[CLSA-2026:1780315683] kernel-uek: Fix of 24 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-03 09:29:40 UTC
Description:
- libceph: make decode_pool() more resilient against corrupted osdmaps {CVE-2025-71116} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() {CVE-2026-23216} - e1000: fix OOB in e1000_tbi_should_accept() {CVE-2025-71093} - ALSA: usb-audio: Use correct version for UAC3 header validation {CVE-2026-23318} - nfnetlink_osf: validate individual option lengths in fingerprints {CVE-2026-23397} - Squashfs: check metadata block offset is within range {CVE-2026-23388} - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled {CVE-2026-23381} - wifi: mac80211: fix NULL deref in mesh_matches_local() {CVE-2026-23396} - icmp: fix NULL pointer dereference in icmp_tag_validation() {CVE-2026-23398} - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them {CVE-2026-23382} - net: usb: kalmia: validate USB endpoints {CVE-2026-23365} - wifi: radiotap: reject radiotap with unknown bits {CVE-2026-23367} - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() {CVE-2026-23356} - batman-adv: reject oversized global TT response buffers {CVE-2026-31659} - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() {CVE-2026-43206} - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak {CVE-2026-43040} - ALSA: ctxfi: Limit PTP to a single page {CVE-2026-31602} - nvdimm/bus: Fix potential use after free in asynchronous initialization {CVE-2026-31399} - usb: class: cdc-wdm: fix reordering issue in read code path {CVE-2026-43427} - media: dvb-net: fix OOB access in ULE extension header tables {CVE-2026-31405} - sysctl: Fix data races in proc_douintvec(). {CVE-2022-49641} - netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() {CVE-2026-43450} - smb: client: reject userspace cifs.spnego descriptions - ALSA: caiaq: fix stack out-of-bounds read in init_card {CVE-2026-31778} - atm: lec: fix use-after-free in sock_def_readable() {CVE-2026-43050}
Updated packages:
  • bpftool-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:c2031536300183e6ae1d4b389f5b37bc8af4bc0489700cb57f57c5d4357a3fcd
  • kernel-uek-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:e6e6b92fe836462457156d5a264382bb1abc40b36dc63f7c362ba67af5f2d12c
  • kernel-uek-container-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:e0eeef333115e8a60aabebc95681a152ad3c66e349ba0234089b699e46acb9d2
  • kernel-uek-container-debug-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:601cef2c38a3f916a3a3063923c7839d023759ee6458591231b3a938090c81e9
  • kernel-uek-debug-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:a126305fb1f6e1d77e85ef05c0c5cd45997f7faad3b639ef04e13584fbc49d4d
  • kernel-uek-debug-devel-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:96c0997141eff83b68144139f23844a2c1a7c03cec5d0e81943a9f0f1fb5a1b6
  • kernel-uek-devel-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:f7f2835ee8e8594b7e14ccf1d0e5b805f192ccd4cb7834ca9aa6be20654dae94
  • kernel-uek-headers-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:725aed3f2b66b3701d2bd7bf341e7e5ba0e3da02c7080083ddb0f9e6e657dbac
  • kernel-uek-tools-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:a54ab6f517f569e2a1e7e67c2763fbc6e874afb6a014d920d219170df733ec95
  • perf-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:51ea1931c8f8930d55ac2dc027b6125524327b77da57792ffe8050fbe5e4da7a
  • python-perf-5.4.17-2136.354.4.el7uek.tuxcare.els5.x86_64.rpm
    sha:dbc83eff6e51f1b42bf6f67fcc2b16e51c620748610bd64109490c3916413e92
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.