[Security Advisory] ALSA-2026:71233: kernel security, bug fix, and enhancement update (Important)
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 10 Type: Security Severity: Important Release date: 2026-10-05 Summary: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007) * kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite (CVE-2026-53266) * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831) * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802) * kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053) * kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383) * kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564) * kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201) * kernel: selinux: check connect-related permissions on TCP Fast Open (CVE-2026-72243) * kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569) * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844) * kernel: net: tun: bound receive headroom (CVE-2026-81000) * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846) Bug Fix(es) and Enhancement(s): * kernel module .ko ELF files with non-zero sh_addr section addresses [almalinux-10.2.z] (JIRA:AlmaLinux-159298) * sctp: prevent peer transport count overflow [almalinux-10.2.z] (JIRA:AlmaLinux-216247) * [AlmaLinux 10] bnxt_en: RX queue restart failed: err=-95 [almalinux-10.2.z] (JIRA:AlmaLinux-247283) * RHIVOS - S32G: backport missing fixes to 10.2 (JIRA:AlmaLinux-259788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-71233.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team
participants (1)
-
AlmaLinux Errata Notifications