Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902) * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206) * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016) * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136) * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329) * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374) * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884) * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879) * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219) * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523) Bug Fix(es) and Enhancement(s): * Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to AlmaLinux 8.10 (JIRA:AlmaLinux-189997) * vhost: reset the vring metadata cache on vring reconfiguration [almalinux-8.10.z] (JIRA:AlmaLinux-224556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902) * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206) * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016) * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136) * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329) * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374) * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884) * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879) * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219) * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523) Bug Fix(es) and Enhancement(s): * Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to AlmaLinux 8.10 (JIRA:AlmaLinux-189997) * vhost: reset the vring metadata cache on vring reconfiguration [almalinux-8.10.z] (JIRA:AlmaLinux-224556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:55764
- https://access.redhat.com/security/cve/CVE-2025-39902
- https://access.redhat.com/security/cve/CVE-2026-17523
- https://access.redhat.com/security/cve/CVE-2026-43206
- https://access.redhat.com/security/cve/CVE-2026-53016
- https://access.redhat.com/security/cve/CVE-2026-53136
- https://access.redhat.com/security/cve/CVE-2026-53329
- https://access.redhat.com/security/cve/CVE-2026-53374
- https://access.redhat.com/security/cve/CVE-2026-63879
- https://access.redhat.com/security/cve/CVE-2026-63884
- https://access.redhat.com/security/cve/CVE-2026-64219
- https://bugzilla.redhat.com/2400594
- https://bugzilla.redhat.com/2467156
- https://bugzilla.redhat.com/2492269
- https://bugzilla.redhat.com/2492768
- https://bugzilla.redhat.com/2495941
- https://bugzilla.redhat.com/2502188
- https://bugzilla.redhat.com/2502321
- https://bugzilla.redhat.com/2502463
- https://bugzilla.redhat.com/2506790
- https://bugzilla.redhat.com/2507407
- https://errata.almalinux.org/8/ALSA-2026-55764.html