| Name: | kernel-debug-core |
| Version: | 6.12.0 |
| Release: | 211.56.1.el10_2 |
| Architecture: | x86_64 |
| Group: | Unspecified |
| Size: | 107306927 |
| License: | ((GPL-2.0-only WITH Linux-syscall-note) OR BSD-2-Clause) AND ((GPL-2.0-only WITH Linux-syscall-note) OR BSD-3-Clause) AND ((GPL-2.0-only WITH Linux-syscall-note) OR CDDL-1.0) AND ((GPL-2.0-only WITH Linux-syscall-note) OR Linux-OpenIB) AND ((GPL-2.0-only WITH Linux-syscall-note) OR MIT) AND ((GPL-2.0-or-later WITH Linux-syscall-note) OR BSD-3-Clause) AND ((GPL-2.0-or-later WITH Linux-syscall-note) OR MIT) AND 0BSD AND BSD-2-Clause AND (BSD-2-Clause OR Apache-2.0) AND BSD-3-Clause AND BSD-3-Clause-Clear AND CC0-1.0 AND GFDL-1.1-no-invariants-or-later AND GPL-1.0-or-later AND (GPL-1.0-or-later OR BSD-3-Clause) AND (GPL-1.0-or-later WITH Linux-syscall-note) AND GPL-2.0-only AND (GPL-2.0-only OR Apache-2.0) AND (GPL-2.0-only OR BSD-2-Clause) AND (GPL-2.0-only OR BSD-3-Clause) AND (GPL-2.0-only OR CDDL-1.0) AND (GPL-2.0-only OR GFDL-1.1-no-invariants-or-later) AND (GPL-2.0-only OR GFDL-1.2-no-invariants-only) AND (GPL-2.0-only WITH Linux-syscall-note) AND GPL-2.0-or-later AND (GPL-2.0-or-later OR BSD-2-Clause) AND (GPL-2.0-or-later OR BSD-3-Clause) AND (GPL-2.0-or-later OR CC-BY-4.0) AND (GPL-2.0-or-later WITH GCC-exception-2.0) AND (GPL-2.0-or-later WITH Linux-syscall-note) AND ISC AND LGPL-2.0-or-later AND (LGPL-2.0-or-later OR BSD-2-Clause) AND (LGPL-2.0-or-later WITH Linux-syscall-note) AND LGPL-2.1-only AND (LGPL-2.1-only OR BSD-2-Clause) AND (LGPL-2.1-only WITH Linux-syscall-note) AND LGPL-2.1-or-later AND (LGPL-2.1-or-later WITH Linux-syscall-note) AND (Linux-OpenIB OR GPL-2.0-only) AND (Linux-OpenIB OR GPL-2.0-only OR BSD-2-Clause) AND Linux-man-pages-copyleft AND MIT AND (MIT OR Apache-2.0) AND (MIT OR GPL-2.0-only) AND (MIT OR GPL-2.0-or-later) AND (MIT OR LGPL-2.1-only) AND (MPL-1.1 OR GPL-2.0-only) AND (X11 OR GPL-2.0-only) AND (X11 OR GPL-2.0-or-later) AND Zlib AND (copyleft-next-0.3.1 OR GPL-2.0-or-later) |
| RPM: |
kernel-debug-core-6.12.0-211.56.1.el10_2.x86_64.rpm
|
| Source RPM: |
kernel-6.12.0-211.56.1.el10_2.src.rpm
|
| Build Date: | Thu Sep 17 2026 |
| Build Host: | build-ol10-x86_64.oracle.com |
| Vendor: | Oracle America |
| URL: | https://www.kernel.org/ |
| Summary: | The Linux kernel compiled with PREEMPT_RT enabled |
| Description: | The kernel package contains the Linux kernel (vmlinuz), the core of any
Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
This variant of the kernel has numerous debugging options enabled.
It should only be installed when trying to gather additional information
on kernel bugs, as some of these options impact performance noticably. |
-
Thu Sep 17 2026 EL Errata <el-errata_ww@oracle.com> [6.12.0-211.56.1.el10_2.OL10]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
-
Wed Sep 16 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.56.1.el10_2]
- redhat/configs: automotive: enable SENSORS_INA2XX (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) Use scoped_guard() to acquire the subsystem lock (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) clean up unused define and outdated comment (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) Make it easier to add more devices (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) Rely on subsystem locking (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) make regulator 'vs' support optional (Jared Kangas) [RHEL-255518]
- hwmon: (ina226) Add support for SY24655 (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) Add support for INA260 (Jared Kangas) [RHEL-255518]
- hwmon: (ina2xx) Add support for has_alerts configuration flag (Jared Kangas) [RHEL-255518]
- hwmon: (core) Use device name as a fallback in devm_hwmon_device_register_with_info (Jared Kangas) [RHEL-255518]
- hwmon: Support guard() and scoped_guard for subsystem locks (Jared Kangas) [RHEL-255518]
- hwmon: Serialize accesses in hwmon core (Jared Kangas) [RHEL-255518]
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Izabela Bakollari) [RHEL-241004] {CVE-2026-68363}
- wifi: iwlwifi: mld: stop TX during firmware restart (Izabela Bakollari) [RHEL-243307] {CVE-2026-64175}
- wifi: iwlwifi: mvm: fix driver-set TX rates on old devices (Izabela Bakollari) [RHEL-243363] {CVE-2026-64176}
- net: wwan: t7xx: fix potential skb->frags overflow in RX path (Izabela Bakollari) [RHEL-245528] {CVE-2026-23172}
- wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Izabela Bakollari) [RHEL-246405] {CVE-2026-63869}
- smb: client: fix multiuser mount with krb5 (Jorge San Emeterio Villalain) [RHEL-254105]
- time/sched_clock: Export symbol for sched_clock register function (Eric Chanudet) [RHEL-255225]
- clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path (Mattijs Korpershoek) [RHEL-255519]
- configs: Add NXP timer Kconfig options for automotive builds (Mattijs Korpershoek) [RHEL-255519]
- clocksource: move NXP timer selection to drivers/clocksource (Mattijs Korpershoek) [RHEL-255519]
- arm64: dts: s32g: add PIT support for s32g2 and s32g3 (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/nxp-pit: Prevent driver unbind (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support (Mattijs Korpershoek) [RHEL-255519]
- ARM: imx: Kconfig: Adjust select after renamed config option (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Rename the VF PIT to NXP PIT (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Unify the function name for irq ack (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Consolidate calls to pit_*_disable/enable (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Encapsulate set counter function (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Enable and disable module on error (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Encapsulate clocksource enable / disable (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Use the node name for the interrupt and timer names (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Encapsulate the PTLCVAL macro (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Encapsulate the macros (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Register the clocksource from the driver (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Convert raw values to BIT macros (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Allocate the struct timer at init time (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Encapsulate the initialization of the cycles_per_jiffy (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Pass the cpu number as parameter (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Rework the base address usage (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Set the scene for multiple timers (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Add COMPILE_TEST option (Mattijs Korpershoek) [RHEL-255519]
- clocksource/drivers/vf-pit: Replace raw_readl/writel to readl/writel (Mattijs Korpershoek) [RHEL-255519]
- redhat/configs: automotive: enable NVMEM_S32G_OCOTP (Mattijs Korpershoek) [RHEL-255516]
- arm64: dts: s32g: Add device tree information for the OCOTP driver (Mattijs Korpershoek) [RHEL-255516]
- nvmem: s32g-ocotp: Add driver for S32G OCOTP (Mattijs Korpershoek) [RHEL-255516]
- dt-bindings: nvmem: Add the nxp,s32g-ocotp yaml file (Mattijs Korpershoek) [RHEL-255516]
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Michal Schmidt) [RHEL-231041] {CVE-2026-72045}
- octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (Michal Schmidt) [RHEL-231041] {CVE-2026-63923}
- dm_early_create: fix freeing used table on dm_resume failure (CKI Backport Bot) [RHEL-244953] {CVE-2026-72102}
- net: slip: serialize receive against buffer reallocation (CKI Backport Bot) [RHEL-241018] {CVE-2026-68143}
- net: qrtr: restrict socket creation to the initial network namespace (CKI Backport Bot) [RHEL-240243] {CVE-2026-68294}
- ALSA: hda/tas2781: Fix device-0 reset issue and handle -EXDEV in block data processing (CKI Backport Bot) [RHEL-239776]
- ice: reject out-of-range ptype in ice_parser_profile_init (CKI Backport Bot) [RHEL-237211] {CVE-2026-68128}
- ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-237201] {CVE-2026-68200}
- netfilter: handle unreadable frags (CKI Backport Bot) [RHEL-234265] {CVE-2026-64414}
- net: ena: PHC: Fix potential use-after-free in get_timestamp (CKI Backport Bot) [RHEL-230631] {CVE-2026-52971}
- ALSA: timer: Fix UAF at snd_timer_user_params() (CKI Backport Bot) [RHEL-228700] {CVE-2026-53192}
- ALSA: seq: Serialize UMP output teardown with event_input (CKI Backport Bot) [RHEL-227727] {CVE-2026-64029}
- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (CKI Backport Bot) [RHEL-227086] {CVE-2026-53193}
- ALSA: timer: Forcibly close timer instances at closing (CKI Backport Bot) [RHEL-227086] {CVE-2026-53193}
- hwrng: virtio: clamp device-reported used.len at copy_data() (CKI Backport Bot) [RHEL-225748] {CVE-2026-64456}
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191611] {CVE-2026-53176}
- soc: qcom: socinfo: Avoid out of bounds read of serial number (CKI Backport Bot) [RHEL-191223] {CVE-2024-58007}
-
Mon Sep 14 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.55.1.el10_2]
- arm64: dts: s32g: add SAR ADC support for s32g2 and s32g3 (Jared Kangas) [RHEL-256890]
- arm64: dts: s32g3: Fix SWT8 watchdog address (Albert Esteve) [RHEL-256890]
- iio: adc: nxp-sar-adc: Fix the delay calculation in nxp_sar_adc_wait_for() (Albert Esteve) [RHEL-256890]
- iio: adc: nxp-sar-adc: harden buffer ISR against per-channel read failure (Albert Esteve) [RHEL-256890]
- iio: adc: nxp-sar-adc: Remove unnecessary type casting (Albert Esteve) [RHEL-256890]
- iio: core: fix uninitialized data in debugfs (Albert Esteve) [RHEL-256890]
- iio: fix potential out-of-bound write (Albert Esteve) [RHEL-256890]
- iio: core: make use of simple_write_to_buffer() (Albert Esteve) [RHEL-256890]
- iio: buffer: Move from int64_t to s64 for timestamp (Albert Esteve) [RHEL-256890]
- iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (Albert Esteve) [RHEL-256890]
- iio: Replace 'sign' field with union in struct iio_scan_type (Albert Esteve) [RHEL-256890]
- iio: buffer: ensure repeat alignment is a power of two (Albert Esteve) [RHEL-256890]
- iio: buffer: cache timestamp offset in scan buffer (Albert Esteve) [RHEL-256890]
- iio: buffer: check return value of iio_compute_scan_bytes() (Albert Esteve) [RHEL-256890]
- iio: core: Clean up device correctly on viio_trigger_alloc() failure (Albert Esteve) [RHEL-256890]
- iio: core: Simplify IIO core managed APIs (Albert Esteve) [RHEL-256890]
- iio: inkern: call iio_device_put() only on mapped devices (Albert Esteve) [RHEL-256890]
- iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name() (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: Use dev_err_probe() to simplify code (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: Use managed API dmaenginem_async_device_register() (Albert Esteve) [RHEL-256890]
- dmaengine: of_dma: Add devm_of_dma_controller_register() (Albert Esteve) [RHEL-256890]
- dt-bindings: dma: fsl-edma: add dma-channel-mask property description (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: don't explicitly disable clocks in .remove() (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: drop unused module alias (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: configure tcd attr with separate src and dst settings (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: Fix clk leak on alloc_chan_resources failure (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: Remove redundant check in fsl_edma_free_chan_resources() (Albert Esteve) [RHEL-256890]
- dmaengine: fsl-edma: fix channel parameter config for fixed channel requests (Albert Esteve) [RHEL-256890]
- i2c: imx: fix clock and pinctrl state inconsistency in runtime PM (Albert Esteve) [RHEL-256890]
- i2c: imx: zero-initialize dma_slave_config for eDMA (Albert Esteve) [RHEL-256890]
- i2c: imx: ensure no clock is generated after last read (Albert Esteve) [RHEL-256890]
- i2c: imx: fix i2c issue when reading multiple messages (Albert Esteve) [RHEL-256890]
- i2c: imx: preserve error state in block data length handler (Albert Esteve) [RHEL-256890]
- redhat/configs: automotive: enable NXP_SAR_ADC as a module (Eric Chanudet) [RHEL-255233]
- iio: adc: nxp-sar-adc: Avoid division by zero (Eric Chanudet) [RHEL-255233]
- iio: adc: nxp-sar-adc: zero-initialize dma_slave_config (Eric Chanudet) [RHEL-255233]
- iio: adc: nxp-sar-adc: fix division by zero in write_raw (Eric Chanudet) [RHEL-255233]
- iio: adc: nxp-sar-adc: Fix DMA channel leak in trigger mode (Eric Chanudet) [RHEL-255233]
- iio: buffer: Fix wait_queue not being removed (Eric Chanudet) [RHEL-255233]
- iio: core: add separate lockdep class for info_exist_lock (Eric Chanudet) [RHEL-255233]
- iio: adc: Add the NXP SAR ADC support for the s32g2/3 platforms (Eric Chanudet) [RHEL-255233]
- dt-bindings: iio: adc: Add the NXP SAR ADC for s32g2/3 platforms (Eric Chanudet) [RHEL-255233]
- iio: core: Replace lockdep_set_class() + mutex_init() by combined call (Eric Chanudet) [RHEL-255233]
- iio: core: Clean up device correctly on iio_device_alloc() failure (Eric Chanudet) [RHEL-255233]
- iio: core: add missing mutex_destroy in iio_dev_release() (Eric Chanudet) [RHEL-255233]
- iio: iio_format_list() should set stride=1 for IIO_VAL_CHAR (Eric Chanudet) [RHEL-255233]
- iio: backend: fix out-of-bound write (Eric Chanudet) [RHEL-255233]
- iio: introduce IIO_DECLARE_BUFFER_WITH_TS macros (Eric Chanudet) [RHEL-255233]
- iio: make IIO_DMA_MINALIGN minimum of 8 bytes (Eric Chanudet) [RHEL-255233]
- iio: backend: make sure to NULL terminate stack buffer (Eric Chanudet) [RHEL-255233]
- iio: core: Rework claim and release of direct mode to work with sparse. (Eric Chanudet) [RHEL-255233]
- iio: backend: fix wrong pointer passed to IS_ERR() (Eric Chanudet) [RHEL-255233]
- iio: buffer: document iio_push_to_buffers_with_ts() (Eric Chanudet) [RHEL-255233]
- iio: introduced iio_push_to_buffers_with_ts() that takes a data_total_len argument. (Eric Chanudet) [RHEL-255233]
- iio: Drop iio_device_claim_direct_scoped() and related infrastructure (Eric Chanudet) [RHEL-255233]
- iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes) [RHEL-256731]
- watchdog: fix hrtimer start when pretimeout is zero (David Arcari) [RHEL-255348]
- smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() (Paulo Alcantara) [RHEL-230559]
- smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() (Paulo Alcantara) [RHEL-230559]
- smb: client: let send_done handle a completion without IB_SEND_SIGNALED (Paulo Alcantara) [RHEL-230559]
- smb: client: let smbd_post_send_negotiate_req() use smbd_post_send() (Paulo Alcantara) [RHEL-230559]
- smb: client: fix last send credit problem causing disconnects (Paulo Alcantara) [RHEL-230559]
- smb: client: make use of smbdirect_socket.send_io.bcredits (Paulo Alcantara) [RHEL-230559]
- smb: client: use smbdirect_send_batch processing (Paulo Alcantara) [RHEL-230559]
- smb: client: introduce and use smbd_{alloc, free}_send_io() (Paulo Alcantara) [RHEL-230559]
- smb: client: split out smbd_ib_post_send() (Paulo Alcantara) [RHEL-230559]
- smb: client: port and use the wait_for_credits logic used by server (Paulo Alcantara) [RHEL-230559]
- smb: client: remove pointless sc->send_io.pending handling in smbd_post_send_iter() (Paulo Alcantara) [RHEL-230559]
- smb: client: remove pointless sc->recv_io.credits.count rollback (Paulo Alcantara) [RHEL-230559]
- smb: client: let smbd_post_send() make use of request->wr (Paulo Alcantara) [RHEL-230559]
- smb: client: let recv_done() queue a refill when the peer is low on credits (Paulo Alcantara) [RHEL-230559]
- smb: client: make use of smbdirect_socket.recv_io.credits.available (Paulo Alcantara) [RHEL-230559]
- smb: server: let send_done handle a completion without IB_SEND_SIGNALED (Paulo Alcantara) [RHEL-230559]
- smb: server: fix last send credit problem causing disconnects (Paulo Alcantara) [RHEL-230559]
- smb: server: make use of smbdirect_socket.send_io.bcredits (Paulo Alcantara) [RHEL-230559]
- smb: server: let recv_done() queue a refill when the peer is low on credits (Paulo Alcantara) [RHEL-230559]
- smb: server: make use of smbdirect_socket.recv_io.credits.available (Paulo Alcantara) [RHEL-230559]
- smb: smbdirect: introduce smbdirect_socket.send_io.bcredits.* (Paulo Alcantara) [RHEL-230559]
- smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (Paulo Alcantara) [RHEL-230559] {CVE-2026-31539}
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CKI Backport Bot) [RHEL-254596] {CVE-2026-74556}
- drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove (Mika Penttilä) [RHEL-222461] {CVE-2026-23466}
- drm/amdgpu: Fix use-after-free race in VM acquire (CKI Backport Bot) [RHEL-222401] {CVE-2026-43370}
- drm/i915: Fix potential overflow of shmem scatterlist length (CKI Backport Bot) [RHEL-222474] {CVE-2026-43368}
- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CKI Backport Bot) [RHEL-222424] {CVE-2026-31656}
- drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CKI Backport Bot) [RHEL-221279] {CVE-2026-31566}
- drm/xe: always keep track of remap prev/next (CKI Backport Bot) [RHEL-222307] {CVE-2026-31479}
- drm/xe: Open-code GGTT MMIO access protection (CKI Backport Bot) [RHEL-222461] {CVE-2026-23466}
- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Mika Penttilä) [RHEL-236579] {CVE-2026-68264}
- mshv: Fix infinite fault loop on permission-denied GPA intercepts (Maxim Levitsky) [RHEL-245035]
- mshv: Fix error handling in mshv_region_pin (Maxim Levitsky) [RHEL-245035]
- mshv: Fix use-after-free in mshv_map_user_memory error path (Maxim Levitsky) [RHEL-245035]
- mshv: pass struct mshv_user_mem_region by reference (Maxim Levitsky) [RHEL-245035]
- mshv: Handle insufficient root memory hypervisor statuses (Maxim Levitsky) [RHEL-245035]
- mshv: Handle insufficient contiguous memory hypervisor status (Maxim Levitsky) [RHEL-245035]
- mshv: Introduce hv_deposit_memory helper functions (Maxim Levitsky) [RHEL-245035]
- mshv: Introduce hv_result_needs_memory() helper function (Maxim Levitsky) [RHEL-245035]
- mshv: Add SMT_ENABLED_GUEST partition creation flag (Maxim Levitsky) [RHEL-245035]
- mshv: Add support for integrated scheduler (Maxim Levitsky) [RHEL-245035]
- mshv: Add debugfs to view hypervisor statistics (Maxim Levitsky) [RHEL-245035]
- mshv: Add data for printing stats page counters (Maxim Levitsky) [RHEL-245035]
- mshv: Update hv_stats_page definitions (Maxim Levitsky) [RHEL-245035]
- mshv: Always map child vp stats pages regardless of scheduler type (Maxim Levitsky) [RHEL-245035]
- mshv: Improve mshv_vp_stats_map/unmap(), add them to mshv_root.h (Maxim Levitsky) [RHEL-245035]
- mshv: Use typed hv_stats_page pointers (Maxim Levitsky) [RHEL-245035]
- mshv: Ignore second stats page map result failure (Maxim Levitsky) [RHEL-245035]
- xfrm: Fix dev use-after-free in xfrm async resumption (Sabrina Dubroca) [RHEL-233037] {CVE-2026-31663}
- xfrm: hold dev ref until after transport_finish NF_HOOK (Sabrina Dubroca) [RHEL-233037] {CVE-2026-31663}
- xfrm: hold device only for the asynchronous decryption (Sabrina Dubroca) [RHEL-233037] {CVE-2026-31663}
- xfrm: input: hold netns during deferred transport reinjection (Sabrina Dubroca) [RHEL-227502] {CVE-2026-63919}
- xfrm: fix stale skb->prev after async crypto steals a GSO segment (Sabrina Dubroca) [RHEL-236113] {CVE-2026-68426}
- xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (Sabrina Dubroca) [RHEL-236113] {CVE-2026-68426}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sabrina Dubroca) [RHEL-228006] {CVE-2026-53239}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Sabrina Dubroca) [RHEL-231756] {CVE-2026-63917}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Sabrina Dubroca) [RHEL-228943] {CVE-2026-63921}
- af_unix: Set gc_in_progress to true in unix_gc(). (Davide Caratti) [RHEL-227544] {CVE-2026-53361}
- af_unix: Give up GC if MSG_PEEK intervened. (Davide Caratti) [RHEL-227544] {CVE-2026-23394}
- af_unix: Consolidate unix_schedule_gc() and wait_for_unix_gc(). (Davide Caratti) [RHEL-227544]
- af_unix: Remove unix_tot_inflight. (Davide Caratti) [RHEL-227544]
- af_unix: Refine wait_for_unix_gc(). (Davide Caratti) [RHEL-227544]
- af_unix: Don't call wait_for_unix_gc() on every sendmsg(). (Davide Caratti) [RHEL-227544]
- af_unix: Don't trigger GC from close() if unnecessary. (Davide Caratti) [RHEL-227544]
- af_unix: Simplify GC state. (Davide Caratti) [RHEL-227544]
- af_unix: Count cyclic SCC. (Davide Caratti) [RHEL-227544]
- af_unix: Initialise scc_index in unix_add_edge(). (Davide Caratti) [RHEL-227544]
- af_unix: Clean up #include under net/unix/. (Davide Caratti) [RHEL-227544]
- af_unix: Explicitly include headers for non-pointer struct fields. (Davide Caratti) [RHEL-227544]
- af_unix: Sort headers. (Davide Caratti) [RHEL-227544]
- unix: fix up for "apparmor: add fine grained af_unix mediation" (Davide Caratti) [RHEL-227544]
- af_unix: Move internal definitions to net/unix/. (Davide Caratti) [RHEL-227544]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190194]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190194] {CVE-2026-53246}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-235912] {CVE-2025-68745}
- lsm: hold cred_guard_mutex for lsm_set_self_attr() (Ricardo Robaina) [RHEL-226807] {CVE-2026-64111}
- tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). (CKI Backport Bot) [RHEL-231909] {CVE-2025-40149}
- netfilter: require Ethernet MAC header before using eth_hdr() (CKI Backport Bot) [RHEL-230672] {CVE-2026-53131}
- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CKI Backport Bot) [RHEL-228717] {CVE-2026-63889}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225792] {CVE-2026-46149}
- sctp: purge outqueue on stale COOKIE-ECHO handling (CKI Backport Bot) [RHEL-188199] {CVE-2026-52924}
- vhost: move vdpa group bound check to vhost_vdpa (CKI Backport Bot) [RHEL-174283] {CVE-2026-43248}
-
Mon Sep 07 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}
-
Mon Sep 07 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}
-
Thu Sep 03 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.52.1.el10_2]
- fuse: fix race between interrupt and resend (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248457] {CVE-2026-64563}
- udp: Fix wildcard bind conflict check when using hash2 (Felix Maurer) [RHEL-218016] {CVE-2026-31503}
- tcp: optimize inet_use_bhash2_on_bind() (Felix Maurer) [RHEL-218016]
- tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232246] {CVE-2026-46015}
- flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232629] {CVE-2026-46306}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226125] {CVE-2026-46266}
- ipv6: anycast: insert aca into global hash under idev->lock (Felix Maurer) [RHEL-230763] {CVE-2026-53259}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226073] {CVE-2026-53275}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225606] {CVE-2026-43339}
- net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225864] {CVE-2026-53223}
- net: add pskb_may_pull() to skb_gro_receive_list() (Felix Maurer) [RHEL-229309] {CVE-2026-53235}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking when updating filter and timer values (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: fix locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- smb: client: fix double-free in SMB2_close() replay (Paulo Alcantara) [RHEL-240056] {CVE-2026-64597}
- selftests: nft_queue.sh: add a parallel stress test (Florian Westphal) [RHEL-132852]
- selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels (Florian Westphal) [RHEL-132852]
- netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [RHEL-132852] {CVE-2026-43084}
- netfilter: nfnetlink_queue: optimize verdict lookup with hash table (Florian Westphal) [RHEL-132852]
- netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation (Florian Westphal) [RHEL-132852]
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Abhishek Rawal) [RHEL-228009] {CVE-2026-53075}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Abhishek Rawal) [RHEL-231711] {CVE-2026-63993}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Abhishek Rawal) [RHEL-225920] {CVE-2026-53228}
- ipv6: add NULL checks for idev in SRv6 paths (Abhishek Rawal) [RHEL-218012] {CVE-2026-23442}
- nvmet-auth: validate reply message payload bounds against transfer length (CKI Backport Bot) [RHEL-234153] {CVE-2026-64319}
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CKI Backport Bot) [RHEL-234204] {CVE-2026-64287}
- KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CKI Backport Bot) [RHEL-229347] {CVE-2026-53277}
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CKI Backport Bot) [RHEL-227269] {CVE-2026-64002}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (CKI Backport Bot) [RHEL-227111] {CVE-2026-52933}
-
Tue Sep 01 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.51.1.el10_2]
- net: ipv6: clear suppressed fib6 rule result (Jamie Bainbridge) [RHEL-246368] {CVE-2026-74581}
- iomap: fix out-of-bounds bitmap_set() with zero-length range (CKI Backport Bot) [RHEL-240183] {CVE-2026-68145}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (CKI Backport Bot) [RHEL-231559] {CVE-2026-63808}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (CKI Backport Bot) [RHEL-229621] {CVE-2026-63824}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (CKI Backport Bot) [RHEL-223128] {CVE-2026-53073}
- smb: client: fix query directory replay double-free (CKI Backport Bot) [RHEL-219150] {CVE-2026-64387}
-
Mon Aug 31 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.50.1.el10_2]
- redhat: add kmap.py tool and kernel-kmap-internal package (Rado Vrbovsky)
- nvmet-auth: reject short AUTH_RECEIVE buffers (CKI Backport Bot) [RHEL-244915] {CVE-2026-72130}
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CKI Backport Bot) [RHEL-242861] {CVE-2026-72069}
- s390: Revert support for DCACHE_WORD_ACCESS (John J Coleman) [RHEL-188180]
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CKI Backport Bot) [RHEL-234051] {CVE-2026-64298}
- nfsd: release layout stid on setlease failure (Scott Mayhew) [RHEL-227794] {CVE-2026-53399}
- NFSv4/flexfiles: reject zero filehandle version count (CKI Backport Bot) [RHEL-229415] {CVE-2026-53392}
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CKI Backport Bot) [RHEL-228036] {CVE-2026-53391}
- NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg (CKI Backport Bot) [RHEL-227946] {CVE-2026-53026}
- pNFS: Fix use-after-free in pnfs_update_layout() (CKI Backport Bot) [RHEL-226322] {CVE-2026-63800}
- nfsd: fix posix_acl leak on SETACL decode failure (CKI Backport Bot) [RHEL-225522] {CVE-2026-53397}
- mm/khugepaged: write all dirty file folios when collapsing (Rafael Aquini) [RHEL-236329] {CVE-2026-68086}
- userfaultfd: prevent registration of special VMAs (Rafael Aquini) [RHEL-237862] {CVE-2026-68166}
- userfaultfd: correctly prevent registering VM_DROPPABLE regions (Rafael Aquini) [RHEL-237862] {CVE-2026-68166}
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (Vladislav Dronov) [RHEL-234477] {CVE-2026-64438}
- mm: shrinker: fix NULL pointer dereference in debugfs (Rafael Aquini) [RHEL-230833] {CVE-2026-64417}
- mm: shrinker: fix shrinker_info teardown race with expansion (Rafael Aquini) [RHEL-230833] {CVE-2026-64418}
- x86/bugs: Make Safe-RET robust against interrupt injection (Waiman Long) [RHEL-230475] {CVE-2026-68480}
- crypto: qat - validate RSA CRT component lengths (CKI Backport Bot) [RHEL-234546] {CVE-2026-64304}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231446] {CVE-2026-64277}
- mm/huge_memory: update file PMD counter before folio_put() (CKI Backport Bot) [RHEL-231228] {CVE-2026-53189}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CKI Backport Bot) [RHEL-230263] {CVE-2026-64276}
- ALSA: virtio: Validate control metadata from the device (CKI Backport Bot) [RHEL-230142] {CVE-2026-64490}
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (CKI Backport Bot) [RHEL-229231] {CVE-2026-64018}
- smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CKI Backport Bot) [RHEL-228550] {CVE-2026-64136}
- bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CKI Backport Bot) [RHEL-225292] {CVE-2026-45970}
- netfilter: ipset: fix race between dump and ip_set_list resize (CKI Backport Bot) [RHEL-227657] {CVE-2026-64189}
- iommu/amd: Fix clone_alias() to use the original device's devid (CKI Backport Bot) [RHEL-227452] {CVE-2026-53053}
- smb: client: fix change notify replay double-free (CKI Backport Bot) [RHEL-226988] {CVE-2026-64384}
- mm/list_lru: drain before clearing xarray entry on reparent (Rafael Aquini) [RHEL-227399] {CVE-2026-53153}
- s390/pfault: Fix virtual vs physical address confusion (Ramesh Chhetri) [RHEL-222507]
- crypto: qat - cancel work on re-enable SR-IOV timeout (CKI Backport Bot) [RHEL-218627]
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CKI Backport Bot) [RHEL-219623] {CVE-2026-64320}
- sctp: hold socket lock when dumping endpoints in sctp_diag (CKI Backport Bot) [RHEL-212393]
- seccomp: passthrough uretprobe systemcall without filtering (Ricardo Robaina) [RHEL-210908] {CVE-2025-21834}
- qede: fix off-by-one in BD ring consumption on build_skb failure (CKI Backport Bot) [RHEL-193043]
- zram: fix use-after-free in zram_bvec_write_partial() (CKI Backport Bot) [RHEL-191442] {CVE-2026-53185}
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Desnes Nunes) [RHEL-191042] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Desnes Nunes) [RHEL-191042] {CVE-2026-53196}
- ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CKI Backport Bot) [RHEL-189631] {CVE-2026-23003}
- ip6_gre: Use cached t->net in ip6erspan_changelink(). (CKI Backport Bot) [RHEL-180136] {CVE-2026-46120}
- netfilter: nf_tables: Fix for duplicate device in netdev hooks (CKI Backport Bot) [RHEL-179761] {CVE-2026-43454}
- netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CKI Backport Bot) [RHEL-179744] {CVE-2026-43450}
-
Wed Aug 19 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.49.1.el10_2]
- udf: fix partition descriptor append bookkeeping (CKI Backport Bot) [RHEL-179570] {CVE-2026-45991}
- cifs: fix time_last_write stamp placement in setattr/truncate paths (Paulo Alcantara) [RHEL-235459]
- cifs: consolidate time_last_write stamp into _cifsFileInfo_put() (Paulo Alcantara) [RHEL-235459]
- cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (Paulo Alcantara) [RHEL-235459]
- cifs: prevent readdir from changing file size due to stale directory metadata (Paulo Alcantara) [RHEL-235459]
- smb: client: fix dir separator in SMB1 UNIX mounts (Paulo Alcantara) [RHEL-235459]
- smb: client: fix sbflags initialization (Paulo Alcantara) [RHEL-235459]
- smb: client: use atomic_t for mnt_cifs_flags (Paulo Alcantara) [RHEL-235459]
- smb: client: fix data corruption due to racy lease checks (Paulo Alcantara) [RHEL-235459]
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226717] {CVE-2026-43493}
- smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive() (Paulo Alcantara) [RHEL-235812]
- smb/client: handle overlapping allocated ranges in fallocate (CKI Backport Bot) [RHEL-236210] {CVE-2026-68388}
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Waiman Long) [RHEL-227850] {CVE-2026-64560}
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Waiman Long) [RHEL-227850] {CVE-2026-64370}
- exit: kill the pointless __exit_signal()->clear_tsk_thread_flag(TIF_SIGPENDING) (Waiman Long) [RHEL-227850]
- exit: change the release_task() paths to call flush_sigqueue() lockless (Waiman Long) [RHEL-227850]
- smb: client: fix double-free in SMB2_open() replay (CKI Backport Bot) [RHEL-234551] {CVE-2026-64382}
- smb: client: mask server-provided mode to 07777 in modefromsid (CKI Backport Bot) [RHEL-234530] {CVE-2026-64379}
- smb: client: fix query_info() replay double-free (CKI Backport Bot) [RHEL-234129] {CVE-2026-64386}
- smb/client: fix out-of-bounds read in symlink_data() (CKI Backport Bot) [RHEL-229066] {CVE-2026-46185}
- blk-mq: reinsert cached request to the list (CKI Backport Bot) [RHEL-213153] {CVE-2026-64017}
- blk-mq: pop cached request if it is usable (CKI Backport Bot) [RHEL-213153] {CVE-2026-64017}
-
Mon Aug 17 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.48.1.el10_2]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Maurizio Lombardi) [RHEL-213217] {CVE-2026-63888}
- drm/i915: Fix potential UAF in TTM object purge (CKI Backport Bot) [RHEL-222740] {CVE-2026-63884}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CKI Backport Bot) [RHEL-222567] {CVE-2026-64219}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CKI Backport Bot) [RHEL-222667] {CVE-2026-53329}
- drm/amdgpu: fix amdgpu_hmm_range_get_pages (Mika Penttilä) [RHEL-222625] {CVE-2026-63879}
- drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CKI Backport Bot) [RHEL-221336] {CVE-2026-43206}
- drm/i915/gem: Fix phys BO pread/pwrite with offset (CKI Backport Bot) [RHEL-222753] {CVE-2026-53356}
- drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CKI Backport Bot) [RHEL-222721] {CVE-2026-45878}
- drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CKI Backport Bot) [RHEL-222701] {CVE-2026-53143}
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CKI Backport Bot) [RHEL-222685] {CVE-2026-53136}
- drm/amdgpu: zero-initialize GART table on allocation (CKI Backport Bot) [RHEL-222646] {CVE-2026-53374}
- drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v7 (CKI Backport Bot) [RHEL-221380] {CVE-2026-43237}
- drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CKI Backport Bot) [RHEL-221380] {CVE-2026-43237}
- sched/psi: Create the psimon kthread outside of cgroup_mutex (CKI Backport Bot) [RHEL-232560] {CVE-2026-52991}
- sched/psi: fix race between file release and pressure write (CKI Backport Bot) [RHEL-232560] {CVE-2026-52991}
- scsi: target: Fix hexadecimal CHAP_I handling (CKI Backport Bot) [RHEL-231667] {CVE-2026-63886}
- scsi: target: iscsi: Validate CHAP_R length before base64 decode (CKI Backport Bot) [RHEL-231667] {CVE-2026-63886}
- memfd: deny writeable mappings when implying SEAL_WRITE (Luiz Capitulino) [RHEL-228531] {CVE-2026-63952}
- mm/memfd: fix spelling in memfd_add_seals() (Luiz Capitulino) [RHEL-228531]
- vhost: reset the vring metadata cache on vring reconfiguration (CKI Backport Bot) [RHEL-224545]
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lukas Herbolt) [RHEL-223954]