[Security Advisory] ALSA-2026:71700: kernel security, bug fix, and enhancement update (Important)
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 9 Type: Security Severity: Important Release date: 2026-09-29 Summary: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: fbcon: Set fb_display[i]->mode to NULL when the mode is released (CVE-2025-40323) * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539) * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230) * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204) * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199) * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311) * kernel: netfilter: nf_queue: hold bridge skb->dev while queued (CVE-2026-52912) * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203) * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290) * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098) * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121) * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108) * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257) * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267) * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266) * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273) * kernel: Linux kernel IPVS: Denial of Service due to stale memory references (CVE-2026-80714) Bug Fix(es) and Enhancement(s): * MADVISE i/o size in AlmaLinux 9 additionally limited by read_ahead_kb - Was addressed in AlmaLinux8 via AlmaLinux-22476 [almalinux-9.8.z] (JIRA:AlmaLinux-260938) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-71700.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team
participants (1)
-
AlmaLinux Errata Notifications