-
Tue Sep 08 2026 EL Errata <el-errata_ww@oracle.com> [6.12.0-211.53.1.el10_2]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
-
Mon Sep 07 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}
-
Thu Sep 03 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.52.1.el10_2]
- fuse: fix race between interrupt and resend (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248457] {CVE-2026-64563}
- udp: Fix wildcard bind conflict check when using hash2 (Felix Maurer) [RHEL-218016] {CVE-2026-31503}
- tcp: optimize inet_use_bhash2_on_bind() (Felix Maurer) [RHEL-218016]
- tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232246] {CVE-2026-46015}
- flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232629] {CVE-2026-46306}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226125] {CVE-2026-46266}
- ipv6: anycast: insert aca into global hash under idev->lock (Felix Maurer) [RHEL-230763] {CVE-2026-53259}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226073] {CVE-2026-53275}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225606] {CVE-2026-43339}
- net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225864] {CVE-2026-53223}
- net: add pskb_may_pull() to skb_gro_receive_list() (Felix Maurer) [RHEL-229309] {CVE-2026-53235}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking when updating filter and timer values (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: fix locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- smb: client: fix double-free in SMB2_close() replay (Paulo Alcantara) [RHEL-240056] {CVE-2026-64597}
- selftests: nft_queue.sh: add a parallel stress test (Florian Westphal) [RHEL-132852]
- selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels (Florian Westphal) [RHEL-132852]
- netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [RHEL-132852] {CVE-2026-43084}
- netfilter: nfnetlink_queue: optimize verdict lookup with hash table (Florian Westphal) [RHEL-132852]
- netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation (Florian Westphal) [RHEL-132852]
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Abhishek Rawal) [RHEL-228009] {CVE-2026-53075}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Abhishek Rawal) [RHEL-231711] {CVE-2026-63993}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Abhishek Rawal) [RHEL-225920] {CVE-2026-53228}
- ipv6: add NULL checks for idev in SRv6 paths (Abhishek Rawal) [RHEL-218012] {CVE-2026-23442}
- nvmet-auth: validate reply message payload bounds against transfer length (CKI Backport Bot) [RHEL-234153] {CVE-2026-64319}
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CKI Backport Bot) [RHEL-234204] {CVE-2026-64287}
- KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CKI Backport Bot) [RHEL-229347] {CVE-2026-53277}
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CKI Backport Bot) [RHEL-227269] {CVE-2026-64002}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (CKI Backport Bot) [RHEL-227111] {CVE-2026-52933}
-
Tue Sep 01 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.51.1.el10_2]
- net: ipv6: clear suppressed fib6 rule result (Jamie Bainbridge) [RHEL-246368] {CVE-2026-74581}
- iomap: fix out-of-bounds bitmap_set() with zero-length range (CKI Backport Bot) [RHEL-240183] {CVE-2026-68145}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (CKI Backport Bot) [RHEL-231559] {CVE-2026-63808}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (CKI Backport Bot) [RHEL-229621] {CVE-2026-63824}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (CKI Backport Bot) [RHEL-223128] {CVE-2026-53073}
- smb: client: fix query directory replay double-free (CKI Backport Bot) [RHEL-219150] {CVE-2026-64387}
-
Mon Aug 31 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.50.1.el10_2]
- redhat: add kmap.py tool and kernel-kmap-internal package (Rado Vrbovsky)
- nvmet-auth: reject short AUTH_RECEIVE buffers (CKI Backport Bot) [RHEL-244915] {CVE-2026-72130}
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CKI Backport Bot) [RHEL-242861] {CVE-2026-72069}
- s390: Revert support for DCACHE_WORD_ACCESS (John J Coleman) [RHEL-188180]
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CKI Backport Bot) [RHEL-234051] {CVE-2026-64298}
- nfsd: release layout stid on setlease failure (Scott Mayhew) [RHEL-227794] {CVE-2026-53399}
- NFSv4/flexfiles: reject zero filehandle version count (CKI Backport Bot) [RHEL-229415] {CVE-2026-53392}
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CKI Backport Bot) [RHEL-228036] {CVE-2026-53391}
- NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg (CKI Backport Bot) [RHEL-227946] {CVE-2026-53026}
- pNFS: Fix use-after-free in pnfs_update_layout() (CKI Backport Bot) [RHEL-226322] {CVE-2026-63800}
- nfsd: fix posix_acl leak on SETACL decode failure (CKI Backport Bot) [RHEL-225522] {CVE-2026-53397}
- mm/khugepaged: write all dirty file folios when collapsing (Rafael Aquini) [RHEL-236329] {CVE-2026-68086}
- userfaultfd: prevent registration of special VMAs (Rafael Aquini) [RHEL-237862] {CVE-2026-68166}
- userfaultfd: correctly prevent registering VM_DROPPABLE regions (Rafael Aquini) [RHEL-237862] {CVE-2026-68166}
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (Vladislav Dronov) [RHEL-234477] {CVE-2026-64438}
- mm: shrinker: fix NULL pointer dereference in debugfs (Rafael Aquini) [RHEL-230833] {CVE-2026-64417}
- mm: shrinker: fix shrinker_info teardown race with expansion (Rafael Aquini) [RHEL-230833] {CVE-2026-64418}
- x86/bugs: Make Safe-RET robust against interrupt injection (Waiman Long) [RHEL-230475] {CVE-2026-68480}
- crypto: qat - validate RSA CRT component lengths (CKI Backport Bot) [RHEL-234546] {CVE-2026-64304}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231446] {CVE-2026-64277}
- mm/huge_memory: update file PMD counter before folio_put() (CKI Backport Bot) [RHEL-231228] {CVE-2026-53189}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CKI Backport Bot) [RHEL-230263] {CVE-2026-64276}
- ALSA: virtio: Validate control metadata from the device (CKI Backport Bot) [RHEL-230142] {CVE-2026-64490}
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (CKI Backport Bot) [RHEL-229231] {CVE-2026-64018}
- smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CKI Backport Bot) [RHEL-228550] {CVE-2026-64136}
- bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CKI Backport Bot) [RHEL-225292] {CVE-2026-45970}
- netfilter: ipset: fix race between dump and ip_set_list resize (CKI Backport Bot) [RHEL-227657] {CVE-2026-64189}
- iommu/amd: Fix clone_alias() to use the original device's devid (CKI Backport Bot) [RHEL-227452] {CVE-2026-53053}
- smb: client: fix change notify replay double-free (CKI Backport Bot) [RHEL-226988] {CVE-2026-64384}
- mm/list_lru: drain before clearing xarray entry on reparent (Rafael Aquini) [RHEL-227399] {CVE-2026-53153}
- s390/pfault: Fix virtual vs physical address confusion (Ramesh Chhetri) [RHEL-222507]
- crypto: qat - cancel work on re-enable SR-IOV timeout (CKI Backport Bot) [RHEL-218627]
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CKI Backport Bot) [RHEL-219623] {CVE-2026-64320}
- sctp: hold socket lock when dumping endpoints in sctp_diag (CKI Backport Bot) [RHEL-212393]
- seccomp: passthrough uretprobe systemcall without filtering (Ricardo Robaina) [RHEL-210908] {CVE-2025-21834}
- qede: fix off-by-one in BD ring consumption on build_skb failure (CKI Backport Bot) [RHEL-193043]
- zram: fix use-after-free in zram_bvec_write_partial() (CKI Backport Bot) [RHEL-191442] {CVE-2026-53185}
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Desnes Nunes) [RHEL-191042] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Desnes Nunes) [RHEL-191042] {CVE-2026-53196}
- ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CKI Backport Bot) [RHEL-189631] {CVE-2026-23003}
- ip6_gre: Use cached t->net in ip6erspan_changelink(). (CKI Backport Bot) [RHEL-180136] {CVE-2026-46120}
- netfilter: nf_tables: Fix for duplicate device in netdev hooks (CKI Backport Bot) [RHEL-179761] {CVE-2026-43454}
- netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CKI Backport Bot) [RHEL-179744] {CVE-2026-43450}
-
Wed Aug 19 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.49.1.el10_2]
- udf: fix partition descriptor append bookkeeping (CKI Backport Bot) [RHEL-179570] {CVE-2026-45991}
- cifs: fix time_last_write stamp placement in setattr/truncate paths (Paulo Alcantara) [RHEL-235459]
- cifs: consolidate time_last_write stamp into _cifsFileInfo_put() (Paulo Alcantara) [RHEL-235459]
- cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (Paulo Alcantara) [RHEL-235459]
- cifs: prevent readdir from changing file size due to stale directory metadata (Paulo Alcantara) [RHEL-235459]
- smb: client: fix dir separator in SMB1 UNIX mounts (Paulo Alcantara) [RHEL-235459]
- smb: client: fix sbflags initialization (Paulo Alcantara) [RHEL-235459]
- smb: client: use atomic_t for mnt_cifs_flags (Paulo Alcantara) [RHEL-235459]
- smb: client: fix data corruption due to racy lease checks (Paulo Alcantara) [RHEL-235459]
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226717] {CVE-2026-43493}
- smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive() (Paulo Alcantara) [RHEL-235812]
- smb/client: handle overlapping allocated ranges in fallocate (CKI Backport Bot) [RHEL-236210] {CVE-2026-68388}
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Waiman Long) [RHEL-227850] {CVE-2026-64560}
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Waiman Long) [RHEL-227850] {CVE-2026-64370}
- exit: kill the pointless __exit_signal()->clear_tsk_thread_flag(TIF_SIGPENDING) (Waiman Long) [RHEL-227850]
- exit: change the release_task() paths to call flush_sigqueue() lockless (Waiman Long) [RHEL-227850]
- smb: client: fix double-free in SMB2_open() replay (CKI Backport Bot) [RHEL-234551] {CVE-2026-64382}
- smb: client: mask server-provided mode to 07777 in modefromsid (CKI Backport Bot) [RHEL-234530] {CVE-2026-64379}
- smb: client: fix query_info() replay double-free (CKI Backport Bot) [RHEL-234129] {CVE-2026-64386}
- smb/client: fix out-of-bounds read in symlink_data() (CKI Backport Bot) [RHEL-229066] {CVE-2026-46185}
- blk-mq: reinsert cached request to the list (CKI Backport Bot) [RHEL-213153] {CVE-2026-64017}
- blk-mq: pop cached request if it is usable (CKI Backport Bot) [RHEL-213153] {CVE-2026-64017}
-
Mon Aug 17 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.48.1.el10_2]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Maurizio Lombardi) [RHEL-213217] {CVE-2026-63888}
- drm/i915: Fix potential UAF in TTM object purge (CKI Backport Bot) [RHEL-222740] {CVE-2026-63884}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CKI Backport Bot) [RHEL-222567] {CVE-2026-64219}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CKI Backport Bot) [RHEL-222667] {CVE-2026-53329}
- drm/amdgpu: fix amdgpu_hmm_range_get_pages (Mika Penttilä) [RHEL-222625] {CVE-2026-63879}
- drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CKI Backport Bot) [RHEL-221336] {CVE-2026-43206}
- drm/i915/gem: Fix phys BO pread/pwrite with offset (CKI Backport Bot) [RHEL-222753] {CVE-2026-53356}
- drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CKI Backport Bot) [RHEL-222721] {CVE-2026-45878}
- drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CKI Backport Bot) [RHEL-222701] {CVE-2026-53143}
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CKI Backport Bot) [RHEL-222685] {CVE-2026-53136}
- drm/amdgpu: zero-initialize GART table on allocation (CKI Backport Bot) [RHEL-222646] {CVE-2026-53374}
- drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v7 (CKI Backport Bot) [RHEL-221380] {CVE-2026-43237}
- drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CKI Backport Bot) [RHEL-221380] {CVE-2026-43237}
- sched/psi: Create the psimon kthread outside of cgroup_mutex (CKI Backport Bot) [RHEL-232560] {CVE-2026-52991}
- sched/psi: fix race between file release and pressure write (CKI Backport Bot) [RHEL-232560] {CVE-2026-52991}
- scsi: target: Fix hexadecimal CHAP_I handling (CKI Backport Bot) [RHEL-231667] {CVE-2026-63886}
- scsi: target: iscsi: Validate CHAP_R length before base64 decode (CKI Backport Bot) [RHEL-231667] {CVE-2026-63886}
- memfd: deny writeable mappings when implying SEAL_WRITE (Luiz Capitulino) [RHEL-228531] {CVE-2026-63952}
- mm/memfd: fix spelling in memfd_add_seals() (Luiz Capitulino) [RHEL-228531]
- vhost: reset the vring metadata cache on vring reconfiguration (CKI Backport Bot) [RHEL-224545]
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lukas Herbolt) [RHEL-223954]
-
Wed Aug 12 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.47.1.el10_2]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Maurizio Lombardi) [RHEL-213198] {CVE-2026-63887}
- perf/aux: Fix page UAF in map_range() (CKI Backport Bot) [RHEL-218475] {CVE-2026-64300}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (CKI Backport Bot) [RHEL-218188] {CVE-2026-53264}
- KVM: SVM: make svm_flush_tlb_gva do a full asid flush if NPT enabled (Paolo Bonzini) [RHEL-214436]
- KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (Paolo Bonzini) [RHEL-214436]
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Aidan Wallace) [RHEL-213472] {CVE-2026-63807}
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Aidan Wallace) [RHEL-213472]
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Aidan Wallace) [RHEL-213472]
- KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state (Aidan Wallace) [RHEL-213472]
- accel/ivpu: Fix signed integer truncation in IPC receive (CKI Backport Bot) [RHEL-190054] {CVE-2026-53202}
- netfilter: nf_conntrack_expect: store master_tuple in expectation (Florian Westphal) [RHEL-185311]
- selftests: netfilter: nft_concat_range.sh: add check for flush+reload bug (Florian Westphal) [RHEL-185311]
- selftests: netfilter: nft_concat_range.sh: add check for overlap detection bug (Florian Westphal) [RHEL-185311]
- selftests: netfilter: nft_concat_range.sh: add check for double-create bug (Florian Westphal) [RHEL-185311]
- netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump (Florian Westphal) [RHEL-185311]
- netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them (Florian Westphal) [RHEL-185311]
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Florian Westphal) [RHEL-185311]
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [RHEL-185311]
- netfilter: nf_log: validate MAC header was set before dumping it (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack: destroy stale expectfn expectations on unregister (Florian Westphal) [RHEL-185311]
- netfilter: revalidate bridge ports (Florian Westphal) [RHEL-185311]
- netfilter: nft_ct: bail out on template ct in get eval (Florian Westphal) [RHEL-185311]
- netfilter: nft_tunnel: fix use-after-free on object destroy (Florian Westphal) [RHEL-185311]
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [RHEL-185311]
- netfilter: synproxy: add mutex to guard hook reference counting (Florian Westphal) [RHEL-185311]
- netfilter: disable payload mangling in userns (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_gre: fix gre keymap list corruption (Florian Westphal) [RHEL-185311]
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Florian Westphal) [RHEL-185311]
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Florian Westphal) [RHEL-185311]
- netfilter: nf_queue: hold bridge skb->dev while queued (Florian Westphal) [RHEL-185311]
- netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Florian Westphal) [RHEL-185311]
- netfilter: ip6t_hbh: reject oversized option lists (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_helper: fix possible null deref during error log (Florian Westphal) [RHEL-185311]
- netfilter: nft_ct: fix missing expect put in obj eval (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_sip: get helper before allocating expectation (Florian Westphal) [RHEL-185311]
- netfilter: ctnetlink: check tuple and mask in expectations created via nfqueue (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_expect: restore helper propagation via expectation (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables (Florian Westphal) [RHEL-185311]
- netfilter: xt_CT: fix usersize for v1 and v2 revision (Florian Westphal) [RHEL-185311]
- netfilter: nft_compat: run xt_check_hooks_{match,target}() from .validate (Florian Westphal) [RHEL-185311]
- netfilter: x_tables: add .check_hooks to matches and targets (Florian Westphal) [RHEL-185311]
- netfilter: xtables: restrict several matches to inet family (Florian Westphal) [RHEL-185311]
- netfilter: nft_fwd_netdev: use recursion counter in neigh egress path (Florian Westphal) [RHEL-185311]
- netfilter: nft_fwd_netdev: add device and headroom validate with neigh forwarding (Florian Westphal) [RHEL-185311]
- netfilter: replace skb_try_make_writable() by skb_ensure_writable() (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [RHEL-185311]
- netfilter: xt_policy: fix strict mode inbound policy matching (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: add hook transactions for device deletions (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase (Florian Westphal) [RHEL-185311]
- rculist: add list_splice_rcu() for private lists (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: use list_del_rcu for netlink hooks (Florian Westphal) [RHEL-185311] {CVE-2026-46324}
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Florian Westphal) [RHEL-185311]
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Florian Westphal) [RHEL-185311]
- netfilter: nat: use kfree_rcu to release ops (Florian Westphal) [RHEL-185311]
- netfilter: conntrack: remove sprintf usage (Florian Westphal) [RHEL-185311]
- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Florian Westphal) [RHEL-185311] {CVE-2026-45841}
- nfnetlink_osf: validate individual option lengths in fingerprints (Florian Westphal) [RHEL-185311] {CVE-2026-23397}
- netfilter: nft_osf: restrict it to ipv4 (Florian Westphal) [RHEL-185311]
- netfilter: nft_ct: fix use-after-free in timeout object destroy (Florian Westphal) [RHEL-185311] {CVE-2026-31665}
- netfilter: xt_multiport: validate range encoding in checkentry (Florian Westphal) [RHEL-185311] {CVE-2026-31681}
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Florian Westphal) [RHEL-185311] {CVE-2026-43085}
- netfilter: nf_tables: reject immediate NF_QUEUE verdict (Florian Westphal) [RHEL-185311] {CVE-2026-43024}
- netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (Florian Westphal) [RHEL-185311] {CVE-2026-31424}
- netfilter: ctnetlink: ignore explicit helper on new expectations (Florian Westphal) [RHEL-185311] {CVE-2026-43025}
- netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (Florian Westphal) [RHEL-185311] {CVE-2026-43026}
- netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr (Florian Westphal) [RHEL-185311]
- netfilter: x_tables: ensure names are nul-terminated (Florian Westphal) [RHEL-185311] {CVE-2026-43028}
- netfilter: nfnetlink_log: account for netlink header size (Florian Westphal) [RHEL-185311] {CVE-2026-31416}
- netfilter: ctnetlink: use netlink policy range checks (Florian Westphal) [RHEL-185311] {CVE-2026-31495}
- netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (Florian Westphal) [RHEL-185311] {CVE-2026-31674}
- netfilter: nf_conntrack_expect: store netns and zone in expectation (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_expect: use expect->helper (Florian Westphal) [RHEL-185311]
- netfilter: nf_conntrack_expect: honor expectation helper field (Florian Westphal) [RHEL-185311]
- netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (Florian Westphal) [RHEL-185311] {CVE-2026-31428}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [RHEL-185311] {CVE-2026-43114}
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Florian Westphal) [RHEL-185311] {CVE-2026-23399}
- netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (Florian Westphal) [RHEL-185311] {CVE-2026-23456}
- netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (Florian Westphal) [RHEL-185311] {CVE-2026-23457}
- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [RHEL-185311] {CVE-2026-31407}
- netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (Florian Westphal) [RHEL-185311] {CVE-2026-23458}
- netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (Florian Westphal) [RHEL-185311] {CVE-2026-43451}
- netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() (Florian Westphal) [RHEL-185311] {CVE-2026-43453}
- netfilter: nf_tables: unconditionally bump set->nelems before insertion (Florian Westphal) [RHEL-185311] {CVE-2026-23272}
- netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (Florian Westphal) [RHEL-185311] {CVE-2026-43233}
- netfilter: nft_set_hash: fix get operation on big endian (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: always walk all pending catchall elements (Florian Westphal) [RHEL-185311] {CVE-2026-23278}
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal) [RHEL-185311] {CVE-2026-23351}
-
Mon Aug 10 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.46.1.el10_2]
- mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (Rafael Aquini) [RHEL-223405] {CVE-2026-64368}
-
Fri Aug 07 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.45.1.el10_2]
- s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (Ramesh Chhetri) [RHEL-222503]
- s390/pkey: Check length in pkey_pckmo handler implementation (Ramesh Chhetri) [RHEL-222505]
- net: openvswitch: reject oversized nested action attrs (CKI Backport Bot) [RHEL-222499] {CVE-2026-64531}
- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Waiman Long) [RHEL-193528] {CVE-2026-52977}
- futex: Require sys_futex_requeue() to have identical flags (Waiman Long) [RHEL-193528] {CVE-2026-31554}
- futex: Clear stale exiting pointer in futex_lock_pi() retry path (Waiman Long) [RHEL-193528] {CVE-2026-31555}
- futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (Waiman Long) [RHEL-193528] {CVE-2026-23415}
- net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CKI Backport Bot) [RHEL-213035]
- drm/amd/display: Do not skip unrelated mode changes in DSC validation (CKI Backport Bot) [RHEL-193676] {CVE-2026-31488}
- shmem: fix recovery on rename failures (Rafael Aquini) [RHEL-189571] {CVE-2025-71072}
- ipc: limit next_id allocation to the valid ID range (Rafael Aquini) [RHEL-188217] {CVE-2026-52923}
- fsnotify: Fix ordering of iput() and watched_objects decrement (Jay Shin) [RHEL-175860] {CVE-2024-53143}