Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it (CVE-2025-38403) * kernel: net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) * kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135) * kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158) * kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service (CVE-2025-40269) * kernel: ext4: fix use-after-free in ext4_orphan_cleanup (CVE-2022-50673) * kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CVE-2025-68349) * kernel: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CVE-2026-22998) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it (CVE-2025-38403) * kernel: net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) * kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135) * kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158) * kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service (CVE-2025-40269) * kernel: ext4: fix use-after-free in ext4_orphan_cleanup (CVE-2022-50673) * kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CVE-2025-68349) * kernel: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CVE-2026-22998) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:2264
- https://access.redhat.com/security/cve/CVE-2022-50673
- https://access.redhat.com/security/cve/CVE-2025-38403
- https://access.redhat.com/security/cve/CVE-2025-40135
- https://access.redhat.com/security/cve/CVE-2025-40158
- https://access.redhat.com/security/cve/CVE-2025-40170
- https://access.redhat.com/security/cve/CVE-2025-40269
- https://access.redhat.com/security/cve/CVE-2025-68349
- https://access.redhat.com/security/cve/CVE-2026-22998
- https://bugzilla.redhat.com/2383421
- https://bugzilla.redhat.com/2414506
- https://bugzilla.redhat.com/2414521
- https://bugzilla.redhat.com/2414523
- https://bugzilla.redhat.com/2419919
- https://bugzilla.redhat.com/2420347
- https://bugzilla.redhat.com/2424880
- https://bugzilla.redhat.com/2432671
- https://errata.almalinux.org/8/ALSA-2026-2264.html