Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
CLSA-2026-1777616064
See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777616064.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1777616064
Upstream
CVE-2022-49410
CVE-2022-49444
CVE-2022-49770
CVE-2022-49870
CVE-2022-49892
CVE-2022-49900
CVE-2022-49907
CVE-2022-49917
CVE-2022-49948
CVE-2022-50142
CVE-2022-50220
CVE-2022-50248
CVE-2022-50286
CVE-2022-50315
CVE-2022-50347
CVE-2022-50351
CVE-2022-50366
CVE-2022-50384
CVE-2022-50411
CVE-2022-50419
CVE-2022-50423
CVE-2022-50460
CVE-2022-50490
CVE-2022-50497
CVE-2022-50551
CVE-2022-50699
CVE-2022-50712
CVE-2022-50720
CVE-2022-50733
CVE-2022-50736
CVE-2022-50740
CVE-2022-50761
CVE-2022-50771
CVE-2022-50777
CVE-2022-50809
CVE-2022-50822
CVE-2022-50829
CVE-2022-50845
CVE-2022-50862
CVE-2023-52693
CVE-2023-53150
CVE-2023-53167
CVE-2023-53176
CVE-2023-53181
CVE-2023-53188
CVE-2023-53189
CVE-2023-53193
CVE-2023-53199
CVE-2023-53200
CVE-2023-53201
CVE-2023-53208
CVE-2023-53211
CVE-2023-53234
CVE-2023-53246
CVE-2023-53251
CVE-2023-53271
CVE-2023-53279
CVE-2023-53295
CVE-2023-53309
CVE-2023-53315
CVE-2023-53320
CVE-2023-53344
CVE-2023-53368
CVE-2023-53369
CVE-2023-53375
CVE-2023-53391
CVE-2023-53400
CVE-2023-53411
CVE-2023-53419
CVE-2023-53426
CVE-2023-53431
CVE-2023-53445
CVE-2023-53450
CVE-2023-53456
CVE-2023-53474
CVE-2023-53479
CVE-2023-53480
CVE-2023-53481
CVE-2023-53482
CVE-2023-53488
CVE-2023-53498
CVE-2023-53509
CVE-2023-53520
CVE-2023-53631
CVE-2023-53648
CVE-2023-53684
CVE-2023-53709
CVE-2023-53719
CVE-2023-53731
CVE-2023-53747
CVE-2023-53806
CVE-2023-53814
CVE-2023-53867
CVE-2023-54006
CVE-2023-54011
CVE-2023-54014
CVE-2023-54021
CVE-2023-54024
CVE-2023-54029
CVE-2023-54031
CVE-2023-54040
CVE-2023-54048
CVE-2023-54053
CVE-2023-54055
CVE-2023-54064
CVE-2023-54090
CVE-2023-54091
CVE-2023-54096
CVE-2023-54100
CVE-2023-54120
CVE-2023-54123
CVE-2023-54131
CVE-2023-54137
CVE-2023-54146
CVE-2023-54156
CVE-2023-54166
CVE-2023-54169
CVE-2023-54170
CVE-2023-54176
CVE-2023-54179
CVE-2023-54197
CVE-2023-54200
CVE-2023-54207
CVE-2023-54214
CVE-2023-54229
CVE-2023-54259
CVE-2023-54263
CVE-2023-54275
CVE-2023-54317
CVE-2023-54325
CVE-2025-23155
CVE-2025-37767
CVE-2025-37940
CVE-2025-37985
CVE-2025-37990
CVE-2025-37992
CVE-2025-37997
CVE-2025-37998
CVE-2025-38009
CVE-2025-38023
CVE-2025-38035
CVE-2025-38037
CVE-2025-38048
CVE-2025-38061
CVE-2025-38063
CVE-2025-38066
CVE-2025-38071
CVE-2025-38072
CVE-2025-38095
CVE-2025-38100
CVE-2025-38112
CVE-2025-38115
CVE-2025-38122
CVE-2025-38126
CVE-2025-38161
CVE-2025-38166
CVE-2025-38174
CVE-2025-38181
CVE-2025-38184
CVE-2025-38190
CVE-2025-38197
CVE-2025-38214
CVE-2025-38222
CVE-2025-38231
CVE-2025-38251
CVE-2025-38285
CVE-2025-38293
CVE-2025-38305
CVE-2025-38312
CVE-2025-38319
CVE-2025-38324
CVE-2025-38334
CVE-2025-38337
CVE-2025-38344
CVE-2025-38345
CVE-2025-38386
CVE-2025-38387
CVE-2025-38391
CVE-2025-38412
CVE-2025-38430
CVE-2025-38439
CVE-2025-38457
CVE-2025-38460
CVE-2025-38466
CVE-2025-38468
CVE-2025-38470
CVE-2025-38474
CVE-2025-38502
CVE-2025-38514
CVE-2025-38528
CVE-2025-38540
CVE-2025-38581
CVE-2025-38601
CVE-2025-38602
CVE-2025-38608
CVE-2025-38617
CVE-2025-38622
CVE-2025-38644
CVE-2025-38695
CVE-2025-38700
CVE-2025-38701
CVE-2025-38706
CVE-2025-38721
CVE-2025-39673
CVE-2025-39676
CVE-2025-39713
CVE-2025-39736
CVE-2025-39737
CVE-2025-39742
CVE-2025-39756
CVE-2025-39764
CVE-2025-39773
CVE-2025-39782
CVE-2025-39795
CVE-2025-39798
CVE-2025-39808
CVE-2025-39812
CVE-2025-39813
CVE-2025-39844
CVE-2025-39845
CVE-2025-39847
CVE-2025-39889
CVE-2025-39953
CVE-2025-39967
CVE-2025-40096
CVE-2025-68301
CVE-2025-68725
CVE-2025-68800
CVE-2025-71068
CVE-2025-71082
CVE-2025-71089
CVE-2025-71091
CVE-2025-71093
CVE-2025-71112
CVE-2025-71116
CVE-2025-71133
CVE-2025-71154
CVE-2025-71238
CVE-2026-22977
CVE-2026-22980
CVE-2026-22984
CVE-2026-22990
CVE-2026-22991
CVE-2026-22992
CVE-2026-23001
CVE-2026-23060
CVE-2026-23076
CVE-2026-23084
CVE-2026-23089
CVE-2026-23097
CVE-2026-23099
CVE-2026-23133
CVE-2026-23144
CVE-2026-23171
CVE-2026-23191
CVE-2026-23193
CVE-2026-23204
CVE-2026-23209
CVE-2026-23216
CVE-2026-31431
Published
2026-05-01T09:15:50Z
Modified
2026-05-29T01:37:53.551671955Z
Summary
kernel: Fix of 260 CVEs
Details
crypto: algif_aead - Fix minimum RX size check for decryption {CVE-2026-31431}
crypto: af
alg - Fix page reassignment overflow in af
alg
pull
tsgl {CVE-2026-31431}
crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec {CVE-2026-31431}
crypto: authencesn - Fix src offset when decrypting in-place {CVE-2026-31431}
crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption {CVE-2026-31431}
crypto: authenc - use memcpy_sglist() instead of null skcipher {CVE-2026-31431}
crypto: algif_aead - snapshot IV for async AEAD requests {CVE-2026-31431}
crypto: algif_aead - Revert to operating out-of-place {CVE-2026-31431}
crypto: algif
aead - use memcpy
sglist() instead of null skcipher {CVE-2026-31431}
crypto: scatterwalk - Backport memcpy_sglist() {CVE-2026-31431}
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf
fw
alloc_request() {CVE-2022-50551}
bonding: limit BOND
MODE
8023AD to Ethernet devices {CVE-2026-23099}
libceph: make decode_pool() more resilient against corrupted osdmaps {CVE-2025-71116}
scsi: qla2xxx: Fix bsg_done() causing double free {CVE-2025-71238}
ftrace: Fix use-after-free for dynamic ftrace_ops {CVE-2022-49892}
intel_th: msu: Fix vmalloced buffers {CVE-2022-50142}
vt: Clear selection before changing the font {CVE-2022-49948}
ACPICA: Fix error code path in acpi
ds
call
control
method() {CVE-2022-50411}
usbnet: Run unregister
netdev() before unbind
all() {CVE-2022-50220}
ipvs: fix WARNING in ip
vs
app
net
cleanup() {CVE-2022-49917}
bpf: Propagate error from htab
lock
bucket() to userspace {CVE-2022-50490}
binfmt
misc: fix shift-out-of-bounds in check
special_flags {CVE-2022-50497}
module: fix [e
shstrndx].sh
size=0 OOB access {CVE-2022-49444}
ceph: avoid putting the realm twice when decoding snaps fails {CVE-2022-49770}
tracing: Fix potential double free in create
var
ref() {CVE-2022-49410}
powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue {CVE-2022-50366}
Bluetooth: hci
sysfs: Fix attempting to call device
add multiple times {CVE-2022-50419}
xsk: Fix xsk_diag use-after-free error during socket cleanup {CVE-2023-53426}
svcrdma: bound check rq_pages index in inline path {CVE-2025-71068}
net: hns3: add VLAN id validation before using {CVE-2025-71112}
net: mdio: fix undefined behavior in bit shift for _
mdiobus
register {CVE-2022-49907}
capabilities: fix undefined behavior in bit shift for CAP
TO
MASK {CVE-2022-49870}
ata: ahci: Match EM
MAX
SLOTS with SATA
PMP
MAX_PORTS {CVE-2022-50315}
i2c: piix4: Fix adapter not be removed in piix4_remove() {CVE-2022-49900}
team: fix check for port enabled in team
queue
override
port
prio_changed() {CVE-2025-71091}
staging: vme
user: Fix possible UAF in tsi148
dma
list
add {CVE-2022-50384}
ALSA: ctxfi: Fix potential OOB access in audio mixer handling {CVE-2026-23076}
ftrace: Add cond
resched() to ftrace
graph
set
hash() {CVE-2025-37940}
net: stmmac: Fix accessing freed irq affinity_hint {CVE-2025-23155}
ext4: set goal start correctly in ext4
mb
normalize_request {CVE-2023-54021}
netfilter: ipset: fix region locking in hash types {CVE-2025-37997}
openvswitch: Fix unsafe attribute parsing in output_userspace() {CVE-2025-37998}
wifi: brcm80211: fmac: Add error handling for brcmf
usb
dl_writeimage() {CVE-2025-37990}
nfs: handle failure of nfs
get
lock_context in unlock path {CVE-2025-38023}
drm/amd/pm: Prevent division by zero {CVE-2025-37767}
netfilter: ctnetlink: remove refcounting in expectation dumpers {CVE-2025-39764}
tracing: Fix null pointer dereference in tracing
err
log_open() {CVE-2023-53167}
ACPICA: Refuse to evaluate a method if arguments are missing {CVE-2025-38386}
scsi: qla2xxx: Pointer may be dereferenced {CVE-2023-53150}
net: pktgen: fix access outside of user given buffer in pktgen
thread
write() {CVE-2025-38061}
dm cache: prevent BUG_ON by blocking retries on failed device resumes {CVE-2025-38066}
libnvdimm/labels: Fix divide error in nd
label
data_init() {CVE-2025-38072}
wifi: iwlwifi: pcie: fix NULL pointer dereference in iwl
pcie
irq
rx
msix_handler() {CVE-2023-53251}
tracing: Free error logs of tracing instances {CVE-2023-53375}
perf: Revert to requiring CAP
SYS
ADMIN for uprobes {CVE-2025-38466}
gve: add missing NULL check for gve
alloc
pending_packet() in TX DQO {CVE-2025-38122}
dma-buf: insert memory barrier before updating num_fences {CVE-2025-38095}
x86/sgx: Prevent attempts to reclaim poisoned pages {CVE-2025-38334}
ext4: inline: fix len overflow in ext4
prepare
inline_data {CVE-2025-38222}
fbdev: Fix fb
set
var to prevent null-ptr-deref in fb
videomode
to_var {CVE-2025-38214}
sctp: initialize more fields in sctp
v6
from_sk() {CVE-2025-39812}
atm: Revert atm
account
tx() if copy
from
iter_full() fails. {CVE-2025-38190}
usb: net: sierra: check for no status endpoint {CVE-2025-38474}
vxlan: Annotate FDB data races {CVE-2025-38037}
tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer {CVE-2025-38184}
calipso: Fix null-ptr-deref in calipso
req
{set,del}attr(). {CVE-2025-38181}
net
sched: sch
sfq: fix a potential crash on gso_skb handling {CVE-2025-38115}
RDMA/mlx5: Initialize obj
event->obj
sub
list before xa
insert {CVE-2025-38387}
jbd2: fix data-race and null-ptr-deref in jbd2
journal
dirty_metadata() {CVE-2025-38337}
mpls: Use rcu
dereference
rtnl() in mpls
route
input_rcu(). {CVE-2025-38324}
fbdev: core: fbcvt: avoid division by 0 in fb
cvt
hperiod() {CVE-2025-38312}
usb: typec: altmodes/displayport: do not index invalid pin_assignments {CVE-2025-38391}
nfsd: nfsd4
spo
must_allow() must check this is a v4 compound request {CVE-2025-38430}
wifi: ath9k: hif
usb: Fix use-after-free in ath9k
hif
usb
reg
in
cb() {CVE-2022-50829}
wifi: mt76: disable napi on driver removal {CVE-2025-38009}
ftrace: Fix potential warning in trace
printk
seq during ftrace_dump {CVE-2025-39813}
net/sched: Abort __tc
modify
qdisc if parent class does not exist {CVE-2025-38457}
scsi: target: iscsi: Fix use-after-free in iscsit
dec
conn
usage
count() {CVE-2026-23216}
Bluetooth: btusb: revert use of devm_kzalloc in btusb {CVE-2025-71082}
e1000: fix OOB in e1000
tbi
should_accept() {CVE-2025-71093}
RDMA/irdma: avoid invalid read in irdma
net
event {CVE-2025-71133}
scsi: qla4xxx: Prevent a potential error pointer dereference {CVE-2025-39676}
ppp: fix race conditions in ppp
fill
forward_path {CVE-2025-39673}
libceph: replace overzealous BUG
ON in osdmap
apply_incremental() {CVE-2026-22990}
thunderbolt: Do not double dequeue a configuration request {CVE-2025-38174}
bnxt
en: Set DMA unmap len correctly for XDP
REDIRECT {CVE-2025-38439}
ACPICA: fix acpi operand cache leak in dswstate.c {CVE-2025-38345}
atm: clip: Fix potential null-ptr-deref in to_atmarpd(). {CVE-2025-38460}
dm: fix unconditional IO throttle caused by REQ_PREFLUSH {CVE-2025-38063}
shmem: use ramfs
kill
sb() for kill_sb method of ramfs-based tmpfs {CVE-2023-53391}
nfsd: Initialize ssc before laundromat_work to prevent NULL dereference {CVE-2025-38231}
udf: Do not update file length for failed writes to inline files {CVE-2023-53295}
bpf: Fix WARN() in get
bpf
raw
tp
regs {CVE-2025-38285}
net/sched: Return NULL when htb
lookup
leaf encounters an empty rbtree {CVE-2025-38468}
nvmet-tcp: don't restore null sk
state
change {CVE-2025-38035}
wifi: iwlwifi: mvm: fix double free on tx path. {CVE-2022-50248}
ACPICA: fix acpi parse and parseext cache leaks {CVE-2025-38344}
bonding: fix use-after-free due to enslave fail after slave array update {CVE-2026-23171}
macvlan: fix error recovery in macvlan
common
newlink() {CVE-2026-23209}
cxl/acpi: Fix a use-after-free in cxl
parse
cfmws() {CVE-2023-53479}
fbcon: Fix OOB access in font allocation
fbcon: fix integer overflow in fbcon
do
set_font {CVE-2025-39967}
ALSA: aloop: Fix racy access at PCM trigger {CVE-2026-23191}
rename(): fix the locking of subdirectories
scsi: qedi: Fix use after free bug in qedi_remove() {CVE-2023-54100}
ixgbe: Fix panic during XDP_TX with > 64 CPUs {CVE-2023-54090}
bpf: Do not let BPF test infra emit invalid GSO types to stack {CVE-2025-68725}
net: usb: rtl8150: fix memory leak on usb
submit
urb() failure {CVE-2025-71154}
scsi: qla2xxx: Check valid rport returned by fc
bsg
to_rport() {CVE-2023-54014}
selinux: enable use of both GFP
KERNEL and GFP
ATOMIC in convert_context() {CVE-2022-50699}
HID: hid-ntrig: fix unable to handle page fault in ntrig
report
version() {CVE-2025-39808}
PCI: Fix dropping valid root bus resources with .end = zero {CVE-2023-53814}
KVM: nSVM: Load L1's TSC multiplier based on L1 state, not L2 state {CVE-2023-53208}
drm/amdgpu: fix amdgpu
irq
put call trace in gmc
v10
0
hw
fini {CVE-2023-53193}
block: avoid possible overflow for chunk
sectors check in blk
stack_limits() {CVE-2025-39795}
libceph: return the handler error from mon
handle
auth_done() {CVE-2026-22992}
Bluetooth: Fix hci
suspend
sync crash {CVE-2023-53520}
jbd2: prevent softlockup in jbd2
log
do_checkpoint() {CVE-2025-39782}
net: sock: fix hardened usercopy panic in sock
recv
errqueue {CVE-2026-22977}
wifi: ath11k: clear initialized flag for deinit-ed srng lists {CVE-2025-38601}
crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec {CVE-2026-23060}
libceph: make free
choose
arg_map() resilient to partial allocation {CVE-2026-22991}
soundwire: fix enumeration completion {CVE-2023-54096}
ext4: fix inode leak in ext4
xattr
inode_create() on an error path {CVE-2022-50845}
ring-buffer: Handle race between rb
move
tail and rb
check
pages {CVE-2023-53709}
netlink: fix potential deadlock in netlink
set
err() {CVE-2023-53731}
xhci: dbc: Fix memory leak in xhci
alloc
dbc() {CVE-2022-50809}
ext4: fix delayed allocation bug in ext4
clu
mapped for bigalloc + inline {CVE-2022-50286}
ubi: ubi
wl
put_peb: Fix infinite loop when wear-leveling work failed {CVE-2023-53481}
driver core: location: Free struct acpi
pld
info *pld before return false {CVE-2023-53211}
x86/mm/64: define ARCH
PAGE
TABLE
SYNC
MASK and arch
sync
kernel_mappings() {CVE-2025-39845}
dma-buf/dma-resv: Stop leaking on krealloc() failure {CVE-2023-53181}
rxrpc: Fix oops due to non-existence of prealloc backlog struct {CVE-2025-38514}
xfrm: Zero padding when dumping algos and encap {CVE-2023-53684}
ALSA: ac97: Fix possible NULL dereference in snd
ac97
mixer {CVE-2023-53648}
vc
screen: reload load of struct vc
data pointer in vcs_write() to avoid UAF {CVE-2023-53747}
ice: fix wrong fallback logic for FDIR {CVE-2023-54040}
cifs: Fix xid leak in cifs_create() {CVE-2022-50351}
drm/amd/display: populate subvp cmd info only for the top pipe {CVE-2023-53806}
netfilter: ctnetlink: fix refcount leak on table dump {CVE-2025-38721}
sfc: fix crash when reading stats while NIC is resetting {CVE-2023-54156}
Bluetooth: Fix race condition in hidp
session
thread {CVE-2023-54120}
bpf: Reject %p% format string in bprintf-like helpers {CVE-2025-38528}
RDMA/bnxt_re: Prevent handling any completions after qp destroy {CVE-2023-54048}
RDMA/siw: Fix immediate work request flush to completion queue {CVE-2022-50736}
net/packet: fix a race in packet
set
ring() and packet_notifier() {CVE-2025-38617}
ext4: do not BUG when INLINE
DATA
FL lacks system.data xattr {CVE-2025-38701}
IB/hfi1: Fix possible panic during hotplug remove {CVE-2023-53488}
cgroup: split cgroup
destroy
wq into 3 workqueues {CVE-2025-39953}
NFS: Fix the setting of capabilities when automounting a new filesystem {CVE-2025-39798}
fs: Prevent file descriptor table allocations exceeding INT_MAX {CVE-2025-39756}
ext4: remove a BUG
ON in ext4
mb
release
group_pa() {CVE-2023-53450}
media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() {CVE-2025-39713}
ALSA: usb-audio: Fix use-after-free in snd
usb
mixer_free() {CVE-2026-23089}
wifi: mac80211: reject TDLS operations when station is not associated {CVE-2025-38644}
ubi: Fix unreferenced object reported by kmemleak in ubi
resize
volume() {CVE-2023-53271}
RDMA/bnxt_re: wraparound mbox producer index {CVE-2023-53201}
x86/iopl: Cure TIF
IO
BITMAP inconsistencies {CVE-2025-38100}
ASoC: core: Check for rtd == NULL in snd
soc
remove
pcm
runtime() {CVE-2025-38706}
scsi: libiscsi: Initialize iscsi
conn->dd
data only if memory is allocated {CVE-2025-38700}
ALSA: hda: Fix Oops by 9.1 surround channel names {CVE-2023-53400}
mm: move page table sync declarations to linux/pgtable.h {CVE-2025-39844}
rcu: Protect rcu
print
task
exp
stall() ->exp_tasks access {CVE-2023-53419}
wifi: ath9k: hif
usb: clean up skbs if ath9k
hif
usb
rx_stream() fails {CVE-2023-53199}
HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras {CVE-2025-38540}
scsi: ses: Don't attach if enclosure has no components {CVE-2023-53431}
ipv6/addrconf: fix a potential refcount underflow for idev {CVE-2023-53189}
wifi: ath11k: Fix SKB corruption in REO destination ring {CVE-2023-53315}
bpf: fix ktls panic with sockmap {CVE-2025-38166}
net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime {CVE-2025-38470}
net: openvswitch: fix race on port output {CVE-2023-53188}
net
sched: Flush gso
skb list too during ->change() {CVE-2025-37992}
netfilter: x_tables: fix percpu counter block leak on error path when creating new netns {CVE-2023-53200}
RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction {CVE-2025-38161}
af
unix: Fix data-race around unix
tot_inflight. {CVE-2023-54006}
watchdog: Fix kmemleak in watchdog
cdev
register {CVE-2023-53234}
usb: idmouse: fix an uninit-value in idmouse_open {CVE-2022-50733}
net: dcb: choose correct policy to parse DCB
ATTR
BCN {CVE-2023-53369}
mmc: rtsx
usb
sdmmc: fix return value check of mmc
add
host() {CVE-2022-50347}
Bluetooth: l2cap: Check encryption key size on incoming connection {CVE-2025-39889}
x86/apic: Don't disable x2APIC if locked {CVE-2022-50720}
serial: 8250: Reinit port->pm on port specific driver unbind {CVE-2023-53176}
devlink: hold region lock when flushing snapshots {CVE-2022-50712}
net: qrtr: Fix a refcount bug in qrtr_recvmsg() {CVE-2023-53445}
be2net: Fix NULL pointer dereference in be
cmd
get
mac
from_list {CVE-2026-23084}
PM: EM: fix memory leak with using debugfs_lookup() {CVE-2023-53411}
vdpa: Add queue index attr to vdpa
nl
policy for nlattr length check {CVE-2023-54031}
atm: clip: prevent NULL deref in clip_push() {CVE-2025-38251}
ceph: fix potential use-after-free bug when trimming caps {CVE-2023-53867}
ACPI: video: check for error while searching for backlight device parent {CVE-2023-52693}
cifs: fix DFS traversal oops without CONFIG
CIFS
DFS_UPCALL {CVE-2023-53246}
x86/xen: Fix memory leak in xen
init
lock_cpu() {CVE-2022-50761}
net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping {CVE-2025-38126}
platform/x86: dell_rbu: Fix list usage {CVE-2025-38197}
x86/kexec: Fix double-free of elf header buffer {CVE-2023-54146}
ptp: remove ptp->n
vclocks check logic in ptp
vclock
in
use() {CVE-2025-38305}
KVM: Destroy target device if coalesced MMIO unregistration fails {CVE-2023-54024}
drm/amd/pp: Fix potential NULL pointer dereference in atomctrl
initialize
mc
reg
table {CVE-2025-38319}
rcu: Fix _
this
cpu
read() lockdep warning in rcu
force
quiescent
state() {CVE-2022-50771}
drm/radeon: Fix integer overflow in radeon
cs
parser_init {CVE-2023-53309}
net: atlantic: fix fragment overflow handling in RX path {CVE-2025-68301}
bpf: Fix oob access in cgroup local storage {CVE-2025-38502}
bpf: Add cookie object to bpf maps {CVE-2025-38502}
misc: vmw
balloon: fix memory leak with using debugfs
lookup() {CVE-2023-53279}
platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks {CVE-2025-38412}
virtio
ring: Fix data race by tagging event
triggered as racy for KCSAN {CVE-2025-38048}
tracing: Fix race issue between cpu buffer write and swap {CVE-2023-53368}
USB: wdm: close race between wdm
open and wdm
wwan
port
stop {CVE-2025-37985}
can: bcm: bcm
tx
setup(): fix KMSAN uninit-value in vfs_write {CVE-2023-53344}
wifi: ath11k: fix node corruption in ar->arvifs list {CVE-2025-38293}
x86/mm: Check return value from memblock
phys
alloc_range() {CVE-2025-38071}
net: Fix TOCTOU issue in sk
is
readable() {CVE-2025-38112}
scsi: mpi3mr: Fix an issue found by KASAN {CVE-2023-54011}
net/sched: cls
u32: use skb
header
pointer
careful() {CVE-2026-23204}
net: add skb
header
pointer_careful() helper
scsi: qla2xxx: Array index may go out of bound {CVE-2023-54179}
net/mlx5e: fix memory leak in mlx5e
ptp
open {CVE-2023-54169}
igc: Fix Kernel Panic during ndo
tx
timeout callback {CVE-2023-54166}
Bluetooth: L2CAP: Fix potential user-after-free {CVE-2023-54214}
RDMA/restrack: Release MR restrack when delete {CVE-2022-50822}
RDMA/irdma: Fix memory leak of PBLE objects {CVE-2023-54055}
wifi: ath11k: Fix memory leak in ath11k
peer
rx
frag
setup {CVE-2023-54275}
mptcp: stricter state check in mptcp_worker {CVE-2023-54176}
nfsd: provide locking for v4
end
grace {CVE-2026-22980}
iommu: disable SVA when CONFIG_X86 is set {CVE-2025-71089}
net: atlantic: add check for MAX
SKB
FRAGS {CVE-2025-68301}
net: atlantic: reduce scope of is
rsc
complete
atlantic: Fix buff
ring OOB in aq
ring
rx
clean
drm/sched: Fix potential double free in drm
sched
job
add
resv_dependencies {CVE-2025-40096}
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe {CVE-2022-50777}
wifi: rt2x00: Fix memory leak when handling surveys {CVE-2023-54131}
wifi: ath9k: hif
usb: fix memory leak of urbs in ath9k
hif
usb
dealloc
tx
urbs() {CVE-2022-50740}
scsi: target: iscsi: Fix use-after-free in iscsit
dec
session
usage
count() {CVE-2026-23193}
mm/damon/sysfs: cleanup attrs subdirs on context dir setup failure {CVE-2026-23144}
ACPICA: Fix use-after-free in acpi
ut
copy
ipackage
to_ipackage() {CVE-2022-50423}
wifi: ath10k: fix dma
free
coherent() pointer {CVE-2026-23133}
bpf: Move bpf map owner out of common struct {CVE-2025-38502}
fs: Lock moved directories
fs: Establish locking order for unrelated directories
mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats {CVE-2025-68800}
macvlan: fix possible UAF in macvlan
forward
source() {CVE-2026-23001}
HID: uclogic: Correct devm device reference for hidinput input_dev name {CVE-2023-54207}
libceph: prevent potential out-of-bounds reads in handle
auth
done() {CVE-2026-22984}
ppp: fix memory leak in pad
compress
skb {CVE-2025-39847}
migrate: correct lock ordering for hugetlb file folios {CVE-2026-23097}
keys: Fix linking a duplicate key to a keyring's assoc_array {CVE-2023-54170}
scsi: qla4xxx: Add length check when parsing nlattrs {CVE-2023-53456}
scsi: mpi3mr: Fix issues in mpi3mr
get
all
tgt
info() {CVE-2023-53320}
wifi: ath11k: fix registration of 6Ghz-only phy without the full channel range {CVE-2023-54229}
wifi: iwlwifi: pcie: fix possible NULL pointer dereference {CVE-2023-54053}
dm flakey: don't corrupt the zero page {CVE-2023-54317}
md/raid10: fix memleak for 'conf->bio_split' {CVE-2023-54123}
crypto: qat - fix out-of-bounds read {CVE-2023-54325}
drm/nouveau/kms/nv50-: init hpd
irq
lock for PIOR DP {CVE-2023-54263}
ipmi:ssif: Fix a memory leak when scanning for an adapter {CVE-2023-54064}
Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" {CVE-2023-54197}
netfilter: nf_tables: always release netdev hooks from notifier {CVE-2023-54200}
wifi: iwlwifi: fix iwl
mvm
max
amsdu
size() for MLO {CVE-2023-54029}
serial: arc
uart: fix of
iomap leak in
arc_serial_probe
{CVE-2023-53719}
soundwire: bus: Fix unbalanced pm
runtime
put() causing usage count underflow {CVE-2023-54259}
vfio/type1: fix cap_migration information leak {CVE-2023-54137}
drm/client: Fix memory leak in drm
client
target_cloned {CVE-2023-54091}
RDMA: hfi1: fix possible divide-by-zero in find
hw
thread_mask() {CVE-2025-39742}
crypto: ccp - Fix crash when rebind ccp device for ccp.ko {CVE-2025-38581}
iwlwifi: Add missing check for alloc
ordered
workqueue {CVE-2025-38602}
net: bridge: fix soft lockup in br
multicast
query_expired() {CVE-2025-39773}
net: drop UFO packets in udp
rcv
segment() {CVE-2025-38622}
iommu: Fix error unwind in iommu
group
alloc() {CVE-2023-53482}
qed: allow sleep in qed
mcp
trace_dump() {CVE-2023-53509}
cifs: Fix xid leak in cifs_flock() {CVE-2022-50460}
platform/x86: dell-sysman: Fix reference leak {CVE-2023-53631}
scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure {CVE-2025-38695}
bpf, ktls: Fix data corruption when using bpf
msg
pop_data() in ktls {CVE-2025-38608}
bpf: prevent decl
tag from being referenced in func
proto {CVE-2022-50862}
mm/kmemleak: avoid deadlock by moving pr
warn() outside kmemleak
lock {CVE-2025-39736}
mm/kmemleak: avoid soft lockup in __kmemleak
do
cleanup() {CVE-2025-39737}
drm/amd/display: Fix potential null dereference {CVE-2023-53498}
x86/MCE/AMD: Use an u64 for bank_map {CVE-2023-53474}
kobject: Add sanity check for kset->kobj.ktype in kset_register() {CVE-2023-53480}
References
https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1777616064.html
Affected packages
CLSA-2026-1777616064 - OSV