlm: validate qr_numregions in dlm_match_regions() {CVE-2026-53043} - ixgbevf: fix use-after-free in VEPA multicast source pruning {CVE-2026-64113} - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 {CVE-2026-64114} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC {CVE-2026-64298} - fuse: re-lock request before returning from fuse_ref_folio() {CVE-2026-64266} - scsi: isci: Fix use-after-free in device removal path {CVE-2026-64103} - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec {CVE-2026-23060} - futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock {CVE-2026-53166} - net: af_key: zero aligned sockaddr tail in PF_KEY exports {CVE-2026-43088} - scsi: aic94xx: fix use-after-free in device removal path {CVE-2025-71075} - i2c: piix4: Fix adapter not be removed in piix4_remove() {CVE-2022-49900} - Bluetooth: MGMT: validate LTK enc_size on load {CVE-2026-43020} - ext4: convert inline data to extents when truncate exceeds inline size {CVE-2026-31452} - can: raw: fix ro->uniq use-after-free in raw_rcv() {CVE-2026-31532} - ALSA: 6fire: fix use-after-free on disconnect {CVE-2026-31581} - ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY {CVE-2026-31597} - netfilter: nf_conntrack_helper: pass helper to expect cleanup {CVE-2026-43027} - drm/amdgpu: Fix use-after-free race in VM acquire {CVE-2026-43370} - xfrm_user: fix info leak in build_mapping() {CVE-2026-43089} - xfs: fix freemap adjustments when adding xattrs to leaf blocks {CVE-2026-43158} - libceph: make decode_pool() more resilient against corrupted osdmaps {CVE-2025-71116} - e1000: fix OOB in e1000_tbi_should_accept() {CVE-2025-71093} - ALSA: usb-audio: Use correct version for UAC3 header validation {CVE-2026-23318} - nfnetlink_osf: validate individual option lengths in fingerprints {CVE-2026-23397} - Squashfs: check metadata block offset is within range {CVE-2026-23388} - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled {CVE-2026-23381} - wifi: mac80211: fix NULL deref in mesh_matches_local() {CVE-2026-23396} - icmp: fix NULL pointer dereference in icmp_tag_validation() {CVE-2026-23398} - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them {CVE-2026-23382} - net: usb: kalmia: validate USB endpoints {CVE-2026-23365} - wifi: radiotap: reject radiotap with unknown bits {CVE-2026-23367} - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() {CVE-2026-23356} - batman-adv: reject oversized global TT response buffers {CVE-2026-31659} - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() {CVE-2026-43206} - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak {CVE-2026-43040} - ALSA: ctxfi: Limit PTP to a single page {CVE-2026-31602} - nvdimm/bus: Fix potential use after free in asynchronous initialization {CVE-2026-31399} - usb: class: cdc-wdm: fix reordering issue in read code path {CVE-2026-43427} - media: dvb-net: fix OOB access in ULE extension header tables {CVE-2026-31405} - sysctl: Fix data races in proc_douintvec(). {CVE-2022-49641} - netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() {CVE-2026-43450} - ALSA: caiaq: fix stack out-of-bounds read in init_card {CVE-2026-31778} - atm: lec: fix use-after-free in sock_def_readable() {CVE-2026-43050} - fs: writeback: fix use-after-free in __mark_inode_dirty() {CVE-2025-39866} - usb: core: config: Prevent OOB read in SS endpoint companion parsing {CVE-2025-39760} - crypto: lzo - Fix compression buffer overrun {CVE-2025-38068} - KVM: x86: Reset IRTE to host control if *new* route isn't postable {CVE-2025-37885} - vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint {CVE-2025-22083} - mm: call the security_mmap_file() LSM hook in remap_file_pages() {CVE-2024-47745} - drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number {CVE-2024-46724} - fou: remove warn in gue_gro_receive on unsupported protocol {CVE-2024-44940} - wifi: iwlwifi: mvm: check n_ssids before accessing the ssids {CVE-2024-40929} - NFSD: Protect against send buffer overflow in NFSv2 READ {CVE-2022-43945} - drm/amd/pm: fix the Out-of-bounds read warning {CVE-2024-46731} - scsi: mpi3mr: Sanitise num_phys {CVE-2024-42159} - NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid {CVE-2025-68349} - net: usb: rtl8150: fix memory leak on usb_submit_urb() failure {CVE-2025-71154} - net: sock: fix hardened usercopy panic in sock_recv_errqueue {CVE-2026-22977} - can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak {CVE-2026-23061} - libceph: make free_choose_arg_map() resilient to partial allocation {CVE-2026-22991} - net/sched: sch_qfq: do not free existing class in qfq_change_class() {CVE-2026-22999} - ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() {CVE-2026-23089} - drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer {CVE-2024-49991} - HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} - bpf, sockmap: Fix race between element replace and close() {CVE-2024-56664} - KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory {CVE-2024-50115} - tty: n_gsm: Fix use-after-free in gsm_cleanup_mux {CVE-2024-50073} - media: xc2028: avoid use-after-free in load_firmware_cb() {CVE-2024-43900} - libceph: fix potential use-after-free in have_mon_and_osd_map() {CVE-2025-68285} - ocfs2: fix possible deadlock between unlink and dio_end_io_write {CVE-2026-31598} - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete {CVE-2026-46116} - net/rds: zero per-item info buffer before handing it to visitors {CVE-2026-52995} - KVM: x86: Fix shadow paging use-after-free due to unexpected role {CVE-2026-53359} - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN {CVE-2026-46113} - net/sched: fix pedit partial COW leading to page cache corruption {CVE-2026-46331} - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv {CVE-2026-46043} - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued {CVE-2026-53163} - rtmutex: Use waiter::task instead of current in remove_waiter() {CVE-2026-43499} - ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() {CVE-2026-43038} - net: skbuff: fix missing zerocopy reference in pskb_carve helpers {CVE-2026-52943} - net: fix fanout UAF in packet_release() via NETDEV_UP race {CVE-2026-31504} - net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null {CVE-2022-50073} - ip6_tunnel: clear skb2->cb[] in ip4ip6_err() {CVE-2026-43037} - batman-adv: hold claim backbone gateways by reference {CVE-2026-31657} - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker {CVE-2026-63890} - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() {CVE-2026-63888} - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf {CVE-2026-63887} - smb: client: reject userspace cifs.spnego descriptions {CVE-2026-46243} - tun: free page on build_skb failure in tun_xdp_one() {CVE-2026-46322} - tap: free page on error paths in tap_get_user_xdp() {CVE-2026-46320} - tun: free page on short-frame rejection in tun_xdp_one() {CVE-2026-46321} - ptrace: slightly saner 'get_dumpable()' logic {CVE-2026-46333} - net: skbuff: propagate shared-frag marker through frag-transfer helpers {CVE-2026-43503} - net: skbuff: preserve shared-frag marker during coalescing {CVE-2026-46300} - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache {CVE-2026-31402} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() {CVE-2026-23216} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() {CVE-2026-23193} - xfrm: esp: avoid in-place decrypt on shared skb frags {CVE-2026-43284} - crypto: algif_aead - Fix minimum RX size check for decryption {CVE-2026-43077} - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl {CVE-2026-43078} - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption {CVE-2026-43033} - crypto: algif_aead - snapshot IV for async AEAD requests {CVE-2026-46028} - crypto: algif_aead - Revert to operating out-of-place {CVE-2026-31431} - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf {CVE-2025-71120} - net/sched: Enforce that teql can only be used as root qdisc {CVE-2026-23074}
Updated packages:
  • bpftool-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:7bc062113655e8fedf2281c2f28db955066c549341a6e86fc47ad5d982f30fdf
  • kernel-uek-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:d9d155aae25ed8f587263620e0438cc1a8b2f3a0c02be0233a0dc5867254d4a6
  • kernel-uek-container-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:efcd72fb1656d7dd20f474480d1eb80513d7eeec26279bff1a19357cc6906b1b
  • kernel-uek-container-debug-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:d03844362357b6d3574c018c3ba8fefa3c8d24d7fcbe68a1737790ce593ef14d
  • kernel-uek-debug-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:57c91dd5392bfbacad62c4d7d1d8f8a303eb65f6f318122bddd1236a2f1ee3e3
  • kernel-uek-debug-devel-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:416a8b4b89e4679c4f5b35a3b6ec05a1471775a819a18d4df5f8243d467dd858
  • kernel-uek-devel-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:3840d0dc6d382a36f3cd60115e08e5a5b8fab2f44866a2202151f67eddf0fa54
  • kernel-uek-headers-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:7016889564d206b7eff668305a21c136df4e3009ef90901e7706019c20a0903e
  • kernel-uek-tools-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:cf11844f81f680cf83e0fa49cb62c8b01219d747e96f494de4dc46b100224c86
  • perf-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:db9c5cb35db9005d764070e9bce5866c5043f464ae75fc2ece04caa44f85e58f
  • python-perf-5.4.17-2136.357.2.el7uek.tuxcare.els1.x86_64.rpm
    sha:f6a885ec28b9a4d7bf1784befbaa5ef66711a05d3ebe4a8c2983f6fc438d05df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.