- kernel-uek-5.15.0-312.187.5.1.el8uek (oel8-uek7)
- 5.15.0-317.197.5.1.el8uek
- 2026-03-10 22:05:03
- 2026-03-11 11:20:07
- K20260310_13
- CVE-2025-38264
- Description:
nvme-tcp: sanitize request list handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38264.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38264-nvme-tcp-sanitize-request-list-handling.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38264
- Description:
nvme-tcp: sanitize request list handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38264.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38264-nvme-tcp-sanitize-request-list-handling-kpatch.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38499
- Description:
clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
- CVE: https://linux.oracle.com/cve/CVE-2025-38499.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38499-clone-private-mnt-make-sure-that-caller-has-cap-sys-admin-in-the-right-userns.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38495
- Description:
HID: core: ensure the allocated report buffer can contain the reserved report ID
- CVE: https://linux.oracle.com/cve/CVE-2025-38495.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38495-hid-core-ensure-the-allocated-report-buffer-can-contain-the-reserved-report-id.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38494
- Description:
HID: core: do not bypass hid_hw_raw_request
- CVE: https://linux.oracle.com/cve/CVE-2025-38494.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38494-hid-core-do-not-bypass-hid-hw-raw-request.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38618
- Description:
vsock: Do not allow binding to VMADDR_PORT_ANY
- CVE: https://linux.oracle.com/cve/CVE-2025-38618.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38618-vsock-do-not-allow-binding-to-vmaddr-port-any.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38466
- Description:
perf: Revert to requiring CAP_SYS_ADMIN for uprobes
- CVE: https://linux.oracle.com/cve/CVE-2025-38466.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38466-perf-revert-to-requiring-cap-sys-admin-for-uprobes.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38441
- Description:
netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto()
- CVE: https://linux.oracle.com/cve/CVE-2025-38441.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38441-netfilter-flowtable-account-for-ethernet-header-in-nf-flow-pppoe-proto.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38443
- Description:
nbd: fix uaf in nbd_genl_connect() error path
- CVE: https://linux.oracle.com/cve/CVE-2025-38443.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38443-nbd-fix-uaf-in-nbd-genl-connect-error-path.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38444
- Description:
raid10: cleanup memleak at raid10_make_request
- CVE: https://linux.oracle.com/cve/CVE-2025-38444.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38444-raid10-cleanup-memleak-at-raid10-make-request.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2024-26775
- Description:
aoe: avoid potential deadlock at set_capacity
- CVE: https://linux.oracle.com/cve/CVE-2024-26775.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2024-26775-aoe-avoid-potential-deadlock-at-set-capacity.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38467
- Description:
drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38467.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38467-drm-exynos-exynos7-drm-decon-add-vblank-check-in-irq-handling.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38464
- Description:
tipc: Fix use-after-free in tipc_conn_close().
- CVE: https://linux.oracle.com/cve/CVE-2025-38464.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38464-tipc-fix-use-after-free-in-tipc-conn-close.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38457
- Description:
net/sched: Abort __tc_modify_qdisc if parent class does not exist
- CVE: https://linux.oracle.com/cve/CVE-2025-38457.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38457-net-sched-abort-tc-modify-qdisc-if-parent-class-does-not-exist.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38445
- Description:
md/raid1: Fix stack memory use after return in raid1_reshape
- CVE: https://linux.oracle.com/cve/CVE-2025-38445.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38445-md-raid1-fix-stack-memory-use-after-return-in-raid1-reshape.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38569
- Description:
benet: fix BUG when creating VFs
- CVE: https://linux.oracle.com/cve/CVE-2025-38569.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38569-benet-fix-bug-when-creating-vfs.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38236
- Description:
Complex adaptation required. Livepatching of this vulnerability can harm the network subsystem..
- CVE:
- Patch: skipped/CVE-2025-38236.patch
- From:
- CVE-2025-38462
- Description:
vsock: Fix transport_{g2h,h2g} TOCTOU
- CVE: https://linux.oracle.com/cve/CVE-2025-38462.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38462-vsock-fix-transport-g2h-h2g-toctou.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38461
- Description:
vsock: Fix transport_* TOCTOU
- CVE: https://linux.oracle.com/cve/CVE-2025-38461.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38461-vsock-fix-transport-toctou.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38375
- Description:
virtio-net: ensure the received length does not exceed allocated size
- CVE: https://linux.oracle.com/cve/CVE-2025-38375.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38375-virtio-net-ensure-the-received-length-does-not-exceed-allocated-size.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-39866
- Description:
fs: writeback: fix use-after-free in __mark_inode_dirty()
- CVE: https://linux.oracle.com/cve/CVE-2025-39866.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-39866-fs-writeback-fix-use-after-free-in-mark-inode-dirty.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38067
- Description:
rseq: Fix segfault on registration when rseq_cs is non-zero
- CVE: https://linux.oracle.com/cve/CVE-2025-38067.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38067-rseq-fix-segfault-on-registration-when-rseq-cs-is-non-zero.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38465
- Description:
netlink: Fix wraparounds of sk->sk_rmem_alloc.
- CVE: https://linux.oracle.com/cve/CVE-2025-38465.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38465-netlink-fix-wraparounds-of-sk-sk-rmem-alloc.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38448
- Description:
usb: gadget: u_serial: Fix race condition in TTY wakeup
- CVE: https://linux.oracle.com/cve/CVE-2025-38448.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38448-usb-gadget-u-serial-fix-race-condition-in-tty-wakeup.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38439
- Description:
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
- CVE: https://linux.oracle.com/cve/CVE-2025-38439.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38439-bnxt-en-set-dma-unmap-len-correctly-for-xdp-redirect.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38727
- Description:
netlink: avoid infinite retry looping in netlink_unicast()
- CVE: https://linux.oracle.com/cve/CVE-2025-38727.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38727-netlink-avoid-infinite-retry-looping-in-netlink-unicast.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38513
- Description:
wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
- CVE: https://linux.oracle.com/cve/CVE-2025-38513.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38513-wifi-zd1211rw-fix-potential-null-pointer-dereference-in-zd-mac-tx-to-dev.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38458
- Description:
atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38458.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38458-atm-clip-Fix-NULL-pointer-dereference-in-vcc_sendmsg.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38458
- Description:
atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38458.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38458-atm-clip-Fix-NULL-pointer-dereference-in-vcc_sendmsg-kpatch.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38459
- Description:
atm: clip: Fix infinite recursive call of clip_push().
- CVE: https://linux.oracle.com/cve/CVE-2025-38459.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38459-atm-clip-Fix-infinite-recursive-call-of-clip_push.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38460
- Description:
atm: clip: Fix potential null-ptr-deref in to_atmarpd().
- CVE: https://linux.oracle.com/cve/CVE-2025-38460.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38460-atm-clip-Fix-potential-null-ptr-deref-in-to_atmarpd.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38546
- Description:
atm: clip: Fix memory leak of struct clip_vcc.
- CVE: https://linux.oracle.com/cve/CVE-2025-38546.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38546-atm-clip-Fix-memory-leak-of-struct-clip_vcc.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38724
- Description:
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
- CVE: https://linux.oracle.com/cve/CVE-2025-38724.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-38724-nfsd-handle-get-client-locked-failure-in-nfsd4-setclientid-confirm.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-disallow-concurrent-writes-in-af_alg_sendmsg.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-fix-incorrect-boolean-values-in-af_alg_ctx.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kpatch
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-disallow-concurrent-writes-in-af_alg_sendmsg-kpatch.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39973
- Description:
i40e: add validation for ring_len param
- CVE: https://linux.oracle.com/cve/CVE-2025-39973.html
- Patch: oel9-uek7/5.15.0-313.189.5.3.el9uek/CVE-2025-39973-i40e-add-validation-for-ring-len-param.patch
- From: 5.15.0-313.189.5.3.el9uek
- CVE-2025-39973
- Description:
i40e: validate ring_len parameter against hardware-specific values
- CVE: https://linux.oracle.com/cve/CVE-2025-39973.html
- Patch: oel9-uek7/5.15.0-313.189.5.3.el9uek/CVE-2025-39973-i40e-validate-ring-len-against-hw-specific-values.patch
- From: 5.15.0-313.189.5.3.el9uek
- CVE-2025-38535
- Description:
phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode
- CVE: https://linux.oracle.com/cve/CVE-2025-38535.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38535-phy-tegra-xusb-fix-unbalanced-regulator-disable-in-utmi-phy-mode.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38497
- Description:
usb: gadget: configfs: Fix OOB read on empty string write
- CVE: https://linux.oracle.com/cve/CVE-2025-38497.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38497-usb-gadget-configfs-fix-oob-read-on-empty-string-write.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38474
- Description:
usb: net: sierra: check for no status endpoint
- CVE: https://linux.oracle.com/cve/CVE-2025-38474.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38474-usb-net-sierra-check-for-no-status-endpoint.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38550
- Description:
ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
- CVE: https://linux.oracle.com/cve/CVE-2025-38550.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38550-ipv6-mcast-delay-put-pmc-idev-in-mld-del-delrec.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38335
- Description:
PEEMPT_RT config isn't enabled
- CVE:
- Patch: skipped/CVE-2025-38335.patch
- From:
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data-kpatch.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38604
- Description:
wifi: rtl818x: Kill URBs before clearing tx status queue
- CVE: https://linux.oracle.com/cve/CVE-2025-38604.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38604-wifi-rtl818x-kill-urbs-before-clearing-tx-status-queue.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39730
- Description:
NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
- CVE: https://linux.oracle.com/cve/CVE-2025-39730.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39730-nfs-fix-filehandle-bounds-checking-in-nfs-fh-to-dentry.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38572
- Description:
ipv6: reject malicious packets in ipv6_gso_segment()
- CVE: https://linux.oracle.com/cve/CVE-2025-38572.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38572-ipv6-reject-malicious-packets-in-ipv6-gso-segment.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39757-alsa-usb-audio-validate-uac3-cluster-segment-descriptors.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Fix size validation in convert_chmap_v3()
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39757-ALSA-usb-audio-fix-size-validation-in-convert_chmap_v3.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39835
- Description:
xfs: do not propagate ENODATA disk errors into xattr code
- CVE: https://linux.oracle.com/cve/CVE-2025-39835.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39835-xfs-do-not-propagate-enodata-disk-errors-into-xattr-code.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39845
- Description:
Out of scope: boot time issue
- CVE:
- Patch: skipped/CVE-2025-39845.patch
- From:
- CVE-2025-39844
- Description:
Out of scope: boot time issue
- CVE:
- Patch: skipped/CVE-2025-39844.patch
- From:
- CVE-2024-50022
- Description:
device-dax: correct pgoff align in dax_set_mapping()
- CVE: https://linux.oracle.com/cve/CVE-2024-50022.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2024-50022-device-dax-correct-pgoff-align-in-dax-set-mapping.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-40019
- Description:
crypto: essiv - Check ssize for decryption and in-place encryption
- CVE: https://linux.oracle.com/cve/CVE-2025-40019.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40019-crypto-essiv-check-ssize-for-decryption-and-in-place-encryption.patch
- From: 5.15.0-315.196.5.1.el9uek
- N/A
- Description:
kpatch add alt asm definitions
- CVE: https://www.kernel.org
- Patch: 5.15.0/kpatch-add-alt-asm-definitions.patch
- From: N/A
- N/A
- Description:
kpatch add paravirt asm definitions
- CVE: N/A
- Patch: 5.15.0/kpatch-add-paravirt-asm-definitions.patch
- From: N/A
- CVE-2025-39885
- Description:
ocfs2: fix recursive semaphore deadlock in fiemap call
- CVE: https://linux.oracle.com/cve/CVE-2025-39885.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39885-ocfs2-fix-recursive-semaphore-deadlock-in-fiemap-call.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39967
- Description:
fbcon: fix integer overflow in fbcon_do_set_font
- CVE: https://linux.oracle.com/cve/CVE-2025-39967.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39967-fbcon-fix-integer-overflow-in-fbcon-do-set-font.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39967
- Description:
fbcon: fix integer overflow in fbcon_do_set_font
- CVE: https://linux.oracle.com/cve/CVE-2025-39967.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39967-fbcon-fix-OOB-access-in-font-allocation.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40027
- Description:
net/9p: fix double req put in p9_fd_cancelled
- CVE: https://linux.oracle.com/cve/CVE-2025-40027.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40027-net-9p-fix-double-req-put-in-p9-fd-cancelled.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40173
- Description:
net/ip6_tunnel: Prevent perpetual tunnel growth
- CVE: https://linux.oracle.com/cve/CVE-2025-40173.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40173-net-ip6-tunnel-prevent-perpetual-tunnel-growth.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40085
- Description:
ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
- CVE: https://linux.oracle.com/cve/CVE-2025-40085.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40085-alsa-usb-audio-fix-null-pointer-deference-in-try-to-register-card.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40115
- Description:
scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
- CVE: https://linux.oracle.com/cve/CVE-2025-40115.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40115-scsi-mpt3sas-fix-crash-in-transport-port-remove-by-using-ioc_info.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39923
- Description:
dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
- CVE: https://linux.oracle.com/cve/CVE-2025-39923.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39923-dmaengine-qcom-bam-dma-fix-dt-error-handling-for-num-channels-ees.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39945
- Description:
cnic: Fix use-after-free bugs in cnic_delete_task
- CVE: https://linux.oracle.com/cve/CVE-2025-39945.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39945-cnic-fix-use-after-free-bugs-in-cnic-delete-task.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39980
- Description:
nexthop: Forbid FDB status change while nexthop is in a group
- CVE: https://linux.oracle.com/cve/CVE-2025-39980.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39980-nexthop-forbid-fdb-status-change-while-nexthop-is-in-a-group.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40011
- Description:
drm/gma500: Fix null dereference in hdmi teardown
- CVE: https://linux.oracle.com/cve/CVE-2025-40011.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40011-drm-gma500-fix-null-dereference-in-hdmi-teardown.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39998
- Description:
scsi: target: target_core_configfs: Add length check to avoid buffer overflow
- CVE: https://linux.oracle.com/cve/CVE-2025-39998.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39998-scsi-target-target-core-configfs-add-length-check-to-avoid-buffer-overflow.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40081
- Description:
perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
- CVE: https://linux.oracle.com/cve/CVE-2025-40081.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40081-perf-arm-spe-prevent-overflow-in-perf-idx2off.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40154
- Description:
ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
- CVE: https://linux.oracle.com/cve/CVE-2025-40154.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40154-asoc-intel-bytcr-rt5640-fix-invalid-quirk-input-mapping.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40140
- Description:
net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
- CVE: https://linux.oracle.com/cve/CVE-2025-40140.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40140-net-usb-remove-disruptive-netif-wake-queue-in-rtl8150-set-multicast.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40048
- Description:
uio_hv_generic: Let userspace take care of interrupt mask
- CVE: https://linux.oracle.com/cve/CVE-2025-40048.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40048-uio-hv-generic-let-userspace-take-care-of-interrupt-mask.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40153
- Description:
mm: hugetlb: avoid soft lockup when mprotect to large memory area
- CVE: https://linux.oracle.com/cve/CVE-2025-40153.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40153-mm-hugetlb-avoid-soft-lockup-when-mprotect-to-large-memory-area.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40030
- Description:
pinctrl: check the return value of pinmux_ops::get_function_name()
- CVE: https://linux.oracle.com/cve/CVE-2025-40030.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40030-pinctrl-check-the-return-value-of-pinmux-ops-get-function-name.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40111
- Description:
drm/vmwgfx: Fix Use-after-free in validation
- CVE: https://linux.oracle.com/cve/CVE-2025-40111.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40111-drm-vmwgfx-fix-use-after-free-in-validation.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40187
- Description:
net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
- CVE: https://linux.oracle.com/cve/CVE-2025-40187.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40187-net-sctp-fix-a-null-dereference-in-sctp-disposition-sctp-sf-do-5-1d-ce.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40186
- Description:
tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
- CVE: https://linux.oracle.com/cve/CVE-2025-40186.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40186-tcp-don-t-call-reqsk-fastopen-remove-in-tcp-conn-request.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40194
- Description:
cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
- CVE: https://linux.oracle.com/cve/CVE-2025-40194.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40194-cpufreq-intel-pstate-fix-object-lifecycle-issue-in-update-qos-request.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40204
- Description:
sctp: Fix MAC comparison to be constant-time
- CVE: https://linux.oracle.com/cve/CVE-2025-40204.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40204-sctp-fix-mac-comparison-to-be-constant-time.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40026
- Description:
KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
- CVE: https://linux.oracle.com/cve/CVE-2025-40026.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40026-kvm-x86-don-t-re-check-l1-intercepts-when-completing-userspace-i-o.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40197
- Description:
media: mc: Clear minor number before put device
- CVE: https://linux.oracle.com/cve/CVE-2025-40197.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40197-media-mc-clear-minor-number-before-put-device.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40134
- Description:
dm: fix NULL pointer dereference in __dm_suspend()
- CVE: https://linux.oracle.com/cve/CVE-2025-40134.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40134-dm-fix-null-pointer-dereference-in-dm-suspend.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40178
- Description:
pid: Add a judgment for ns null in pid_nr_ns
- CVE: https://linux.oracle.com/cve/CVE-2025-40178.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40178-pid-add-a-judgment-for-ns-null-in-pid-nr-ns.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39913
- Description:
tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
- CVE: https://linux.oracle.com/cve/CVE-2025-39913.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39913-tcp-bpf-call-sk-msg-free-when-tcp-bpf-send-verdict-fails-to-allocate-psock-cork.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40021
- Description:
tracing: dynevent: Add a missing lockdown check on dynevent
- CVE: https://linux.oracle.com/cve/CVE-2025-40021.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40021-tracing-dynevent-add-a-missing-lockdown-check-on-dynevent.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39996
- Description:
media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
- CVE: https://linux.oracle.com/cve/CVE-2025-39996.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39996-media-b2c2-fix-use-after-free-causing-by-irq-check-work-in-flexcop-pci-remove.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40109
- Description:
crypto: rng - Ensure set_ent is always present
- CVE: https://linux.oracle.com/cve/CVE-2025-40109.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40109-crypto-rng-ensure-set-ent-is-always-present.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40109
- Description:
crypto: rng - Ensure set_ent is always present (kpatch adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2025-40109.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40109-crypto-rng-ensure-set-ent-is-always-present-kpatch.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40125
- Description:
blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
- CVE: https://linux.oracle.com/cve/CVE-2025-40125.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40125-blk-mq-check-kobject-state-in-sysfs-before-deleting-in-blk-mq-unregister-hctx.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40078
- Description:
bpf: Explicitly check accesses to bpf_sock_addr
- CVE: https://linux.oracle.com/cve/CVE-2025-40078.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40078-bpf-explicitly-check-accesses-to-bpf-sock-addr.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40055
- Description:
ocfs2: fix double free in user_cluster_connect()
- CVE: https://linux.oracle.com/cve/CVE-2025-40055.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40055-ocfs2-fix-double-free-in-user-cluster-connect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40183
- Description:
bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
- CVE: https://linux.oracle.com/cve/CVE-2025-40183.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40183-bpf-fix-metadata-dst-leak-bpf-redirect-neigh-v-46.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40167
- Description:
ext4: detect invalid INLINE_DATA + EXTENTS flag combination
- CVE: https://linux.oracle.com/cve/CVE-2025-40167.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40167-ext4-detect-invalid-inline-data-extents-flag-combination.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-38678
- Description:
netfilter: nf_tables: reject duplicate device on updates
- CVE: https://linux.oracle.com/cve/CVE-2025-38678.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-38678-netfilter-nf-tables-reject-duplicate-device-on-updates.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40035
- Description:
Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
- CVE: https://linux.oracle.com/cve/CVE-2025-40035.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40035-input-uinput-zero-initialize-uinput-ff-upload-compat-to-avoid-info-leak.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40105
- Description:
vfs: Don't leak disconnected dentries on umount
- CVE: https://linux.oracle.com/cve/CVE-2025-40105.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40105-vfs-don-t-leak-disconnected-dentries-on-umount.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40094
- Description:
usb: gadget: f_acm: Refactor bind path to use __free()
- CVE: https://linux.oracle.com/cve/CVE-2025-40094.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40094-usb-gadget-f-acm-refactor-bind-path-to-use-free.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2024-43876
- Description:
PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()
- CVE: https://linux.oracle.com/cve/CVE-2024-43876.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2024-43876-pci-rcar-demote-warn-to-dev-warn-ratelimited-in-rcar-pcie-wakeup.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39880
- Description:
libceph: fix invalid accesses to ceph_connection_v1_info
- CVE: https://linux.oracle.com/cve/CVE-2025-39880.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39880-libceph-fix-invalid-accesses-to-ceph-connection-v1-info.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39911
- Description:
i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path
- CVE: https://linux.oracle.com/cve/CVE-2025-39911.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39911-i40e-fix-irq-freeing-in-i40e-vsi-request-irq-msix-error-path-5.15.0-314.193.5.5.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39883
- Description:
mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
- CVE: https://linux.oracle.com/cve/CVE-2025-39883.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39883-mm-memory-failure-fix-vm-bug-on-page-pagepoisoned-page-when-unpoison-memory.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39949
- Description:
qed: Don't collect too many protection override GRC elements
- CVE: https://linux.oracle.com/cve/CVE-2025-39949.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39949-qed-don-t-collect-too-many-protection-override-grc-elements.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39955
- Description:
tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().
- CVE: https://linux.oracle.com/cve/CVE-2025-39955.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39955-tcp-clear-tcp-sk-sk-fastopen-rsk-in-tcp-disconnect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-22058
- Description:
udp: Fix memory accounting leak.
- CVE: https://linux.oracle.com/cve/CVE-2025-22058.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-22058-udp-fix-memory-accounting-leak.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2024-43877
- Description:
Introduced and fixed in v5.15.0-315.196.3, no live patching needed.
- CVE:
- Patch: skipped/CVE-2024-43877.patch
- From:
- CVE-2025-40020
- Description:
can: peak_usb: fix shift-out-of-bounds issue
- CVE: https://linux.oracle.com/cve/CVE-2025-40020.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40020-can-peak-usb-fix-shift-out-of-bounds-issue.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39993
- Description:
media: rc: fix races with imon_disconnect()
- CVE: https://linux.oracle.com/cve/CVE-2025-39993.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39993-media-rc-fix-races-with-imon-disconnect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39994
- Description:
media: tuner: xc5000: Fix use-after-free in xc5000_release
- CVE: https://linux.oracle.com/cve/CVE-2025-39994.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39994-media-tuner-xc5000-fix-use-after-free-in-xc5000-release-5.15.0-314.193.5.5.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40118
- Description:
scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
- CVE: https://linux.oracle.com/cve/CVE-2025-40118.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40118-scsi-pm80xx-fix-array-index-out-of-of-bounds-on-rmmod.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40070
- Description:
pps: fix warning in pps_register_cdev when register device fail
- CVE: https://linux.oracle.com/cve/CVE-2025-40070.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40070-pps-fix-warning-in-pps-register-cdev-when-register-device-fail.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40121
- Description:
ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
- CVE: https://linux.oracle.com/cve/CVE-2025-40121.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40121-asoc-intel-bytcr-rt5651-fix-invalid-quirk-input-mapping.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40053
- Description:
net: dlink: handle copy_thresh allocation failure
- CVE: https://linux.oracle.com/cve/CVE-2025-40053.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40053-net-dlink-handle-copy-thresh-allocation-failure.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40044
- Description:
fs: udf: fix OOB read in lengthAllocDescs handling
- CVE: https://linux.oracle.com/cve/CVE-2025-40044.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40044-fs-udf-fix-oob-read-in-lengthallocdescs-handling.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40179
- Description:
ext4: verify orphan file size is not too big
- CVE: https://linux.oracle.com/cve/CVE-2025-40179.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40179-ext4-verify-orphan-file-size-is-not-too-big-5.15.0-313.189.5.3.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40179
- Description:
ext4: verify orphan file size is not too big (kpatch adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2025-40179.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40179-ext4-verify-orphan-file-size-is-not-too-big-5.15.0-313.189.5.3.el9uek-kpatch.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40190
- Description:
ext4: guard against EA inode refcount underflow in xattr update
- CVE: https://linux.oracle.com/cve/CVE-2025-40190.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40190-ext4-guard-against-ea-inode-refcount-underflow-in-xattr-update.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40271
- Description:
fs/proc: fix uaf in proc_readdir_de()
- CVE: https://linux.oracle.com/cve/CVE-2025-40271.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40271-fs-proc-fix-uaf-in-proc-readdir-de.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-40280
- Description:
tipc: Fix use-after-free in tipc_mon_reinit_self().
- CVE: https://linux.oracle.com/cve/CVE-2025-40280.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40280-tipc-fix-use-after-free-in-tipc-mon-reinit-self.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-40250
- Description:
net/mlx5: Clean up only new IRQ glue on request_irq() failure
- CVE: https://linux.oracle.com/cve/CVE-2025-40250.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40250-net-mlx5-clean-up-only-new-irq-glue-on-request-irq-failure.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-40258
- Description:
mptcp: fix race condition in mptcp_schedule_work()
- CVE: https://linux.oracle.com/cve/CVE-2025-40258.html
- Patch: oel9-uek7/5.15.0-316.196.4.2.el9uek/CVE-2025-40258-mptcp-fix-race-condition-in-mptcp-schedule-work.patch
- From: 5.15.0-316.196.4.2.el9uek
- CVE-2025-40319
- Description:
bpf: Sync pending IRQ work before freeing ring buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40319.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40319-bpf-sync-pending-irq-work-before-freeing-ring-buffer.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68192
- Description:
net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
- CVE: https://linux.oracle.com/cve/CVE-2025-68192.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68192-net-usb-qmi-wwan-initialize-mac-header-offset-in-qmimux-rx-fixup.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68244
- Description:
drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD
- CVE: https://linux.oracle.com/cve/CVE-2025-68244.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68244-drm-i915-avoid-lock-inversion-when-pinning-to-ggtt-on-chv-bxt-vtd.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40283
- Description:
Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
- CVE: https://linux.oracle.com/cve/CVE-2025-40283.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40283-bluetooth-btusb-reorder-cleanup-in-btusb-disconnect-to-avoid-uaf.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40281
- Description:
sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
- CVE: https://linux.oracle.com/cve/CVE-2025-40281.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40281-sctp-prevent-possible-shift-out-of-bounds-in-sctp-transport-update-rto.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40275
- Description:
ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
- CVE: https://linux.oracle.com/cve/CVE-2025-40275.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40275-alsa-usb-audio-fix-null-pointer-dereference-in-snd-usb-mixer-controls-badd.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40040
- Description:
mm/ksm: fix flag-dropping behavior in ksm_madvise
- CVE: https://linux.oracle.com/cve/CVE-2025-40040.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40040-mm-ksm-fix-flag-dropping-behavior-in-ksm-madvise.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68241
- Description:
ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
- CVE: https://linux.oracle.com/cve/CVE-2025-68241.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68241-ipv4-route-prevent-rt-bind-exception-from-rebinding-stale-fnhe.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40264
- Description:
be2net: pass wrb_params in case of OS2BMC
- CVE: https://linux.oracle.com/cve/CVE-2025-40264.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40264-be2net-pass-wrb-params-in-case-of-os2bmc.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40259
- Description:
scsi: sg: Do not sleep in atomic context
- CVE: https://linux.oracle.com/cve/CVE-2025-40259.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40259-scsi-sg-do-not-sleep-in-atomic-context.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40324
- Description:
NFSD: Fix crash in nfsd4_read_release()
- CVE: https://linux.oracle.com/cve/CVE-2025-40324.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40324-nfsd-fix-crash-in-nfsd4-read-release.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40211
- Description:
ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
- CVE: https://linux.oracle.com/cve/CVE-2025-40211.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40211-acpi-video-fix-use-after-free-in-acpi-video-switch-brightness.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40342
- Description:
nvme-fc: use lock accessing port_state and rport state
- CVE: https://linux.oracle.com/cve/CVE-2025-40342.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40342-nvme-fc-use-lock-accessing-port-state-and-rport-state.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40363
- Description:
net: ipv6: fix field-spanning memcpy warning in AH output
- CVE: https://linux.oracle.com/cve/CVE-2025-40363.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40363-net-ipv6-fix-field-spanning-memcpy-warning-in-ah-output.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68185
- Description:
nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
- CVE: https://linux.oracle.com/cve/CVE-2025-68185.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68185-nfs4-setup-readdir-insufficient-locking-for-d-parent-d-inode-dereferencing.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40309
- Description:
Bluetooth: SCO: Fix UAF on sco_conn_free
- CVE: https://linux.oracle.com/cve/CVE-2025-40309.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40309-bluetooth-sco-fix-uaf-on-sco-conn-free.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40308
- Description:
Bluetooth: bcsp: receive data only if registered
- CVE: https://linux.oracle.com/cve/CVE-2025-40308.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40308-bluetooth-bcsp-receive-data-only-if-registered.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40261
- Description:
nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
- CVE: https://linux.oracle.com/cve/CVE-2025-40261.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40261-nvme-nvme-fc-ensure-ioerr-work-is-cancelled-in-nvme-fc-delete-ctrl.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68284
- Description:
libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
- CVE: https://linux.oracle.com/cve/CVE-2025-68284.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68284-libceph-prevent-potential-out-of-bounds-writes-in-handle-auth-session-key.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40034
- Description:
PCI/AER: Avoid NULL pointer dereference in aer_ratelimit()
- CVE: https://linux.oracle.com/cve/CVE-2025-40034.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40034-pci-aer-avoid-null-pointer-dereference-in-aer-ratelimit.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40322
- Description:
fbdev: bitblit: bound-check glyph index in bit_putcs*
- CVE: https://linux.oracle.com/cve/CVE-2025-40322.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40322-fbdev-bitblit-bound-check-glyph-index-in-bit-putcs.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40304
- Description:
fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-40304.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40304-fbdev-add-bounds-checking-in-bit-putcs-to-fix-vmalloc-out-of-bounds.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40277
- Description:
drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
- CVE: https://linux.oracle.com/cve/CVE-2025-40277.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40277-drm-vmwgfx-validate-command-header-size-against-svga-cmd-max-datasize.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40269
- Description:
ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40269.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40269-alsa-usb-audio-fix-potential-overflow-of-pcm-transfer-buffer.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40269
- Description:
ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40269.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40269-ALSA-usb-audio-Fix-missing-unlock-at-error-path-of-maxpacksize-check.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40272
- Description:
mm/secretmem: fix use-after-free race in fault handler
- CVE: https://linux.oracle.com/cve/CVE-2025-40272.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40272-mm-secretmem-fix-use-after-free-race-in-fault-handler.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68301
- Description:
net: atlantic: fix fragment overflow handling in RX path
- CVE: https://linux.oracle.com/cve/CVE-2025-68301.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68301-net-atlantic-fix-fragment-overflow-handling-in-rx-path.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40345
- Description:
usb: storage: sddr55: Reject out-of-bound new_pba
- CVE: https://linux.oracle.com/cve/CVE-2025-40345.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40345-usb-storage-sddr55-reject-out-of-bound-new-pba.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68287
- Description:
usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
- CVE: https://linux.oracle.com/cve/CVE-2025-68287.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68287-usb-dwc3-fix-race-condition-between-concurrent-dwc3-remove-requests-call-paths.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68285
- Description:
libceph: fix potential use-after-free in have_mon_and_osd_map()
- CVE: https://linux.oracle.com/cve/CVE-2025-68285.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68285
- Description:
libceph: fix potential use-after-free in have_mon_and_osd_map()
- CVE: https://linux.oracle.com/cve/CVE-2025-68285.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map-kpatch.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-38239
- Description:
scsi: megaraid_sas: Fix invalid node index
- CVE: https://linux.oracle.com/cve/CVE-2025-38239.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-38239-scsi-megaraid-sas-fix-invalid-node-index.patch
- From: 5.15.0-317.197.5.1.el9uek