Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: bonding: check xdp prog when set bond mode (CVE-2025-22105) * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980) * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015) * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097) * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166) * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279) * kernel: nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails (CVE-2025-38400) * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405) * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441) * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470) * kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() (CVE-2025-39866) * kernel: dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134) * kernel: wifi: mac80211_hwsim: fix typo in frequency notification (CVE-2026-23040) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: bonding: check xdp prog when set bond mode (CVE-2025-22105) * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980) * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015) * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097) * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166) * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279) * kernel: nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails (CVE-2025-38400) * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405) * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441) * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470) * kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() (CVE-2025-39866) * kernel: dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134) * kernel: wifi: mac80211_hwsim: fix typo in frequency notification (CVE-2026-23040) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:18587
- https://access.redhat.com/security/cve/CVE-2025-22105
- https://access.redhat.com/security/cve/CVE-2025-37980
- https://access.redhat.com/security/cve/CVE-2025-38015
- https://access.redhat.com/security/cve/CVE-2025-38097
- https://access.redhat.com/security/cve/CVE-2025-38166
- https://access.redhat.com/security/cve/CVE-2025-38279
- https://access.redhat.com/security/cve/CVE-2025-38400
- https://access.redhat.com/security/cve/CVE-2025-38405
- https://access.redhat.com/security/cve/CVE-2025-38441
- https://access.redhat.com/security/cve/CVE-2025-38470
- https://access.redhat.com/security/cve/CVE-2025-39866
- https://access.redhat.com/security/cve/CVE-2025-40134
- https://access.redhat.com/security/cve/CVE-2026-23040
- https://access.redhat.com/security/cve/CVE-2026-23243
- https://bugzilla.redhat.com/2360247
- https://bugzilla.redhat.com/2367614
- https://bugzilla.redhat.com/2373343
- https://bugzilla.redhat.com/2376060
- https://bugzilla.redhat.com/2376065
- https://bugzilla.redhat.com/2379178
- https://bugzilla.redhat.com/2383397
- https://bugzilla.redhat.com/2383399
- https://bugzilla.redhat.com/2383478
- https://bugzilla.redhat.com/2383906
- https://bugzilla.redhat.com/2396940
- https://bugzilla.redhat.com/2414468
- https://bugzilla.redhat.com/2436806
- https://bugzilla.redhat.com/2448594
- https://errata.almalinux.org/9/ALSA-2026-18587.html