Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/xe: Make dma-fences compliant with the safe access rules (CVE-2025-38703) * kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length (CVE-2025-39933) * kernel: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE (CVE-2025-40277) * kernel: usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths (CVE-2025-68287) * kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/xe: Make dma-fences compliant with the safe access rules (CVE-2025-38703) * kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length (CVE-2025-39933) * kernel: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE (CVE-2025-40277) * kernel: usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths (CVE-2025-68287) * kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:0793
- https://access.redhat.com/security/cve/CVE-2025-38703
- https://access.redhat.com/security/cve/CVE-2025-39933
- https://access.redhat.com/security/cve/CVE-2025-40277
- https://access.redhat.com/security/cve/CVE-2025-68285
- https://access.redhat.com/security/cve/CVE-2025-68287
- https://bugzilla.redhat.com/2393157
- https://bugzilla.redhat.com/2401432
- https://bugzilla.redhat.com/2419954
- https://bugzilla.redhat.com/2422788
- https://bugzilla.redhat.com/2422801
- https://errata.almalinux.org/9/ALSA-2026-0793.html