Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg (CVE-2024-56633) * kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (CVE-2025-21839) * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980) * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015) * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097) * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166) * kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (CVE-2025-38202) * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279) * kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267) * kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (CVE-2025-38275) * kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled (CVE-2025-38346) * kernel: ACPICA: fix acpi operand cache leak in dswstate.c (CVE-2025-38345) * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405) * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441) * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470) * kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() (CVE-2025-39866) * kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() (CVE-2025-40034) * kernel: dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134) * kernel: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" (CVE-2025-40210) * kernel: Linux kernel MPTCP: Privilege escalation or denial of service via use-after-free in timer handling (CVE-2025-40257) * kernel: smb: client: fix potential cfid UAF in smb2_query_info_compound (CVE-2025-40320) * kernel: wifi: mac80211_hwsim: fix typo in frequency notification (CVE-2026-23040) * kernel: Kernel: Privilege escalation or denial of service in nf_tables via inverted element activity check (CVE-2026-23111) * kernel: Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild (CVE-2026-23210) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg (CVE-2024-56633) * kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (CVE-2025-21839) * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980) * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015) * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097) * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166) * kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (CVE-2025-38202) * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279) * kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267) * kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (CVE-2025-38275) * kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled (CVE-2025-38346) * kernel: ACPICA: fix acpi operand cache leak in dswstate.c (CVE-2025-38345) * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405) * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441) * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470) * kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() (CVE-2025-39866) * kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() (CVE-2025-40034) * kernel: dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134) * kernel: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" (CVE-2025-40210) * kernel: Linux kernel MPTCP: Privilege escalation or denial of service via use-after-free in timer handling (CVE-2025-40257) * kernel: smb: client: fix potential cfid UAF in smb2_query_info_compound (CVE-2025-40320) * kernel: wifi: mac80211_hwsim: fix typo in frequency notification (CVE-2026-23040) * kernel: Kernel: Privilege escalation or denial of service in nf_tables via inverted element activity check (CVE-2026-23111) * kernel: Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild (CVE-2026-23210) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:18134
- https://access.redhat.com/security/cve/CVE-2024-56633
- https://access.redhat.com/security/cve/CVE-2025-21839
- https://access.redhat.com/security/cve/CVE-2025-37980
- https://access.redhat.com/security/cve/CVE-2025-38015
- https://access.redhat.com/security/cve/CVE-2025-38097
- https://access.redhat.com/security/cve/CVE-2025-38166
- https://access.redhat.com/security/cve/CVE-2025-38202
- https://access.redhat.com/security/cve/CVE-2025-38267
- https://access.redhat.com/security/cve/CVE-2025-38275
- https://access.redhat.com/security/cve/CVE-2025-38279
- https://access.redhat.com/security/cve/CVE-2025-38345
- https://access.redhat.com/security/cve/CVE-2025-38346
- https://access.redhat.com/security/cve/CVE-2025-38405
- https://access.redhat.com/security/cve/CVE-2025-38441
- https://access.redhat.com/security/cve/CVE-2025-38470
- https://access.redhat.com/security/cve/CVE-2025-39866
- https://access.redhat.com/security/cve/CVE-2025-40034
- https://access.redhat.com/security/cve/CVE-2025-40134
- https://access.redhat.com/security/cve/CVE-2025-40210
- https://access.redhat.com/security/cve/CVE-2025-40257
- https://access.redhat.com/security/cve/CVE-2025-40320
- https://access.redhat.com/security/cve/CVE-2026-23040
- https://access.redhat.com/security/cve/CVE-2026-23111
- https://access.redhat.com/security/cve/CVE-2026-23210
- https://access.redhat.com/security/cve/CVE-2026-23243
- https://bugzilla.redhat.com/2334549
- https://bugzilla.redhat.com/2350585
- https://bugzilla.redhat.com/2367614
- https://bugzilla.redhat.com/2373343
- https://bugzilla.redhat.com/2376060
- https://bugzilla.redhat.com/2376065
- https://bugzilla.redhat.com/2376382
- https://bugzilla.redhat.com/2379178
- https://bugzilla.redhat.com/2379187
- https://bugzilla.redhat.com/2379199
- https://bugzilla.redhat.com/2379237
- https://bugzilla.redhat.com/2379239
- https://bugzilla.redhat.com/2383399
- https://bugzilla.redhat.com/2383478
- https://bugzilla.redhat.com/2383906
- https://bugzilla.redhat.com/2396940
- https://bugzilla.redhat.com/2406782
- https://bugzilla.redhat.com/2414468
- https://bugzilla.redhat.com/2416307
- https://bugzilla.redhat.com/2418880
- https://bugzilla.redhat.com/2419945
- https://bugzilla.redhat.com/2436806
- https://bugzilla.redhat.com/2439687
- https://bugzilla.redhat.com/2439895
- https://bugzilla.redhat.com/2448594
- https://errata.almalinux.org/10/ALSA-2026-18134.html