[CLSA-2026:1790030905] kernel: Fix of 49 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-21 23:05:45 UTC
Description:
- usb: free iso schedules on failed submit {CVE-2026-64348} - udf: validate VAT header length against the VAT inode size {CVE-2026-64323} - USB: idmouse: fix use-after-free on disconnect race {CVE-2026-64344} - USB: ldusb: fix use-after-free on disconnect race {CVE-2026-64343} - USB: iowarrior: fix use-after-free on disconnect race {CVE-2026-64341} - USB: iowarrior: fix use-after-free on disconnect {CVE-2026-64342} - can: bcm: restore op->flags assignment lost in the bcm_tx_lock backport {CVE-2025-38004} - can: bcm: fix out-of-bounds frame read introduced by the bcm_tx_lock backport {CVE-2025-38004} - dm-log: fix a bitset_size overflow on 32bit machines {CVE-2026-72105} - scsi: aic94xx: fix use-after-free in device removal path {CVE-2025-71075} - dm log: fix out-of-bounds write due to region_count overflow {CVE-2026-53059} - netfilter: xt_policy: fix strict mode inbound policy matching {CVE-2026-52920} - phonet: pep: fix use-after-free in pep_get_sb() {CVE-2026-68144} - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 {CVE-2026-64114} - Input: touchwin - reset the packet index on every complete packet {CVE-2026-64271} - IB/mad: Drop unmatched RMPP responses before reassembly {CVE-2026-68425} - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() {CVE-2026-68413} - Bluetooth: RFCOMM: Fix session UAF in set_termios {CVE-2026-68188} - sctp: fix auth_hmacs array size in struct sctp_cookie {CVE-2026-68376} - net: slip: serialize receive against buffer reallocation {CVE-2026-68143} - pppoe: reload header pointer after dev_hard_header() {CVE-2026-68121} - Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame {CVE-2026-53254} - net: af_key: zero aligned sockaddr tail in PF_KEY exports {CVE-2026-43088} - netfilter: nf_conntrack_sip: don't use simple_strtoul {CVE-2026-52986} - tcp: fix potential race in tcp_v6_syn_recv_sock() {CVE-2026-43198} - netfilter: ctnetlink: ensure safe access to master conntrack {CVE-2026-43116} - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress {CVE-2023-52974} - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() {CVE-2026-53256} - Bluetooth: bnep: reject short frames before parsing {CVE-2026-53253} - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() {CVE-2026-31408} - ext4: fix e4b bitmap inconsistency reports {CVE-2026-45942} - RDMA/srp: bound SRP_RSP sense copy by the received length {CVE-2026-53186} - inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP {CVE-2026-46266} - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache {CVE-2026-31402} - ipv6: mcast: Fix use-after-free when processing MLD queries {CVE-2026-53275} - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check {CVE-2026-52998} - RDMA/umad: Reject negative data_len in ib_umad_write() {CVE-2026-23243} - can: bcm: Fix UAF in bcm_proc_show() {CVE-2023-52922} - netfilter: xt_tcpmss: check remaining length before reading option length {CVE-2026-43190} - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() {CVE-2026-23455} - netfilter: nf_conntrack_irc: fix possible out-of-bounds read {CVE-2026-53268} - scsi: libfc: Fix use after free in fc_exch_abts_resp() {CVE-2022-49114} - drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers() {CVE-2022-50185} - wifi: libertas: fix use-after-free in lbs_free_adapter() {CVE-2026-23281} - ALSA: usb-audio: Fix an OOB bug in parse_audio_mixer_unit {CVE-2019-15117} - vfs: introduce FMODE_UNSIGNED_OFFSET for allowing negative f_pos {CVE-2019-18675} - infiniband: fix a possible use-after-free bug {CVE-2018-14734} - phonet: pep: fix use-after-free in pep_get_sb() {CVE-2026-68144} - Bluetooth: RFCOMM: validate skb length in MCC handlers {CVE-2026-53254} - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold {CVE-2026-31408} - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete {CVE-2026-46116} - netfilter: require Ethernet MAC header before using eth_hdr() {CVE-2026-53131} - ip6_tunnel: clear skb2->cb[] in ip4ip6_err() {CVE-2026-43037} - btrfs: tree-checker: Enhance chunk checker to validate chunk profile {CVE-2019-19816} - atm: lec: fix use-after-free in sock_def_readable() {CVE-2026-43050} - scsi: aic94xx: fix use-after-free in device removal path {CVE-2025-71075} - usb: class: cdc-wdm: fix reordering issue in read code path {CVE-2026-43427} - btrfs: Don't submit any btree write bio if the fs has errors {CVE-2019-19377} - HID: make arrays usage and value to be the same {CVE-2021-0512} - Input: touchwin - reset the packet index on every complete packet {CVE-2026-64271} - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 {CVE-2026-64114} - netfilter: xt_policy: fix strict mode inbound policy matching {CVE-2026-52920} - ip6_tunnel: clear skb2->cb[] in ip4ip6_err() {CVE-2026-43037} - dm log: fix out-of-bounds write due to region_count overflow {CVE-2026-53059} - ALSA: caiaq: fix stack out-of-bounds read in init_card - ext4: make sure bitmaps and the inode table don't overlap with bg descriptors {CVE-2018-10879} - ext4: always check block group bounds in ext4_init_block_bitmap() {CVE-2018-10879} - sctp: validate embedded INIT chunk and address list lengths in COOKIE_ECHO {CVE-2026-53224} - sctp: validate cached peer INIT chunk length in COOKIE_ECHO {CVE-2026-53246}
Updated packages:
  • kernel-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:181e034435653b8398ff2afebd70b13393d075f858838ca24c06944caf9050ef
  • kernel-abi-whitelists-2.6.32-754.35.8.el6.tuxcare.els35.noarch.rpm
    sha:f85c7981bafebec4d2804c3fb81a2e097e49187f5e3232bae47b59183aed233e
  • kernel-debug-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:90dde5e64abac711d1697133c82eab360454284bec983aa4d0cbf8d141f827a3
  • kernel-debug-devel-2.6.32-754.35.8.el6.tuxcare.els35.i686.rpm
    sha:787de2c0f57da80632604df3a0538b24b1e1ef5fefb5997807d0b15e5c332209
  • kernel-debug-devel-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:cc8c319b58a0d1d6586f7c1bd777d9a72162113164c0b904991cf0279fc79749
  • kernel-devel-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:bbd907597f36bb15dce850193469a4e41c8490cb7a9ec692fe89adcc4bc8740b
  • kernel-doc-2.6.32-754.35.8.el6.tuxcare.els35.noarch.rpm
    sha:467b1b0dc7409d2803c96bfb7f5d9c1e001f6fe69dd61d46716690452ec48afb
  • kernel-firmware-2.6.32-754.35.8.el6.tuxcare.els35.noarch.rpm
    sha:3e76d9c4f58217472d217da0b0f681f24251cb99a87b15e0265970cb35a4c980
  • kernel-headers-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:c86bdae9ae2a441f63b0c71f985117b43aa372a2da3bbb70c2973fa962250936
  • perf-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:54525ae774be345e4b1bd8aeee937981eafe5046e10925ff901a58211fdf32af
  • python-perf-2.6.32-754.35.8.el6.tuxcare.els35.x86_64.rpm
    sha:589e65015eb114c4777d874e10c620699bb26c66ecf489cceedf81cf83fd461f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.