Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ACPI: extlog: fix NULL pointer dereference check (CVE-2023-52605) * kernel: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (CVE-2024-50264) * kernel: HID: core: zero-initialize the report buffer (CVE-2024-50302) * kernel: can: bcm: Fix UAF in bcm_proc_show() (CVE-2023-52922) * kernel: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof (CVE-2024-53113) * kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (CVE-2024-53197) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ACPI: extlog: fix NULL pointer dereference check (CVE-2023-52605) * kernel: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (CVE-2024-50264) * kernel: HID: core: zero-initialize the report buffer (CVE-2024-50302) * kernel: can: bcm: Fix UAF in bcm_proc_show() (CVE-2023-52922) * kernel: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof (CVE-2024-53113) * kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (CVE-2024-53197) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:2627
- https://access.redhat.com/security/cve/CVE-2023-52605
- https://access.redhat.com/security/cve/CVE-2023-52922
- https://access.redhat.com/security/cve/CVE-2024-50264
- https://access.redhat.com/security/cve/CVE-2024-50302
- https://access.redhat.com/security/cve/CVE-2024-53113
- https://access.redhat.com/security/cve/CVE-2024-53197
- https://bugzilla.redhat.com/2268295
- https://bugzilla.redhat.com/2327168
- https://bugzilla.redhat.com/2327169
- https://bugzilla.redhat.com/2329370
- https://bugzilla.redhat.com/2329924
- https://bugzilla.redhat.com/2334412
- https://errata.almalinux.org/9/ALSA-2025-2627.html