CLSA-2025-1757962453

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2025-1757962453
Upstream
Published
2025-09-15T18:54:17Z
Modified
2026-06-01T00:33:14.228217910Z
Summary
kernel: Fix of 32 CVEs
Details
  • inet: fully convert sk->skrxdst to RCU rules {CVE-2021-47103}
  • ALSA: usb-audio: Fix out of bounds reads when finding clock sources {CVE-2024-53150}
  • posix-cpu-timers: fix race between handleposixcputimers() and posixcputimerdel() {CVE-2025-38352}
  • can: peak_usb: fix use after free bugs {CVE-2021-47670}
  • wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds {CVE-2025-38159}
  • RDMA/rxe: Fix error unwind in rxecreateqp() {CVE-2022-50127}
  • i40e: fix MMIO write access to an invalid page in i40eclearhw {CVE-2025-38200}
  • udp: Fix memory accounting leak. {CVE-2025-22058}
  • ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50083}
  • ext4: correct the misjudgment in ext4igetextra_inode {CVE-2022-50083}
  • ext4: correct maxinlinexattrvaluesize computing {CVE-2022-50083}
  • ext4: fix use-after-free in ext4xattrset_entry {CVE-2022-50083}
  • ext4: add EXT4INODEHASXATTRSPACE macro in xattr.h {CVE-2022-50083}
  • Bluetooth: hcicore: Fix use-after-free in vhciflush() {CVE-2025-38250}
  • net_sched: ets: Fix double list add in class with netem as child qdisc {CVE-2025-38085}
  • mm/hugetlb: fix hugepmdunshare() vs GUP-fast race {CVE-2025-38085}
  • padata: fix UAF in padata_reorder {CVE-2025-21727}
  • net/sched: Always pass notifications when child class becomes empty {CVE-2025-38350}
  • codel: remove sch->q.qlen check before qdisctreereduce_backlog() {CVE-2025-38177}
  • schets: make estqlen_notify() idempotent {CVE-2025-38177}
  • schqfq: make qfqqlen_notify() idempotent {CVE-2025-38177}
  • schhfsc: make hfscqlen_notify() idempotent {CVE-2025-38177}
  • schdrr: make drrqlen_notify() idempotent {CVE-2025-38177}
  • schhtb: make htbqlen_notify() idempotent {CVE-2025-38177}
  • schhfsc: Fix qlen accounting bug when using peek in hfscenqueue() {CVE-2025-38000}
  • mptcp: do not queue data on closed subflows {CVE-2022-50070}
  • mptcp: export mptcpsubflowactive {CVE-2022-50070}
  • net/sched: schqfq: Fix race condition on qfqaggregate {CVE-2025-38477}
  • tipc: Fix use-after-free in tipcconnclose(). {CVE-2025-38464}
  • RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction {CVE-2025-38211}
  • scsi: lpfc: Use memcpy() for BIOS version {CVE-2025-38332}
  • crypto: algifhash - fix double free in hashaccept {CVE-2025-38079}
  • ext4: avoid resizing to a partial cluster size {CVE-2022-50020}
  • net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc {CVE-2025-37890}
  • net: tipc: fix refcount warning in tipcaeadencrypt {CVE-2025-38273}
  • ice: xsk: prohibit usage of non-balanced queue id {CVE-2022-50003}
  • net/tipc: fix slab-use-after-free Read in tipcaeadencrypt_done {CVE-2025-38052}
  • virtio-gpu: fix a missing check to avoid NULL dereference {CVE-2022-50181}
  • usb: xhciplatremove: avoid NULL dereference {CVE-2022-50133}
  • ASoC: SOF: Intel: hda-ipc: Do not process IPC reply before firmware boot {CVE-2022-50015}
  • netfilter: nft_tproxy: restrict to prerouting hook {CVE-2022-50001}
  • scsi: storvsc: Remove WQMEMRECLAIM from storvscerrorwq {CVE-2022-49986}
  • ath11k: fix netdev open race {CVE-2022-50187}
References

Affected packages

TuxCare:CentOS:8.5
bpftool

Package

Name
bpftool
Purl
pkg:rpm/tuxcare/bpftool?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel

Package

Name
kernel
Purl
pkg:rpm/tuxcare/kernel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-core

Package

Name
kernel-core
Purl
pkg:rpm/tuxcare/kernel-core?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-cross-headers

Package

Name
kernel-cross-headers
Purl
pkg:rpm/tuxcare/kernel-cross-headers?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug

Package

Name
kernel-debug
Purl
pkg:rpm/tuxcare/kernel-debug?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug-core

Package

Name
kernel-debug-core
Purl
pkg:rpm/tuxcare/kernel-debug-core?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug-devel

Package

Name
kernel-debug-devel
Purl
pkg:rpm/tuxcare/kernel-debug-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug-modules

Package

Name
kernel-debug-modules
Purl
pkg:rpm/tuxcare/kernel-debug-modules?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug-modules-extra

Package

Name
kernel-debug-modules-extra
Purl
pkg:rpm/tuxcare/kernel-debug-modules-extra?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-debug-modules-internal

Package

Name
kernel-debug-modules-internal
Purl
pkg:rpm/tuxcare/kernel-debug-modules-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-devel

Package

Name
kernel-devel
Purl
pkg:rpm/tuxcare/kernel-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-headers

Package

Name
kernel-headers
Purl
pkg:rpm/tuxcare/kernel-headers?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-ipaclones-internal

Package

Name
kernel-ipaclones-internal
Purl
pkg:rpm/tuxcare/kernel-ipaclones-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-modules

Package

Name
kernel-modules
Purl
pkg:rpm/tuxcare/kernel-modules?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-modules-extra

Package

Name
kernel-modules-extra
Purl
pkg:rpm/tuxcare/kernel-modules-extra?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-modules-internal

Package

Name
kernel-modules-internal
Purl
pkg:rpm/tuxcare/kernel-modules-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-selftests-internal

Package

Name
kernel-selftests-internal
Purl
pkg:rpm/tuxcare/kernel-selftests-internal?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-tools

Package

Name
kernel-tools
Purl
pkg:rpm/tuxcare/kernel-tools?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-tools-libs

Package

Name
kernel-tools-libs
Purl
pkg:rpm/tuxcare/kernel-tools-libs?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
kernel-tools-libs-devel

Package

Name
kernel-tools-libs-devel
Purl
pkg:rpm/tuxcare/kernel-tools-libs-devel?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
perf

Package

Name
perf
Purl
pkg:rpm/tuxcare/perf?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"
python3-perf

Package

Name
python3-perf
Purl
pkg:rpm/tuxcare/python3-perf?distro=centos-8.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-348.7.1.el8_5.tuxcare.els31

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2025-1757962453.json"