The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it (CVE-2025-38403)
kernel: net: use dstdevrcu() in sksetupcaps() (CVE-2025-40170)
kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135)
kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158)
kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service (CVE-2025-40269)
kernel: ext4: fix use-after-free in ext4orphancleanup (CVE-2022-50673)
kernel: NFSv4/pNFS: Clear NFSINOLAYOUTCOMMIT in pnfsmarklayoutstateidinvalid (CVE-2025-68349)
kernel: nvme-tcp: fix NULL pointer dereferences in nvmettcpbuildpduiovec (CVE-2026-22998)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.