-
Thu Sep 24 2026 EL Errata <el-errata_ww@oracle.com> [5.14.0-687.51.1.el9_8.OL9]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
-
Tue Sep 22 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.51.1.el9_8]
- net: tun: bound receive headroom (CKI Backport Bot) [RHEL-264401] {CVE-2026-81000}
- xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264350] {CVE-2026-80844}
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CKI Backport Bot) [RHEL-262595] {CVE-2026-89846}
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CKI Backport Bot) [RHEL-260449] {CVE-2026-64534}
- af_unix: Drop all SCM attributes for SOCKMAP. (Davide Caratti) [RHEL-229264] {CVE-2026-53005}
- smb: client: fix double-free in SMB2_flush() replay (CKI Backport Bot) [RHEL-253169] {CVE-2026-64383}
- RHEL: revert "block: only zero non-PI metadata tuples in bio_integrity_prep" (Jeff Moyer) [RHEL-189969] {CVE-2026-23007}
- block: don't overwrite bip_vcnt in bio_integrity_copy_user() (Jeff Moyer) [RHEL-232369] {CVE-2026-64053}
- blk-cgroup: fix UAF in __blkcg_rstat_flush() (Jeff Moyer) [RHEL-230287] {CVE-2026-63802}
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CKI Backport Bot) [RHEL-243625] {CVE-2026-72261}
- netfilter: nft_fib: reject fib expression on the netdev egress hook (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) [RHEL-236634]
- netfilter: nft_ct: expectation timeouts are passed in milliseconds (Florian Westphal) [RHEL-236634]
- netfilter: nft_compat: ebtables emulation must reject non-bridge targets (Florian Westphal) [RHEL-236634]
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal) [RHEL-236634]
- netfilter: nft_flow_offload: zero device address for non-ether case (Florian Westphal) [RHEL-236634]
- netfilter: nft_meta_bridge: add validate callback for get operations (Florian Westphal) [RHEL-236634]
- netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables_offload: drop device refcount on error (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables_offload: add nft_flow_action_entry_next() and use it (Florian Westphal) [RHEL-236634]
- netfilter: nft_byteorder: remove multi-register support (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: fix dst corruption in same register operation (Florian Westphal) [RHEL-236634] {CVE-2026-64006}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Florian Westphal) [RHEL-236634] {CVE-2026-53134}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [RHEL-236634] {CVE-2026-53218}
- netfilter: nft_ct: bail out on template ct in get eval (Florian Westphal) [RHEL-236634] {CVE-2026-53267}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Florian Westphal) [RHEL-236634] {CVE-2026-53212}
- netfilter: disable payload mangling in userns (Florian Westphal) [RHEL-236634]
- netfilter: nft_ct: fix missing expect put in obj eval (Florian Westphal) [RHEL-236634] {CVE-2026-52970}
- netfilter: nft_compat: run xt_check_hooks_{match,target}() from .validate (Florian Westphal) [RHEL-236634]
- netfilter: nft_fwd_netdev: use recursion counter in neigh egress path (Florian Westphal) [RHEL-236634]
- netfilter: nft_fwd_netdev: add device and headroom validate with neigh forwarding (Florian Westphal) [RHEL-236634]
- netfilter: replace skb_try_make_writable() by skb_ensure_writable() (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: use list_del_rcu for netlink hooks (Florian Westphal) [RHEL-236634] {CVE-2026-46324}
- netfilter: nf_tables: Introduce functions freeing nft_hook objects (Florian Westphal) [RHEL-236634]
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Florian Westphal) [RHEL-236634] {CVE-2026-52998}
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Florian Westphal) [RHEL-236634] {CVE-2026-52999}
- netfilter: nft_osf: restrict it to ipv4 (Florian Westphal) [RHEL-236634]
- netfilter: nft_ct: fix use-after-free in timeout object destroy (Florian Westphal) [RHEL-236634] {CVE-2026-31665}
- netfilter: nft_set_pipapo_avx2: remove redundant loop in lookup_slow (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: increment data in one step (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: reject immediate NF_QUEUE verdict (Florian Westphal) [RHEL-236634] {CVE-2026-43024}
- netfilter: nfnetlink_log: account for netlink header size (Florian Westphal) [RHEL-236634] {CVE-2026-31416}
- selftests: netfilter: nft_concat_range.sh: add check for flush+reload bug (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: always walk all pending catchall elements (Florian Westphal) [RHEL-236634] {CVE-2026-23278}
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal) [RHEL-236634] {CVE-2026-23351}
- netfilter: nf_tables: clone set on flush only (Florian Westphal) [RHEL-236634] {CVE-2026-23385}
- netfilter: nf_tables: fix memory leak in nf_tables_newrule() (Florian Westphal) [RHEL-236634]
- selftests: netfilter: nft_concat_range.sh: add check for overlap detection bug (Florian Westphal) [RHEL-236634]
- netfilter: nft_ct: add seqadj extension for natted connections (Florian Westphal) [RHEL-236634] {CVE-2025-68206}
- netfilter: nf_tables: use C99 struct initializer for nft_set_iter (Florian Westphal) [RHEL-236634]
- netfilter: nft_objref: validate objref and objrefmap expressions (Florian Westphal) [RHEL-236634] {CVE-2025-40206}
- selftests: netfilter: nft_concat_range.sh: add check for double-create bug (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo_avx2: fix skip of expired entries (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: use 0 genmask for packetpath lookups (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: don't check genbit from packetpath lookups (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: all transaction allocations can now sleep (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: allow iter callbacks to sleep (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: Store real pointer, adjust later. (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo_avx2: split lookup function in two parts (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: don't return bogus extension pointer (Florian Westphal) [RHEL-236634]
- selftests: netfilter: nft_concat_range.sh: send packets to empty set (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: adjust lockdep assertions handling (Florian Westphal) [RHEL-236634]
- selftests: netfilter: nft_concat_range.sh: add datapath check for map fill bug (Florian Westphal) [RHEL-236634]
- selftests: netfilter: nft_concat_range.sh: prefer per element counters for testing (Florian Westphal) [RHEL-236634]
- netfilter: nft_tunnel: fix geneve_opt dump (Florian Westphal) [RHEL-236634]
- selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_hash: GC reaps elements with conncount for dynamic sets only (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: Flowtable hook's pf value never varies (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: remove the genmask parameter (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: do not defer rule destruction via call_rcu (Florian Westphal) [RHEL-236634] {CVE-2024-56655}
- netfilter: nf_tables: wait for rcu grace period on net_device removal (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: fix null deref for empty set (Florian Westphal) [RHEL-236634] {CVE-2025-39867}
- netfilter: nft_set_pipapo: prefer kvmalloc for scratch maps (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: merge pipapo_get/lookup (Florian Westphal) [RHEL-236634]
- netfilter: nft_set: remove one argument from lookup and update functions (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: remove unused arguments (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX (Florian Westphal) [RHEL-236634] {CVE-2025-38201}
- netfilter: nft_set_pipapo: prevent overflow in lookup table allocation (Florian Westphal) [RHEL-236634] {CVE-2025-38162}
- netfilter: nf_tables: missing objects with no memcg accounting (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: allow clone callbacks to sleep (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: remove dirty flag (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: prepare destroy function for on-demand clone (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: speed up bulk element insertions (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo: shrink data structures (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_pipapo_avx2: remove redundant pointer lt (Florian Westphal) [RHEL-236634]
- netfilter: nft_ct: drop pending enqueued packets on removal (Florian Westphal) [RHEL-236634] {CVE-2026-43060}
- netfilter: nf_tables: cleanup documentation (Florian Westphal) [RHEL-236634]
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Florian Westphal) [RHEL-236634] {CVE-2026-23399}
- netfilter: x_tables: add .check_hooks to matches and targets (Florian Westphal) [RHEL-236634]
- netfilter: xtables: restrict several matches to inet family (Florian Westphal) [RHEL-236634] {CVE-2026-53001}
- netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: use rcu chain hook list iterator from netlink dump path (Florian Westphal) [RHEL-236634]
- netfilter: nft_set_bitmap: fix lockdep splat due to missing annotation (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: avoid false-positive lockdep splats in set walker (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: avoid false-positive lockdep splats with flowtables (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: avoid false-positive lockdep splats with sets (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: missing extended netlink error in lookup functions (Florian Westphal) [RHEL-236634]
- netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion (Florian Westphal) [RHEL-236634]
- ALSA: timer: drain a slave's callback before its master detaches it (CKI Backport Bot) [RHEL-236081] {CVE-2026-68201}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CKI Backport Bot) [RHEL-234304] {CVE-2026-64564}
- mac802154: llsec: add skb_cow_data() before in-place crypto (CKI Backport Bot) [RHEL-231022] {CVE-2026-63831}
- sctp: prevent peer transport count overflow (Xin Long) [RHEL-216251]
-
Mon Sep 21 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.50.1.el9_8]
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (CKI Backport Bot) [RHEL-264235] {CVE-2025-39964}
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CKI Backport Bot) [RHEL-264235] {CVE-2025-39964}
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Rafael Aquini) [RHEL-254487] {CVE-2026-74518}
- smb: client: fix multiuser mount with krb5 (Jorge San Emeterio Villalain) [RHEL-254108]
- net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (Mohammad Heib) [RHEL-242927] {CVE-2026-72072}
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (Eder Zulian) [RHEL-228484]
- iommu/vt-d: Fix race condition during PASID entry replacement (Eder Zulian) [RHEL-228484] {CVE-2026-45945}
- iommu/vt-d: Clear Present bit before tearing down context entry (Eder Zulian) [RHEL-228484] {CVE-2026-45944}
- iommu/vt-d: Clear Present bit before tearing down PASID entry (Eder Zulian) [RHEL-228484] {CVE-2026-45894}
- libceph: Reject monmaps advertising zero monitors (CKI Backport Bot) [RHEL-237896] {CVE-2026-68155}
- libceph: guard missing CRUSH type name lookup (CKI Backport Bot) [RHEL-237554] {CVE-2026-68157}
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (CKI Backport Bot) [RHEL-237486] {CVE-2026-68156}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (CKI Backport Bot) [RHEL-237311] {CVE-2026-68188}
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CKI Backport Bot) [RHEL-236850] {CVE-2026-68391}
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CKI Backport Bot) [RHEL-236791] {CVE-2026-68293}
- dm cache policy smq: check allocation under invalidate lock (CKI Backport Bot) [RHEL-231819] {CVE-2026-53062}
- dm cache policy smq: fix missing locks in invalidating cache blocks (CKI Backport Bot) [RHEL-231819] {CVE-2026-53062}
- crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CKI Backport Bot) [RHEL-230406] {CVE-2026-45959}
- keys: Pin request_key_auth payload in instantiate paths (CKI Backport Bot) [RHEL-225501] {CVE-2026-63823}
- ice: call netif_keep_dst() once when entering switchdev mode (Jakub Ramaseuski) [RHEL-213003]
- ice: fix ice_init_link() error return preventing probe (Jakub Ramaseuski) [RHEL-213003]
- ice: fix AQ error code comparison in ice_set_pauseparam() (Jakub Ramaseuski) [RHEL-213003]
- ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (Jakub Ramaseuski) [RHEL-213003]
- ice: dpll: fix memory leak in ice_dpll_init_info error paths (Jakub Ramaseuski) [RHEL-213003]
- ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info (Jakub Ramaseuski) [RHEL-213003]
- ice: remove redundant checks from PTP init (Jakub Ramaseuski) [RHEL-213003]
- ice: implement E825 TX ref clock control and TXC hardware sync status (Jakub Ramaseuski) [RHEL-213003]
- ice: add Tx reference clock index handling to AN restart command (Jakub Ramaseuski) [RHEL-213003]
- ice: implement CPI support for E825C (Jakub Ramaseuski) [RHEL-213003]
- ice: introduce TXC DPLL device and TX ref clock pin framework for E825 (Jakub Ramaseuski) [RHEL-213003]
- ice: fix missing priority callbacks for U.FL DPLL pins (Jakub Ramaseuski) [RHEL-213003]
- ice: restore PTP Rx timestamp config after ethtool set-channels (Jakub Ramaseuski) [RHEL-213003]
- ice: ptp: use primary NAC semaphore on E825 (Jakub Ramaseuski) [RHEL-213003]
- ice: ptp: serialize E825 PHY timer start with PTP lock (Jakub Ramaseuski) [RHEL-213003]
- ice: fix setting promisc mode while adding VID filter (Jakub Ramaseuski) [RHEL-213003]
- ice: fix VF queue configuration with low MTU values (Jakub Ramaseuski) [RHEL-213003]
- ice: fix locking around wait_event_interruptible_locked_irq (Jakub Ramaseuski) [RHEL-213003]
- ice: dpll: Fix compilation warning (Jakub Ramaseuski) [RHEL-213003]
- ice: mention fw_activate action along with devlink reload (Jakub Ramaseuski) [RHEL-213003]
- ice: dpll: fix misplaced header macros (Jakub Ramaseuski) [RHEL-213003]
- ice: dpll: fix rclk pin state get for E810 (Jakub Ramaseuski) [RHEL-213003]
- Revert "ice: dpll: fix rclk pin state get and misplaced header macros" (Jakub Ramaseuski) [RHEL-213003]
- ice: fix locking in ice_dcb_rebuild() (Jakub Ramaseuski) [RHEL-213003]
- ice: fix setting RSS VSI hash for E830 (Jakub Ramaseuski) [RHEL-213003]
- ice: fix potential NULL pointer deref in error path of ice_set_ringparam() (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-53007}
- ice: fix race condition in TX timestamp ring cleanup (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-53008}
- ice: fix ICE_AQ_LINK_SPEED_M for 200G (Jakub Ramaseuski) [RHEL-213003]
- ice: fix PHY config on media change with link-down-on-close (Jakub Ramaseuski) [RHEL-213003]
- ice: Fix memory leak in ice_set_ringparam() (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-23389}
- ice: fix double-free of tx_buf skb (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-53009}
- ice: fix double free in ice_sf_eth_activate() error path (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-46162}
- ice: update PCS latency settings for E825 10G/25Gb modes (Jakub Ramaseuski) [RHEL-213003]
- ice: fix 'adjust' timer programming for E830 devices (Jakub Ramaseuski) [RHEL-213003]
- ice: use bitmap_empty() in ice_vf_has_no_qs_ena (Jakub Ramaseuski) [RHEL-213003]
- ice: ptp: don't WARN when controlling PF is unavailable (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-43346}
- ice: use ice_update_eth_stats() for representor stats (Jakub Ramaseuski) [RHEL-213003]
- ice: fix inverted ready check for VF representors (Jakub Ramaseuski) [RHEL-213003]
- drivers: net: ice: fix devlink parameters get without irdma (Jakub Ramaseuski) [RHEL-213003]
- ice: fix retry for AQ command 0x06EE (Jakub Ramaseuski) [RHEL-213003]
- ice: reintroduce retry mechanism for indirect AQ (Jakub Ramaseuski) [RHEL-213003]
- ice: fix adding AQ LLDP filter for VF (Jakub Ramaseuski) [RHEL-213003]
- ice: recap the VSI and QoS info after rebuild (Jakub Ramaseuski) [RHEL-213003]
- ice: stop counting UDP csum mismatch as rx_errors (Jakub Ramaseuski) [RHEL-213003]
- ice: convert all ring stats to u64_stats_t (Jakub Ramaseuski) [RHEL-213003]
- ice: shorten ring stat names and add accessors (Jakub Ramaseuski) [RHEL-213003]
- ice: use u64_stats API to access pkts/bytes in dim sample (Jakub Ramaseuski) [RHEL-213003]
- ice: remove ice_q_stats struct and use struct_group (Jakub Ramaseuski) [RHEL-213003]
- ice: pass pointer to ice_fetch_u64_stats_per_ring (Jakub Ramaseuski) [RHEL-213003]
- ice: unify PHY FW loading status handler for E800 devices (Jakub Ramaseuski) [RHEL-213003]
- ice: Make name member of struct ice_cgu_pin_desc const (Jakub Ramaseuski) [RHEL-213003]
- dpll: use pin owner's dpll ref for pin-level attribute reporting (Jakub Ramaseuski) [RHEL-213003]
- dpll: allow fwnode pins to attempt state change without capability bit (Jakub Ramaseuski) [RHEL-213003]
- dpll: extend pin notifier with notification source ID (Jakub Ramaseuski) [RHEL-213003]
- dpll: balance create/delete notifications in __dpll_pin_(un)register (Jakub Ramaseuski) [RHEL-213003]
- dpll: guard sync-pair removal on full pin unregister (Jakub Ramaseuski) [RHEL-213003]
- dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() (Jakub Ramaseuski) [RHEL-213003]
- dpll: send delete notification before unregister in on-pin rollback (Jakub Ramaseuski) [RHEL-213003]
- dpll: fix stale iteration in dpll_pin_on_pin_unregister() (Jakub Ramaseuski) [RHEL-213003]
- dpll: allow registering FW-identified pin with a different DPLL (Jakub Ramaseuski) [RHEL-213003]
- dpll: add generic DPLL type (Jakub Ramaseuski) [RHEL-213003]
- dpll: zl3073x: make frequency monitor a per-device attribute (Jakub Ramaseuski) [RHEL-213003]
- dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-63977}
- dpll: export __dpll_device_change_ntf() for use under dpll_lock (Jakub Ramaseuski) [RHEL-213003]
- dpll: change dpll_netdev_pin_handle_size() to assume DPLL_A_PIN_ID will be used (Jakub Ramaseuski) [RHEL-213003]
- dpll: zl3073x: fix memory leak on pin registration failure (Jakub Ramaseuski) [RHEL-213003]
- dpll: zl3073x: Use named initializers for struct i2c_device_id (Jakub Ramaseuski) [RHEL-213003]
- dpll: Prevent duplicate registrations (Jakub Ramaseuski) [RHEL-213003] {CVE-2026-23129}
-
Wed Sep 16 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.49.1.el9_8]
- selinux: check connect-related permissions on TCP Fast Open (CKI Backport Bot) [RHEL-258014] {CVE-2026-72243}
- gfs2: Get rid of sd_async_glock_wait (Andreas Gruenbacher) [RHEL-253986]
- watchdog: fix hrtimer start when pretimeout is zero (Krzysztof Pawlinski) [RHEL-255217]
- iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes) [RHEL-256733]
- wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Izabela Bakollari) [RHEL-246399] {CVE-2026-63869}
- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (Izabela Bakollari) [RHEL-240350] {CVE-2026-64174}
- wifi: brcmfmac: cyw: fix heap overflow on a short auth frame (Izabela Bakollari) [RHEL-242723] {CVE-2026-72003}
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Izabela Bakollari) [RHEL-244100] {CVE-2026-72298}
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Izabela Bakollari) [RHEL-241012] {CVE-2026-68363}
- wifi: iwlwifi: mld: stop TX during firmware restart (Izabela Bakollari) [RHEL-243302] {CVE-2026-64175}
- wifi: iwlwifi: mvm: fix driver-set TX rates on old devices (Izabela Bakollari) [RHEL-243366] {CVE-2026-64176}
- net: wwan: t7xx: fix potential skb->frags overflow in RX path (Izabela Bakollari) [RHEL-245512] {CVE-2026-23172}
- gfs2: Remove the glock lru list and shrinker (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Skip dlm unlocks earlier (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Don't cache unreferenced glocks (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Enable automatic glock hash table shrinking (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Introduce glock_{type,number,sbd} helpers (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Minor gfs2_glock_cb cleanup (Andreas Gruenbacher) [RHEL-252544]
- gfs2: Clean up glock demote logic (Andreas Gruenbacher) [RHEL-252544]
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CKI Backport Bot) [RHEL-237156] {CVE-2026-68159}
- libceph: Amend checking to fix `make W=1` build breakage (CKI Backport Bot) [RHEL-237156] {CVE-2026-68159}
- gfs2: Clean up SDF_JOURNAL_LIVE flag handling (Andreas Gruenbacher) [RHEL-252540]
- gfs2: No longer thaw filesystems during a withdraw (Andreas Gruenbacher) [RHEL-252540]
- gfs2: gfs2_freeze_unlock cleanup (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Refcounting fix in gfs2_thaw_super (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Minor gfs2_{freeze,thaw}_super cleanup (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Withdraw immediately in gfs2_trans_add_meta (Andreas Gruenbacher) [RHEL-252540]
- gfs2: New gfs2_withdraw_helper (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Clean up properly during a withdraw (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Rename gfs2_{gl_dq_holders => withdraw_glocks} (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: fix infinite loop when checking ail item count before go_inval" (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Allow some glocks to be used during withdraw" (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Check for log write errors before telling dlm to unlock" (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: fix a deadlock on withdraw-during-mount" (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (6/6) (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (5/6) (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (4/6) (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (3/6) (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (2/6) (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: Force withdraw to replay journals and wait for it to finish" (1/6) (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Follow-up to flag rename in sysfs status file (Andreas Gruenbacher) [RHEL-252540]
- Revert "gfs2: don't stop reads while withdraw in progress" (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Rename LM_FLAG_{NOEXP -> RECOVER} (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Kill gfs2_io_error_bh_wd (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Withdraw immediately on log write errors (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Rename gfs2_{withdrawing_or_ => }withdrawn (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Fix freeze consistency check in log_write_header (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Get rid of delayed withdraws (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Fix usage of bio->bi_status in gfs2_end_log_write (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Asynchronous withdraw (Andreas Gruenbacher) [RHEL-252540]
- gfs2: Add clean argument to lm_unmount hook (Andreas Gruenbacher) [RHEL-252540]
- xfrm: Fix dev use-after-free in xfrm async resumption (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
- xfrm: hold dev ref until after transport_finish NF_HOOK (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
- xfrm: hold device only for the asynchronous decryption (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
- xfrm: input: hold netns during deferred transport reinjection (Sabrina Dubroca) [RHEL-227508] {CVE-2026-63919}
- xfrm: fix stale skb->prev after async crypto steals a GSO segment (Sabrina Dubroca) [RHEL-236120] {CVE-2026-68426}
- xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (Sabrina Dubroca) [RHEL-236120] {CVE-2026-68426}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sabrina Dubroca) [RHEL-228016] {CVE-2026-53239}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Sabrina Dubroca) [RHEL-231753] {CVE-2026-63917}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Sabrina Dubroca) [RHEL-228936] {CVE-2026-63921}
- dm_early_create: fix freeing used table on dm_resume failure (CKI Backport Bot) [RHEL-244932] {CVE-2026-72102}
- ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-243028] {CVE-2026-68200}
- ice: reject out-of-range ptype in ice_parser_profile_init (CKI Backport Bot) [RHEL-240325] {CVE-2026-68128}
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Kamal Heib) [RHEL-233826] {CVE-2026-64582}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Kamal Heib) [RHEL-226877] {CVE-2026-46133}
- RDMA/rxe: Fix race condition in QP timer handlers (Kamal Heib) [RHEL-226914] {CVE-2026-45910}
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Kamal Heib) [RHEL-228182] {CVE-2026-46043}
- RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (Kamal Heib) [RHEL-226315] {CVE-2026-46114}
- net: ena: PHC: Fix potential use-after-free in get_timestamp (CKI Backport Bot) [RHEL-230627] {CVE-2026-52971}
- ALSA: timer: Fix UAF at snd_timer_user_params() (CKI Backport Bot) [RHEL-228693] {CVE-2026-53192}
- ALSA: seq: Serialize UMP output teardown with event_input (CKI Backport Bot) [RHEL-227713] {CVE-2026-64029}
- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (CKI Backport Bot) [RHEL-227087] {CVE-2026-53193}
- ALSA: timer: Forcibly close timer instances at closing (CKI Backport Bot) [RHEL-227087] {CVE-2026-53193}
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (CKI Backport Bot) [RHEL-226406] {CVE-2026-63913}
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191605] {CVE-2026-53176}
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Desnes Nunes) [RHEL-191035] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Desnes Nunes) [RHEL-191035] {CVE-2026-53196}
-
Mon Sep 14 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.48.1.el9_8]
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CKI Backport Bot) [RHEL-254594] {CVE-2026-74556}
- gfs2: bufdata allocation race (Andreas Gruenbacher) [RHEL-178223]
- gfs2: Remove trans_drain code duplication (Andreas Gruenbacher) [RHEL-178223]
- gfs2: Move gfs2_remove_from_journal to log.c (Andreas Gruenbacher) [RHEL-178223]
- gfs2: Get rid of gfs2_log_[un]lock helpers (Andreas Gruenbacher) [RHEL-178223]
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Michal Schmidt) [RHEL-242822] {CVE-2026-72045}
- octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (Michal Schmidt) [RHEL-231042] {CVE-2026-63923}
- net: qrtr: restrict socket creation to the initial network namespace (CKI Backport Bot) [RHEL-240242] {CVE-2026-68294}
- net: slip: serialize receive against buffer reallocation (CKI Backport Bot) [RHEL-237383] {CVE-2026-68143}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225660] {CVE-2026-64015}
- vhost: move vdpa group bound check to vhost_vdpa (Jon Maloy) [RHEL-174277] {CVE-2026-43248}
-
Wed Sep 09 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.47.1.el9_8]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244958] {CVE-2026-72098}
- mm/khugepaged: write all dirty file folios when collapsing (Rafael Aquini) [RHEL-236332] {CVE-2026-68086}
- drm/amdgpu: Fix use-after-free race in VM acquire (CKI Backport Bot) [RHEL-222396] {CVE-2026-43370}
- drm/i915: Fix potential overflow of shmem scatterlist length (CKI Backport Bot) [RHEL-222481] {CVE-2026-43368}
- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CKI Backport Bot) [RHEL-222417] {CVE-2026-31656}
- drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CKI Backport Bot) [RHEL-221275] {CVE-2026-31566}
- drm/xe: always keep track of remap prev/next (CKI Backport Bot) [RHEL-222300] {CVE-2026-31479}
- drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove (José Expósito) [RHEL-222458]
- drm/xe: Open-code GGTT MMIO access protection (CKI Backport Bot) [RHEL-222458] {CVE-2026-23466}
- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (José Expósito) [RHEL-236583] {CVE-2026-68264}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228880] {CVE-2026-63801}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238037] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229470] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231574] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236147] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237395] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237093] {CVE-2026-68300}
- selftests: nft_queue.sh: add a parallel stress test (Florian Westphal) [RHEL-224489]
- kselftest: add test for nfqueue induced conntrack race (Florian Westphal) [RHEL-224489]
- selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels (Florian Westphal) [RHEL-224489]
- selftests: netfilter: nft_queue.sh: fix spurious timeout on debug kernel (Florian Westphal) [RHEL-224489]
- selftests: netfilter: nft_queue.sh: reduce test file size for debug build (Florian Westphal) [RHEL-224489]
- netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [RHEL-224489] {CVE-2026-43084}
- netfilter: nfnetlink_queue: optimize verdict lookup with hash table (Florian Westphal) [RHEL-224489]
- netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation (Florian Westphal) [RHEL-224489]
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-235907] {CVE-2025-68745}
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190206]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190206] {CVE-2026-53246}
- wifi: cfg80211: reject empty PMSR peer lists (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
- wifi: cfg80211: validate PMSR measurement type data (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
- wifi: cfg80211: validate PMSR FTM preamble range (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
- wifi: cfg80211: bound element ID read when checking non-inheritance (Jose Ignacio Tornos Martinez) [RHEL-236961] {CVE-2026-68402}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232010] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231682] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231682] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230975] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230587] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229728] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227619] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227619] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232670] {CVE-2026-53072}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231059] {CVE-2026-63947}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230073] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230005] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228756] {CVE-2026-63975}
- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CKI Backport Bot) [RHEL-228721] {CVE-2026-63889}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227910] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227882] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227536] {CVE-2026-43334}
- iommu/amd: Fix clone_alias() to use the original device's devid (CKI Backport Bot) [RHEL-227454] {CVE-2026-53053}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-226431] {CVE-2026-63945}
- Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame (CKI Backport Bot) [RHEL-225646] {CVE-2026-53254}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225646] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225576] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225553] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193025]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193025]
- qede: fix off-by-one in BD ring consumption on build_skb failure (CKI Backport Bot) [RHEL-193050]
- rtnetlink: add missing netlink_ns_capable() check for peer netns (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- rtnetlink: Try the outer netns attribute in rtnl_get_peer_net(). (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- rtnetlink: fix double call of rtnl_link_get_net_ifla() (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- vxcan: Set VXCAN_INFO_PEER to vxcan_link_ops.peer_type. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- veth: Set VETH_INFO_PEER to veth_link_ops.peer_type. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- rtnetlink: Add peer_type in struct rtnl_link_ops. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
- gfs2: Fix data loss during inode evict (Andreas Gruenbacher) [RHEL-178219]
- gfs2: minor evict_[un]linked_inode cleanup (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Avoid unnecessary transactions in evict_linked_inode (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Remove unnecessary check in gfs2_evict_inode (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Call unlock_new_inode before d_instantiate (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Don't remember delete unless it's successful (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Remove redundant check for GLF_INSTANTIATE_NEEDED (Andreas Gruenbacher) [RHEL-178219]
- gfs2: fiemap page fault fix (Andreas Gruenbacher) [RHEL-178219]
- gfs2: Don't get stuck writing page onto itself under direct I/O (Andreas Gruenbacher) [RHEL-178219]
-
Thu Sep 03 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.46.1.el9_8]
- tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232236] {CVE-2026-46015}
- flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232633] {CVE-2026-46306}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226126] {CVE-2026-46266}
- ipv4: icmp: convert to dev_net_rcu() (Felix Maurer) [RHEL-226126]
- ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226071] {CVE-2026-53275}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225592] {CVE-2026-43339}
- ipv6: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891]
- ipv4: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891] {CVE-2026-53366}
- inet: ping: fix recent breakage (Felix Maurer) [RHEL-212891]
- net: unify alloclen calculation for paged requests (Felix Maurer) [RHEL-212891]
- net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225858] {CVE-2026-53223}
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248451] {CVE-2026-64563}
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246930] {CVE-2026-74480}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244971] {CVE-2026-72129}
- Revert "net/smc: Introduce TCP ULP support" (Jan Polensky) [RHEL-227559] {CVE-2026-46330}
- smb: client: fix double-free in SMB2_close() replay (CKI Backport Bot) [RHEL-240049] {CVE-2026-64597}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226689] {CVE-2026-43493}
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CKI Backport Bot) [RHEL-230988] {CVE-2026-64034}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225785] {CVE-2026-46149}
- netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224454] {CVE-2026-53002}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189457] {CVE-2026-43133}
- mm/ksm: add option to deduplicate only zero pages (Andrea Arcangeli) [RHEL-249161]
- mm/ksm: don't waste time searching stable tree for fast changing page (Andrea Arcangeli) [RHEL-249161]
- mm/hugetlb.c: undo errant change (Andrea Arcangeli) [RHEL-249161]
- mm/ksm: refactor out try_to_merge_with_zero_page() (Andrea Arcangeli) [RHEL-249161]
-
Wed Sep 02 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.45.1.el9_8]
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (Jon Maloy) [RHEL-234207] {CVE-2026-64287}
- nvmet-auth: validate reply message payload bounds against transfer length (CKI Backport Bot) [RHEL-234145] {CVE-2026-64319}
- smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CKI Backport Bot) [RHEL-228852] {CVE-2026-64136}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (CKI Backport Bot) [RHEL-227107] {CVE-2026-52933}
- smb: client: fix change notify replay double-free (CKI Backport Bot) [RHEL-226985] {CVE-2026-64384}
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CKI Backport Bot) [RHEL-219614] {CVE-2026-64320}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (CKI Backport Bot) [RHEL-216699] {CVE-2025-38004}
- can: bcm: add locking when updating filter and timer values (CKI Backport Bot) [RHEL-216699] {CVE-2025-38004}
- can: bcm: fix locking for bcm_op runtime updates (CKI Backport Bot) [RHEL-216699] {CVE-2025-38004}
- can: bcm: add locking for bcm_op runtime updates (CKI Backport Bot) [RHEL-216699] {CVE-2025-38004}
- netfilter: nat: use kfree_rcu to release ops (Florian Westphal) [RHEL-188518] {CVE-2026-53000}
-
Tue Sep 01 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.44.1.el9_8]
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Waiman Long) [RHEL-242684] {CVE-2026-72069}
- locking/rt: Add sparse annotation for RCU. (Waiman Long) [RHEL-242684]
- iomap: fix out-of-bounds bitmap_set() with zero-length range (CKI Backport Bot) [RHEL-240191] {CVE-2026-68145}
- iomap: hold state_lock over call to ifs_set_range_uptodate() (CKI Backport Bot) [RHEL-240191] {CVE-2026-68145}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (CKI Backport Bot) [RHEL-231461] {CVE-2026-63808}
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CKI Backport Bot) [RHEL-227266] {CVE-2026-64002}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (CKI Backport Bot) [RHEL-223126] {CVE-2026-53073}
-
Mon Aug 31 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.43.1.el9_8]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Maurizio Lombardi) [RHEL-213202] {CVE-2026-63887}
- redhat: add kmap.py tool and kernel-kmap-internal package (Rado Vrbovsky)
- nvmet-auth: reject short AUTH_RECEIVE buffers (CKI Backport Bot) [RHEL-244913] {CVE-2026-72130}
- sched/rt: Skip currently executing CPU in rto_next_cpu() (CKI Backport Bot) [RHEL-240634]
- smc: Fix use-after-free in __pnet_find_base_ndev(). (Ramesh Chhetri) [RHEL-152651] {CVE-2025-40064}
- userfaultfd: prevent registration of special VMAs (Rafael Aquini) [RHEL-240761] {CVE-2026-68166}
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CKI Backport Bot) [RHEL-234043] {CVE-2026-64298}
- nfsd: release layout stid on setlease failure (Scott Mayhew) [RHEL-227785] {CVE-2026-53399}
- NFSv4/flexfiles: reject zero filehandle version count (Scott Mayhew) [RHEL-229407] {CVE-2026-53392}
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CKI Backport Bot) [RHEL-228038] {CVE-2026-53391}
- pNFS: Fix use-after-free in pnfs_update_layout() (CKI Backport Bot) [RHEL-226457] {CVE-2026-63800}
- nfsd: fix posix_acl leak on SETACL decode failure (CKI Backport Bot) [RHEL-225521] {CVE-2026-53397}
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (Vladislav Dronov) [RHEL-234488] {CVE-2026-64438}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Bruno Meneguele) [RHEL-229627] {CVE-2026-63824}
- KEYS: fix length validation in keyctl_pkey_params_get_2() (Bruno Meneguele) [RHEL-229627] {CVE-2026-63824}
- x86/bugs: Make Safe-RET robust against interrupt injection (Waiman Long) [RHEL-230496] {CVE-2026-68480}
- x86: Clean up names/macros conflicting with ptrace-abi.h (Waiman Long) [RHEL-230496]
- crypto: qat - validate RSA CRT component lengths (CKI Backport Bot) [RHEL-234535] {CVE-2026-64304}
- tpm: tpm_tis: stop transmit if retries are exhausted (Štěpán Horáček) [RHEL-213940]
- tpm: tpm_tis: add error logging for data transfer (Štěpán Horáček) [RHEL-213940]
- tpm, tpm_tis: Workaround failed command reception on Infineon devices (Štěpán Horáček) [RHEL-213940]
- tpm_tis: Resend command to recover from data transfer errors (Štěpán Horáček) [RHEL-213940]
- tpm_tis: Use responseRetry to recover from data transfer errors (Štěpán Horáček) [RHEL-213940]
- scsi: target: Fix hexadecimal CHAP_I handling (CKI Backport Bot) [RHEL-231664] {CVE-2026-63886}
- scsi: target: iscsi: Validate CHAP_R length before base64 decode (CKI Backport Bot) [RHEL-231664] {CVE-2026-63886}
- ALSA: virtio: Validate control metadata from the device (CKI Backport Bot) [RHEL-230139] {CVE-2026-64490}
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (CKI Backport Bot) [RHEL-229228] {CVE-2026-64018}
- smb/client: fix out-of-bounds read in symlink_data() (CKI Backport Bot) [RHEL-229064] {CVE-2026-46185}
- bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CKI Backport Bot) [RHEL-225285] {CVE-2026-45970}
- RDMA/siw: bound Read Response placement to the RREAD length (CKI Backport Bot) [RHEL-219525] {CVE-2026-64268}
- smb: client: fix query directory replay double-free (CKI Backport Bot) [RHEL-219152] {CVE-2026-64387}
- KEYS: trusted: Fix a memory leak in tpm2_load_cmd (Štěpán Horáček) [RHEL-189953] {CVE-2025-71147}